Report
Protecting operations evolves as a core business capability.
Claroty presents the results of an independent global survey of 2,000 cybersecurity, technology, and business leaders responsible for the protection of operational environments. The findings shed light on their approach and how it impacts their ability to maintain business continuity, drive digital transformation, and achieve compliance for critical infrastructure.
Survey respondents emphasized a need for risk reduction in operational environments. 58% said they’d suffered a cyberattack impacting operations, and pointed out these incidents result in operational downtime, safety incidents, and financial loss.
Top Impacts From Operational Incidents:
43%
Operational Downtime
40%
Safety incidents/hazards
35%
Financial Loss
Financial Impact of CPS-Related Incidents
Approximately what was the total financial impact of cybersecurity incidents experienced by your organization?
Downtime Resulting from Operational Cyber Incidents
How much operational downtime resulted from your organization’s most significant CPS-related cyber incident?
The unification of security and risk management under a single, internal domain was cited as a key driver of digital transformation and convergence efforts. Yet only 16% of organizations claim operational security governance is fully integrated. This fragmentation may prevent business and technology leaders from obtaining a full picture of risk.
Integration of IT and Operational Security Governance
To what extent has your organization integrated IT and CPS security governance and
risk management?
Structural problems also remain around operations that include accountability and budget control over operational protection. 84% of accountability is split between the CIO/IT office (39%), the CISO and security teams (28%), and operations (17%), while a similar split is noted regarding budget control.
Ownership or Control of Operational Security Budget
Who is primarily responsible for operational security budgets within your organization?
70% of respondents said artificial intelligence (AI) is playing a role to varying degrees within operational environments, and more than 1 in 10 said they rely on AI extensively. Respondents acknowledged that while there have been largely positive impacts because of advanced technologies, there are some newly introduced risks.
Positive Impacts
48%
AI has improved operational efficiency and productivity
46%
AI has improved decision-making through automation and analytics
37%
AI has enabled new business models, products, or services
Negative or Neutral Impacts
40%
AI has introduced new cybersecurity, compliance, or operational risks
33%
AI implementation has created operational challenges, disruption, or change management issues
6%
AI has had little or no impact on our organization to date
Regulatory compliance programs continue to drive cybersecurity investments and strategies, and yet while 75% of survey respondents said they have a proactive and structured approach to compliance management, there are regulatory and operational barriers threaten overall compliance efforts and cyber insurance readiness.
Current Approaches to Managing Cybersecurity Compliance Requirements
Which of the following best describes your organization’s current approach to managing cybersecurity compliance requirements for critical infrastructure?
We have a structured approach, with defined practices to track requirements and demonstrate compliance
43%
We have a proactive approach, with automated processes to continuously monitor requirements and align controls to relevant frameworks
32%
We meet compliance requirements but rely heavily on manual processes for tracking and reporting
15%
We are working to understand and address relevant compliance requirements
8%
We do not currently have a defined approach for managing critical infrastructure compliance requirements
2%
Operationally, governance fragmentation, technical debt, and connectivity to third parties pose the biggest barriers to compliance.
Operational Compliance Barriers
What is the single biggest operational barrier to achieving full compliance across your organization’s CPS?
IT/OT alignment challenges: Gaps in skills, ownership, or collaboration between IT security and OT teams
29%
Legacy systems: Difficulty maintaining compliance for older, proprietary systems that cannot be easily patched or updated
26%
Third-party risk: Difficulty tracking and enforcing compliance requirements across hardware and software suppliers
25%
Limited visibility: Lack of a complete, real-time inventory of connected CPS/OT assets
16%
None of the above
4%
Please complete the form to view the Report.