Key Takeaways
- More than half of industrial organizations now place OT cybersecurity under the CISO or CSO (53% in 2026 vs. 16% in 2022).
- Self‑assessed maturity has dropped sharply; the share of organizations rating themselves at the highest level (Level 4) fell from 49% to 17% in one year, while lower‑level ratings rose.
- Improved detection, not a surge in attacks, explains the rise in reported incidents (71% saw 1‑9 attacks, up from 47%).
- Cost reduction has overtaken risk reduction as the top cybersecurity performance metric, creating tension with impending regulation.
- Nearly nine in ten respondents expect new OT‑specific regulations within five years, and most plan to bring OT security under CISO oversight within the next 12 months.
- Phishing (76%) and ransomware (50%) remain the leading intrusion types; network segmentation, microsegmentation, and zero‑trust remote access continue to be the primary defensive controls.
- Organizations refreshing hardware without first fixing foundational security gaps risk enlarging their attack surface.
- A baseline maturity audit within 90 days of governance transfer and OT‑specific incident‑response playbooks are recommended to close credibility gaps at the board level.
Governance Shift Toward the CISO Accelerates
OT security governance has been migrating to the C‑suite for several years, but Fortinet’s 2026 State of Operational Technology and Cybersecurity Report shows a sharp acceleration. Over half of the surveyed industrial organizations (53%) now assign OT cybersecurity responsibility to the Chief Information Security Officer (CISO) or Chief Security Officer (CSO), up dramatically from just 16% in 2022. The finding rests on a global survey of more than 700 OT professionals, indicating that the trend is broad‑based rather than isolated to a few early adopters.
Maturity Self‑Assessments Reveal a Reality Check
While the governance headline is striking, the report’s maturity self‑assessment data tells a more nuanced story. Organizations rating themselves at the highest maturity level (Level 4) plummeted from 49% to 17% in a single year. Conversely, the share of organizations at Level 0 rose from 1% to 5%, and Levels 1 + 2 together jumped from 18% to 44%. Fortinet interprets this downward recalibration as a positive sign: better tools, larger security teams, and heightened executive oversight have exposed gaps that earlier, overly optimistic self‑assessments missed.
Governance Outpacing Operational Readiness
The simultaneous rise in CISO ownership and the drop in self‑reported maturity suggest that governance is moving faster than the underlying security programs can support. A CISO who now oversees OT risk but inherits a Level 2‑type program faces a credibility gap when presenting risk posture to the board. The report notes that this mismatch can undermine confidence in the CISO’s ability to manage OT‑related threats effectively, even as OT security becomes a standing agenda item at executive meetings.
Visibility vs. Frequency of Intrusions
Reported intrusions have become more visible, but not necessarily more frequent. Seventy‑one percent of respondents said they experienced one to nine attacks in the past year, up from 47% in the previous survey. Fortinet attributes much of this increase to improved detection capabilities rather than a true rise in attack volume. Nonetheless, the heightened visibility underscores the need for robust monitoring and response capabilities.
Dwell Time Trends Complicate Outage Metrics
Revenue‑impacting outages did show improvement, with operational shutdowns falling from 52% to 42% of incidents. However, attacker dwell time data adds complexity: incidents lasting weeks or months have increased, even as short‑dwell attacks have flattened. Extended dwell times enable surveillance, intellectual‑property theft, and potential physical disruption—effects that an annual outage metric does not capture. Consequently, organizations must look beyond outage counts to assess true risk.
Hardware Refresh Without Security Foundations Expands Risk
The hardware landscape offers additional context. Forty percent of respondents report that their industrial control systems (ICS) are under five years old, up from 20% the prior year, indicating an accelerated equipment refresh cycle. Yet, as maturity self‑assessments have corrected downward, many organizations are modernizing hardware without first addressing foundational OT security gaps. This practice risks transferring legacy vulnerabilities onto new equipment, thereby enlarging an already‑expanded attack surface.
Governance Gaps When the CISO Does Not Own OT
In the 47% of organizations where the CISO does not retain OT security responsibility, ownership is described as “more broadly distributed across non‑technical vice presidents and C‑suite leaders.” This diffuse model can dilute accountability and impede coordinated response. Parallel data from the NASCIO‑Deloitte 2026 study show declining CISO confidence (from 48% to 22% in one year), suggesting that authority and confidence are not advancing in tandem.
Regulatory Expectations Intensify
Regulatory pressure looms large: 89% of respondents now anticipate new OT‑specific regulations within five years, up sharply from 66% in 2025. This 20‑point shift toward the two‑to‑five‑year horizon indicates that organizations view compliance as an imminent operational deadline. At the same time, cost reduction has displaced risk reduction as the top cybersecurity performance metric, creating a tension between budgetary constraints and the looming regulatory clock that the report does not fully resolve.
Dominant Threat Vectors and Defensive Priorities
Phishing (76%) and ransomware (50%) remain the most frequently reported intrusion types. The report consistently recommends network segmentation, microsegmentation, and secure remote access grounded in zero‑trust principles as the primary defensive controls—advice that has anchored Fortinet’s OT guidance for three consecutive surveys. These measures aim to limit lateral movement and protect critical processes even as attackers evolve.
Three Controls That Correlate With Higher Maturity
Fortinet’s analysis links specific controls to better maturity outcomes. First, enforcing IT/OT network segmentation before hardware modernization prevents legacy risks from being copied onto new equipment; organizations with segmentation in place report lower business disruption. Second, anchoring CISO OT ownership to a maturity‑baseline audit within 90 days of governance transfer provides a ground‑truth foundation for board reporting and risk‑management decisions. Third, building incident‑response playbooks that name OT‑specific production scenarios—such as assembly‑line shutdowns or safety‑system trips—ensures that generic IR plans address the unique continuity, sequencing, and recovery constraints of operational technology environments.
Implications for the Boardroom and Beyond
As OT cybersecurity becomes a regular boardroom topic, the need for clear, production‑focused metrics grows. The report suggests that boards should demand baseline maturity audits, segmentation verification, and OT‑tailored IR playbooks to close the credibility gap between governance ambition and operational reality. Only by aligning executive oversight with concrete, measurable controls can organizations effectively manage the expanding attack surface while preparing for forthcoming regulatory demands.

