Recent headlines have highlighted a growing reality: U.S. critical infrastructure faces an increase in cyber threats and attacks. Securing these essential networks has moved from a background concern to a daily operational priority, a shift underscored by last week's Executive Order declaring a national emergency to protect the bulk-power system.
While attacks against critical infrastructure aren’t new, they are becoming more prevalent, disruptive, and intentional. As a recent Dragos 2026 OT/ICS Cybersecurity Report and Year in Review states: “Adversaries are mapping how control systems work, understanding where commands originate, how they propagate, and where physical effects can be induced.” In other words, adversarial cyber actors are transitioning their operations solely out of cyberspace, to targets that impact and affect the real world: the local water supply, electric grid, medical care facilities, and other critical infrastructure that could significantly impact our daily lives.
While critical infrastructure security and attacks may not be as mainstream or top of mind as AI is for most people, it absolutely needs to be. AI won’t be useful when your toilets don’t have water to flush, or when your HVAC is unavailable and your datacenter is starting to overheat. These are real problems that need to be addressed before it’s too late.
Why attacks on critical infrastructure are rising #
This surge in cyber attacks against critical infrastructure is not random or purposeless, and there are multiple factors contributing to their increase:
- Ongoing geopolitical conflicts around the world
- AI tooling enabling and empowering cyber actors at all levels of expertise to conduct more sophisticated attacks
- Underfunded and understaffed operational technology (OT) system owners
- The (often accidental) convergence of IT and OT systems
The combination of these four factors is contributing to a ‘perfect storm’ for critical infrastructure and OT system owners. Due to geopolitical conflicts, adversaries are increasingly motivated to attack critical infrastructure, either positioning themselves for future exploitation, or intending to disrupt day-to-day life for their targets.
New AI tooling has made critical infrastructure and OT technologies easier to understand and target. In previous eras, these technologies were niche information silos. Now, attackers no longer need to be an expert on BACnet or Modbus; they simply feed an AI agent some markdown, point it at a target and let it find critical exposures.
When pitted against highly motivated adversaries armed with powerful AI tooling, critical infrastructure owners, who are often underfunded and under-resourced, face mounting challenges. The convergence of IT and OT systems has compounded traditional problems, enabling adversaries to jump between what used to be a separate and distinct IT and OT networks. And, in many environments, disconnecting the OT from the IT is no longer feasible. OT system owners may not control the IT infrastructure they are connecting to; IT system owners may not realize they have OT systems on their network. The net effect is that convergence has made critical infrastructure more vulnerable.
The real-world risk of IT/OT convergence #
At runZero, we conducted a recent internal survey of LAN environments, and found that every industry we evaluated has some OT floating around their addressable network space, and furthermore, nearly every industry has some fraction of that OT gear directly exposed to the internet, representing a reachable attack surface for adversaries.
Additionally, when OT organizations have security controls such as firewalls, reverse proxies, or VPN’s, that doesn’t mean the network is secure. For the past three years, about 40 vulnerabilities per year involving these network-edge technologies have appeared on the CISA KEV as exploited vulnerabilities. That includes 2026, with several months still to go. As exploits accelerate, it’s becoming increasingly difficult to truly rely on these technologies to keep your network protected.
Tips for securing your critical infrastructure #
There are quite a few steps OT and IT defenders can take to harden critical infrastructure environments which runZero is uniquely positioned to help with:
Identification of publicly accessible PLCs. The primary directive from the FBI and EPA is to remove PLCs from the public-facing internet. The only problem is that many defenders may not know that they have any PLCs on the public internet, let alone multiple, or where and how they are connected. runZero can scan both your internal and external attack surfaces to discover every PLC you have, identify where it’s connected, and tell you how many hops away it is from the internet.

Default credential discovery. Raise your hand if you’ve never changed the default password on your router? With Default Password detection, runZero can help organizations prevent cyber actors from walking right in with valid, if not default and weak, credentials.

Attack path mapping. Understanding the potential paths that adversaries could take to exploit a network, high value targets, or move laterally once inside a network is table stakes. OT and IT system owners need more than a network diagram. They need to know the weaknesses, where they lie, and how they could be exploited. runZero’s attack path mapping enables system owners to see how cyber actors could get in and where they could pivot to from that entry point.

Native identification of EOL edge devices. Unfortunately, edge security devices are consistently an initial vector that cyber actors use to gain access to a network. While the advisory doesn’t mention upgrading these devices, it should be considered best practice to do so.

runZero is already helping to protect a broad range of customers with critical infrastructure including:
- Telecommunications
- Government services
- Healthcare
- Municipal utilities
- Biotech & pharmaceuticals
- Aerospace & defense
These are complex environments, and we understand the evolving threat landscape defenders are facing today. With runZero, you can know every asset on your attack surface, uncover hidden exposures, map every attack path, and validate your segmentation integrity.
Plus, if you are responsible for a local or small municipality (or any organization with 100 assets or fewer), we offer our Community Edition completely free. If you’re ready to start a free trial of runZero today, visit: https://www.runzero.com/try/.