46% of Industrial Companies Suffered a Cyber Incident, and 90% Are Confident They Can Recover

Industrial cybersecurity concept illustrating IT/OT connected factory risk

Nearly half of the industrial organizations surveyed by Rockwell Automation suffered at least one cybersecurity incident over the past year, but nine out of ten say they are confident in their ability to contain or recover from one. The study reveals a paradox in connected factories: companies are increasing their cybersecurity investment even as exposure grows from artificial intelligence, the convergence of information technology and operational technology (IT/OT), and the number of connected systems.

Industrial cybersecurity in 20 seconds

  • 46% suffered a cybersecurity incident in the past 12 months.
  • 90% are confident they can prevent, contain or recover from an attack.
  • 62% have already invested in cybersecurity platforms.
  • 45% plan to use artificial intelligence and machine learning in cybersecurity over the next 12 months.
  • 35% consider cybersecurity one of the main external obstacles to growth.

The data comes from the report Operational Resilience in the Age of Connectivity, produced by Rockwell Automation based on a survey conducted by Sapio Research among leaders of industrial organizations in 17 countries. The report’s methodology covers 1,560 participants, from various management levels up to senior leadership and across sectors such as food and beverage, automotive, semiconductors, energy and life sciences.

The study paints a picture in which cybersecurity is no longer limited to protecting computers and corporate networks. The connection between industrial systems, sensors, machines, applications and data platforms means that any new connection point can also become a new dependency — the same challenge Rockwell has been addressing on the product side with its SecureOT portfolio for industrial environments.

Industry is investing more, but exposure is also growing

62% of the surveyed organizations have already invested in cybersecurity platforms, including asset inventory systems, intrusion detection and secure remote access. The report also ranks cybersecurity as the second-highest technology category in perceived return on investment over the past 12 months.

That figure contrasts with the 46% who say they suffered an incident during the same period. The gap between the two numbers is one of the study’s main findings: investing in tools doesn’t automatically mean having operational resilience.

The report devotes much of its analysis to that gap. An organization can have protection systems in place and still struggle to know which assets are connected, which ones carry greater exposure, or how to recover a facility after an attack.

The survey also places cybersecurity among the main external obstacles to growth. The figure appears as 35% in the report’s infographic, while the narrative text on another page cites 34%. In both cases, the conclusion is the same: roughly one in three participants identifies cyber risk as one of the biggest external barriers to growth over the next 12 months.

The report notes that the main challenge isn’t a lack of awareness about the problem. Industrial companies understand the impact an incident can have on continuity, productivity and the business. The difficulty lies in protecting operations that increasingly depend on more connections.

IT and OT: more connection, more points to protect

The convergence between IT and OT emerges as one of the study’s central themes.

IT covers the systems traditionally used to manage information and business processes. OT, or operational technology, comprises the systems that control and monitor physical and industrial processes. The separation between the two worlds has been narrowing as factories adopt connectivity, data analytics, remote access, automation and artificial intelligence.

According to the report, IT/OT integration points rank among the areas considered most vulnerable to incidents, behind only IT systems and corporate networks.

The problem isn’t just the possibility of an attacker accessing a system. An intrusion that starts on a corporate network can end up affecting industrial systems when connections exist between the two environments.

The report explains that each additional connection creates a new dependency, and each dependency can introduce a point of exposure. This particularly affects facilities that combine modern equipment with legacy systems, devices connected through industrial networks, and temporary or remote-access connections.

The infographic on page 3 itself places protecting the IT/OT architecture among companies’ priorities: 37% believe securing that architecture will generate positive business outcomes over the next five years.

Cybersecurity thus becomes part of how operations are designed, not just a set of tools installed afterward.

Artificial intelligence also enters the defense

Artificial intelligence appears in the study both as a source of new dependencies and as a tool for improving protection.

45% of participants say they plan to use artificial intelligence and machine learning in cybersecurity initiatives over the next 12 months. The report ties this goal to improving detection, monitoring and risk management capabilities.

AI adoption is also increasing within industrial operations. This means production systems generate and use more data, and that data flows among a growing number of assets, users, devices and applications.

The question remains the same: more analytical capability can bring advantages, but it also increases the number of elements that need protecting.

The report suggests organizations are moving away from treating cybersecurity as an initiative isolated within the IT department. The trend it identifies is integrating protection into digital transformation strategies alongside automation, cloud, artificial intelligence and connected operations — consistent with an earlier Rockwell survey in which 61% of manufacturing cybersecurity professionals said they planned to adopt AI to strengthen protection.

Resilience starts with knowing what’s connected

One of the report’s most concrete sections focuses on asset inventory. Rockwell Automation points out that limited visibility is one of the common obstacles to improving resilience.

An organization may have legacy systems, devices connected through industrial networks, poorly documented equipment or temporary connections. Without a complete inventory, it becomes harder to determine which assets are exposed and which are critical to keeping production running.

The report proposes using that information to prioritize security actions based on operational impact rather than solely on the technical severity of a vulnerability.

The same logic applies to vulnerability management. The report suggests companies should prioritize fixing risks based on which systems could affect production, reduce the time needed to resolve issues, and use standards such as NIST, NIS2 and IEC 62443 as references for structuring their security programs.

It also highlights continuous monitoring. The goal is to detect anomalous behavior and threats before they cause a disruption, complementing that monitoring with predefined response and recovery procedures.

On page 5 of the report, Rockwell breaks these capabilities into four areas: asset inventory and lifecycle, risk and vulnerability management, managed detection and response, and incident response and recovery.

The last of these is especially relevant for industrial environments. Detecting an attack isn’t enough if there’s no capacity afterward to quickly restore critical systems. The report suggests response procedures should be tested and should coordinate IT, OT and operations teams.

The ultimate goal isn’t to promise that a factory can avoid any incident. It’s to ensure that an attack doesn’t paralyze for a prolonged period an operation that increasingly depends on digital systems.

The report itself sums up that idea on its last page: industrial cybersecurity is no longer just about protecting assets, but about the ability to sustain operations, recover them, and keep generating value after a disruption.

Frequently asked questions

How many industrial organizations suffered a cyber incident?

46% of participating organizations said they had suffered a cybersecurity incident in the 12 months prior to the survey. The study gathered responses from 1,560 participants across 17 countries.

What percentage of companies are confident they can recover from an attack?

90% say they are confident in their ability to prevent, contain or recover from a cybersecurity incident.

How is industry using artificial intelligence in cybersecurity?

45% of the surveyed organizations plan to apply artificial intelligence and machine learning to cybersecurity initiatives over the next 12 months, mainly to improve detection, monitoring and risk management.

Why does IT/OT convergence increase risk?

The connection between business systems and industrial systems widens the points of communication and can let a threat that starts in one environment affect the other. The report ranks IT/OT connections among the areas most vulnerable to incidents.

Scroll to Top