New Research from Cyolo and Ponemon Institute Identifies Significant Gaps in Securing Access to Connected OT Environments
Today, Cyolo, the access company for the digital enterprise, in partnership with Ponemon Institute, released a global study exploring how organizations that operate critical infrastructure, industrial control systems (ICS), and other operational technology (OT) systems are managing access and risk in an era of rising connectivity.
“Our world has become increasingly interconnected, and the findings of this report highlight the vital need for organizations to reevaluate and enhance their strategies for ensuring secure access into OT environments,” said Larry Ponemon, Chairman and Founder of the Ponemon Institute.
The report, “Managing Access & Risk in the Increasingly Connected Operational Technology (OT) Environment,” reveals that many industrial organizations lack the resources, expertise, and collaborative processes to effectively mitigate threats and ensure secure access to OT systems. The report is based on a survey of 1,056 security professionals across the United States and EMEA who work in organizations that run an OT environment and are knowledgeable about their organization’s approach to managing OT security and risk.
Ensuring secure access to OT environments is about more than just cybersecurity. These environments contain highly sensitive systems and critical infrastructure responsible for keeping manufacturing lines running, water and electricity flowing, and performing other tasks vital to the smooth functioning of our communities.
OT systems were historically isolated for security reasons but are now facing increased connectivity to IT networks and the internet (sometimes called IT/OT convergence). At the same time, more third-party vendors and contractors are being given remote access to OT environments. These shifts introduce serious new risks that can leave organizations exposed to safety and security threats if access and connectivity are not properly controlled.
Overall key findings include:
- Organizations allow dozens of third-party users to access OT environments. 73% permit third-party access to OT environments, with an average of 77 third parties per organization granted such access. Challenges to securing third-party access include preventing unauthorized access (44%), aligning IT and OT security priorities (43%), and giving users too much privileged access (35 percent).
- Visibility into industrial assets is dismal. 73% lack an authoritative OT asset inventory, putting organizations at significant risk.
- IT and OT teams share responsibility for OT security but do not communicate enough to achieve optimal outcomes. 71% report that IT or IT and OT together are responsible for securing OT environments. However, collaboration and communication are lacking, with 37% reporting little or no collaboration, and 19% reporting that teams talk about OT security issues only when an incident occurs.
- Security is seen not only as a goal of IT/OT convergence but also as an obstacle. Reducing security risk is the top objective of companies pursuing IT/OT convergence (59%), and yet one-third (33%) of organizations not pursuing convergence cite security risk as a top factor for their decision.
“We are at a crucial point in the evolution of OT security, and the need to secure access to critical systems from internal and external threats is more urgent than ever. The stakes are exceptionally high, as a breach could jeopardize not just data but also the functioning of critical infrastructure, risking the safety of workers and the environment,” said Joe O'Donnell, Executive Vice President of Corporate Development and General Manager of OT at Cyolo. “This research reveals a pressing need for new approaches, especially in areas like third-party and privileged access, the security of legacy systems, and collaboration between IT and OT teams. Cyolo is dedicated to supporting organizations in navigating these challenges and working towards a secure, resilient future for OT environments.”
Access the full report here.
Register to attend a joint webinar from Cyolo and Ponemon Institute, on Tuesday, March 12 at 11am ET here: Behind the Ponemon Report: Risk & Access Management in the OT Environment.
During this session Dr. Larry Ponemon will share top insights from the research, with industry analysis added by Cyolo’s Joe O’Donnell and Adi Karisik, Global Principal for OT Cybersecurity at Jacobs Engineering.
About Cyolo
Cyolo enables privileged remote operations by connecting verified identities directly to applications with continuous authorization throughout the connection. Purpose-built for deployment in every type of environment, Cyolo’s Remote Privileged Access Management (RPAM) solution combines multiple security functions required to mitigate high risk access, including zero-trust access for users and devices, MFA for the last mile, IdP capabilities, credentials vault, secure file transfer, supervised access, session recording, and much more into a single, cost-effective, easy to deploy, and user-friendly platform.
Consolidate your security stack and experience the power of seamless and secure operations across any application in any environment, from critical infrastructure to cloud. Visit https://cyolo.io/ to learn more.
About Ponemon Institute
Ponemon Institute is dedicated to independent research and education that advances responsible information and privacy management practices within business and government. Our mission is to conduct high quality, empirical studies on critical issues affecting the management and security of sensitive information about people and organizations. We uphold strict data confidentiality, privacy and ethical research standards. We do not collect any personally identifiable information from individuals (or company identifiable information in our business research). Furthermore, we have strict quality standards to ensure that subjects are not asked extraneous, irrelevant or improper questions.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240221222283/en/
Contact information
Cyolo Media Inquiries
10Fold
cyolo@10Fold.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
OpZira, Inc. Launches to Advance Ophthalmic Diagnostics with Innovative Medical Device Portfolio3.9.2025 20:23:00 EEST | Press release
OpZira™, Inc., a forward-thinking ophthalmic medical device company founded on a legacy of research excellence, today announced its official formation. OpZira is dedicated to delivering innovative technologies that enhance the detection and monitoring of ocular disease, empowering clinicians with advanced diagnostic tools. OpZira’s creation follows Alcon’s acquisition of LumiThera (https://www.alcon.com/media-release/alcon-completes-acquisition-lumithera/) and its innovative Valeda® Light Delivery System, the first and only FDA-authorized treatment for dry age-related macular degeneration (AMD). As part of the transaction, LumiThera’s diagnostic product lines were spun off to LumiThera shareholders, leading to the establishment of OpZira, Inc. OpZira’s product portfolio includes: AdaptDx Pro® – A wearable dark adaptometer that leverages AI to ensure a consistent patient experience. Impaired dark adaptation speed, a key early indicator of rod-mediated dysfunction, is often among the fir
BTG Bioliquids and NanosTech Partner to Deliver End-to-End Advanced Biofuels Solution3.9.2025 19:19:00 EEST | Press release
BTG Bioliquids BV (BTL), a Netherlands-based leader in fast pyrolysis technology, and NanosTech Technology & Innovations Ltd. (NanosTech), a Canada-based catalyst development and manufacturing company, have signed a Memorandum of Understanding (MOU) to deliver a fully integrated solution to produce advanced, drop-in biofuels. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250903698730/en/ The partnership combines BTL’s proven fast pyrolysis technology, which converts sustainable biomass into bio-oil, with NanosTech’s proprietary Aquaprocessing (AQP) platform, which upgrades even the most challenging bio-oils into refinery-ready feedstocks to produce fuels such as sustainable aviation fuel (SAF), renewable diesel, and marine fuels. The two companies are now actively collaborating to determine the location in Canada and Europe for the new 500-barrel-per-day modular biorefinery system. This system can be deployed near the feeds
Armis Named a Leader in IoT Security Solutions, Q3 2025 Evaluation3.9.2025 16:58:00 EEST | Press release
Armis, the cyber exposure management & security company, today announced that it has been named a Leader in The Forrester Wave™: IoT Security Solutions, Q3 2025. This achievement comes on the heels of Armis being named a Leader in The Forrester Wave™: Unified Vulnerability Management Solutions, Q3 2025. In this Forrester Wave™, Armis is ranked a Leader and achieved the highest scores possible in 9 key criteria. According to the report, “Armis’ vision centers on delivering enterprise-wide exposure management that goes beyond IoT and OT devices. Its innovation investments and acquisitions support this goal. Its roadmap aligns with customer priorities while anticipating future needs to ensure the platform evolves alongside its clients. This forward-looking strategy fosters successful adoption and helps customers deploy the Centrix platform successfully.” “We’re proud to once again be recognized by Forrester as a leader and specifically highlighted by customers for our overall effectivenes
Rapid Medical™ Surpasses 1,000 Cases With DRIVEWIRE™ 24 in North America and Expands Into Europe With MDR Approval3.9.2025 16:46:00 EEST | Press release
Rapid Medical™, a leading developer of active endovascular devices, announces that its DRIVEWIRE™ 24 steerable guidewire has been used in more than 1,000 neurovascular procedures in North America during a limited commercial launch beginning earlier this year. The company also announced receipt of CE Mark under the European Medical Device Regulation (MDR), as presented at the 2025 ESMINT Annual Meeting. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250903530140/en/ “In my experience, the wire provides a unique combination of precision and support that simply hasn’t been possible with conventional technologies,” stated Dr. Erez Nossek, a neurosurgeon at NYU Langone in New York, NY. “It has become a reliable tool that allows us to approach any anatomy with greater efficiency and less time.” As the first steerable 0.024” guidewire, DRIVEWIRE has quickly become a go-to technology in ischemic stroke, aneurysms, and other complex
Andersen Consulting Strengthens End-to-End Technology Capabilities Through Collaboration with FirstQA Systems3.9.2025 16:30:00 EEST | Press release
Andersen Consulting adds depth to its digital transformation and AI capabilities through a Collaboration Agreement with FirstQA Systems, a leading technology services provider known for its expertise in business AI, digital transformation, and cybersecurity. Headquartered in Japan since 2011, FirstQA Systems K.K. is a consulting-led technology services firm supporting Fortune 500 companies and multinational enterprises across Asia, Europe, and North America. The firm specializes in AI, digital transformation (leveraging ServiceNow, SAP, and Salesforce platforms), and IT and OT cybersecurity. Through its group company, Himitsu Lab Limited, FirstQA Systems delivers next-generation Agentic AI solutions powered by the HIMITSU8™ Unified Development Framework (UDF)™. The company’s industry expertise spans manufacturing, pharmaceuticals, and banking and financial services. "Our collaboration with Andersen Consulting represents an exciting step forward for enterprise transformation," said Nave
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom