If replacing aging industrial systems is unrealistic in the short term, how should organisations respond?
The answer emerging across experts is clear: resilience must become operational, continuous, and identity-driven.
Trevor Dearing of Illumio suggests going beyond resilience toward “anti-fragility” — systems that improve after stress rather than merely surviving it.
Identity as the Core Control Layer
A recurring theme across industry leaders is identity.
James Maude of BeyondTrust emphasises that organisations must tightly manage privileged access. Employees, contractors, and vendors should have only the permissions necessary to perform their tasks — nothing more.
Brian Reed of Corsha points to automated machine identity and continuous authentication as scalable controls for industrial environments.
Zero trust principles are increasingly being adapted for OT. Agnidipta Sarkar of ColorTokens recommends microsegmentation to prevent lateral movement and passwordless authentication to reduce credential misuse.
In many modern breaches, the initial entry point is not a sophisticated exploit — it is compromised credentials. In ICS environments, where a single privileged account can influence physical processes, identity governance becomes mission critical.
Continuous Threat Exposure Management
Carlos Buenano of Armis describes Continuous Threat Exposure Management (CTEM) as becoming central to OT security.
Instead of periodic vulnerability scanning, CTEM prioritises exposures based on operational and safety impact. It aligns cybersecurity risk with physical process risk.
This is a significant shift. In ICS, not all vulnerabilities are equal. A low-scoring vulnerability in a safety-critical controller may be more dangerous than a high-scoring one in a peripheral system.
Industrial environments require contextual risk prioritisation. Security teams must understand operational impact, not just CVSS scores. Bridging the knowledge gap between IT security and operational engineering is essential.
The Role — and Limits — of AI
Artificial intelligence is increasingly used for:
- Passive anomaly detection
- Behavioural baselining
- Physical access monitoring
- Real-time alert prioritisation
Darktrace’s Jeff Macre notes that AI-driven anomaly detection can safely operate in fragile ICS networks, reducing false positives and helping teams focus on actionable events.
However, Gary Schwartz cautions that anomaly detection only identifies symptoms after compromise manifests. It does not eliminate supply chain risk.
Bryson Bort warns that security tools themselves introduce risk if they rely heavily on internet connectivity.
AI enhances detection and response — but it is not a cure-all.
AI should be deployed as an augmentation tool, not an automation replacement. Human oversight remains essential, particularly in environments where physical safety is involved.
Two Immediate Priorities for 2026
Experts identify two urgent needs:
- Complete and continuous asset inventory
- Workforce development and cross-discipline training
Christian Terlecki of Armis stresses the importance of continuous CPS discovery — understanding not just what devices exist, but what their operational role is and how they interconnect.
Sam Maesschalck of Immersive highlights workforce upskilling. IT and OT teams must collaborate, and realistic scenario-based exercises must become standard practice.
Technology without trained personnel creates a false sense of security. Organisations investing in OT-specific training and joint IT–OT exercises will mature faster than those relying solely on tools or external assessments.
The Road Ahead
ICS security will not be solved with a single technology, vendor, or compliance checklist.
It requires:
- Identity-centric access control
- Microsegmentation
- Continuous exposure management
- Supply chain transparency
- AI-assisted monitoring
- Skilled and coordinated teams
Jeremy Epstein reflects that cybersecurity professionals often feel pessimistic because threats evolve faster than defences. But steady improvement is possible.
Industrial systems were built for durability. Now they must be secured for adaptability.
The goal is not to eliminate all risk — that is unrealistic in critical infrastructure. The goal is to reduce dwell time, contain compromise quickly, and maintain operational continuity under pressure.
Cybersecurity for ICS in 2026 is no longer about prevention alone.
It is about visibility, validation, and resilience — continuously tested.