Operational technology (OT) and industrial control system (ICS) defenders face a critical challenge due to the lack of available data on real-world cyberattacks. Unlike IT environments, where logs and telemetry are routinely collected and analyzed post-incident, most OT operators do not capture sufficient data, making forensic analysis and incident response extremely difficult. Rob Lee, CEO of Dragos, highlights that in OT environments, instructions—whether legitimate or malicious—are transient and often disappear unless specialized monitoring tools are in place prior to an attack.
This data scarcity leaves OT environments particularly vulnerable, especially as nation-state adversaries increasingly target critical infrastructure. Without proactive data collection and monitoring, organizations have little chance of determining whether a cyberattack has occurred or understanding its impact, putting essential services at risk and leaving significant blind spots in national and industrial cybersecurity posture.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.