Opens in a new tab

Critical Infrastructure Operators Run Seven Security Tools and Still Cannot See Every OT Asset

  • Home
  • Blog
  • Critical Infrastructure Operators Run Seven Security Tools and Still Cannot See Every OT Asset
Aged control cabinets in an industrial OT room

Critical infrastructure operators run seven separate security tools on average, and most still cannot see every asset on their operational technology networks. That is the picture from a Palo Alto Networks survey of more than 1,600 security and operations leaders, which shows how visibility gaps, tool sprawl, and aging equipment continue to shape cybersecurity risk in power, water, manufacturing, and other essential industries.

What the survey measured and who responded

The research drew responses from more than 1,600 security and operations leaders working in operational technology environments. Respondents described the number of security tools their teams operate, the visibility they have into connected equipment, the breaches they experienced in the past year, and their plans for AI and IT-OT convergence. The findings point to a sector that has invested in tools but has not yet solved the basics of asset visibility or team coordination.

Legacy equipment is the most common visibility problem

Old operational technology tops the list of obstacles. Fifty-two percent of respondents named legacy OT as their biggest visibility challenge. Another forty-two percent said legacy equipment that cannot be patched was their biggest cybersecurity risk. Knowing a machine is connected to the network does not update its software, and that gap between visibility and patchability is where risk concentrates.

Even among respondents who said they see everything on their networks, forty-nine percent still listed legacy OT as a problem. The result is a clear pattern: more visibility tooling does not remove the underlying issue of equipment that predates modern security models.

More tools did not simplify the work

Operators are managing an average of seven separate security tools. Fifty-nine percent of respondents said the tools make operations more complicated, and fifty-six percent reported higher operating costs as a result. Just over half still sort alerts using a standard severity score or handle triage by hand. The data suggests that adding a tool for each new gap has produced complexity without producing faster, cleaner response.

Breaches were common in the past year

Fifty-nine percent of organizations experienced a significant security breach in the previous twelve months, and one in five was hit more than once. Half of respondents named safety concerns among the impacts of incidents. Unplanned downtime carried a mean cost of $288,563 per hour.

Containment is improving from a low base. Fifteen percent of respondents now contain incidents in minutes through automation, up from ten percent a year earlier. Fifty-one percent said they want to reach automated containment within the next twelve months, while fifteen percent have already done so.

AI is the next worry

Ninety-five percent of respondents said they are concerned about attacks powered by what the survey calls Frontier AI. Ninety-one percent expect AI-driven security tools to help defend against those threats. Few organizations have AI deployed at scale. Only nineteen percent use AI across four or more operational areas, and those areas include process optimization and predictive maintenance, so the figure is not limited to security.

IT and OT teams still work apart

Seventy-four percent of respondents have not integrated their IT and OT security operations. Among those, forty-four percent blamed incompatible technology and another forty-four percent pointed to differing priorities between the two teams. Automated alert correlation was the most popular idea for closing the divide, picked by fifty-two percent of respondents as the change that would most speed IT and OT convergence over the next two years.

What this means for operators

The survey draws a line from equipment age to operational risk. Legacy OT that cannot be patched remains the dominant concern, and visibility tools alone do not address it. Tool consolidation, automated alert correlation, and tighter IT-OT coordination are the practical next steps the respondents identified. AI is on the wish list as both a defensive tool and a new threat category, but deployment remains early.

FAQ

What did the survey find about legacy equipment in critical infrastructure?

Legacy operational technology was named the biggest visibility problem by 52 percent of respondents, and 42 percent said legacy equipment that cannot be patched was their biggest cybersecurity risk. Even respondents who said they see everything on their networks still listed legacy OT as a challenge 49 percent of the time.

How many security tools do critical infrastructure operators use?

Operators run an average of seven separate security tools. Fifty-nine percent of respondents said those tools made work more complicated, and 56 percent reported higher operating costs. Just over half still sort alerts with a standard severity score or by hand.

How concerned are operators about AI-powered attacks?

Ninety-five percent of respondents said they are concerned about attacks powered by Frontier AI. Ninety-one percent expect AI-driven security tools to help defend against them. Only 19 percent currently use AI across four or more operational areas, a figure that includes process optimization and predictive maintenance, not security alone.


This article summarizes reporting from helpnetsecurity.com.

← All Articles