您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [Fortinet]:2025年运营技术(OT)与网络安全现状报告 - 发现报告

2025年运营技术(OT)与网络安全现状报告

信息技术 2026-06-24 - Fortinet 淘金 曹艳平
报告封面

Key Takeaways. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .3Executive Summary. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6Introduction. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6Critical Insights for OT Security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7A Deep Dive into the 2025 Survey. . . . . . . . . . . . . . . . . . . . . . . . . . . .9Global Impact. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13Best Practices. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14Methodology. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15Conclusion. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .16 Key Takeaways An indication of increasing cybersecurity maturity is the global trend of corporations planning to integrateoperational technology (OT) cybersecurity under the CISO, which increased again this year as part of an ongoingtrend to consolidate OT responsibility within the C-suite. Now, more than half (52%) of organizations report that According to theFortinet 2025 Threat Landscape Report, nation-state actors continue actively using ransomwareagainst manufacturing companies, the most targeted sector.1In this year’sState of Operational Technologyand Cybersecurity Report, increasing awareness of OT cyber risk within organizations continues to drive theassignment of that risk to an executive, most commonly the CISO. For four consecutive years, OT risk and OT cybersecurity maturity shows signs of progress in both process and solution maturity. As process maturity isless intrusive and more administrative, it is quicker to mature, and nearly half of organizations (49%) state thattheir cybersecurity program’s maturity is at Level 4, where processes are continuously improved through feedback OT networks are quickly evolving as modernization and digitalization connect and enable the use of richoperational data to optimize operations. However, increasing connectivity also poses several risks. Criminalransomware crews are targeting manufacturing as they monetize production interruptions and extract ransomsmore effectively by preying upon a manufacturer’s need to return to operations quickly. Additionally, well-funded, As organizations advance in their maturity level and adopt more advanced solutions, we see declines in most intrusion types.Compared to previous years, intrusions improved significantly, from 6% reporting no intrusions in 2022 to 52% in 2025. Infact, 65% of companies at maturity Level 4 reported zero intrusions compared to 46% within Levels 0–2. Those companies As organizations increase their maturity and take OT security more seriously, they are doing more to plan for changesin regulations and compliance. In 2025, the majority (66%) expect increased regulation in five years or less, with 40% of Executive Summary Introduction Critical Insights for OT Security Global Impact Best Practices TIP: Implement a strategy for secure networking. By startingwith segmentation, you initiate visibility of assets betweenzones that can support the need for asset inventory. Startwith segmentation and then the basic steps of asset TIP: Security tools with effective machine learningcapabilities can empower data aggregation and analysis todetect and respond more quickly to potential threats. TIP: A combination of application-layer policies, OTvulnerability protections, and virtual patching can greatlyreduce the exposure of vulnerable legacy systems. TIP: Security platforms featuring context-aware generativeAI capabilities can help organizations further strengthentheir security posture and increase operational efficiency TIP: Your threat intelligence and security services shouldinclude specialized intrusion prevention system signaturesdesigned to detect and block malicious traffic targeting OT Methodology Conclusion