A recent survey of over 1,600 security and operations leaders in critical infrastructure organizations reveals that despite widespread adoption of security tools, many operators still lack full visibility into their operational technology (OT) networks and struggle with the risks posed by legacy equipment. The study, conducted by Palo Alto Networks, highlights a significant challenge in securing critical infrastructure, where decades-old OT systems are increasingly connected to modern networks without adequate security model updates.
The survey found that, on average, large critical infrastructure operators utilize seven distinct security tools. However, this proliferation of tools often complicates operations, with 59% of respondents reporting increased complexity and 56% noting higher operating costs. More than half of the organizations still rely on standard severity scores or manual processes to triage security alerts.
A primary concern identified by 52% of respondents is the presence of legacy OT equipment, which hinders network visibility. Furthermore, 42% consider unpatchable legacy equipment to be their greatest cybersecurity risk. Even among the 49% of respondents who believe they have complete network visibility, legacy OT remains a significant challenge, indicating that simply knowing an asset exists does not address its software vulnerabilities.
The past year saw a high incidence of security breaches, with 59% of organizations experiencing at least one significant incident, and one in five reporting multiple breaches. These incidents frequently have safety implications, cited by half of the respondents, and result in substantial financial losses due to unplanned downtime, averaging $288,563 per hour. While containment times are improving, only 15% of organizations currently resolve incidents within minutes through automation, an increase from 10% a year prior. Fifty-one percent aim to achieve this level of rapid containment within the next 12 months.
Looking ahead, there is considerable apprehension regarding advanced AI-powered attacks, with 95% of respondents expressing concern about "Frontier AI." Concurrently, 91% anticipate that AI-driven security tools will be crucial for defense. However, AI adoption in security is still nascent; only 19% of organizations use AI across four or more operational areas, and this figure includes applications beyond security, such as process optimization and predictive maintenance.
Another persistent issue is the lack of integration between IT and OT security operations, with 74% of organizations reporting separate functions. Among these, 44% attribute the divide to incompatible technology, and an equal percentage point to differing priorities between IT and OT teams. Automated alert correlation is seen as the most impactful solution for bridging this gap, with 52% of respondents identifying it as the key to accelerating IT and OT convergence over the next two years.






