Full Report
The percentage of ICS computers on which denylisted internet resources were blocked increased in all regions
Analysis Summary
# Industry News: Global Rise in ICS Exposure to Denylisted Internet Resources
## Summary
The Q2 2026 threat landscape report for industrial automation systems reveals a global increase in the percentage of Industrial Control Systems (ICS) attempting to access blocked or denylisted internet resources. This trend signals a persistent erosion of the "air gap" and an increase in unauthorized outbound communications from critical infrastructure environments.
## Key Details
- **Date:** August 25, 2026
- **Companies Involved:** Kaspersky ICS CERT (Reporting Authority)
- **Category:** Market Analysis / Threat Intelligence
## The Story
The latest data from Q2 2026 indicates a troubling trend: the percentage of ICS computers encountering denylisted internet resources has increased across every monitored geographical region. Despite long-standing industry recommendations for strict network segmentation, industrial assets are increasingly interacting with malicious or unauthorized web domains.
This rise is attributed to several factors: the continued integration of IIoT (Industrial Internet of Things) devices that require cloud connectivity, weakened perimeter security due to remote maintenance requirements, and the proliferation of sophisticated malware designed to "phone home" to Command and Control (C2) servers. The report highlights that while security software is successfully blocking these connections, the sheer volume of attempts suggests that industrial networks are being probed or compromised at a higher frequency than in previous quarters.
## Business Impact
### For the Companies Involved
- **Kaspersky:** Solidifies its position as a dominant provider of specialized industrial threat intelligence, driving demand for its KICS (Kaspersky Industrial CyberSecurity) product suite.
### For Competitors
- **Strategic Pressure:** Firms like Dragos, Claroty, and Nozomi Networks face increased pressure to demonstrate their platforms' efficacy in preventing outbound "denylisted" communication rather than just passive monitoring.
### For Customers
- **Operational Risk:** Industrial operators face higher potential for downtime if blocked resources are indicative of dormant malware ready to execute a payload.
- **Regulatory Pressure:** Organizations in critical sectors (energy, water, manufacturing) may face stricter compliance audits regarding outbound traffic filtering.
### For the Market
- **Increased Spending:** Expect a shift in CAPEX/OPEX toward "Secure Access Service Edge" (SASE) for industrial environments and advanced perimeter firewalls capable of deep packet inspection for ICS protocols.
## Technical Implications
The data points to a failure in traditional "Default Deny" policies. Technically, this suggests that ICS workstations—often running legacy OS versions—are being used for general web browsing or are infected with modular trojans that utilize encrypted channels (HTTPS/TLS) to bypass basic port filtering.
## Strategic Analysis
- **Market Positioning:** The report shifts the narrative from "inbound attacks" to "outbound unauthorized communication," highlighting a gap in internal governance.
- **Competitive Advantage:** Vendors who can offer automated, AI-driven denylist updates that don't interfere with industrial latency requirements will gain a significant edge.
- **Challenges:** The primary obstacle remains the "production first" mentality, where blocking a resource might inadvertently shut down a critical process if a legitimate update server is misclassified.
## Industry Reactions
- **Analyst Opinions:** Analysts suggest this is a lagging indicator of the "IT/OT convergence" risks that were warned about five years ago finally manifesting at scale.
- **Market Response:** Shares in industrial cybersecurity firms remain bullish as the perceived risk profile of manufacturing and utilities increases.
## Future Outlook
- **Predictions:** By 2027, the use of Zero Trust Network Access (ZTNA) within the factory floor will likely become a standard requirement for insurance eligibility.
- **What to watch for:** A potential surge in ransomware attacks following this period of increased "beaconing" to denylisted sites, as attackers often test connectivity before launching disruptive operations.
## For Security Professionals
Practitioners should immediately audit outbound traffic logs from their OT zones. The increase in denylisted resource hits suggests that current "air gaps" are likely non-existent. Priority should be given to implementing strict egress filtering and updating localized denylists to prevent compromised ICS assets from establishing C2 persistence.