THREAT BRIEFING · 22.09.2026 DEENFRES

Practice & Implementation

OT Security: 119 Ransomware Groups Target Industrial Facilities

By Benedikt Langer · March 14, 2026 · 8 min read

119 active ransomware groups are now specifically targeting industrial facilities – 49 percent more than last year. Dragos has identified three new threat actor groups specializing in operational technology: Sylvanite, Azurite, and Pyroxen. At the same time, Forescout reported a record high of 508 ICS advisories disclosing 2,155 vulnerabilities in 2025. For operators of critical infrastructure, OT security is no longer optional – it’s a matter of survival.

Key Takeaways

  • 🏭 119 ransomware groups focused on industry, up 49% from last year (Dragos, 2025).
  • ⚠️ 508 ICS advisories with 2,155 vulnerabilities in 2025 – the highest number ever recorded (Forescout).
  • 🔍 3 new OT threat actor groups identified: Sylvanite, Azurite, and Pyroxen (Dragos).
  • 💥 Over 60 hacktivist groups become active within hours of geopolitical escalations.
  • 🛡️ IT-to-OT pivoting is the growing primary attack vector – network convergence without protection.

The Threat Landscape: More Groups, More Vulnerabilities, More Attacks

The latest OT/ICS report from Dragos paints an alarming picture. The number of ransomware groups specifically targeting industrial organizations has risen to 119 – 49 percent more than the previous year. These are no amateurs: the three newly identified groups, Sylvanite, Azurite, and Pyroxen, demonstrate a level of sophistication that even seasoned OT security experts find concerning. Related reading: OT Security 2026.

Sylvanite focuses on energy providers in Western Europe. Azurite targets manufacturing companies with connected SCADA systems. Pyroxen specializes in logistics and transportation infrastructure. All three use IT networks as entry points and then move laterally into OT environments. The pattern is consistent: compromised VPN access or phishing in IT, followed by pivoting through unsecured gateways into production control systems.

“The convergence of IT and OT creates efficiency – but also an attack surface that many industrial organizations still don’t fully understand. The boundary between these two worlds is often the weakest link.”

Dragos OT/ICS Year in Review, 2025

IT-to-OT pivoting: Why classic segmentation isn’t enough

Most industrial companies installed a firewall between IT and OT at some point and considered the job done. Reality tells a different story: remote maintenance access for machine manufacturers, historian servers streaming production data to the cloud, ERP connections to the manufacturing control system. Each of these links is a potential attack vector.

The Purdue Model (the classic reference architecture for OT segmentation) calls for strict layer separation: Enterprise (Level 4–5), DMZ (Level 3.5), Manufacturing Operations (Level 3), Control (Level 2), Field (Level 0–1). In practice, most organisations never implemented this separation cleanly or have eroded it over the years.

Forescout reports that 38 % of OT vulnerabilities lie in Levels 3 and 4 – exactly the zone that should act as the DMZ. In other words, even companies with OT segmentation often fail to protect the very layer that is supposed to buffer IT from OT.

119
Ransomware groups (industrial)

2.155
ICS vulnerabilities (2025)

+49 %
Increase in attacker groups YoY

Hacktivism: When geopolitics becomes an operational disruption

A new threat vector is intensifying the risk: hacktivism targeting industrial facilities. Dragos documents that within hours of geopolitical escalations more than 60 hacktivist groups swing into action. Their targets: SCADA systems, waterworks, power utilities. The attacks are technically simple – default credentials, exposed HMIs – but the impact is real: operational downtime, data exfiltration, public embarrassment.

For German industrial companies this is relevant because hacktivism does not discriminate by company size or sector. A mid-sized supplier with an unprotected PLC on the public internet can be hit just as easily as a DAX-listed conglomerate. The KRITIS umbrella act and NIS2 sharpen liability: operators of critical infrastructure must prove they have implemented adequate protective measures.

What industrial companies need to do now

Step 1: Asset inventory of the OT environment (immediately). You cannot protect what you do not know. Catalog every device in the OT environment: PLCs, HMIs, historian servers, network switches, remote-maintenance links. Passive scanning tools such as Claroty, Nozomi Networks or Dragos Platform map OT networks without disrupting operations.

Step 2: Secure every IT/OT transition (this week). Every data path between IT and OT must be guarded by a dedicated firewall with whitelist rules – no “any-to-any” policies. Remote-maintenance access only via jump hosts with MFA. Audit vendor VPNs and set strict time limits.

Step 3: Deploy OT-specific monitoring (1–3 months). Standard IT SIEMs do not understand OT protocols (Modbus, S7, DNP3). Install OT monitoring with anomaly detection. Claroty, Nozomi and Dragos offer solutions that parse industrial protocols and flag anomalous communication patterns.

Step 4: OT incident-response plan (1–3 months). An IT incident-response plan is useless when the production line is down. OT IR prioritises safety over data confidentiality. Define who can trigger an emergency stop, how manual production continues, and how control systems are restored from clean backups.

The Counterargument: OT Security Is Expensive and Slows Production

Many industrial companies resist OT security projects. The objections: passive scans can still disrupt controls, firewalls between IT and OT slow data flows, and the cost of OT monitoring platforms (€50,000 to €200,000 per year) is significant for mid-sized firms.

The response to these concerns is straightforward: what’s the cost of a production outage? ThyssenKrupp estimated its 2022 cyber incident at a double-digit million-euro sum. Norsk Hydro lost more than €70 million to ransomware in manufacturing in 2019. Investing in OT security is a fraction of the potential damage. And passive monitoring solutions demonstrably do not affect production operations.

Conclusion: OT Security Is the Next Mandatory Discipline

119 ransomware groups, 2,155 ICS vulnerabilities, three new attacker groups specialising in industrial targets. The threat landscape for operational technology has never been more serious. NIS2 and the KRITIS umbrella law make OT security a CEO-level obligation. If you lack an asset inventory today, no IT/OT segmentation, and no OT monitoring, you’re walking straight into the next incident. The first step costs nothing: compile a list of every device and connection in the OT environment. Step two: audit remote-access pathways. Both are achievable within a week.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

We’re not a KRITIS operator. Does OT security still apply to us?

Yes. Ransomware groups don’t distinguish between KRITIS and non-KRITIS targets. If you run a connected production line, you’re in their sights. Moreover, NIS2 broadens the circle of affected companies substantially: many suppliers and service providers now fall under the obligations even if they don’t operate critical infrastructure themselves.

Can passive OT monitoring really avoid disrupting production?

Exactly. Passive monitoring solutions (Claroty, Nozomi, Dragos) analyse network traffic via mirror ports (SPAN) or network TAPs. They send no packets into the OT network and therefore cannot influence controllers. Active scans (such as Nmap or Nessus), by contrast, should never be used in OT environments because they can crash PLC controllers.

What’s the entry-level cost of OT security for a company with three production sites?

Asset inventory can be done with built-in tools (network scans, documentation). Dedicated OT monitoring platforms start at €15,000 per site per year for the base licence. For three sites, budget €50,000 to €80,000 annually. Add one-off implementation costs of €20,000 to €40,000. Against that stand average incident costs of €1.8 million (Sophos) to €70 million (Norsk Hydro).

Our machine builders demand remote access. How do we secure that?

Remote access is the most common attack vector in OT environments. Three immediate actions: first, route all remote access through a central jump host (no direct SPS access). Second, enforce MFA for every remote session. Third, impose time limits: enable remote sessions only on request (no always-on VPN). Log every session with timestamp and actions performed.

How do the KRITIS umbrella law and NIS2 relate to OT security?

The KRITIS umbrella law governs physical security and resilience of critical infrastructures. NIS2 governs cyber security. Together they mean: operators must manage both physical and digital risks, senior management is personally liable, and the BSI can conduct audits. For OT environments this translates into concrete obligations: network segmentation, monitoring, incident response and regular testing are no longer recommendations – they’re mandatory.

Further Reading in the Network

More from the MBF Media Network

cloudmagazinTLS Certs 2026: 200-Day Validity Ends Manual ManagementMyBusinessFutureBitkom AI Study 2026: 41% of Companies Use AI, SMEs Catch Up

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH