Palo Alto Networks’ 2026 State of Critical Infrastructure Cybersecurity report found that 60% of critical infrastructure organizations experienced a significant security breach in the past year, with half of those organizations reporting physical safety concerns as a result. The report also highlighted growing concern over the impact of artificial intelligence on critical infrastructure security, with 95% of security leaders expressing concern about frontier AI-powered attacks.
Based on a survey of more than 1,600 critical infrastructure security leaders across 11 countries and five sectors, the ‘2026 State of Critical Infrastructure Cybersecurity Report’ found that 68% of organizations lack complete, real-time visibility into all assets connected to their OT (operational technology) networks. Legacy OT systems were identified as a major contributor to the visibility gap, while 42% of respondents named legacy, unpatchable OT assets as their single biggest cybersecurity risk.
Research disclosed that the speed of vulnerability exploitation is widening the gap between attackers and defenders, noting that 29% of CVEs in 2026 were exploited within 24 hours, compared with an industry average of 55 days to deploy a patch. At the same time, 74% of organizations have not fully integrated IT and OT security operations, while organizations use an average of seven disparate security systems and tools to monitor and identify risk.
Palo Alto revealed a cybersecurity readiness gap that is growing from both sides. Organizations are already struggling with visibility, legacy systems, and fragmented defenses, while a new class of AI-powered attackers can find and exploit weaknesses at machine speed.
Incomplete visibility remains a fundamental challenge in operational technology (OT) environments. This comes as 68% of organizations do not have complete, real-time visibility of all assets connected to their OT networks, and more than half of this challenge was attributed to legacy OT systems. Security tool sprawl adds to the problem, as organizations use an average of seven disparate security systems and tools to monitor and identify risk, and most say that sprawl adds complexity and cost. When a tool detects a threat but cannot act on it, the alert waits for a person. Against attacks that move at machine speed, that handoff is the exposure.
IT and OT security operations also remain largely separate in many organizations. Although teams are moving toward closer collaboration, 74% have not yet fully integrated IT and OT security operations across their organization. Technology incompatibility and differing priorities remain leading barriers, leaving gaps between where threats are detected and where action needs to happen.
At the center of these challenges are unpatchable assets, with 42% of respondents naming legacy, unpatchable OT assets as their single biggest cybersecurity risk. Unpatchability is not a failure of the people running these systems but the natural result of equipment designed for safety and uptime above all else. It does mean, however, that the assets leaders worry about most are the ones patching cannot protect.
According to the Palo Alto survey, 59% of organizations were affected by a significant security breach in the last twelve months, and one in five of them were affected multiple times. Of these businesses, 96% experienced significant impacts. Half of organizations (50%) cited safety concerns as an impact, followed by unplanned downtime (49%), production disruption (46%), and financial losses (46%). Supply chain disruption and reputational damage were each cited by 39%, and delayed regulatory reporting by 30%. Only 4% said they had not observed significant impact from security incidents.
Threat intelligence integrated into security monitoring and response is the most common OT security capability in place, at 55%. Operational risk prioritization based on asset criticality and threat exposure, and policy enforcement and access controls, were each reported by 53% of organizations. Automated threat detection and response was reported by 52%, continuous monitoring of private 5G/LTE traffic by 43%, virtual patching or compensating controls by 40%, and comprehensive asset visibility by 37%. Only 17% of organizations have implemented more than four of these capabilities. Alert prioritization is considered either ‘important’ or ‘critical’ by 92% of respondents, yet 51% still rely on CVSS scoring or manual review of alerts.
The report identified that organizations rely on an average of seven disparate security systems and tools. Of respondents, 59% cited operational complexity with multiple management systems and 56% cited higher operational costs as consequences. In addition, 46% reported gaps in cybersecurity coverage, 41% reported delayed incident response, and 34% reported siloed alert prioritization. The findings also note that efforts to address visibility gaps can themselves create additional complexity.
When asked about their biggest security gaps in 5G environments, respondents most often chose data protection (52%), followed by third-party access (43%) and application security (40%). Access management was cited by 38%, network segmentation by 33%, device identity by 31%, and asset visibility by 29%. Overall, 84% of organizations expect 5G to be ‘widely’ or ‘extensively’ adopted within the next two to three years, which means its role in OT networks is set to grow significantly.
Common consequence of incomplete visibility is security blind spots (54%), followed by operational inefficiencies (48%). Slower incident response and difficulty assessing risk were each cited by 46%. Compliance challenges were reported by 39%, increased downtime by 37%, and increased staffing burden by 36%. In addition, 42% of organizations identify legacy, unpatchable OT assets as their biggest cybersecurity risk.
It mentioned that legacy OT systems are the biggest visibility challenge, cited by 52% of respondents, followed by the lack of a centralized visibility tool at 37%. IoT devices and unmanaged devices were each cited by 33%, private 5G-connected devices by 31%, temporary maintenance devices by 30%, and shadow IT by 28%. Notably, 49% of those with full asset visibility still find legacy OT to be a challenge, which shows that visibility alone does not remove the operational burden of aging infrastructure.
Palo Alto reported that AI is rapidly changing both sides of the critical infrastructure security equation. While many organizations are beginning to harness AI to improve operations and automate security processes, AI-powered adversaries are increasing the speed and sophistication of the threat landscape and intensifying the pressure on defensive capabilities.
Almost all organizations (95%) are concerned about Frontier AI-powered attacks targeting critical infrastructure, and 91% expect AI-driven cybersecurity to play an important role in defending against them. Concern is highest at the upper-middle of the scale: 35% of respondents said they are very concerned and 15% extremely concerned, while 29% are moderately concerned, 16% slightly concerned and only 5% not concerned at all.
Expectations for AI-based defenses are similarly strong, with 44% holding high expectations of fighting AI with AI and 47% holding medium expectations that AI will play a role. Only 8% have low expectations and 1% have none. Despite these expectations, organizations’ current cybersecurity capabilities are lagging behind the growing level of AI risk, hampered by technical constraints of legacy infrastructure and persistent operational barriers.
Almost all organizations report using AI in some capacity, but few have deployed it at scale, with only 19% using it across four or more operational areas. Security monitoring (66%) and process optimization (64%) are the most common applications, followed by quality assurance (55%), predictive maintenance (52%) and energy efficiency (47%). Just 1% said they are not using AI.
This comes as nearly half of organizations (47%) have deployed AI across three areas, while 26% have done so across two areas and 8% across one area or none. The findings indicate that many organizations are still experimenting with individual AI applications rather than embedding the technology across their operations.
Automation is also set to shift toward troubleshooting and remediation. Today, improving routine functions such as machine maintenance is the most common application, used by 47% of organizations, followed closely by automated troubleshooting at 46%. Human-to-machine chatbots and voice assistance and autonomous remediation of alerts are each used by 35%, while compliance reporting is used by 32%.
Looking ahead in the next one to two years, automated troubleshooting tops the list at 60%, meaning three in five organizations expect to have invested in it, followed by autonomous remediation of alerts at 56% and improving routine functions at 50%. Compliance reporting is expected to reach 41% and chatbots and voice assistance 36%, reflecting a growing focus on automation and AI-driven OT network security.
The Palo Alto report also assessed that closer IT and OT security collaboration is now more important than ever, but integration remains low, hindered by both organizational and technical barriers. Breaking down these silos and creating shared visibility, intelligence and workflows is becoming critical to reducing complexity and building more coordinated cyber defense.
As IT and OT environments become increasingly interconnected, closer coordination between their security operations is becoming more important, yet alignment remains a work in progress for most organizations. Overall, 74% of organizations do not have fully integrated IT and OT security operations. Only 26% report that their IT and OT security operations are fully integrated, while 51% are partially integrated, 19% are somewhat separate and 4% are fully separate. The findings stress that bringing the two together is a critical first step, but that its value depends on what organizations can do with the combined view. Without comprehensive visibility across OT environments, security teams can still have blind spots that leave critical infrastructure exposed.
Among organizations that have not fully integrated IT and OT security operations, technology incompatibility and differing priorities between IT and OT teams rank equally as the two leading barriers, each cited by 44% of respondents. Organizational silos were cited by 37% and skills gaps by 36%, followed by reliance on manual processes at 34% and budget ownership at 32%. Lack of executive support was the least commonly cited barrier, at 24%. The findings conclude that overcoming these barriers will require more than compatible technology, and that aligning priorities, processes and people across IT and OT can help create the shared understanding needed for faster, more coordinated security operations.
Automated alert correlation and prioritization between IT and OT environments tops organizations’ efforts to improve IT/OT convergence, with 52% citing it as their key priority. Unified visibility and response across IT and OT environments follows at 45%, while a unified SOC platform with consistent workflows across IT and OT and automated compliance reporting aligned to OT standards, such as IEC and NIST, were each cited by 44%.
Shared performance dashboards across IT and OT teams were cited by 41%, and OT-specific threat intelligence and response by 32%. Together, these findings show that organizations see technologies that facilitate shared understanding as important enablers of closer IT/OT collaboration, particularly where they can reduce manual processes and give teams a more consistent view of risk.
The report recognized that organizations know that OT cybersecurity is exposed and where gaps are increasing risk, but many continue to face barriers that slow progress toward improved resilience. Limited visibility, operational complexity, evolving AI-powered threats and fragmented IT/OT operations mean that disconnect between strategic intent and operational readiness persists.
Visibility is the foundation of every effective OT security strategy, and without it, every other security investment is built on guesswork. Complete, real-time visibility across connected assets enables organizations to identify unmanaged devices and vulnerabilities, better understand where cyber risk is concentrated and prioritize action. This helps reduce security blind spots and accelerate incident response.
Adding more security tools does not automatically lead to better security outcomes. Greater consolidation, automation and alert prioritization can reduce operational complexity and cost while enabling faster threat response and remediation. AI is reshaping threat landscape and cyber defense. As AI-powered attacks become increasingly sophisticated, AI-driven cybersecurity capabilities are becoming more important for improving monitoring, detection, prioritization and response.
Critical infrastructure cybersecurity increasingly depends on effective collaboration between IT and OT teams, and integration of their security operations remains a work in progress. Shared visibility, coordinated security operations and common workflows can help organizations respond more effectively and strengthen overall resilience.


