Only 14% of business leaders have full OT visibility - why it's time to take a more honest view of risk
Tue, 4th Aug 2026 (Today)
For many years, operational technology (OT) security was built around a straightforward principle: create a strong perimeter, control access and keep threats outside the environment. That approach made sense when operational systems were largely isolated from the rest of the business.
Today, those environments look very different. OT systems are increasingly connected to IT networks, cloud platforms, remote users and third-party providers. These connections are critical because they support greater efficiency, visibility and innovation, but they also create more pathways through which disruption can occur.
Traditional controls still matter, but they need to sit within a broader resilience strategy. Alongside preventing attacks, organisations need to identify unusual activity, contain incidents and restore operations before a cyber event becomes a prolonged business disruption. This means shifting from a mindset focused mainly on defence to one that also considers response and recovery.
A clearer picture of OT maturity
Fortinet's 2026 State of Operational Technology and Cybersecurity Report highlights a change in how organisations view their maturity.
The proportion of respondents rating their cybersecurity processes at the highest level fell from 49 percent in 2025 to 17 percent in 2026. At first glance, that could suggest organisations are moving backwards, but in practice it may reflect a more realistic understanding of their security posture.
As OT and IT teams gain better tools, experience and visibility, they often uncover gaps that were not previously apparent. Processes that looked robust on paper can appear different once system dependencies, access pathways and operational risks are examined more closely.
This can be positive. An organisation cannot address risks it has not identified, and awareness creates a stronger foundation for improvement. For New Zealand organisations, the findings are a reminder that cyber maturity depends on how controls perform in the operating environment.
Visibility creates the foundation
Visibility is one of the most important elements of OT resilience. The report found that only 14 percent of respondents had full visibility across their OT systems, while almost a quarter could see only around half of their environment.
Having visibility means more than maintaining a list of connected assets. Organisations need to understand how devices communicate, where IT and OT systems depend on one another, who has access and which systems are most important to safety, production and service continuity.
This context becomes particularly valuable during an incident. When teams understand what is connected and how operations fit together, they are better placed to recognise abnormal behaviour, determine which systems may be affected and respond without creating unnecessary disruption.
The report also found that 71 percent of respondents detected between one and nine intrusions, compared with 47 percent the previous year. While this may partly reflect increased malicious activity, it can also indicate that organisations are becoming better at identifying events that previously went unnoticed. Discovering more issues as visibility improves can be uncomfortable, but it gives teams the information they need to respond earlier.
IT and OT teams need a shared view
Visibility is most useful when it extends across the boundary between IT and OT. Many incidents that affect control systems begin elsewhere in the business, yet separate security operations can leave each team seeing only part of the path an attacker has taken.
Bringing IT and OT monitoring and response closer together provides a shared picture of an incident, along with the engineering knowledge needed to understand its implications for process safety, production and service continuity.
It can also reduce delays, as rather than passing an alert between separate teams, a coordinated approach creates a clearer escalation path and lets security and operational specialists assess cyber risk and operational impact together. The aim is to combine the strengths of both so the response protects availability and safety, as well as systems and data.
Segmentation helps limit disruption
Segmentation helps ensure that an intrusion or technical issue in one part of the environment does not automatically spread across the organisation.
The report found that 24 percent of respondents said both their IT and OT systems had been affected by intrusions, down from 60 percent the previous year. While several factors may be involved, stronger separation may be helping organisations limit the reach of incidents.
Effective segmentation should reflect how systems are used in practice. Proper zone and conduit design can restrict unnecessary communication, reduce lateral movement and allow affected areas to be isolated while other parts of the organisation continue operating.
This is particularly important in OT environments, where shutting down a system may affect safety, production or essential services. The aim is not simply to block traffic, but to give organisations greater control over containment.
Remote access requires careful management
Remote access is central to many OT environments, with external specialists, vendors and maintenance teams often needing to connect to critical systems.
Risk increases when access is broad, remains active for longer than necessary or is not closely monitored. Stronger authentication, role-based permissions, temporary access and session monitoring can reduce that risk while preserving the flexibility and expertise external providers offer.
Resilience is built over time
OT cybersecurity maturity is not defined by a single technology or by the expectation that every intrusion can be prevented. It develops through better visibility, effective segmentation, controlled access and incident response planning that reflects the realities of the operational environment.
It also relies on collaboration. Security, operations, engineering and executive teams each bring a different view of risk, and organisations are better prepared when those perspectives are brought together.
Overall, resilience comes from understanding where exposure exists, preparing for disruption and ensuring the organisation can respond and recover without losing control of critical operations. The goal is not to remove every vulnerability, but to reduce the likelihood that a single incident becomes a prolonged operational crisis.