Connected FM: A Blog by IFMA

The Top Cyber Threats to Industrial Control Systems in 2026

Written by Fabian Sandoval | 25 August 2026

Industrial control systems used to feel like somebody else’s problem. The refinery team worried about them. The utility operator owned them. The plant engineer handled the weird acronyms.

In 2026, that separation feels pretty fake. If you oversee facilities with building automation, power infrastructure, water systems, manufacturing assets, or distributed sites, ICS risk is sitting much closer to your desk than it used to.

The biggest shift isn’t just technical. It’s practical. Cyber incidents are now showing up as downtime, locked-out operators, broken remote visibility, and stressed teams trying to keep real environments running while security catches up.

The breach still starts where people feel safest

A lot of teams still picture an ICS attack as someone directly “hacking the controller.” Sometimes that happens, but the more common route is much less dramatic. The compromise starts in regular IT, with stolen credentials, remote access abuse, a weak vendor connection, or a workstation that never should’ve been trusted as much as it was. TXOne’s 2026 OT/ICS report says 96% of OT security incidents originate from IT-level compromises, which tells you exactly where the real front door often is.

That matters for facility leaders because the attack path rarely respects org charts. Finance has one network problem, a contractor laptop gets reused somewhere it shouldn’t, an engineer signs in remotely, and suddenly, the issue isn’t “cyber” in the abstract anymore. It’s a controls problem. It’s an operations problem. It’s the kind of problem that turns maintenance schedules, safety checks, and tenant comfort into collateral damage.

Internet-exposed controllers are still an open invitation

One of the most frustrating things about ICS security in 2026 is how many incidents still trace back to exposures that should’ve been closed years ago. On April 7, 2026, the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warned that foreign-affiliated actors were actively targeting internet-exposed PLCs across U.S. critical infrastructure. The advisory says the actors intended to cause disruption, including manipulating project files and changing what operators saw on HMI and SCADA displays.

That warning didn’t land in a vacuum. Censys said it identified 5,219 internet-exposed Rockwell Automation and Allen-Bradley hosts globally, with 74.6% of that exposure in the United States. Even more revealing, the data showed a heavy concentration on cellular carrier networks, which points to field-deployed devices using cellular modems as their path to the internet. That’s exactly the kind of quiet convenience that becomes a loud liability during an incident.

This is why “remote visibility” needs a harder look in 2026. Plenty of facilities love the convenience of checking assets off-site, annotating data in a careless manner, or letting third parties troubleshoot quickly.

But exposed PLCs, fragile remote access setups, and internet-facing HMIs are still one of the easiest ways to turn a maintenance shortcut into a security event. CISA has repeatedly warned that even unsophisticated actors can exploit internet-accessible OT and ICS devices when basic hygiene is missing.

Ransomware and destructive malware aren’t staying in IT lanes

For years, some teams talked themselves into believing ransomware was mostly an office-side headache. Annoying, expensive, disruptive, sure, but still separate from the physical process. That distinction keeps looking weaker.

Dragos says ransomware groups with reach into OT environments surged in its 2026 reporting, and its Year in Review says industrial organizations are dealing with significant operational disruption tied to these threats. This isn’t just about encrypted file shares anymore.

The Poland energy sector incident from late December 2025 is a sharp reminder of what “operational impact” really means. CERT Polska says coordinated attacks hit more than 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant supplying heat to nearly half a million customers.

The attackers damaged RTUs, disrupted communications with the distribution operator, used wiper malware, and pursued destructive outcomes rather than simple nuisance access.

The most dangerous actors are learning how your process works

The threat that should make every ICS owner pause isn’t only exposure. It’s patience. Dragos says adversaries have moved beyond simple prepositioning and are now mapping control loops and learning how industrial processes can be manipulated for real-world effect.

That’s a different class of threat. It means attackers aren’t satisfied with getting in. They’re studying what matters, what breaks cleanly, what alarms first, and what operators will trust when a screen says everything’s fine.

The Poland incident again shows why that matters. CERT Polska says the attack on the combined heat and power plant was preceded by long-term infiltration and theft of sensitive operational information, which then helped the attacker gain privileged access and move freely across systems.

That’s not smash-and-grab behavior. That’s preparation. It’s the kind of campaign that rewards weak asset inventories, poor segmentation, and teams that still don’t have a reliable picture of what’s actually connected.

And the visibility problem is still brutal. Dragos says only 30% of OT networks have visibility, 56% can’t see below the IT/OT boundary, and 88% struggle with detection and response.

At the same time, CISA continues issuing ICS advisories, while Nozomi’s February 2026 research highlights fresh disclosures involving products such as CODESYS and Phoenix Contact in March 2026. So the last threat on this list is the one underneath all the others: defenders still can’t see enough, fast enough, in environments where new weaknesses keep appearing.

Why this matters for facility managers

The top cyber threats to industrial control systems in 2026 aren’t scary because they’re futuristic. They’re scary because they’re practical. Stolen credentials, exposed controllers, weak remote access, ransomware spillover, and patient adversaries studying physical processes all hit the places facility teams rely on most.

That’s why ICS security now belongs in the same conversation as uptime, resilience, vendor management, and business continuity. The facilities that do best this year won’t be the ones that panic. They’ll be the ones that finally treat visibility and segmentation like operational necessities.