Today’s OT security landscape is defined by three parallel trends: nation‑state actors expanding targeting to a broader set of PLC vendors, continued high-volume scanning and vulnerability activity against industrial‑connected devices, and a growing but still immature effort to apply AI and secure‑development practices to OT systems. Policy and certification moves from industry and national authorities are trying to close governance and supply‑chain gaps even as operational defenders face targeted adversaries and legacy weaknesses in device ecosystems.
U.S. agencies update advisory on Iranian‑affiliated targeting of internet‑connected PLCs
On July 22, 2026, a joint advisory from CISA, FBI, NSA, EPA, DOE, U.S. Cyber Command’s CNMF, and Treasury expanded observed targeting of internet‑connected OT devices to include Schneider Electric and Siemens PLCs in addition to Rockwell Automation/Allen‑Bradley equipment. The update notes operational disruptions and financial losses across government, water/wastewater, and energy sectors, adds observed tactics such as use of configuration software and project‑file exfiltration, and reiterates mitigations including securing cellular modems, isolated architectures, project‑file validation, and monitoring reusable code modules (for example, Rockwell Add‑On Instructions) for malicious changes.
Source: https://www.ic3.gov/CSA/2026/260722.pdf
Study — OT/ICS AI adoption limited despite widespread interest
A Takepoint Research study sponsored by Nozomi Networks and BlastWave (published July 22, 2026) finds broad interest in AI for OT security — 87.7% of respondents are using, evaluating, piloting, or planning AI — but only 7.9% have deployed AI across multiple OT cybersecurity functions and roughly 5.0% report active deployment. The survey also highlights governance gaps: nearly two‑thirds view attacks on AI systems or operational data as a major/emerging risk, yet only 11.9% have formally mapped and reviewed AI‑driven decisions that could affect physical processes, safety systems, or continuity.
SonicWall report: manufacturing sees targeted OT/IT activity and heavy camera‑vulnerability hits
SonicWall’s 2026 Manufacturing Protect Brief reports 474 million manufacturing intrusion‑prevention events in H1 2026 (despite a 56.2% year‑over‑year decline in IPS volume), which the vendor characterizes as a shift toward more targeted activity against increasingly interconnected OT/IT estates. The report also attributes some of the largest observed hit counts to the Hikvision IP camera command‑injection issue (CVE‑2021‑36260), which produced roughly 43 million hits in the period; SonicWall’s figures reflect observed hits and blocks rather than confirmed compromises.
Panasonic Industry announces IEC 62443‑4‑1 process certification, increases product‑security transparency
Panasonic Industry announced on July 23, 2026 that its Industrial Device Business Division is IEC 62443‑4‑1 certified for secure product‑development lifecycle processes, a certification TÜV SÜD says was awarded in November 2025. In conjunction with the announcement, Panasonic launched a product‑security portal and published product‑security and vulnerability‑handling information — an example of vendors making lifecycle security and disclosure practices more visible ahead of the EU Cyber Resilience Act’s December 2027 enforcement.
Source: https://www.electronicsmedia.info/2026/07/23/iec-62443-4-1-certification/
Singapore to update critical‑infrastructure cybersecurity code for APT and AI‑enabled threats
Singapore’s Cyber Security Agency announced on July 22, 2026 that it will publish an updated Cybersecurity Code of Practice for Critical Information Infrastructure later in 2026, plus a new code for cloud services. The planned revisions target APT and AI‑enabled threats and will add technical guidance for adversarial‑attack simulation, penetration testing, threat hunting, and stronger governance expectations such as board oversight, annual resilience frameworks, higher Cyber Trust Mark requirements, and detection across interconnected network segments.
Closing note: Operators should prioritize network segmentation and project‑file integrity controls, validate AI governance and decision‑mapping where AI is being evaluated or deployed, track vendor lifecycle‑security commitments, and monitor authoritative advisories for evolving mitigation guidance.