Claroty, the cyber-physical systems (CPS) protection company, today published new research on operational security trends and challenges facing global organizations, including the fact that 58% of CPS operators say they've experienced a cyberattack impacting operational environments in the last 12 months. The report, "The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability," is based on a global survey of 2,000 business and technology leaders whose organizations manage CPS.
The survey showed that cyber incidents impacting CPS result in material effects on the health of a business. It's a fact that's driving today's cybersecurity investment priorities: 37% said operational risk and cyber threats are a top driver of investment, followed by digital transformation/modernization 36% and risk of business disruption or revenue loss 29%.
The top impacts from operational incidents were: operational downtime selected by 43% of respondents, safety incidents and hazards 40%, and financial loss 35%. The average financial loss from an incident impacting operations was $1.04 million, and losses hit larger companies hardest: organizations with at least 5,000 employees saw $1.6M in average losses, and those with at least 10,000 employees saw $2.25M in average losses.
Third-party access also contributed to operational risk, with 75% saying they suffered at least one incident impacting operations related to third-party access and 49% said they had only partial or no monitoring of third-party connections. Despite costly impacts, IT and operational security remain fragmented, with only a mere 16% reporting that they've fully integrated the two.
Respondents indicated they are ready to implement AI across operational environments to improve efficiency and support human-in-the-loop expertise. 30% said effective use of AI, automation, and advanced analytics is a top success factor for digital transformation. 70% said AI is being used in operational environments, and 71% said AI is a baseline cybersecurity procurement requirement.
Respondents said AI has improved operational efficiency 48%, decision-making 46%, and enabled new business models 37%. Respondents consider AI-powered cyberattacks selected by 37% as a greater risk to operational integrity than ransomware 27%, supply chain compromises 23%, and legacy OT assets 21%.
Navigating compliance shows 29% cite IT/OT alignment challenges, 26% legacy technical debt, 16% limited asset visibility as operational barriers. Top compliance barriers are keeping up with evolving regulations 38%, managing compliance across multiple sites 35%, and implementing policies 34%. 82% of organizations that have fully integrated IT/OT governance have proactive compliance approach.
"Businesses have quickly realized that prioritizing operational resilience is key to ensuring robust protection across the world's most critical infrastructure," said Sean Tufts, Field CTO at Claroty.
About Claroty
Claroty empowers organizations to protect the mission-critical infrastructure that underpins modern life. The AI-powered Claroty Platform serves as the single source of operational truth, providing the deepest visibility and broadest protection across cyber-physical systems (CPS), leveraging five core solutions: asset inventory, exposure management, network protection, secure access, and threat detection.