Recent headlines have highlighted a growing reality: U.S. critical infrastructure faces an increase in cyber threats and attacks. Securing these essential networks has moved from a background concern to a daily operational priority, a shift underscored by last week's Executive Order declaring a national emergency to protect the bulk-power system.

While attacks against critical infrastructure aren’t new, they are becoming more prevalent, disruptive, and intentional. As a recent Dragos 2026 OT/ICS Cybersecurity Report and Year in Review states: “Adversaries are mapping how control systems work, understanding where commands originate, how they propagate, and where physical effects can be induced.” In other words, adversarial cyber actors are transitioning their operations solely out of cyberspace, to targets that impact and affect the real world: the local water supply, electric grid, medical care facilities, and other critical infrastructure that could significantly impact our daily lives.

While critical infrastructure security and attacks may not be as mainstream or top of mind as AI is for most people, it absolutely needs to be. AI won’t be useful when your toilets don’t have water to flush, or when your HVAC is unavailable and your datacenter is starting to overheat. These are real problems that need to be addressed before it’s too late.

Why attacks on critical infrastructure are rising #

This surge in cyber attacks against critical infrastructure is not random or purposeless, and there are multiple factors contributing to their increase:

  • Ongoing geopolitical conflicts around the world
  • AI tooling enabling and empowering cyber actors at all levels of expertise to conduct more sophisticated attacks
  • Underfunded and understaffed operational technology (OT) system owners
  • The (often accidental) convergence of IT and OT systems

The combination of these four factors is contributing to a ‘perfect storm’ for critical infrastructure and OT system owners. Due to geopolitical conflicts, adversaries are increasingly motivated to attack critical infrastructure, either positioning themselves for future exploitation, or intending to disrupt day-to-day life for their targets.

New AI tooling has made critical infrastructure and OT technologies easier to understand and target. In previous eras, these technologies were niche information silos. Now, attackers no longer need to be an expert on BACnet or Modbus; they simply feed an AI agent some markdown, point it at a target and let it find critical exposures.

When pitted against highly motivated adversaries armed with powerful AI tooling, critical infrastructure owners, who are often underfunded and under-resourced, face mounting challenges. The convergence of IT and OT systems has compounded traditional problems, enabling adversaries to jump between what used to be a separate and distinct IT and OT networks. And, in many environments, disconnecting the OT from the IT is no longer feasible. OT system owners may not control the IT infrastructure they are connecting to; IT system owners may not realize they have OT systems on their network. The net effect is that convergence has made critical infrastructure more vulnerable.

The real-world risk of IT/OT convergence #

At runZero, we conducted a recent internal survey of LAN environments, and found that every industry we evaluated has some OT floating around their addressable network space, and furthermore, nearly every industry has some fraction of that OT gear directly exposed to the internet, representing a reachable attack surface for adversaries.

Additionally, when OT organizations have security controls such as firewalls, reverse proxies, or VPN’s, that doesn’t mean the network is secure. For the past three years, about 40 vulnerabilities per year involving these network-edge technologies have appeared on the CISA KEV as exploited vulnerabilities. That includes 2026, with several months still to go. As exploits accelerate, it’s becoming increasingly difficult to truly rely on these technologies to keep your network protected.

Tips for securing your critical infrastructure #

There are quite a few steps OT and IT defenders can take to harden critical infrastructure environments which runZero is uniquely positioned to help with:

  • Identification of publicly accessible PLCs. The primary directive from the FBI and EPA is to remove PLCs from the public-facing internet. The only problem is that many defenders may not know that they have any PLCs on the public internet, let alone multiple, or where and how they are connected. runZero can scan both your internal and external attack surfaces to discover every PLC you have, identify where it’s connected, and tell you how many hops away it is from the internet.

  • Default credential discovery. Raise your hand if you’ve never changed the default password on your router? With Default Password detection, runZero can help organizations prevent cyber actors from walking right in with valid, if not default and weak, credentials.

  • Attack path mapping. Understanding the potential paths that adversaries could take to exploit a network, high value targets, or move laterally once inside a network is table stakes. OT and IT system owners need more than a network diagram. They need to know the weaknesses, where they lie, and how they could be exploited. runZero’s attack path mapping enables system owners to see how cyber actors could get in and where they could pivot to from that entry point.

  • Native identification of EOL edge devices. Unfortunately, edge security devices are consistently an initial vector that cyber actors use to gain access to a network. While the advisory doesn’t mention upgrading these devices, it should be considered best practice to do so.

runZero is already helping to protect a broad range of customers with critical infrastructure including:

  • Telecommunications
  • Government services
  • Healthcare
  • Municipal utilities
  • Biotech & pharmaceuticals
  • Aerospace & defense

These are complex environments, and we understand the evolving threat landscape defenders are facing today. With runZero, you can know every asset on your attack surface, uncover hidden exposures, map every attack path, and validate your segmentation integrity.

Plus, if you are responsible for a local or small municipality (or any organization with 100 assets or fewer), we offer our Community Edition completely free. If you’re ready to start a free trial of runZero today, visit: https://www.runzero.com/try/.

Written by Colin Dupreay

Colin is a Federal Solutions Engineer at runZero. With almost a decade of experience supporting Public Sector customers, Colin is passionate about protecting and securing our nations networks.

More about Colin Dupreay
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
runZero 5.1 is here: Secure AI workflows, enhanced integrations, and expanded autonomous discovery
runZero 5.1 takes on the heavy lifting across five key areas, enabling you to unmask and remediate exposures with less friction and more speed.
Podcasts
Know Your Adversary with HD Moore
runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
runZero Hour, Ep. 33: Hacker Summer Camp: we survived the Vegas heat (and the bugs)
In this post-Hacker Summer Camp recap, the runZero team break down the research, tools, and trends discussed at BSides Las Vegas, Black Hat and DEF...
Podcasts
The Internet's biggest point of failure
Join Tod Beardsley on Secure & Scale as he explores the future of vulnerability management, CVE fragmentation, and how AI is changing security...
Webcasts
Mind the gaps: securing the modern IT/OT attack surface
In this webcast, HD Moore and GigaOm Analyst Chris Ray discuss key methods for hardening OT defenses and share insights from the new OT report.
Webcasts
runZero Hour, Ep. 32: AI-pocalypse now? Why the 2026 DBIR is actually good news
In this episode of runZero Hour, Tod Beardsley, Brianna Cluck, and Verizon's Alex Pinto broke down 2026 DBIR trends, AI threats, and runZero 5.0.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.