Daily OT Security News: October 07, 2026

Daily OT Security News — October 07, 2026: concise summaries of five verified developments affecting OT and IoT security.

Survey finds 68% of critical-infrastructure organizations lack complete real-time OT asset visibility

Palo Alto Networks surveyed more than 1,600 critical-infrastructure security leaders across 11 countries and five sectors and found 68% lack complete real-time visibility of all assets connected to OT networks, with legacy OT systems accounting for more than half of that challenge. The survey also reported 42% view legacy unpatchable OT assets as their biggest cybersecurity risk, 95% expressed concern about frontier-AI-powered attacks, and 60% had experienced a significant breach in the prior year.

Source: Palo Alto Networks Blog.

Forescout study finds healthcare IoMT and OT far behind IT in post-quantum cryptography readiness

Forescout Research–Vedere Labs analyzed over 2.5 million devices across more than 50 healthcare delivery organizations and found only 6% of IoMT devices and 16% of OT devices used SSH implementations capable of supporting post-quantum cryptography, compared with 50% of IT devices. The research also identified more than 5,500 internet-exposed healthcare systems and noted only 31% of those systems supported TLS 1.3.

Source: Industrial Cyber.

OT Cyber Coalition urges CISA to establish mandatory federal OT cybersecurity baseline

The Operational Technology Cybersecurity Coalition called on CISA to issue a Binding Operational Directive establishing federal OT cybersecurity requirements for Federal Civilian Executive Branch agencies, covering OT asset visibility, network segmentation, enforceable remote-access controls, configuration baselines, incident preparedness, and tested backup and recovery. The coalition also recommended assigning a senior official or unified office accountability for OT inventory, configuration, recovery, incident readiness, and risk reporting.

Source: Industrial Cyber.

QNAP announces IEC 62443-4-1 secure-development certification

QNAP announced it obtained IEC 62443-4-1 certification in 2026, which defines product-security development lifecycle requirements within the IEC industrial automation and control systems cybersecurity framework. The company said the certification audit evaluates development processes across areas including secure design, verification and validation, vulnerability issue management, and security-update management, and noted it uses SBOM and DevSecOps practices along with external testing and a vulnerability bounty program.

Source: QNAP Blog.

CISA republishes advisory on critical flaws in end-of-life Hitachi Energy RTU500 firmware

CISA republished Hitachi Energy’s advisory on October 6, 2026, noting end-of-life RTU500-series CMU firmware 11.x and earlier is likely affected while currently supported versions are not. The advisory lists six CVEs including CVE-2026-8065 through CVE-2026-8067 with a maximum CVSS v3 score of 9.8 and recommends upgrading unsupported firmware and applying defense-in-depth controls.

Source: U.S. Cybersecurity and Infrastructure Security Agency (CISA).

End of briefing.

Share this