Industrial control systems under sustained threat
The article highlights that industrial control system (ICS) security will remain one of the most persistent challenges for critical infrastructure operators in 2026. According to Jeff Macre, Principal OT Security Solutions Architect at Darktrace, ICS environments were originally designed for safety and reliability rather than cybersecurity, leaving long‑standing weaknesses such as unauthenticated protocols, flat networks, and hardware with long lifecycles that are difficult to patch or replace. These limitations, combined with poor asset visibility and the high risk of operational downtime, mean that foundational security issues in OT environments are expected to persist well into the future.

Geopolitical and AI‑assisted threats escalate
Experts cited in the article warn that OT‑focused malware and ransomware are increasingly linked to geopolitical tensions and state‑aligned campaigns. One example is VoltRuptor, a sophisticated ICS/SCADA malware developed by the Infrastructure Destruction Squad, featuring multi‑protocol support, persistence, and anti‑forensics capabilities. This malware has been deployed against critical infrastructure and is available on dark‑web forums, signaling the commoditization of advanced OT attack tools. Michael Freeman, Head of Threat Intelligence at Armis, adds that by 2026 more than a third of global energy and utilities infrastructure will have experienced cyber pre‑positioning, where adversaries quietly map systems and collect operational data in preparation for future disruption.

Expansion into supply chains and hybrid warfare
The report further warns that critical infrastructure targeting will expand into logistics, manufacturing, agriculture, and supply‑chain hubs, areas that can cause widespread societal disruption if compromised. Experts predict that attackers will increasingly blend cyber intrusion with misinformation and physical disruption in hybrid warfare campaigns, using AI to scale reconnaissance and coordination across multiple sectors. Nation‑states are also expected to deepen collaboration in cyber operations, making attribution more difficult and increasing the risk of coordinated, multi‑country attacks. As a result, security leaders are urged to shift toward resilience‑focused strategies, including segmentation, continuous monitoring, and post‑breach containment to limit operational impact.