Skip to main content
HomeTopicsOperational Technology

Operational Technology

We've curated 12 cybersecurity statistics about Operational technology to help you understand how the integration of IT and OT systems is shaping security practices and addressing vulnerabilities in critical infrastructure in 2025.

Showing 1-12 of 12 results

Organizations with comprehensive OT visibility detect and contain OT ransomware incidents in an average of 5 days, compared to the industry-wide average of 42 days.

Dragos2/22/2026
Incident ResponseRansomware

The average dwell time for ransomware in OT environments is 42 days.

Dragos2/22/2026
RansomwareDwell Time

KAMACITE conducted sustained reconnaissance of U.S. industrial devices from March through July 2025.

Dragos2/22/2026
ReconnaissanceIndustrial Devices

The number of ransomware groups targeting industrial organizations increased 49% year-over-year to 119 groups, collectively impacting 3,300 organizations globally.

Dragos2/22/2026
RansomwareIndustrial Security

87% of CIOs say AI agents are already embedded in critical operations.

Dataiku2/14/2026
AI IntegrationAI Agents

Attacks using OT protocols surge by 84%, led by Modbus (57%), Ethernet/IP (22%), and BACnet (8%).

Forescout Technologies Inc2/5/2026
OT Protocols

Transportation and shipping ranked second in detections by Trellix, accounting for 27.6% of all threats detected from April 1 to September 30, 2025.

Trellix11/22/2025
Operational technologyTransportation

Manufacturing represented 41.5% of all Trellix detections of threats targeting operational technology from April 1 to September 30, 2025.

Trellix11/22/2025
Operational technologyManufacturing

The utilities, energy/oil and gas, and aerospace and defense industries combined accounted for 21.5% of all detections by Trellix between April 1 to September 30, 2025.

Trellix11/22/2025
Operational technologyUtilities

PowerShell was the primary attack vector with 96,061 detections by Trellix, followed by Cobalt Strike with 85,986 detections targeting the IT-to-OT boundary.

Trellix11/22/2025
Operational technologyPowerShell

The average time from vulnerability disclosure to patch deployment in operational technology environments exceeds 180 days, compared to 30 days for traditional IT systems.

Trellix11/22/2025
Operational technologyVulnerability disclosure

There were 333 ransomware attacks detected by Trellix specifically targeting critical infrastructure sectors from April 1 to September 30, 2025.

Trellix11/22/2025
Operational technologyRansomware