Site navigation

59% of Critical Infrastructure Organisations Hit by Cyber Breaches

Graham Turner

,

Critical infrastructure breaches
Ageing OT systems, fragmented security operations and emerging AI threats are complicating efforts to strengthen resilience.

Nearly six in ten critical infrastructure organisations experienced a significant security breach in the past year, with ageing technology, limited network visibility and fragmented security operations leaving essential services exposed to cyber threats, according to new research.

Palo Alto Networks’ inaugural State of Critical Infrastructure Cybersecurity Report found that 59% of organisations had experienced a significant security breach in the previous 12 months, with one in five affected multiple times.

Of those experiencing breaches, 96% reported significant impacts, including safety concerns, unplanned downtime, production disruption and financial losses.

The findings come from research commissioned by Palo Alto Networks and conducted in collaboration with Sapio Research, involving more than 1,600 respondents across 11 countries, including the UK.

Participants represented large organisations operating in five sectors: manufacturing, healthcare and life sciences, energy and utilities, transportation, and government and the public sector.

The report identifies a widening gap between the cyber risks facing critical infrastructure and organisations’ ability to protect increasingly interconnected operational environments.

One of the most significant challenges is incomplete visibility across operational technology (OT) networks, with 68% of respondents reporting that they cannot fully account for every connected asset in real time.

On average, 23% of assets connected to OT environments are classified as unmanaged or difficult to monitor, while 52% of organisations identify legacy OT systems as one of their biggest visibility challenges.

A further 37% cite the absence of centralised visibility tools, while 33% identify Internet of Things devices and unmanaged equipment as significant obstacles.

These gaps are contributing to wider operational difficulties, with 54% of respondents identifying security blind spots as a consequence of incomplete visibility, followed by operational inefficiencies at 48% and slower incident response at 46%.

Meanwhile, 42% identify legacy, unpatchable OT assets as their biggest cyber security risk.

The report also highlights the growing complexity of security operations, with organisations relying on an average of seven separate security systems and tools.

Some 59% say managing multiple security systems increases operational complexity, while 56% report higher operating costs and 46% identify gaps in cyber security coverage.

The operational consequences of security incidents can be substantial. Among the impacts identified by respondents, 50% cited safety concerns, 49% reported unplanned downtime, and 46% highlighted production disruption and financial losses.

The research places the mean cost of unplanned downtime at $288,563 per hour, underlining the potential financial consequences of cyber incidents affecting essential infrastructure.

Although incident response capabilities have improved, more than a third of organisations still report taking days or weeks to contain or resolve incidents.

Limited visibility across environments and a high proportion of legacy infrastructure were jointly identified as the leading barriers to effective incident response, each cited by 40% of respondents.

AI Threats Add to Security Pressures

Artificial intelligence is introducing further challenges for critical infrastructure operators, with 95% of respondents expressing some level of concern about attacks powered by frontier AI.

Half of respondents were either very or extremely concerned about these threats, while 91% expect AI-driven cyber security solutions to play a role in defending against them.

However, the research suggests that AI deployment across critical infrastructure operations remains relatively limited in scope.

While almost all organisations surveyed are using AI in some capacity, only 19% have deployed the technology across four or more operational areas.

Security monitoring is currently the most common application, cited by 66% of respondents, followed by process optimisation at 64%, quality assurance at 55%, predictive maintenance at 52% and energy efficiency at 47%.

Automation is also expected to become more prominent, with 60% of organisations planning to invest in automated troubleshooting over the next one to two years and 56% expecting to adopt autonomous remediation of alerts.

Despite these ambitions, the report highlights persistent organisational and technical barriers to improving cyber resilience.

Some 74% of respondents have yet to fully integrate their information technology (IT) and OT security operations, despite growing interconnectivity between the two environments.

Among organisations without fully integrated operations, technology incompatibility and differing priorities between IT and OT teams were the most commonly cited barriers, each identified by 44% of respondents.


Recommended reading


Organisational silos were highlighted by 37%, followed by skills gaps at 36% and reliance on manual processes at 34%.

Looking ahead, 52% of respondents identified automated alert correlation and prioritisation as a priority for improving IT/OT security integration over the next two years.

Another 45% highlighted unified visibility and response capabilities, while 44% identified the need for a unified security operations centre platform with consistent workflows across both environments.

The research also points to growing connectivity as an additional consideration, with 84% of organisations expecting 5G to be widely or extensively adopted within the next two to three years.

Data protection was the most commonly cited security concern associated with 5G environments, identified by 52% of respondents, followed by third-party access at 43% and application security at 40%.

Rich Campagna, SVP, Product Management, Network Security at Palo Alto Networks, said: “This report captures the experiences of more than 1,600 of those leaders, and it’s clear they’re facing real challenges: incomplete visibility into their environments, difficulty prioritizing the risks that matter most, and a new generation of AI-powered attacks moving faster than defenders can respond.”

Graham Turner

Sub Editor

Latest News

Awards Diversity

Shortlist for 2026 Scotland Women in Technology Awards Revealed

Featured Security

Don’t Miss Out! Join Us in Cardiff For CymruSec 2026

Editor's Picks Security

59% of Critical Infrastructure Organisations Hit by Cyber Breaches

Data Protection

ICO Secures Better Data Protection from AI Developers