Industrial Automation Cybersecurity Threat Landscape: Q2 2026 Analysis
Industrial Automation Faces a Changing OT Cybersecurity Landscape
Industrial automation environments faced a shifting cybersecurity landscape during Q2 2026. Kaspersky data shows that threat exposure increased across five regions during the quarter. East Asia recorded the largest increase, rising by 2.0 percentage points. Africa followed with a 0.5 percentage-point increase.These changes affect PLC, DCS, SCADA, and other industrial control systems. Moreover, connected engineering workstations create additional pathways between enterprise IT and operational technology.East Asia showed higher percentages across nearly every major threat category. The region recorded particularly strong growth in malicious scripts, phishing pages, spyware, and viruses. It also experienced the largest increase in internet-based threats.Email-based attacks also increased across ICS computers in East Asia. Therefore, organizations should treat email security as part of their broader OT defense strategy.East Asia Shows Rising Risks for Factory Automation
East Asia recorded increases across almost every measured threat category. The only exception involved miners, which did not follow the regional growth pattern.Malicious scripts and phishing pages showed especially strong growth. Spyware also increased by 0.53 percentage points during the quarter. These figures indicate growing exposure around connected industrial workstations and engineering environments.For factory automation operators, this trend deserves close attention. Engineering PCs often exchange project files, maintenance documents, and configuration data. Consequently, compromised endpoints can create indirect risks for PLC and DCS environments.From an operational perspective, organizations should isolate engineering networks from ordinary office traffic. They should also restrict unnecessary internet access from industrial workstations.Biometrics Sector Records the Highest Industry Exposure
The biometrics sector recorded the highest overall rate among the selected industries. Malicious objects reached 26.44% of ICS computers in this sector.Several operational factors may explain this result. Biometric systems often require internet connectivity and extensive email communication. Organizations may also use email for access approvals, administrative workflows, and data exchange.At the same time, some deployments operate with limited cybersecurity controls. This combination creates additional exposure for connected industrial and building automation systems.The biometrics sector ranked first for several threat categories. These included malicious scripts, phishing pages, malicious documents, spyware, ransomware, and worms.It also recorded the highest exposure to email-based threats. Notably, email threats exceeded internet threats within the biometrics sector.For industrial automation teams, this finding highlights a broader issue. Cybersecurity controls must cover both network traffic and user-driven communication channels.Industrial Automation Industries Continue to See a Downward Trend
Across the selected industries, the global average continued to decline. However, regional increases show that global averages can hide important local risks.This distinction matters for multinational manufacturers and system integrators. A company may operate plants with very different cybersecurity profiles across regions.Therefore, security teams should combine global benchmarks with plant-level monitoring. They should also assess individual OT assets, communication paths, and user access patterns.Kaspersky Detects Thousands of Malware Families
Kaspersky security solutions blocked malware from 10,904 different malware families during Q2 2026. These detections covered multiple malware categories affecting industrial automation systems.The quarterly data also showed increases in several threat categories. These included denylisted internet resources, malicious documents, worms, ransomware, and AutoCAD-related malware.The AutoCAD finding deserves attention from engineering organizations. Design departments frequently use engineering software alongside PLC, DCS, and SCADA development tools.Attackers can therefore target engineering files as an entry point into industrial environments. Organizations should scan design files before transferring them into protected engineering networks.Malicious Scripts and Phishing Pages Remain the Leading Threat
Malicious scripts and phishing pages remained the most frequently blocked threat category. However, the global percentage declined to 5.42% during Q2 2026.East Asia moved in the opposite direction. Its percentage increased by 0.93 percentage points to 4.86%.This figure represents the region's second-highest level during the past three years. The increase also affected almost every surveyed industry in the region.Construction was the only surveyed industry without an increase. Biometrics recorded the highest level at 9.01%. Building automation followed at 6.49%.These results demonstrate the importance of browser and endpoint security. Industrial workstations increasingly interact with web services, remote support platforms, and enterprise applications.For PLC and DCS environments, organizations should restrict browser access on dedicated engineering stations. They should also maintain application allowlists where operational requirements permit.Denylisted Internet Resources Move Into Second Place
Denylisted internet resources became the second-ranked threat category during Q2 2026. They moved ahead of spyware in the global rankings.The global percentage reached 4.31%, continuing a two-quarter upward trend. All measured regions recorded increases during the quarter.Russia showed the largest quarterly increase at 1.33 percentage points. It also recorded the highest regional figure at 5.17%.The region previously reached the top position in 2022 and 2024. Both previous peaks occurred during the second quarter.Within Russia, electric power recorded the highest industry figure at 6.61%. Engineering and ICS integration followed at 5.62%.These figures have particular relevance for power automation. Electric utilities operate extensive networks of protection relays, RTUs, PLCs, and control systems.Internet access should therefore remain tightly controlled around critical OT assets. Security teams should also monitor outbound connections from engineering and maintenance workstations.Malicious Documents Increase After a Three-Quarter Decline
Malicious documents ranked fourth among the measured threat categories. Their global percentage increased to 1.77% during Q2 2026.The category had declined during the previous three quarters. It therefore reached its lowest level in three years before the latest increase.Seven regions recorded quarterly growth. South America showed the largest increase at 1.35 percentage points. Southern Europe followed with a 0.48 percentage-point increase.South America ranked second globally for malicious document exposure. Its percentage reached 3.56%, representing its fourth-highest level over three years.Biometrics recorded the highest industry figure in South America at 6.67%. Southern Europe ranked first among regions at 3.63%.Biometrics again recorded the highest industry percentage in Southern Europe. Its figure reached 11.48% during Q2 2026.The trend matters for industrial engineering teams because documents can carry executable content. PDF and Microsoft Office files frequently circulate between suppliers, integrators, and plant personnel.Organizations should therefore inspect attachments before introducing them into OT environments. They should also separate document exchange systems from engineering networks whenever practical.Spyware Reaches Its Lowest Level Since 2022
Spyware ranked third among the measured threat categories. Its global percentage declined to 3.30%, the lowest level recorded since 2022.However, three regions reported quarterly increases. East Asia increased by 0.53 percentage points. Southeast Asia followed with a 0.42 percentage-point increase.East Asia reached 4.77% and ranked third globally for spyware exposure. Africa and Southeast Asia recorded higher regional figures.Mainland China recorded the highest country-level figure in East Asia at 6.61%. The electric power sector reached 11.75% within the region. Manufacturing followed at 5.87%.Every surveyed East Asian industry exceeded the regional average. This result suggests that sector-specific exposure can differ substantially from regional averages.For manufacturing plants, spyware can create risks beyond ordinary endpoint compromise. Unauthorized monitoring may expose engineering information, production data, credentials, or network details.What Q2 2026 Means for PLC and DCS Security
The Q2 2026 data highlights a key challenge for industrial automation cybersecurity. Threat levels can vary sharply between regions, industries, and individual facilities.PLC and DCS environments require particularly careful segmentation. Operators should separate enterprise IT, industrial DMZs, supervisory networks, and control networks.Remote access also requires strict authentication and monitoring. Organizations should minimize unnecessary internet connectivity around PLC programming stations and DCS engineering servers.Moreover, endpoint protection remains important even when controllers themselves run specialized firmware. Engineering workstations can provide attackers with indirect access to control environments.Practical Cybersecurity Measures for Factory Automation
Industrial organizations can strengthen OT security through several practical controls.First, maintain accurate inventories for PLC, DCS, SCADA, HMI, and engineering assets. Second, segment control networks from office and public-facing networks.Third, restrict internet access from dedicated engineering workstations. Fourth, scan email attachments and engineering documents before they enter protected environments.In addition, monitor remote-access sessions and disable unused accounts. Organizations should also apply security patches according to validated OT maintenance procedures.Network monitoring can further identify unusual outbound connections and unauthorized communication. Where supported, teams should use industrial firewalls and intrusion detection systems designed for OT environments.Application Scenario: Protecting a Multi-Plant Manufacturing Network
Consider a manufacturer operating several plants across Asia and Europe. Each facility uses PLC-based production lines and a centralized DCS for selected processes.The company allows engineers to exchange project files through corporate email. Some engineering workstations also have direct internet access for vendor support.A safer architecture would place email services within the enterprise network. An industrial DMZ could then control approved data transfers into the OT environment.Engineering workstations should receive only necessary network access. Meanwhile, PLC programming tools and DCS engineering servers should remain inside controlled OT zones.This architecture reduces the likelihood that a phishing event reaches the control network. It also limits the potential impact of compromised engineering endpoints.Expert View: OT Security Must Follow the Process Architecture
The Q2 2026 figures show that industrial cybersecurity cannot rely on a single defensive layer. Threats increasingly enter through users, documents, browsers, and network connections.In my experience with industrial control environments, engineering workstations often deserve more attention. They connect maintenance personnel, vendors, configuration tools, and control systems.Therefore, cybersecurity teams should protect the complete operational workflow. They should not focus only on PLC controllers or perimeter firewalls.A practical OT strategy combines segmentation, endpoint protection, access control, monitoring, and disciplined maintenance. It should also align with recognized industrial cybersecurity frameworks such as IEC 62443.Conclusion: Industrial Automation Needs Layered OT Protection
Q2 2026 data shows a mixed global threat picture for industrial automation systems. The global average declined in several categories, yet important regional increases continued.East Asia emerged as a major area of concern during the quarter. Meanwhile, biometrics showed the highest overall industry exposure among selected sectors.For PLC, DCS, SCADA, and factory automation environments, these trends reinforce several priorities. Organizations should control internet access, secure engineering endpoints, inspect documents, and segment OT networks.Most importantly, security teams should evaluate local plant conditions rather than rely solely on global averages. That approach provides a more realistic basis for protecting industrial control systems.
Read More
Categories:
Uncategorized
