IndustrialCyber

Rockwell finds 46% of industrial organizations faced cyber incidents as AI adoption, IT/OT convergence reshape resilience


Rockwell Automation disclosed that 46% of industrial organizations experienced a cyber incident in the past year, while 90% said they were confident in their ability to contain a cyber incident. The research also found that 34% of organizations identified cybersecurity as one of the biggest external obstacles to growth over the next 12 months, second only to workforce shortages. At the same time, 62% said they had already invested in cybersecurity platforms such as asset inventory, intrusion detection systems and secure remote access, while cybersecurity ranked as the second-leading return-on-investment driver among technology investments.

In new research titled ‘Operational Resilience in the Age of Connectivity,’ Rockwell highlighted a growing focus on operational resilience as industrial environments become more connected through IT/OT convergence, AI and expanding operational data flows. Rockwell found that IT/OT integration points rank among the most vulnerable areas to cyber incidents, while 45% of organizations plan to use AI and machine learning for cybersecurity over the next 12 months and 37% said securing IT/OT architecture will drive positive business outcomes over the next five years. 

The company said resilience requires more than individual security tools, emphasizing asset visibility, risk-based vulnerability management, secure architecture, continuous monitoring and tested incident response and recovery capabilities to reduce disruption and sustain operations.

Rockwell observed that AI adoption continues to rise. IT and OT environments continue to converge. Operational data moves across more assets, users, devices, and applications than ever before. Every connection creates another dependency. Every dependency creates another point of exposure. The good news is that organizations are rising to the challenge. They no longer treat cybersecurity as a separate IT initiative but are instead increasingly viewing it as part of operational performance. The companies leading the next phase of industrial operations will be those that build visibility, secure architecture and response capabilities that keep production moving during disruption.

Organizations are investing in technologies, architectures, and capabilities needed to strengthen cyber resilience, with 62% having already invested in cybersecurity platforms and 45% planning to use AI and machine learning for cybersecurity over the next 12 months. IT/OT integration points rank among the most vulnerable to cyber incidents, just behind IT systems and enterprise networks. Cybersecurity is also the second-leading return on investment (ROI) driver among technology investments, and respondents say it delivered among the highest ROI over the past 12 months.

Even so, 35% of industrial organizations identify cybersecurity as one of the biggest external obstacles to growth over the next 12 months, second only to workforce shortages. Meanwhile, 37% say securing IT/OT architecture will drive positive business outcomes over the next five years. Together, the findings point to a shift toward embedding cybersecurity in broader digital transformation strategies alongside AI, automation, cloud, and connected operations. As environments become more interconnected, resilience depends on how well organizations turn investment into coordinated action.

Rockwell identified that limited visibility is one of the most common barriers to resilience. Without a complete view of the environment, including legacy systems, serially connected devices, and temporary connections, organizations lack the starting point for meaningful risk reduction. Comprehensive asset visibility helps them prioritize cyber risk, reduce operational, safety, and cybersecurity blind spots, and make faster decisions by showing which assets are connected, exposed, and most critical to production and business operations. It also accelerates risk reduction by prioritizing remediation on operational impact rather than vulnerability severity alone. Continuous asset lifecycle management keeps the environment secure and supported over time, and the resulting foundation supports compensating controls and other components of end-to-end cybersecurity.

Organizations cannot eliminate all cyber risk, but they can improve their security posture by speeding up how they identify, prioritize, and respond to threats before operations are affected. As industrial operations become more connected, effective risk management depends on contextual visibility, risk-based decision-making, and operational continuity through disruption. A risk-based vulnerability management program helps organizations prioritize remediation by operational impact rather than severity scores alone, reduce mean time to remediation across OT assets, and demonstrate measurable compliance progress against IEC 62443, NIST CSF, and NIS2. It also enables informed investment decisions by aligning cybersecurity spending with business risk tolerance and operational objectives.

As IT and OT environments become increasingly interconnected, organizations face a growing challenge in distinguishing routine security events from threats that could disrupt operations. 

Continuous monitoring helps them understand the risks that matter most before those risks cause disruption. A proactive detection and response program accelerates detection and response through 24/7 monitoring and continuous visibility across IT and OT environments. It enables faster, more informed decision-making by providing contextual insight into which threats need immediate action. It also closes the skills gap by extending internal capabilities with dedicated OT security expertise, without the cost of building and maintaining a full in-house security operations center (SOC). Finally, it strengthens the program’s effectiveness by integrating threat detection with vulnerability management, incident response, governance, and continuous improvement efforts.

When a cybersecurity incident occurs, a quick response is critical in determining how much damage, downtime, and cost an organization may face. Containing an incident is only part of the challenge, and organizations must understand the importance of recovery readiness for operational resilience. When the worst happens, they need to restore services quickly and return to normal operations. 

A mature incident response program reduces the impact of cyber incidents through predefined, tested response and containment procedures. It accelerates operational recovery by coordinating response and recovery across IT, OT, and operational teams, and it minimizes downtime by improving recovery readiness for critical systems. It also strengthens stakeholder trust through clear communication, governance, and incident management during and after an event. Lastly, it supports a detailed incident investigation to identify root cause and apply lessons learned, so cyber resilience continues to strengthen over time.

In conclusion, Rockwell assessed that in a more connected industrial environment, cybersecurity is no longer only about protecting assets. It is about enabling resilient operations that can adapt, recover and continue delivering business value.

“Industrial organizations are investing heavily in cybersecurity, AI and connected operations. Those investments are increasing confidence, but technology alone does not create resilience,” according to the report. “The organizations that gain the most value from cybersecurity will be those that take a proactive, programmatic approach. By building visibility, risk-based decision-making, secure architectures, continuous monitoring and recovery readiness into their operations from the start, they can reduce operational risk, sustain production and enable the business to move forward with confidence.”



Source link