Fortinet’s eighth “State of Operational Technology and Cybersecurity Report” finds organizations professionalizing OT security programs — but longer attacker dwell times signal new risks for industrial operators.
Eight years after its first edition, Fortinet’s latest “State of Operational Technology and Cybersecurity Report” paints a nuanced picture of industrial control system security. The study is based on a global survey of more than 700 OT professionals at companies with over 1,000 employees, conducted on Fortinet’s behalf by market research firm Empanel Online. Respondents were primarily plant operations and manufacturing leaders, with nearly half holding vice president titles.
According to the company, the study shows organizations are increasingly professionalizing their OT security programs, yet continue to struggle with structural weaknesses. Only a minority of respondents have fully established the processes and tools needed to effectively counter the growing wave of cyberattacks.
Responsibility shifts back to specialized leadership
A central finding concerns where OT security responsibility sits organizationally. In 2026, 60% of respondents report that ultimate responsibility rests with the chief information security officer (CISO) or chief information officer (CIO), down from 69% the previous year. Fortinet interprets this as a sign of maturity: the C-suite has brought OT risk under control to the point that responsibility can be delegated back to specialized leadership roles. At the same time, 81% said they intend to move OT cybersecurity under the CISO within the next twelve months, marking the fifth consecutive annual increase.
Process maturity paints a mixed picture
On process maturity, the report shows a mixed trend. The share of organizations at maturity level 0, meaning no documented core processes, rose from 1% (2025) to 5% (2026). Levels 1 and 2 also increased sharply, from 5% to 17% and from 13% to 27% respectively. Meanwhile, the share of highly mature organizations at level 4 declined from 49% to 17%. According to the company, this is less a step backward than a recalibration: as teams become more experienced, better resourced, and more diverse, they are more realistically assessing where security gaps actually remain.
Attacker dwell time is rising
The report highlights attacker dwell time, the length of time intruders remain undetected in a network, as a critical indicator. While short dwell times of minutes to hours have flattened somewhat, longer dwell times of weeks or months have risen noticeably: incidents with dwell times of several weeks increased from 6% to 13%, and those lasting several months rose from 5% to 7%. Long undetected attacks significantly increase the risk of surveillance, data loss, and physical disruption, the report notes.
At the same time, fewer organizations reported that both IT and OT systems were affected simultaneously by an intrusion: that share dropped from 60% (2025) to 24% (2026), the lowest figure since 2022. Fortinet attributes this to improved segmentation between IT and OT networks. Among intrusion types, phishing remains the most common threat at 76%, followed by ransomware or wiper attacks at 50%, a slight decline from 54% the previous year.
Regulation is expected sooner
Expectations of new regulatory requirements have risen sharply: 89% of respondents now expect additional rules within five years, up from 66% in 2025. Notably, the anticipated timeline has shifted from five-plus years toward the two-to-five-year window, suggesting organizations want to actively prepare for upcoming compliance demands.
Industrial control systems get younger
The report views the accelerating modernization of industrial control systems (ICS) positively: 40% of respondents said their systems are less than five years old, a sharp increase from 20% the previous year. Because many OT devices are, according to Fortinet, more than 20 years old and inherently insecure by design, modernization is considered a key lever for reducing risk.
Recommendations: segmentation, SecOps integration, and a platform approach
Based on the survey findings, Fortinet outlines several recommendations. First, segmenting and microsegmenting IT and OT networks to limit the lateral spread of attacks. Second, the report advises fully integrating OT systems, production processes, and plant-level roles into incident response planning and security operations (SecOps). Third, Fortinet recommends a platform approach to security architecture: rather than relying on numerous point solutions from different vendors, consolidated platforms with centralized management, threat intelligence, and increasingly generative AI can improve visibility and speed up response times.
On methodology: the online survey, conducted by Empanel Online, included professionals from more than 25 countries, with a focus on manufacturing (33%), oil, gas and refining (19%), and energy and utilities (17%).

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de