Executive Summary

In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents.

This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.

Why This Matters Now

Industrial systems are experiencing unprecedented threat evolution as attackers exploit the convergence of IT and OT environments, making traditional security approaches insufficient for protecting critical infrastructure in an increasingly connected industrial landscape.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Malicious scripts and phishing pages led at 5.42%, followed by denylisted internet resources at 4.31%, and spyware at 3.30% of affected ICS computers globally.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this multi-vector industrial control systems campaign by limiting lateral movement pathways and reducing attacker reach across interconnected ICS networks. The segmented architecture could have reduced the blast radius of ransomware deployment across critical infrastructure facilities.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric controls would likely have reduced the attack surface of internet-facing industrial systems by enforcing identity-aware access policies and constraining direct internet connectivity to critical ICS components.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have constrained privilege escalation by limiting access scope between different industrial system components and reducing the ability to exploit elevated permissions across segmented network zones.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have significantly reduced lateral movement capabilities by constraining inter-system communication pathways and limiting the reachability of legitimate remote access tools across segmented industrial network zones.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected and constrained command and control communications by providing centralized monitoring across distributed industrial infrastructure and limiting connectivity to known malicious internet resources.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained data exfiltration by monitoring and limiting outbound data flows from industrial systems, potentially reducing the volume of operational technology data accessible through unauthorized channels.

Impact (Mitigations)

While some ransomware deployment may still occur within compromised segments, the overall impact would likely be significantly reduced through contained blast radius, with isolated network zones potentially limiting ransomware spread across critical infrastructure facilities.

Impact at a Glance

Affected Business Functions

  • Industrial Control Systems Operations
  • Manufacturing Process Control
  • Building Automation Systems
  • Critical Infrastructure Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $150,000

Data Exposure

Industrial control system configurations, operational technology network topology, biometric access control data, engineering documentation, and AutoCAD design files across multiple industry sectors including electric power, manufacturing, and building automation systems

Recommended Actions

  • Implement Zero Trust Segmentation with microsegmentation policies to isolate industrial control systems from corporate networks and prevent lateral movement between OT and IT environments
  • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications to denylisted internet resources and detect covert C2 channels used by threat actors
  • Enable East-West Traffic Security monitoring to detect and prevent worm propagation and lateral movement within industrial networks, particularly between building automation and critical infrastructure systems
  • Establish Multicloud Visibility & Control with centralized monitoring of industrial automation systems to detect anomalous interactions and suspicious remote access tool usage like AnyDesk
  • Implement Encrypted Traffic (HPE) protection with MACsec and IPsec to secure data in transit and prevent exfiltration of sensitive operational technology data through email and internet channels

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image