VYPR
researchPublished Oct 7, 2026· 1 source

Legacy Equipment Hampers OT Network Visibility for Critical Infrastructure

A Palo Alto Networks survey reveals critical infrastructure operators struggle with network visibility due to widespread legacy equipment, despite using multiple security tools.

Despite deploying an average of seven distinct security tools, a significant majority of critical infrastructure operators still face challenges in achieving comprehensive visibility across their operational technology (OT) networks. A recent survey by Palo Alto Networks, which polled over 1,600 security and operations leaders, highlights that legacy equipment remains the most pervasive obstacle.

According to the survey findings, 52% of respondents identified legacy OT systems as their primary visibility concern. Compounding this issue, 42% pointed to legacy equipment that cannot be patched as their most significant cybersecurity risk. Alarmingly, even among those who claim to have full visibility, nearly half still acknowledge legacy OT as a persistent challenge, underscoring the difficulty of securing outdated systems even when their presence is known.

"Cybersecurity in critical infrastructure today is at a dangerous point where we’ve connected decades-old OT to modern networks faster than we’ve updated the security models needed to protect them," stated one VP of IT at a US manufacturer, encapsulating the industry's precarious position. This sentiment reflects a broader trend of integrating older, often vulnerable, operational technology into contemporary network infrastructures without adequate security modernization.

The proliferation of security tools, intended to bolster defenses, has paradoxically introduced complexity and increased operational costs for many organizations. Fifty-nine percent of respondents reported that their security tool stack complicates operations, while 56% noted higher operating expenses. The practice of adding a new tool for every identified gap has led to an unwieldy and often inefficient security posture, with over half of teams still manually sorting or relying on basic severity scores for alerts.

Breaches continue to be a stark reality for critical infrastructure operators, with 59% experiencing a significant security incident in the past year, and one in five facing multiple breaches. The impact extends beyond financial losses, as half of the respondents cited safety concerns as a consequence of these incidents. The average cost of unplanned downtime alone was reported to be $288,563 per hour, emphasizing the critical need for robust security and operational continuity.

While containment times are improving from a low baseline, with 15% of organizations now achieving containment within minutes through automation (up from 10% a year prior), the majority are still striving for faster response. Fifty-one percent aim to reach this level of automated containment within the next twelve months.

The survey also shed light on the growing concerns surrounding Artificial Intelligence. Ninety-five percent of respondents expressed apprehension about attacks powered by advanced AI, while simultaneously anticipating that AI-driven security tools will be crucial for defense. However, current adoption of AI in security operations remains nascent, with only 19% utilizing it across four or more operational areas, and these often include non-security functions like process optimization.

Furthermore, the persistent divide between IT and OT security teams remains a significant hurdle, with 74% of organizations yet to integrate their operations. Incompatible technologies and differing priorities are cited as the primary reasons for this separation. Automated alert correlation is identified as a key technology that could accelerate IT and OT convergence over the next two years, with 52% of respondents highlighting its importance.

Synthesized by Vypr AI