Increasing Number of Attacks Exposing Critical Infrastructure Security Gaps

Visibility issues, legacy assets and AI threats led to over half experiencing a breach in the last year.

Industrial refinery and solar panel facility with digital connectivity icons representing smart manufacturing and renewable energy integration
istock.com/metamorworks

According to a new report from Palo Alto Networks, nearly 60 percent of critical infrastructure organizations experienced a significant cybersecurity incident in the past year. The State of Critical Infrastructure Cybersecurity Report also detailed widespread gaps in OT visibility, legacy infrastructure challenges, and IT/OT integration obstacles that continue to complicate security. 

More detailed findings include:

  • 68 percent reported not having complete, real-time visibility into all assets connected to their OT networks.
  • An average of 23 percent of connected OT assets are unmanaged or difficult to monitor.
  • 42 percent identify legacy, unpatchable OT assets as their biggest cybersecurity risk.
  • 59 percent experienced a significant security breach in the past year, with one in five affected multiple times.
  • Among organizations experiencing incidents, 50 percent cited safety concerns, 49 percent experienced unplanned downtime, 46 percent saw production disruption, and 46 percent were hit with financial losses.
  • 74 percent have not fully integrated their IT and OT security operations.
  • Only 37 percent have comprehensive OT asset visibility, while 40 percent have virtual patching or other compensating controls for vulnerable assets.
  • 95 percent are concerned about Frontier AI-powered attacks targeting critical infrastructure, while 91 percent expect AI-driven cybersecurity to play a role in defending against them.ㅤ
  • Organizations are using an average of seven disparate security systems and tools.
  • 59 percent said multiple systems create operational complexity, and 41 percent said tool sprawl contributes to delayed incident response.

Industry stakeholders shared their thoughts on these findings.

Jacob Krell, Director of Secure AI Solutions & Cybersecurity, Suzu Labs

“Critical infrastructure security is constrained by assets that cannot be taken offline long enough to patch, while geopolitical tensions and expanding connectivity increase pressure on providers already working with limited resources.ㅤ

“The Report connects that pressure to real operational consequences. The common thread is incomplete visibility across legacy systems, unmanaged devices, private 5G networks, and other connected assets. Separate IT and OT security teams, along with multiple disconnected tools, make the response slower and harder to coordinate.

“The burden is heavier for utilities, manufacturers, transport operators, and government agencies because they cannot treat cybersecurity as a normal software-maintenance exercise. A security team may know that a programmable logic controller (PLC) is vulnerable, but still lack a reliable answer to the question that matters operationally, which pump, production step, or safety process does it control? Without that context, a vulnerability score cannot tell the team what to protect first.ㅤ

“Time-to-protection is the meaningful measure for unpatchable OT. Passive asset discovery, network segmentation, strict remote access, and virtual patching can block exploitation while engineering teams test a vendor fix and schedule a safe maintenance window.ㅤ

“AI will compress the attacker’s timeline while defenders are still establishing what a connected asset does, what it controls, and whether it can be safely changed. Constrained headcount makes that gap harder to close. 

AI can multiply a small team’s reach, but safe use still requires people who understand the model, the network, and the physical process. A facility without that technical talent could turn automation into another unmonitored dependency. For providers facing geopolitical pressure and constrained resources, connecting every alert to the physical process that asset controls is the priority.”ㅤ

Damon Small, Board of Directors, Xcape, Inc.ㅤ

“Operational disruptions averaging nearly $290,000 per hour in downtime highlight the staggering financial risks of operational technology (OT) vulnerabilities. The convergence of OT and IT networks has been underway for nearly three decades, yielding tangible business efficiencies while simultaneously introducing severe cyber threats. 

"Early examples of targeted OT attacks date back to the 2000s and have steadily escalated in frequency and sophistication. Today, legacy and unpatchable devices combined with fragmented security operations leave defenders blind to over two-thirds of their connected environments. 

"Rather than chasing hype around emerging threat vectors, security leaders must prioritize foundational controls: continuous passive network monitoring to establish real-time asset inventories, strict network segmentation to isolate vulnerable systems, and unified identity enforcement across IT and OT boundaries.”ㅤ

John Strand, Owner, Black Hills Information Security, Inc.ㅤ

“This is unfortunately what we should expect when we look at a lot of these organizations. What you’re seeing is technological spread. Organizations have a tremendous amount of legacy technology that can’t simply be ripped out and replaced. 

"At the same time, newer and more secure technologies are being introduced, but that doesn’t mean they’re evenly distributed across the organization. There’s that great quote, ‘The future is already here. It’s just not evenly distributed.’ I think this story is a perfect example of that.ㅤ

“What worries me even more is the coming age of AI, where people can create applications and SaaS services incredibly quickly without necessarily knowing how to code. I believe the technical complexity of these environments is going to increase, not decrease. And complexity is the enemy of computer security. 

"Security teams are going to be dealing with new technologies being deployed incredibly quickly, legacy technologies that were never properly secured, and constant pressure to get things into production as fast as possible. All of those problems become even more pronounced when you get into SCADA, ICS, and OT environments.”

More in Safety