In brief: According to the vendor, the decline in OT security maturity in the Fortinet 2026 report results from more realistic self-assessment rather than actual deterioration, while CISOs are increasingly taking on responsibility for OT cybersecurity.
The share of companies placing their OT security at the highest maturity level has fallen from 49 to 17 percent within a year, according to Fortinet. Fortinet itself does not interpret this as deterioration, but as a correction following previously unrealistic self-assessment.
For the State of Operational Technology and Cybersecurity Report 2026, Fortinet surveyed more than 700 professionals from the OT environment worldwide. The study measures the maturity of OT security programs using a five-level model ranging from Level 0 (unstructured, undocumented processes) to Level 4 (fully optimized, automated security architecture). In this year’s edition, values shift markedly toward lower levels: Level 0 rose from 1 to 5 percent, Level 1 from 5 to 17 percent, and Level 2 from 13 to 27 percent. Fortinet attributes this not to an actual worsening of the security situation, but to more joint IT and OT security teams, increased budgets, and specialized OT security solutions, which have for the first time given companies a realistic view of existing gaps.
The report is also relevant for CISOs because organizational responsibility for OT cybersecurity is shifting: 81 percent of respondents plan to transfer this responsibility to the CISO within the next twelve months — a trend that, according to the report, has now grown for the fifth consecutive year. OT security is thus increasingly becoming a matter for company leadership rather than production managers alone. At the same time, the regulatory framework in Europe is tightening: since December 2025, Germany’s NIS2 implementation act has applied without a transition period, and in September 2026 the EU Cyber Resilience Act will introduce the first binding reporting obligations for manufacturers of connected products.
The report shows progress in network visibility: 14 percent of companies report full visibility into their OT environments, up from 5 percent the previous year. At the same time, 23 percent report having visibility into only half of their own OT infrastructure — meaning nearly one in four companies is defending networks with blind spots. This gap is gaining weight as, according to the report, longer dwell times of attackers in compromised networks are increasing, while short dwell times remain stable. The longer attackers remain undetected, the more time they have for system reconnaissance, theft of intellectual property, and preparation of attacks with greater operational impact.
Among attack vectors, phishing remains the most common method of initial access at 76 percent, while ransomware continues to rank among the central threats at 50 percent. One figure stands out positively: only 24 percent of companies now report attacks affecting both IT and OT systems, down from 60 percent the previous year. Fortinet attributes this to improved network segmentation. Additionally, 89 percent of surveyed OT leaders expect rising investment in OT security within the next five years, with regulatory pressure from NIS2 and the Cyber Resilience Act serving as an additional argument for budget decisions.
Source: www.it-daily.net · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.