Organizations are taking OT security more seriously as more than half (52%) of organizations report that the CISO/CSO is responsible for OT.
This means an increase from 16% in 2022. Also, 95% of organizations report that the C-Suite is responsible for OT, up from 41% in 2022.
These are from a Fortinet based on data from a global survey of more than 550 OT professionals, conducted by a third-party research company. Survey respondents were from different locations around the world, including Singapore.
“We see this trend reflected in a notable increase in the assignment of responsibility for OT risk to the C-suite, alongside an uptick in organizations self-reporting increased rates of OT security maturity,” said Nirav Shah, SVP of products and solutions at Fortinet.
“Alongside these trends, we’re seeing a decrease in the impact of intrusions in organizations that prioritize OT security,” he said. “Everyone from the C-suite on down needs to commit to protecting sensitive OT systems and allocating the necessary resources to secure their critical operations.”
Findings show that responsibility for OT security continues to elevate within executive ranks. There has been a significant increase in the global trend of corporations planning to integrate cybersecurity under the CISO or other executives.
As accountability continues to shift into executive leadership, OT security is elevated to a high-profile issue at the board level. The top internal leaders who influence OT cybersecurity decisions are now most likely to be the CISO or CSO by an increasingly wide margin.
Also, OT cybersecurity maturity is affecting the impact of intrusions. Self-reported OT security maturity has made notable progress this year.
At the basic Level 1, 26% of organizations report establishing visibility and implementing segmentation, up from 20% in the previous year. The largest number of organizations state their security maturity is at the Level 2 access and profiling phase.
Further, adopting cybersecurity best practices is having a positive impact. In addition to the Levels of maturity affecting the impact of intrusions, it appears that adopting best practices such as implementing basic cyber hygiene and better training and awareness are having a real impact, including a significant drop in business email compromise.
Other best practices include incorporating threat intelligence, which spiked (49%) since 2024. Additionally, the report saw a significant decrease in the number of OT device vendors, which is a sign of maturity and operational efficiency.
More organizations (78%) are now using only one to four OT vendors, which indicates that many of these organizations are consolidating vendors as part of their best practices.














