← All articles

· Rimon Soliman

Rockwell: 46% of Industrial Organizations Suffered a Cyber Incident

New Rockwell Automation research, reported on October 8, 2026, shows a gap between incidents experienced and confidence in containing them. As AI and IT/OT convergence advance, integration points become the real front line to defend.

cybersecurityIT/OTAIPLC/SCADAresilience

On October 8, 2026, Industrial Cyber reported the findings of new Rockwell Automation research titled "Operational Resilience in the Age of Connectivity". This article is based on the publication's coverage, not on Rockwell's original report, which I have not reviewed directly.

The key numbers

According to the report:

  • 46% of industrial organizations had a cyber incident in the past year;
  • yet 90% say they are confident they could contain one;
  • 34% name cybersecurity among the biggest external obstacles to growth over the next 12 months, second only to staff shortages (the article cites 35% in one place, so the exact figure is uncertain);
  • 62% have already invested in security platforms such as asset inventory, intrusion detection and secure remote access;
  • 45% plan to use AI/ML for cybersecurity in the next 12 months.

The most interesting finding is the gap between actual incidents and stated confidence: almost one company in two has had an incident, yet nine in ten believe they can handle one. From the available information alone we cannot say how well founded that confidence is, but it is a signal worth taking seriously.

Security as a business issue

The research describes cybersecurity as the second-highest return-on-investment factor among technologies, with respondents placing it among the highest-ROI areas over the past 12 months. In addition, 37% believe that securing the IT/OT architecture will deliver positive business results over the next five years. Rockwell frames the topic as part of operational performance rather than a separate IT project.

IT/OT convergence and AI widen the attack surface

IT/OT integration points rank among the most vulnerable areas, right after IT systems and corporate networks. Rockwell's message is that every connection creates a new dependency and a new point of exposure.

For those working with PLCs and SCADA, the link is direct: AI agents, data pipelines and cloud connections add links to environments that were often designed to be isolated. Incidents tend to concentrate precisely at these interfaces.

Rockwell's recommendations

The reported recommendations are:

  • asset visibility, including legacy systems, serially connected devices and temporary connections: poor visibility is cited as one of the most common barriers to resilience;
  • risk-based vulnerability management, with priorities set by operational impact and not only by severity;
  • secure architecture;
  • continuous monitoring;
  • tested incident response and recovery;
  • ongoing asset lifecycle management.

What to do before adding AI integrations

A pragmatic order of work emerges from this picture. Before connecting new AI components to a plant, it makes sense to:

  • build a complete asset inventory, including temporary connections and older equipment;
  • map the IT/OT interfaces: who talks to whom, over which paths and with what privileges;
  • actually test recovery, rather than merely documenting it.

Caveats when reading the data

This is vendor-commissioned research that also promotes Rockwell's own approach. In the text of the article I read, neither the sample size nor the methodology was given, and the final part of the piece was not available, so some content may be missing. The percentages should therefore be treated as indicative, more useful as a direction than as a precise measurement.

Every connection added, AI included, is one more dependency to understand and protect.