Rockwell Automation has released a new report ‘Anatomy of 100+ Cybersecurity Incidents in Industrial Operations’. The global study conducted by Cyentia Institute analyzed 122 cyber security events that included a direct compromise of operational technology (OT) and/or industrial control system (ICS) operations, collecting and reviewing nearly 100 data points for each incident.
The report states that nearly 60% of cyber attacks against the industrial sector are led by state-affiliated actors and often unintentionally enabled by internal personnel (about 33% of the time).
Key findings include:
- OT/ICS cyber security incidents in the last three years have already exceeded the total number reported between 1991-2000.
- Threat actors are most intensely focused on the energy sector (39% of attacks) – over three times more than the next most frequently attacked verticals, critical manufacturing (11%) and transportation (10%).
- Phishing remains the most popular attack technique (34%), underscoring the importance of cyber security tactics such as segmentation, air gapping, zero trust and security awareness training to mitigate risks.
- In more than half of OT/ICS incidents, supervisory control and data acquisition (SCADA) systems are targeted (53%), with programmable logic controllers (PLCs) as the next-most-common target (22%).
- More than 80% of threat actors come from outside organizations, yet insiders play an unintentional role in opening the door for threat actors in approximately one-third of incidents.
- In the OT/ICS incidents studied, 60% resulted in operational disruption and 40% resulted in unauthorized access or data exposure. However, the damage of cyber attacks extends beyond the impacted enterprise, as broader supply chains were also impacted 65% of the time.






