What does cyber pre-positioning mean?
The attacker gains quiet access and maps the network without launching an immediate attack, so they can cause disruption at a chosen moment (e.g., a geopolitical crisis).
2026 reports reveal new threat groups, pre-positioning in energy infrastructure, and transient devices in 27% of OT incidents. A full threat-and-defense analysis.
Operational Technology (OT) and Industrial Control Systems (ICS) — which run water, power, oil, and production lines — have become the front line of cyber conflict in 2026. Unlike IT, the attacker's goal in OT is often physical disruption, not just data theft.
The 2026 Dragos Year in Review identified three new threat groups targeting critical infrastructure. Attackers have advanced from targeting isolated devices to mapping entire industrial control systems, operating as coordinated ecosystems.
Nearly 27% of OT incidents stem from transient devices: USB drives, contractor laptops, and maintenance tools that bypass the IT/OT boundary. They are often unmonitored and open a direct path to the heart of the industrial process.
Between January 2023 and January 2026, 6,737 vulnerabilities were published. Industrial protocols such as Modbus, DNP3, and BACnet still appear on internet-facing infrastructure; they often lack authentication and encryption, making them easy prey.
| Metric (through Jan 2026) | Value |
|---|---|
| Vulnerabilities published (since 2023) | 6,737 |
| ICS-CERT advisories (since 2010) | 3,637 |
| Affected products | 2,783 from 689 vendors |
The attacker gains quiet access and maps the network without launching an immediate attack, so they can cause disruption at a chosen moment (e.g., a geopolitical crisis).
They bypass the IT/OT boundary and are often unmonitored; an infected USB or contractor laptop can carry malware straight into the control network.
Part of it; but many legacy devices don't support it, so network segmentation and passive monitoring are essential complements.
Follow the related articles in this category and round out your organization's security strategy.
IT/OT convergence widens the attack surface. A guide to zero trust and device PKI, supply-chain transparency with SBOM, and secure-by-design.
A practical guide to combining the Purdue Model, the Level 3.5 industrial DMZ, zero trust with PKI, and IEC 62443 to secure IT/OT convergence.
A comprehensive guide to AI agents in 2026: building blocks, ReAct and multi-agent design patterns, MCP and A2A standards, governance, and real use cases in banking and security.