CIOs should treat operational technology (OT) and cyber-physical systems (CPS) security as a business-resilience issue: identify what an incident could interrupt, prioritize exposures by their effect on essential processes, and make IT, security, and operations jointly accountable. A cyber incident in these environments can mean more than lost data or unavailable IT services; it can disrupt production, patient care, or building operations, and may create safety hazards.
Why operational security belongs in resilience planning
OT and CPS connect digital systems to physical processes. The consequence of a compromise therefore depends on what the affected systems do: a production line may stop, a healthcare process may be disrupted, or a facility may be unable to operate as expected. CIOs need to connect security decisions to those outcomes rather than treating vulnerability reduction as an end in itself.
In an October 6, 2026 article sponsored by Claroty and authored by Sean Tufts, Claroty’s Field CTO, Tufts wrote: “As more business-critical systems move online, CIOs need to understand what a cyber incident could disrupt, not just which assets are vulnerable.” The framing is useful for executive planning, but the evidence cited alongside it should be read in context.
Claroty said it partnered with Sapio Research on a global survey of 2,000 full-time business and technology leaders across 16 industries and more than 40 countries. Respondents were involved in technology purchasing or implementation as decision-makers, members of decision-making teams, or influencers. The figures below are vendor-commissioned survey results, not independently verified estimates of how often incidents affect all organizations.
What the 2026 survey reported
Claroty’s October 6, 2026 announcement reported the following responses about operational security experiences and impacts over the prior 12 months:
#1 Best Overall
| Survey finding | Reported result |
|---|---|
| Respondents whose organization experienced a cyberattack affecting operational environments | 58% |
| Average operational downtime reported for a CPS cyber incident | Three days |
| Average financial loss reported for an incident affecting operations | $1.04 million |
| Respondents who selected safety incidents or hazards among operational-incident impacts | 40% |
| Respondents reporting at least one operational incident related to third-party access | 75% |
| Respondents identifying CIOs or IT organizations as primarily accountable for CPS security | 39% |
These are survey responses, not causal findings or universal incident rates. Claroty’s sponsored article also said 16% of respondents described IT and operational security governance as fully integrated, while 49% had partial or no monitoring of third-party connections. Those figures likewise describe the survey as presented by Claroty; they should not be generalized beyond its respondents.
Priority 1: Understand the operational consequences
Start by asking what would stop, degrade, or become unsafe if a connected asset were compromised or unavailable. Build an inventory of operational assets and connect each one to the processes it supports, its owner, its dependencies, and the access paths that reach it. A device list without process context cannot tell leaders which failures matter most.
Map assets to essential processes
- Identify connected OT and CPS assets, including systems managed by operations, facilities, or external service providers.
- Record who owns each asset and which production, care, or facility function depends on it.
- Document dependencies and communications with other assets, networks, and business services.
- Describe plausible consequences of loss of availability, unauthorized changes, or unsafe operation in terms operations leaders recognize.
Use this map to bring operational consequences into risk discussions alongside data loss and IT service availability. The relevant impact will differ by organization and process, so the people responsible for running those processes need to help define it.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
Priority 2: Prioritize exposures by operational impact
A vulnerability count alone is not a remediation plan. A flaw on an isolated asset may present a different operational risk from an exposure on a system that supports a critical process, communicates with other systems, or is reachable through a third party. Correlate vulnerability information with asset criticality, connections, access, and the process at stake before deciding what to address first.
Use context to set remediation order
- Establish criticality: determine which process depends on the asset and what interruption or unsafe behavior could result.
- Trace exposure: identify network communications, remote access paths, and who can reach or change the system.
- Assess the available response: consider whether the exposure can be reduced through access restrictions or other controls while a safe maintenance window is planned.
- Coordinate changes: agree on remediation timing with operations owners and validate that the change will not create a greater operational risk.
Legacy protocols, long system lifecycles, and limited maintenance windows can make immediate patching disruptive or impractical. That does not make an exposure irrelevant; it means leaders should evaluate mitigations and remediation timing against the system’s actual operational role rather than assume every fix can be applied at once.
Priority 3: Bridge IT and operational governance
Security responsibilities often cross organizational lines. IT and security teams may manage networks and controls, while operations teams own the processes that must remain safe and available. A shared view of assets, exposures, and recovery responsibilities gives those teams a basis for making decisions together.
Manage third-party access as a critical connection
Vendors may need remote access to maintain or support operational systems. Treat each such connection as an entry path into a critical environment: define who may connect, what they may reach, and how access is governed and monitored. Claroty’s sponsored article reported that 49% of its survey respondents had partial or no monitoring of third-party connections, and its survey announcement said 75% reported at least one operational incident related to third-party access. These vendor-commissioned responses underscore why third-party access belongs in operational risk discussions, but do not establish that access caused every reported incident.
Make continuity and recovery an IT-operations responsibility
Include OT and CPS in continuity and recovery planning, not just conventional IT services. Agree in advance who makes decisions during an incident, which operational processes take priority, and how restoration will be coordinated between IT, security, and operations. The plan should reflect the dependencies and consequences identified in the asset inventory, so recovery choices account for physical operations as well as digital systems.
Rank #4
How CIOs can turn the priorities into an operating model
Use a recurring cross-functional review to keep the inventory, exposure priorities, access controls, and recovery plans connected. A practical agenda is to review changes to critical assets and dependencies, examine the highest-consequence exposures, confirm third-party access arrangements, and resolve gaps in decision ownership. Assign follow-up actions to named IT, security, and operations owners.
When evaluating a security approach, focus on whether it provides useful visibility into assets and processes, supports exposure prioritization, helps govern third-party access, fits the organization’s existing IT/OT practices, and can be implemented without introducing unacceptable operational risk. Consider deployment requirements as part of that assessment. These are evaluation criteria, not product test results or an endorsement of a particular vendor.
Quick Recap
Sources
- CIO, “Close the operational security gap: 3 priorities for CIOs,” sponsored BrandPost, October 6, 2026.
- Claroty, survey announcement and methodology for “The Global State of Operational Security 2026,” October 6, 2026.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

