Skip to content

Vulnerability Warning: Approximately one out of every ten operational technology (OT) systems in use today is at least a decade old or older.

Industrial Operational Technology (OT) systems, often long-standing in production facilities, face elevated cyber threat risks, as indicated by a study by Sophos.

Outdated Operational Technology: Nearly a Tenth of Existing Systems Have Reached, or Surpassed, the...
Outdated Operational Technology: Nearly a Tenth of Existing Systems Have Reached, or Surpassed, the Decade Mark

Vulnerability Warning: Approximately one out of every ten operational technology (OT) systems in use today is at least a decade old or older.

In a comprehensive survey conducted by techconsult on behalf of Sophos, between July and August 2025, the cybersecurity practices of 211 production facilities across Germany were scrutinized. The study, however, did not disclose the name of the company that carried out the research on the security risks of Operational Technology (OT) systems in German production halls.

The survey revealed some interesting findings. A significant portion, 64.9%, of the companies surveyed regularly check the IT security of their suppliers. This proactive approach to supplier security is commendable, as it helps safeguard the overall security of the production facilities.

However, there are still some companies that are less vigilant. A third of the companies have implemented supplier security checks to some extent, while 8.5% have plans to do so in the future. Another 19.4% only perform these checks occasionally.

Sophos, a leading cybersecurity company, emphasizes employee training as a crucial measure to sensitize employees for the most important risk sources. Regular updates are also recommended as an indispensable building block for cybersecurity.

Another important aspect highlighted in the study is the integration of IT and production for successful security implementation. Supply chain audits are recommended for creating reliability with suppliers. In fact, 57.3% of the companies surveyed have formulated contractual requirements for cybersecurity with their suppliers.

One concerning finding from the survey is that 12.3% of the companies completely refrain from checking the security of their OT systems. This lack of vigilance can potentially expose these companies to significant risks.

For those interested in learning more about the survey, further information can be found at www.sophos.de. It is crucial for companies to prioritize cybersecurity, especially in the critical area of OT systems, to ensure the continuity of their operations and protect against potential threats. Regular backups of production data and machine parameters, preferably separate from the production network, are advised as a precautionary measure.

Read also:

Latest