Enterprises are increasingly exposed to cybersecurity risks due to the proliferation of unmanaged and diverse extended Internet of Things (xIoT) and operational technology (OT) devices within their networks. Research analyzing over 10 million devices across 700 organizations found that two-thirds of networked devices are not traditional IT assets, but rather include network gear, OT, IoT, and medical equipment. Common high-risk device types such as VoIP phones, IP cameras, point-of-sale systems, and uninterruptible power supplies are often widespread yet remain unmanaged, creating significant security blind spots. The diversity of device functions, vendors, and operating system versions further complicates risk management, making it challenging for security teams to identify, patch, and mitigate vulnerabilities effectively.
Manufacturers, in particular, face heightened OT security challenges due to legacy technology, lack of asset visibility, and the growing number of access points resulting from mergers and acquisitions. The complexity of managing access permissions, especially with multiple users sharing admin accounts, increases the difficulty of incident response and overall security posture. Despite increased awareness of these risks, the combination of device diversity, legacy systems, and human factors continues to present substantial obstacles to securing enterprise and manufacturing environments against cyber threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A Help Net Security report highlighted that enterprises are increasingly unable to maintain visibility into the connected xIoT devices operating inside their networks. The reference indicates this loss of device awareness as a current security development affecting enterprise environments.
Industry experts described manufacturers as facing ongoing OT security risk from legacy systems, limited asset visibility, expanding vendor and M&A access paths, and weak identity and access management practices. They also noted that IT/OT convergence, patching constraints, workforce shortages, and rapid technology adoption are making the problem harder to manage.
A cyberattack on Colonial Pipeline was cited as a prominent example of how operational technology and critical infrastructure incidents can drive board-level attention to OT security risk. The reference uses the incident as historical context for growing concern over manufacturing and industrial cyber exposure.
A ransomware incident affecting Asahi was identified as a recent high-profile case underscoring the business impact of OT-related cyber risk in manufacturing environments. It is presented as evidence that such incidents continue to raise concern at the board level.
An attack affecting Jaguar Land Rover was referenced as part of the set of notable incidents increasing executive awareness of OT and manufacturing cybersecurity risk. The article does not provide additional specifics beyond its role as an example of impactful disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.