Full Report
New research from cyber-physical systems (CPS) protection vendor Claroty found that 58% of CPS operators said they experienced... The post Claroty finds 58% of CPS operators faced operational cyberattacks as third-party access and AI risks grow appeared first on Industrial Cyber.
Analysis Summary
# Industry News: Operational Cyberattacks Surge Among CPS Operators Amid Rising AI and Third-Party Risks
## Summary
A comprehensive global survey by Claroty reveals that 58% of Cyber-Physical Systems (CPS) operators suffered operational cyberattacks in the past year, resulting in significant downtime and financial losses. The research highlights a critical shift in the threat landscape driven by the weaponization of frontier AI models and pervasive risks from unmonitored third-party access.
## Key Details
- **Date:** October 8, 2026
- **Companies Involved:** Claroty (Primary), Anthropic, OpenAI (referenced regarding AI models)
- **Category:** Market Research & Industry Analysis
## The Story
Claroty’s report, *“The Global State of Operational Security 2026,”* paints a sobering picture of the vulnerability of critical infrastructure. Surveying 2,000 leaders across 40 countries, the data shows that cyberattacks are no longer just data breaches but functional disruptions. 43% of respondents reported operational downtime, with nearly 10% suffering outages lasting up to a full month.
The report identifies two primary catalysts for this escalation:
1. **Third-Party Exposure:** 75% of respondents linked operational incidents to third-party access, yet nearly half admit to having little to no monitoring of these external connections.
2. **AI-Driven Exploitation:** The arrival of advanced models like GPT-5.6-Cyber has compressed the time between vulnerability discovery and exploit availability, allowing attackers to bypass traditional defense timelines.
Geopolitical tensions—specifically involving Russia and Iran—further exacerbate the risk to Western water, healthcare, and energy sectors.
## Business Impact
### For the Companies Involved
- **Claroty:** Strengthens its market position as a thought leader and essential partner for CPS protection, likely driving demand for its secure remote access and threat detection modules.
### For Competitors
- **Increased Competition:** Peers like Dragos, Nozomi Networks, and Microsoft (Defender for IoT) must now match Claroty’s focus on "Operational Resilience" over mere asset visibility.
- **Innovation Pressure:** Competitors will need to integrate AI-driven triage tools to counter the speed of AI-based attacks mentioned in the report.
### For Customers
- **Financial Consequences:** Large organizations (10k+ employees) now face average losses of $2.25 million per incident.
- **Operational Shift:** Customers are being forced to pivot from "asset-centric" mindsets to "process-centric" resilience, prioritizing recovery capabilities alongside prevention.
### For the Market
- **Increased Spending:** 37% of organizations now cite "operational risk" as the primary driver for cyber investment, surpassing digital transformation for the first time.
- **Consolidation of IT/OT:** The persistent 16% integration rate suggests a massive untapped market for services that bridge the IT/OT security gap.
## Technical Implications
The report highlights the "dizzying pace" of vulnerability exploitation enabled by frontier AI. Technically, this necessitates **Automated Triage and Remediation** strategies, as human-led response times are no longer sufficient to counter AI-generated proof-of-concept exploits. The mention of STUN traffic concealment by botnets like "Cling" also points to more sophisticated network obfuscation techniques in OT environments.
## Strategic Analysis
- **Market Positioning:** Claroty is moving beyond "visibility" to "resilience," aligning its brand with business continuity rather than just IT security.
- **Competitive Advantage:** By identifying third-party access as a 75% failure point, Claroty creates a clear strategic path for its "Secure Remote Access" product line.
- **Challenges:** The ongoing fragmentation between IT and OT teams (only 16% integrated) remains the largest hurdle to effective implementation of these security solutions.
## Industry Reactions
- **Claroty (Sean Tufts, Field CTO):** Emphasizes a "seismic shift" in the threat landscape, urging organizations to protect core processes without halting operations.
- **Market Response:** The data suggests a shift in budget allocation toward CPS, as safety incidents (40%) and financial loss (35%) become boardroom-level concerns.
## Future Outlook
- **Predictive AI Defense:** Expect a surge in security tools that use AI to predict and patch vulnerabilities before frontier AI models can exploit them.
- **Regulatory Pressure:** As evidenced by the OT Cyber Coalition's calls for CISA directives, we should expect more mandatory federal cybersecurity requirements for critical infrastructure in late 2026/2027.
## For Security Professionals
Practitioners should prioritize **Third-Party Access Management (PAM for OT)** and **Incident Response playbooks** that account for multi-day outages. With AI narrowing the window for patching, focus must shift toward "Secure-by-Design" principles and proactive risk reduction rather than reactive monitoring.