4 MIN READ
Picture a control room at a regional water utility on a Tuesday morning. The operator on shift watches the SCADA console, sees the chlorine feed controller showing zero, sees the pumps showing stopped. The phone rings. The attack everyone treated as theoretical is no longer theoretical. Critical infrastructure in 2026 runs as the operational reality an operator has to live with, not the hypothetical scenario a budget meeting uses to justify spend.
Most of the attacks on critical infrastructure in 2025 and 2026 share the same lineage. Ransomware that pivots to the OT network. A supply chain compromise through a trusted vendor. An insider who never got offboarded properly. Three patterns, each running on a different motive, all of them ending in the same place. Production system stopped, regulator notified, operator on the phone asking how the attackers got in.
The patterns the wave has run on
Ransomware on the OT network has been the most visible pattern of 2025 and 2026. An attacker breaches the IT network, moves laterally to the OT network, encrypts the OT servers, and the production system stops. The ransom is demanded because production cannot run without the OT, and the OT operator has less margin to refuse than the IT operator ever did.
The supply chain compromise has been the next pattern. An attacker compromises a third party vendor, a remote management vendor, a SCADA software vendor, an industrial control vendor, then uses the vendor access to reach every customer at once. SolarWinds, Kaseya, MOVEit. The pattern is older than it looks and keeps showing up because the trust relationship between operator and vendor sits as the trust relationship an attacker exploits.
Insider enabled access has been the rare but most damaging variant. A disgruntled employee, a contractor still holding valid credentials after the offboarding, a partner with an active VPN connection. The access is legitimate and the breach lands without tripping the usual alerts. By the time anyone notices, the production system has stopped.
Where the surface actually sits
The IT/OT boundary is where most of the trouble starts. The corporate network connects to the industrial control network. The boundary the segmentation was supposed to protect, the boundary an attacker crosses through the remote management tool, the vendor portal, the engineer’s laptop. Most of the visible incidents in 2025 and 2026 crossed that boundary first.
Remote access runs a close second. The engineer, the vendor, the contractor all connect to the OT network from a remote location. The VPN that was supposed to provide the secure access, the VPN an attacker has compromised through a stolen credential, the entry point that ends up showing up in roughly half of the postmortems.
Legacy OT is the harder problem. The industrial control system installed in the 1990s cannot be patched because the vendor stopped supporting it, cannot be replaced because the production process depends on it. Attackers have been reading the same CVE database and know the system is unpatched. The 2025 and 2026 wave has not invented new OT exploits, it has reused old ones against systems that have not been touched in twenty years.
What the operator is doing about it
Three moves that work without shutting down the production. Segment the IT from the OT. The architecture team can implement this without disrupting production, putting the OT network on an isolated VLAN and the remote access behind a jump host. The segmentation is the move the operator should have done years ago.
Inventory the OT assets. Every controller, every sensor, every HMI, named in a single source of truth. The inventory costs a quarter and enables every other security control. Without it, nothing else works. With it, patching, segmentation, and threat hunting all have something to point at.
Subscribe to OT threat intelligence. Dragos, Claroty, Nozomi. The IT threat intelligence does not cover the OT attacker, and the OT threat intelligence is the only feed that names the indicator before the production system stops. Whoever does the three holds the line. Whoever pretends critical infrastructure is not a target owns the outage.

The bottom line
Critical infrastructure in 2026 is a target. Segmentation, inventory, OT specific threat intelligence. Whoever does the three holds the line. Whoever pretends the critical infrastructure is not a target owns the outage.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



