Industrial Control Systems (ICS) power the infrastructure we depend on every day — electricity, water, transport, manufacturing, and increasingly, smart cities.
Many of these systems were engineered for safety and uptime long before cybersecurity became a primary design consideration. They were built to operate reliably for decades. And they have.
The challenge is that today’s threat environment looks very different from the one these systems were designed for.
Bryson Bort, CEO and founder of SCYTHE, often jokes that you can identify an ICS device because it is at least 20 years old. Behind the humour is a serious reality: industrial systems were not built for a world of persistent cyber threats, AI-driven reconnaissance, and global ransomware campaigns.
Why ICS Environments Remain Exposed
Tim Mackey, head of software supply chain risk strategy at Black Duck, explains that systems built using best practices of the past can easily become vulnerable as attacker capabilities evolve. What was considered secure 20 years ago may no longer withstand modern adversary techniques.
Industrial systems typically face several structural constraints:
- Long hardware lifecycles (often 20–30 years or more)
- Limited patching windows due to uptime requirements
- Outdated protocols without authentication
- Flat network architectures
- High operational risk associated with downtime
Jeff Macre, principal OT security solutions architect at Darktrace, notes that visibility is often limited. Many operators cannot easily take systems offline to upgrade or replace them. The result is an ecosystem where security improvements must coexist with aging infrastructure.
Dario Perfettibile of Kiteworks adds that the problem is not simply technical — it is economic and operational. Replacing industrial systems can cost millions per site and may require extended outages that critical services cannot tolerate.
This tension between uptime and security is not limited to utilities or national infrastructure. Many manufacturing plants, logistics hubs, healthcare facilities, and building management systems now operate under similar constraints. The ICS challenge is increasingly becoming a business-wide challenge.
Why ICS Is a Strategic Target
Industrial Control Systems attract two categories of adversaries:
- Cybercriminal groups seeking financial gain
- Nation-state actors seeking political leverage or strategic advantage
Raed Albuliwi of Xona describes critical infrastructure as a strategic target. Ransomware operators understand that operators are measured on uptime. Disruption creates pressure. That pressure creates leverage.
Meanwhile, state-aligned actors are increasingly focused on what is known as “pre-positioning” — quietly infiltrating systems to establish long-term access that can be activated during geopolitical conflict.
Michael Freeman of Armis warns that by 2026, more than a third of global energy and utilities infrastructure may have experienced pre-positioning activity. This does not necessarily mean immediate disruption. It means access is being established quietly.
Gary Schwartz of NetRise explains that supply chain infiltration is now a preferred path. Adversaries insert themselves into software and firmware pipelines, creating footholds that may appear benign during peacetime but can be weaponised later.
We have already seen real-world examples:
- Russian attacks on Ukraine’s power grid
- Reconnaissance of water systems
- OT-focused malware such as VoltRuptor
The shift is clear: attackers are investing in persistence, not just disruption.
For organisations operating industrial environments, the risk model must evolve from “Can we stop ransomware?” to “If an adversary already has quiet access, would we detect it?” Detection speed and internal visibility now matter as much as perimeter defence.
The Expanding Threat Surface
As IT, OT, and IoT environments converge, the attack surface expands. Alex Mosher of Armis notes that seemingly minor IoT devices can become entry points that allow lateral movement into operational networks.
Joe Saunders of RunSafe Security highlights another factor: AI-driven electricity demand. As data centres grow, so does dependency on energy grids and industrial systems that power them. This increases the strategic value of targeting these environments.
Jeremy Epstein of Georgia Tech Research Institute adds that new infrastructure projects, such as Small Modular Reactors, will operate for decades. Security decisions made now will persist for 30 to 50 years.
Industrial systems are no longer isolated islands. They are interconnected ecosystems.
And that changes everything.