Critical infrastructure operators now run seven separate security tools on average, yet most still cannot see every asset on their operational technology networks, a survey of more than 1,600 security and operations leaders finds. Legacy equipment is the top reason, named by 52 percent of respondents as the biggest visibility problem, and 42 percent call unpatchable legacy gear their single largest cybersecurity risk.
What the survey found
The survey, published by Palo Alto Networks, covers large operators across critical infrastructure. The headline gap is between the number of tools deployed and what those tools actually show. Even among respondents who say they can see everything, 49 percent still list legacy OT as a challenge, which means knowing a machine is on the network does not update its software.
Legacy equipment is the most common finding
Old equipment staying on the network is the most common visibility problem, and it is also the most cited cybersecurity risk. Forty-two percent of respondents call legacy equipment that cannot be patched their biggest risk, ahead of any other category in the survey.
The result is a security posture where decades of operational hardware now sit on modern networks. Cybersecurity in critical infrastructure today sits at the point where decades-old OT has been joined to modern networks faster than the security models needed to protect them have been updated, according to one VP of IT at a US manufacturer quoted in the report.
Buying more tools did not close the gap
Tool sprawl is its own problem. Fifty-nine percent of respondents say the tools make operations more complicated, and 56 percent report higher operating costs from running so many platforms side by side. Just over half still sort alerts with a standard severity score or by hand. Each time a new gap appears and a new tool is added, the survey describes the resulting pileup as the next reason day-to-day security work gets harder.
Breaches and downtime costs
Fifty-nine percent of respondents had a significant security breach in the past twelve months, and one in five was hit more than once. Half of respondents list safety concerns among the impacts of incidents, not just data loss. Unplanned downtime costs a mean of $288,563 per hour across the operators surveyed.
Containment is getting faster from a low starting point. Fifteen percent now contain incidents in minutes through automation, up from 10 percent a year ago. Fifty-one percent want to reach that level within the next twelve months, and fifteen percent are there today.
AI is the next concern on the list
Ninety-five percent of respondents are concerned about attacks powered by what the survey calls Frontier AI. Ninety-one percent expect AI-driven security tools to help defend against those attacks, but few have much AI in place yet. Only 19 percent use it across four or more operational areas, and those areas cover process optimization and predictive maintenance along with security, so the figure is not limited to defense.
IT and OT teams still work apart
Seventy-four percent of respondents have not integrated their IT and OT security operations. Among them, 44 percent name incompatible technology as the blocker and 44 percent name differing priorities between the two teams. Automated alert correlation tops the wish list for what would speed IT and OT convergence over the next two years, picked by 52 percent of respondents.
What the numbers add up to
The pattern the survey describes is straightforward. Legacy hardware on the network keeps the asset list incomplete. New tools are layered on top to close each new gap, which raises cost and slows alert work. Breaches follow, downtime costs a mean of $288,563 per hour, and IT and OT teams still work in separate stacks. Automated alert correlation is the most wanted bridge between the two sides.
FAQ
How many security tools do critical infrastructure operators run on average?
Seven separate security tools on average, according to the survey of more than 1,600 security and operations leaders.
What is the most common visibility problem on OT networks?
Legacy OT equipment, named by 52 percent of respondents as the biggest visibility problem.
What does the survey say about AI in critical infrastructure security?
Ninety-five percent are concerned about AI-powered attacks, 91 percent expect AI-driven tools to help defend against them, and only 19 percent use AI across four or more operational areas today.
This article summarizes reporting from helpnetsecurity.com.

