New research from cyber-physical systems (CPS) protection vendor Claroty found that 58% of CPS operators said they experienced a cyberattack that affected operational environments in the past 12 months. The global survey of 2,000 business and technology leaders across 16 industries and more than 40 countries found that operational downtime was the most commonly reported impact, cited by 43% of respondents, followed by safety incidents and hazards at 40% and financial loss at 35%. The average financial loss from an incident affecting operations was $1.04 million, rising to $1.6 million among organizations with at least 5,000 employees and $2.25 million among those with at least 10,000 employees.
In its research report titled ‘The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability,’ Claroty identified that CPS-related cyber incidents caused an average of three days of operational downtime, with nearly 10% of respondents reporting disruptions lasting eight to 30 days. Third-party access was another significant source of operational risk, with 75% of respondents saying they had experienced at least one operations-impacting incident linked to third-party access, while 49% reported only partial or no monitoring of third-party connections.
At the same time, IT and operational security remained fragmented, with only 16% saying the two had been fully integrated. Operational risk and cyber threats were identified as the leading driver of cybersecurity investment by 37% of respondents, ahead of digital transformation and modernization at 36% and business disruption or revenue loss at 29%.
“Businesses have quickly realized that prioritizing operational resilience is key to ensuring robust protection across the world’s most critical infrastructure,” Sean Tufts, field CTO at Claroty, said in a Tuesday media statement. “Critical infrastructure organizations are experiencing a seismic shift in the threat landscape, given the proliferation of AI threats and the current geopolitical landscape. This is driving them to re-position from a standard asset-centric mindset to one centered on operational resilience that combines proactive risk reduction with robust recovery capabilities that protect core processes without halting operations.”
The researchers said that security teams have faced a dizzying pace of change in the first nine months of 2026. Most prominent is the arrival of frontier AI models such as Anthropic’s Claude Mythos and OpenAI’s GPT-5.6-Cyber, which have redefined vulnerability discovery and exploitation and sharply narrowed the window between disclosure and the availability of proof-of-concept exploits. Business and technology leaders are under pressure to build triage and remediation strategies that can handle an already crushing wave of disclosures while preserving business continuity.
Frontier models are only one facet of the adversarial landscape. Fighting in the Middle East and Ukraine continues to drive cyberattacks by Iran and Russia against Western critical infrastructure. Iran has been especially active against U.S. industries, including the Stryker healthcare supply chain attacks and a string of incidents affecting water and wastewater facilities. In these sectors, CPS and OT are the linchpins of patient safety, clean water, and other critical services.
Attackers are also turning operational assets against enterprises worldwide. Earlier this year, Claroty’s Team82 showed how insecure, internet-facing assets can give attackers an initial foothold inside companies or let them disrupt industrial processes. The survey results confirm this trend and underscore the need for ongoing risk reduction. Fifty-eight percent of respondents, or roughly three in five, said a cyberattack had affected their operations in the past 12 months, threatening business health, compliance efforts, and insurability. Among those compromised, 94% reported a financial impact, with the average cost approaching $1.1 million.
Organizations report mixed experiences with AI in operational environments. On the positive side, 48% said AI has improved operational efficiency and productivity, 46% said it has improved decision-making through automation and analytics, and 37% said it has enabled new business models, products, or services. On the negative or neutral side, 40% said AI has introduced new cybersecurity, compliance, or operational risks, and 33% said its implementation has created operational challenges, disruption, or change management issues. Only 6% said AI has had little or no impact on their organization to date.
“AI, meanwhile, represents the next technology revolution. The effective use of AI, automation, and advanced analytics was highlighted in the success of digital transformation initiatives by 30% of respondents,” Claroty reported. “Technology and business leaders recognize AI is growing as a business priority, and operational environments are one area that may soon greatly benefit from AI’s ability to carry out predictive analytics and maintenance and optimize production processes.”
AI is changing operations at an unprecedented pace, and organizations are adopting it for everything from offloading manual tasks to enhancing existing automation and making complex autonomous decisions at machine speed. That speed carries significant risk if AI is improperly implemented, managed, or controlled. For CIOs, COOs, and security teams, AI is at once a vital technology, an operational and security control, and an attack vector. Defensively, AI agents correlate threat intelligence and alert data to inform remediation and mitigation decisions. They can also contextualize asset information to establish baseline behaviors, detect anomalies, and recommend compensating controls or mitigation advice. AI is an offensive capability as well.
The OpenAI-Hugging Face incident shows what can happen without guardrails and humans in the loop. OpenAI’s new frontier agent escaped a sandboxed test environment while searching for the answer to a benchmark test, chaining together zero-day vulnerabilities and stolen credentials to find an internet connection and breach a Hugging Face database. Since the incident came to light in July, its scope has widened and questions about the security of AI agents have surfaced. Going forward, AI is a strategic issue for CIOs and COOs, who must weigh adoption against risk. Survey respondents reported mixed results: most cited positive impacts, but acknowledged new risks.
Claroty observed that cyber threats, threat intelligence, or operational risk is the biggest driver of cybersecurity investment in respondents’ CPS environments, cited by 37%, followed closely by technology modernization and digital transformation at 36%. Risk of business disruption or revenue loss follows at 29%, while regulatory compliance requirements and operational resilience or uptime requirements were each cited by 26%. Customer, partner, and market expectations (22%) and supply chain risk or supplier agreements (21%) rank next. Past cyber incidents and board or executive mandates were each named by 20%, and insurance requirements or financial pressure ranked last at 15%.
Strong operational security and risk management was the factor most often cited as important to digital transformation success, at 33%, followed by skilled workforce training at 31%. Effective use of AI, automation, and advanced analytics and high-quality data and data governance were each named by 30%, while modernization and integration of legacy IT/OT systems drew 29%. Respondents also cited a clear digital transformation strategy and roadmap (26%), adequate budget and investment (25%), effective change management and cross-team collaboration (24%), and support from technology partners and vendors (23%). Executive leadership support ranked lowest at 20%.
The report mentioned that IT-related disruptions affecting operations (37%) and AI-powered cyberattacks (35%) led the list of concerns, with respondents able to select up to three responses. Ransomware and insecure or unmonitored third-party access were each cited by 27%, followed by insecure third-party vendor access (26%), supply chain compromise (23%), and vulnerable legacy OT systems (21%). Smaller shares named insider threats (19%), shadow OT/CPS assets (16%), unpatched CPS assets (16%), and nation-state attacks (14%), while just 2% reported no significant threats.
Of the 53% of respondents who identified third-party access as a risk, three in four said they had experienced at least one CPS-related cybersecurity incident that stemmed from a third party and affected operations. Overall, organizations reported an average of three incidents from third-party access.
For many organizations, cybersecurity programs are largely regulatory compliance programs. Despite warnings to the contrary, many treat industry regulations and frameworks from bodies such as NIST and NERC as the goal of their security programs rather than as a minimum standard. For CIOs and COOs who are increasingly tasked with operational protection, that may soon flip, with operational resilience becoming the program’s North Star. Though decidedly less mature, operational resilience ensures that critical operational assets can withstand ongoing cyberattacks and continue to support key business goals even after a compromise.
Achieving it falls to CIOs and operations teams, who must maintain visibility into systems and assets to limit exposures, implement controls such as virtual network segmentation to confine the blast radius of attacks to as few critical systems as possible, and be able to restore expected process availability and functions after a disruptive or damaging event.
Meanwhile, 75% of survey respondents said they have a proactive and structured approach to compliance management. However, they also face operational barriers, such as IT/OT alignment and legacy technical debt, that threaten compliance efforts and cyber insurance readiness.
Cyber insurance underwriters apply extensive rigor to determine insurability, and operational resilience is one of their guiding principles, assessed through a checklist of controls and processes that must be in place to secure coverage. Even if three-quarters of respondents have compliance in hand, significant challenges remain as the regulatory and threat landscapes evolve quickly and transformative technologies such as AI take hold in operational environments.
Claroty’s survey found that cybersecurity is in the midst of a fundamental shift, with the protection of operational environments increasingly becoming a core business capability. CIOs, COOs, and CISOs are re-orienting the protection of their mission-critical infrastructure assets toward measurable operational resilience. Operational security must operate on the assumption that compromise is inevitable, and assets must be protected, segmented, and governed so they can withstand and rapidly recover from a disruptive incident. As leaders enter their 2027 budget planning cycles, the survey results point to four recommendations.
First, organizations should bridge the IT/OT governance divide by establishing a unified IT and operational governance model co-owned by the CIO, COO, and CISO. While CIOs hold primary accountability for operational protection (39%), budget control and oversight remain fragmented across IT, security, and operations. Joint governance aligns operational uptime with enterprise security priorities and eliminates structural friction.
Second, organizations should mandate strict third-party access controls and monitoring by enforcing access controls, session recording, and continuous monitoring for all external vendors. Third-party access is a major vulnerability, driving an average of three operational cyber incidents per enterprise. Because 49% of organizations maintain only partial or no monitoring of external connections, securing vendor access provides immediate exposure reduction and satisfies critical cyber insurance underwriting requirements.
Third, organizations should modernize their business continuity plans for operations by transitioning business continuity and disaster recovery frameworks from traditional IT failover to operational restoration. While 70% of organizations include operations in their recovery plans, cyber incidents still cause an average of three days of downtime and more than $1 million in financial losses. Regular cyberattack drills, offline operational recovery, manual overrides, and segmented failsafes are vital to preserving revenue and avoiding safety hazards.
Fourth, organizations should secure AI adoption to accelerate digital transformation by establishing proactive AI risk frameworks that safely scale modern operational capabilities. AI adoption is accelerating, with 70% of organizations leveraging AI in operational environments and 35% identifying AI-powered attacks as a top threat to operational integrity. Integrating robust guardrails and security baselines allows leadership to capture the efficiency of digital transformation without increasing exposure.
In July, Claroty’s Team82 analyzed more than 750,000 CPS assets across major data centers and found that while only 0.4% of infrastructure devices are directly internet-facing, 18.42% sit one hop from an exposed system, including 41% of power distribution units and 33% of HVAC systems. Insecure protocols add to the risk, with 88% of building management systems and 83% of OT devices relying on them. Team82 ties the exposure to growing IT/OT convergence and urges zero-trust segmentation, continuous exposure management, and protocol-aware threat detection.


