OT & Infrastructure

The OT/ICS Threat Landscape in 2026: Ransomware, Pre-positioning, and Transient Devices

2026 reports reveal new threat groups, pre-positioning in energy infrastructure, and transient devices in 27% of OT incidents. A full threat-and-defense analysis.

Updated: 2026-07-08 9 min read
Industrial environment and process control systems
Critical infrastructure has become a prime target for threat groups.

Operational Technology (OT) and Industrial Control Systems (ICS) — which run water, power, oil, and production lines — have become the front line of cyber conflict in 2026. Unlike IT, the attacker's goal in OT is often physical disruption, not just data theft.

> 1/3of global energy infrastructure that has seen cyber pre-positioning activity

What Has Changed?

Motion view: the threat and defense cycle
Motion view: the threat and defense cycle

The 2026 Dragos Year in Review identified three new threat groups targeting critical infrastructure. Attackers have advanced from targeting isolated devices to mapping entire industrial control systems, operating as coordinated ecosystems.

  • Pre-positioning: quiet access, data collection, and operational mapping for a future attack.
  • Industrial ransomware: still the primary driver of operational disruption across critical sectors.
  • AI-powered data exfiltration: stealing industrial data to train more sophisticated attack models.

Transient Devices: The Weak Link

Nearly 27% of OT incidents stem from transient devices: USB drives, contractor laptops, and maintenance tools that bypass the IT/OT boundary. They are often unmonitored and open a direct path to the heart of the industrial process.

~27%share of transient devices (USB, contractor laptops) in OT incidents

Vulnerabilities and Exposed Protocols

Between January 2023 and January 2026, 6,737 vulnerabilities were published. Industrial protocols such as Modbus, DNP3, and BACnet still appear on internet-facing infrastructure; they often lack authentication and encryption, making them easy prey.

Metric (through Jan 2026)Value
Vulnerabilities published (since 2023)6,737
ICS-CERT advisories (since 2010)3,637
Affected products2,783 from 689 vendors

Why Is Critical Infrastructure a Target?

  • High civilian impact and value as leverage,
  • A large number of internet-exposed ICS devices,
  • Historical underinvestment in OT security compared with IT.

Frequently asked questions

What does cyber pre-positioning mean?

The attacker gains quiet access and maps the network without launching an immediate attack, so they can cause disruption at a chosen moment (e.g., a geopolitical crisis).

Why are transient devices dangerous?

They bypass the IT/OT boundary and are often unmonitored; an infected USB or contractor laptop can carry malware straight into the control network.

Is encrypting industrial protocols the answer?

Part of it; but many legacy devices don't support it, so network segmentation and passive monitoring are essential complements.

Found this analysis useful?

Follow the related articles in this category and round out your organization's security strategy.

Back to articles

Related articles