OT cyber threats are moving into the control loop, and manufacturers are in the blast radius

Dragos’ 2026 Year in Review OT/ICS Cybersecurity Report finds adversaries shifting from simple intrusion to deeper targeting of the industrial control loop.

OT cyber threats insights

  • Threat actors are moving beyond simple network access and are actively mapping and learning industrial control loops to enable potential disruptive operations.
  • Many ransomware and cyber incidents in manufacturing are misclassified as IT events, even when they directly impact operational technology and production systems.
  • Most industrial organizations still lack sufficient OT network visibility to determine root cause during incidents, leaving them unable to confidently detect, investigate, or prove cyber involvement.

Industrial cybersecurity leaders have warned for years that attackers weren’t just “breaking in,” they were learning how to operate the plant. Dragos’ 2026 OT/ICS Cybersecurity Report: A Year in Review and a recent media briefing led by Dragos CEO Rob M. Lee suggest that shift is no longer theoretical. The pattern Dragos highlights across 2025 is that multiple threat teams are moving beyond opportunistic access and deeper into the control loop. This means they have access to the systems and workflows that translate digital commands into physical outcomes.

For manufacturers, that evolution matters because the plant floor is increasingly where the business feels pain fastest: production interruptions, quality losses, recovery delays, and often uncertainty about what actually happened.

As Lee put it, “a large number of [threat groups] are getting into the control loop itself.”

From access to operational understanding

Historically, many advanced threat groups targeting industrial organizations focused on getting into networks and maintaining a foothold for potential future use. According to Lee, that is changing.

“In the world of operations technology,” he said, “the entire point is what we call the control loop — the ability to enact change in the physical world.”

That includes opening breakers, changing setpoints, modifying ladder logic or altering controller configurations. According to Dragos’ 2026 Year in Review, sustained reconnaissance activity in 2025 targeted industrial components “in a sequence that suggests intent to understand entire control loops, not isolated devices.”

Lee described this shift as more than incremental: “What we’re seeing a number of groups now do is instead of just prepositioning, they’re getting in place and mapping out and learning those control loops, indicating that there is more willingness to take that next step and use that access for disruptive purposes.”

For manufacturers, this evolution matters. An attacker who understands how your production line works does not need exotic malware to cause disruption. Native functionality can be enough.

“If an operator and engineer can cause change in the physical world through operations,” Lee said, “then so can an adversary.”

The front door isn’t IT anymore

Another major takeaway from both the report and briefing is that attackers are increasingly targeting operational environments directly. Historically, many organizations assumed that protecting enterprise information technology (IT) networks would indirectly protect operational technology (OT). But in today’s connected plants, that assumption is often false.

Lee explained that many industrial environments now have direct connectivity — VPNs, remote access gateways and jump hosts — exposed to the internet.

“Historically speaking, a lot of security teams felt, if I protect my enterprise IT environment, I will protect my OT environment,” he said. “But with the connectivity and rapid change of our operations environments … a lot of our operations environments are directly connected out to VPN infrastructure … irrespective of your IT networks.

“It’s not really just the back door into the average network. It’s really just the front door is now widely available.”

Dragos’ report reinforces this. VPN and jump host compromise, either through active exploitation or credential reuse, continues to appear prominently in incident response cases. For manufacturing operations, this makes remote access governance and monitoring a production reliability issue, not just an IT security concern.

Ransomware is not “just IT”

Ransomware remains a dominant threat to industrial organizations. In 2025, Dragos tracked 119 ransomware groups impacting more than 3,300 industrial organizations. But Lee argues that the industry often misclassifies these events.

“There’s a disservice being done in the broader community,” he said. “You’ll get a ransomware case in a manufacturing network at the plant floor, impacting operations directly … and a security firm … looks at the environment and goes, ‘Oh, look, a Windows system got hit. It’s an IT incident.’”

However, many of those Windows systems host supervisory control and data acquisition (SCADA) software, human-machine interface (HMI) applications or engineering tools central to operations.

“It is an operations incident,” Lee emphasized, “not just impacting operations.”

If an engineering workstation or SCADA server is encrypted, production stops. Labeling the disruption “just IT” obscures where risk truly resides and can lead to the wrong defensive investments.

The root-cause problem of cyber intrusions

Perhaps the most sobering insight from the 2026 report is how often organizations cannot determine what actually happened during an incident. In 2025, 30% of Dragos’ incident response cases began with unexplained operational issues treated as potentially cyber-related. Many lacked the data necessary to confirm or rule out cyber involvement.

Lee described the structural challenge this way: “In the world of OT, we deal with systems, systems and physics. … It’s not the logs on a controller that matter. It is somebody got on the engineering workstation, changed the logic and had a manifestation of a physical event.”

The critical data is often network telemetry, or transient command traffic that disappears if not recorded.

“If you didn’t collect it when it was sent,” he said, “it’s gone.”

That leads to uncomfortable outcomes: outages, equipment damage or anomalous behavior where organizations simply cannot determine root cause. Dragos found that 82% of organizations lacked criteria for when operational anomalies should trigger a cyber investigation.

“We still have this huge prevention bias about keep adversaries outside the house,” Lee said. “In a connected world, the idea that you can keep people outside the house is gone.”

The industry, he argues, must balance prevention with detection and response inside OT networks.

OT cyber threats and reality

The 2026 report also highlights structural challenges in industrial vulnerability management. Some of the more sobering stats were:

  • Median time from disclosure to public weaponized exploit: 24 days.
  • 4% of ICS vulnerabilities actively exploited at disclosure.
  • 26% of advisories offered no patch.
  • 25% contained incorrect CVSS scores.

Industrial environments often operate on 20- or 30-year equipment lifecycles. Lee cautioned against simplistic “patch everything” narratives. Instead, organizations must prioritize vulnerabilities based on operational context and real exploitability, not just severity scores.

“You could spend all your money and all your resources chasing vulnerabilities and wouldn’t move the needle as much as you’re thinking,” he said.

Cyber risks manufacturers should focus on

Dragos recommends several behaviors for manufacturing and industrial automation leaders that can help protect OT systems from disruption.

  • Treat remote access as a production-critical system.
  • Enforce strong authentication, and inventory all external connections.
  • Deploy OT-aware network monitoring to capture control loop activity.
  • Define in advance when operational anomalies should trigger cyber investigation.
  • Frame ransomware and cyber events in operational terms.

The broader message from Dragos’ 2026 Year in Review is not that industrial cybersecurity is failing across the board. Many leading asset owners are investing and improving. But as Lee warned, the transformation of industrial environments — more connectivity, more digitalization, more automation — must be matched with an equally serious investment in visibility and response.

“In a connected world,” he said, “the inability to understand root cause analysis of what’s actually happening inside these operations networks is really, really core.”

LEARNING OBJECTIVES

  • Understand how modern threat actors are shifting from basic network intrusion to mapping and potentially manipulating industrial control loops.
  • Recognize why ransomware and other cyber incidents in manufacturing are often misclassified as IT issues despite directly impacting OT and production systems.
  • Identify the critical importance of OT network visibility and root-cause analysis capabilities in strengthening industrial cybersecurity resilience.

CONSIDER THIS

Can my organization clearly see and prove what is happening inside our control network if an adversary gains access to our plant systems?