Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What were the essential IIoT security trends for 2020? Reports from that period pointed to a widening gap between industrial connectivity and security readiness: connecting operational technology (OT) to IT and internet-connected systems could improve visibility and efficiency, but it also expanded the systems and pathways defenders needed to protect. Survey responses highlighted coordination, monitoring and aging-system concerns, while security vendors reported threats involving industrial endpoints and removable media. These findings describe particular surveys and datasets—not a universal measure of industrial risk.

Why IIoT changed the security picture

Industrial Internet of Things (IIoT) connects sensors, control equipment and operational data to networks and applications. Industrial control systems (ICS) include configurations such as supervisory control and data acquisition (SCADA), distributed control systems (DCS) and programmable logic controllers (PLCs). Because these systems can affect physical processes, a cyber incident may threaten more than data confidentiality: it can interfere with visibility, control or continuity of operations.

Connectivity does not itself cause compromise. It changes the attack surface and the security requirements around industrial environments. A 2020 Lloyd’s Register Foundation foresight review discussed IIoT’s relevance to critical infrastructure, including energy, transport, buildings and manufacturing, where failures may have serious consequences. An IEEE survey and a separate review in Computers & Security also framed interconnectivity and IT convergence as important parts of the changing security context.

What the 2020 evidence reported

The figures below come from different kinds of evidence. Surveys measure what respondents said or believed; vendor telemetry records activity visible to a particular provider’s products or infrastructure. Neither should be read as a census of every industrial organization or endpoint.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Source and evidence type Population or data period Reported finding
Ponemon Institute, study sponsored by TÜV Rheinland; practitioner survey published June 15, 2020 2,258 cybersecurity practitioners across sectors including energy, manufacturing, transportation, health and life science, automotive, and oil and gas; the survey description does not state a survey geography. 63% said OT and IT security risk-management efforts were not coordinated. 47% said OT technology-related cybersecurity threats had increased in the prior year. 61% said replacing outdated and aging connected control systems was needed to minimize OT-related risks. 57% said their organization’s security operations or business continuity teams believed there would be one or more serious attacks in OT; this is a reported belief, not an observed attack probability. The study also reported that 52% identified vulnerable software as a risk, and fewer than half said they were very effective at response and containment or continuous monitoring.
Kaspersky; industrial-organization survey release, October 13, 2020 Survey population as described by Kaspersky; its release does not specify its size or geography. 55% of organizations were confident IoT would change ICS security. 20% had prioritized IIoT-related incidents; 19% reported active network and traffic monitoring, and 14% had introduced network anomaly detection.
Honeywell; industrial cybersecurity product-data report, July 8, 2020 Data from hundreds of industrial facilities, including a 12-month comparison; not a universal estimate. 45% of locations detected at least one inbound threat via removable media. The share of threats specifically targeting OT rose from 16% to 28%, while threats capable of causing loss of view or other major OT disruption rose from 26% to 59%.
Kaspersky; ICS telemetry release published March 25, 2021 Attacks observed in the second half of 2020; Kaspersky reported results globally and across examined countries and sectors. 33.4% of ICS computers were attacked globally in Kaspersky’s measure for H2 2020, an increase of 0.85 percentage points. The release also said the attacked share increased in 62% of the examined countries. These are provider telemetry results for a specific period.

How to interpret the period’s main trends

Security capability lagged the pace of connection

The contrast in Kaspersky’s survey between confidence that IoT would change ICS security and the reported adoption of monitoring and anomaly detection suggests that perceived transformation did not necessarily come with mature detection capability. Ponemon respondents also described weak coordination between OT and IT risk management, as well as constraints in continuous monitoring and incident response. These are respondent reports, not independent audits of every participant’s controls.

The aging and vulnerable software concerns matter because industrial environments may rely on connected control systems that are difficult to replace or update without operational planning. The survey findings identify the problem as respondents saw it; they do not establish how many sites had a particular unpatched vulnerability.

Endpoints and removable media remained relevant

Honeywell’s report drew attention to threats arriving through removable media, including USB devices. Its director of Cybersecurity Research and engineering fellow, Eric Knapp, said: “USB-borne malware continues to be a major risk for industrial operators.” The percentages in the table apply to Honeywell’s dataset and comparison, not to all industrial sites.

Trend Micro’s June 2021 retrospective analyzed its 2020 ICS endpoint detections through Smart Protection Network infrastructure. Its data included ransomware, coinminers, Conficker and legacy malware; the report described legacy malware spreading through removable drives. Ransomware can disrupt process visibility and control, while coinminers can consume endpoint capacity. In Trend Micro’s 2020 ICS ransomware detections, Ryuk represented 19.8%, Nefilim 14.6%, Sodinokibi 13.5% and LockBit 10.4%. Those shares describe Trend Micro detections, not the distribution of all industrial ransomware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Threat activity varied by measure and place

Kaspersky’s H2 2020 telemetry indicates that activity did not move uniformly across all sectors and examined countries. Its global attacked-computer figure is tied to the provider’s measurement and that half-year window; it should not be treated as the probability that any individual facility was attacked. The Ponemon figure about anticipated serious attacks measures respondents’ expectations, not incidents observed by Kaspersky or another telemetry provider.

Security priorities for industrial teams

The sources point to a set of complementary practices rather than a single control that can eliminate risk. Industrial operators should adapt them to safety, uptime and process constraints.

  1. Build security into IIoT projects. Assess a device’s security before deployment and consider relevant security credentials when selecting equipment. Include security requirements in design and procurement rather than treating them as a retrofit.
  2. Coordinate OT and IT ownership. Define who is responsible for risk decisions, monitoring, escalation and incident response across the teams. Train OT and IT staff so that security procedures reflect both cyber risks and operational realities.
  3. Maintain vulnerability and update processes. Track vendor vulnerability notices, software updates and patches for systems and network equipment. Plan changes with operational constraints in mind, particularly where aging or vulnerable software is involved.
  4. Monitor OT network activity. Establish traffic monitoring and methods for investigating anomalies. Plan data collection and detection around the environment’s operational constraints; a monitoring control is useful only when teams can interpret and act on its alerts.
  5. Control removable media. Set procedures for approving and scanning removable devices, and support those controls with staff training and operational process changes. Endpoint tools alone do not replace clear handling practices.
  6. Review defenses and current threats. Use regular security audits and relevant threat intelligence to reassess controls and response plans. None of the recommendations in these sources guarantees immunity from cyber risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What these trends do—and do not—show

The 2020 evidence supports a historically grounded conclusion: industrial security teams were dealing with greater connectivity alongside reported gaps in coordination, monitoring and legacy-system resilience, while provider datasets documented threats involving endpoints and removable media. The sources are not interchangeable. Ponemon and Kaspersky survey findings reflect respondent answers; Honeywell and Trend Micro describe their own product or infrastructure telemetry; Kaspersky’s H2 report is also vendor telemetry. Lloyd’s Register Foundation and IEEE provide review and synthesis rather than a direct incident count.

Accordingly, these reports are useful for understanding concerns and defensive priorities reported around 2020, but their figures should not be presented as current threat rates or generalized beyond each study’s stated population and measurement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.