OT network visibility still blocked by legacy equipment

OT network visibility still blocked by legacy equipment

Big critical infrastructure operators use an average of seven different security tools, yet most of them still lack a full view of the assets on their operational technology (OT) networks. That is the main finding of a Palo Alto Networks survey of more than 1,600 security and operations leaders.

OT refers to the hardware and software that monitor and control physical processes, such as industrial machinery, power systems and production lines. Unlike office IT, much of this equipment stays in service for decades.

Seeing a device is not the same as securing it

Legacy OT is the visibility problem respondents named most often, at 52 percent. A further 42 percent say legacy equipment that cannot be patched is their single biggest cybersecurity risk.

Full visibility does not remove the problem. Among respondents who say they can see every asset, 49 percent still list legacy OT as a challenge. An inventory shows that an old controller exists, but it does nothing to bring that controller's software up to date.

"Cybersecurity in critical infrastructure today is at a dangerous point where we've connected decades-old OT to modern networks faster than we've updated the security models needed to protect them," said a VP of IT at a US manufacturer who took part in the research.

More tools, more complexity

Adding products has not closed the gaps. Fifty-nine percent of respondents say their security tools make operations more complicated, and 56 percent report that operating costs have gone up as a result.

Alert handling remains basic in many organizations. Just over half still triage alerts using a standard severity score or manually. The survey describes a familiar cycle: a new gap appears, a new tool is bought, and the stack keeps growing without a matching improvement in coverage.

Breaches and downtime

Incidents were frequent over the past year. Fifty-nine percent of respondents suffered a significant security breach in the last twelve months, and one in five was breached more than once.

The impact goes beyond data. Half of respondents list safety concerns among the consequences of incidents. Unplanned downtime costs organizations a mean of $288,563 per hour.

Response times are improving, though slowly. Fifteen percent of respondents now contain incidents within minutes using automation, compared with 10 percent a year earlier. Fifty-one percent want to reach that level within the next twelve months.

AI: high concern, low adoption

Ninety-five percent of respondents are worried about attacks powered by what the survey calls Frontier AI. Ninety-one percent expect AI-driven security tools to help them defend against such attacks.

Actual deployment lags behind those expectations. Only 19 percent use AI across four or more operational areas. That figure also covers non-security uses such as process optimization and predictive maintenance, so it overstates how much AI is being applied to defense.

IT and OT still separated

Seventy-four percent of organizations have not integrated their IT and OT security operations. Among those, 44 percent cite incompatible technology and 44 percent cite differing priorities between the two teams.

When asked what would most speed up IT and OT convergence over the next two years, 52 percent picked automated alert correlation, making it the top choice.

Our Take

The survey points to a structural problem rather than a tooling gap. Operators have invested in visibility, but the equipment they can now see often cannot be patched, and the extra products have added cost and complexity. This suggests that for many organizations the next step is less about buying and more about consolidating, compensating for unpatchable systems, and getting IT and OT teams to work from shared data.

The findings fit a wider pattern of attackers going after the systems that connect industrial and corporate networks. Recent incidents, such as Warlock ransomware hitting water and telecom operators through SharePoint flaws, and a steady stream of edge device bugs like the MikroTik RouterOS pre-auth root flaw, show how IT weaknesses can become an entry point into operational environments.

The AI numbers deserve attention too. Concern is almost universal, while real deployment is limited, echoing Microsoft's recent assessment that attackers currently lead defenders in the AI race. It is worth watching whether the share of operators containing incidents within minutes grows faster next year, and whether automated alert correlation actually narrows the IT and OT divide or simply becomes the eighth tool in the stack.