The critical infrastructure that powers our utilities, factories, transportation systems and hospitals has never been more at risk.
Decades-old OT infrastructure built for networking rather than security is now operating alongside a new wave of connected technologies, from IoT and private 5G to physical AI, rapidly expanding the attack surface. At the same time, Frontier AI is shrinking the time it takes for a newly discovered vulnerability to be exploited – from months to minutes.
That combination raises an urgent question. How vulnerable are the systems that power our daily lives, and how ready are organizations to defend them?
To find out, Palo Alto Networks surveyed more than 1,600 critical infrastructure security leaders across 11 countries and five critical sectors for the new 2026 State of Critical Infrastructure Cybersecurity Report. They describe their day-to-day challenges, including incomplete visibility into their environments, difficulty prioritizing the risks that matter most and a new generation of AI-powered attacks that leaves less time to respond. They’re also aligned on the outcomes they need – from keeping operations resilient to making risk and compliance provable, and reducing the cost and complexity of security.
Frontier AI Is Widening The Cybersecurity Readiness Gap
The findings reveal a cybersecurity readiness gap growing from both sides: organizations are already struggling with visibility, legacy systems and fragmented defenses, while a new class of AI-powered attackers can find and exploit weaknesses at machine speed.
Today's defenses are already under pressure
- Incomplete visibility: OT visibility remains a fundamental challenge. 68% of organizations do not have complete, real-time visibility of all assets connected to their OT networks. More than half of this challenge was attributed to legacy OT systems.
- Security tool sprawl: Organizations use an average of seven disparate security systems and tools to monitor and identify risk, and most say that sprawl adds complexity and cost. When a tool detects a threat but can't act on it, the alert waits for a person. Against attacks that move at machine speed, that handoff is the exposure.
- IT and OT security operations remain largely separate in many organizations: While teams are moving toward closer collaboration, 74% have not yet fully integrated IT and OT security operations across their organization. Technology incompatibility and differing priorities remain leading barriers, leaving gaps between where threats are detected and where action needs to happen.
- Unpatchable assets at the center: 42% name legacy, unpatchable OT assets as their single biggest cybersecurity risk. Unpatchability isn't a failure of the people running these systems. It's the natural result of equipment designed for safety and uptime above all else. But it means the assets leaders worry about most are the ones patching can't protect.
And leaders are bracing for AI-powered attacks
95% of leaders cited concerns about Frontier AI-powered attacks on critical infrastructure. That concern is coming at a time when many organizations are already under significant strain. 60% suffered a significant security breach in the past year, and half cited physical safety concerns as a result. Those organizations were already under strain before the newest, more capable generation of Frontier AI models arrived.
Frontier AI changes the pace of attacks. In 2026, 29% of CVEs were exploited within 24 hours, while the industry average to deploy a patch is 55 days. Vulnerability discovery is accelerating, attacks are moving faster, and AI is increasingly being used to lower the barriers to targeting OT environments – from identifying weaknesses in widely used software to generating attack logic for industrial systems.
That creates a widening mismatch for defenders. Critical infrastructure operators may still need weeks to test and deploy a patch, while attackers can move on newly discovered vulnerabilities in hours or even minutes. Frontier AI doesn’t create the underlying weaknesses in these environments. It compresses the time leaders have to find them, prioritize them and protect against them before they can be exploited.
What Critical Infrastructure Leaders Should Prioritize Now
Closing that gap doesn’t start with replacing every legacy system or piece of equipment. It starts with matching the speed of the attack with the speed of the defense – and leaders already recognize that need. 91% expect AI-driven cybersecurity to play a role in defending against exploits accelerated by Frontier AI models.
The report’s findings point to five priorities for getting there.
- Know what matters, not just what’s connected. 92% of respondents say alert prioritization is important or critical, yet only half still rely on CVSS scores or manual review. Continuous, non-intrusive visibility across OT, IoT, IT and private 5G – ranked by what each asset controls, how exposed it is and the operational impact if it fails – lets teams spend their limited time on the risks that could actually stop operations. It also helps make risk and compliance provable.
- Contain threats before they spread. Only about half of organizations (53%) have policy enforcement and access controls in place across connected assets and users. Frontier AI shrinks how long attackers need to get in. Segmentation limits how far they can go. Access controls and secure remote access based on what each asset is and what it controls keep one compromised device, whether on the plant floor or at a remote cellular site, from becoming a plant-wide outage.
- Protect critical infrastructure at machine speed. The traditional model of finding a vulnerability, waiting for the vendor's fix and scheduling a maintenance window worked when attackers moved slowly. It breaks down when AI can find and exploit a flaw in minutes and the industry average to deploy a patch is 55 days. Yet only 40% of organizations have virtual patching or other immediate compensating controls in place today.
Closing that gap takes AI-driven defenses that stop exploits of known and unknown vulnerabilities at the network, within hours of a new threat emerging and before an official fix is available, without touching the device or halting the process. The measure that matters is no longer time-to-patch. It's time-to-protection. - Accelerate IT and OT collaboration and coordinate cyber protection. Critical infrastructure cybersecurity increasingly depends on effective collaboration between IT and OT teams. Shared visibility, coordinated security operations and common workflows can help organizations respond more effectively and strengthen operational resilience. This has the potential to accelerate threat containment, while reducing operational cost and complexity.
Protecting Critical Infrastructure for What Comes Next
The goal is to make systems harder to exploit by putting the right protections around them.
What critical infrastructure needs is a platform that sees the whole environment, prioritizes threats based on operational and safety risk, and maximizes automation in incident response while keeping operators in control of critical decisions.
Palo Alto Networks is deeply committed to protecting the critical infrastructure society depends on, continually investing in the security capabilities operators need for what comes next. Most recently, the release of PAN-OS 12.2 Ceres introduced new capabilities including Frontier Virtual Patching, new ruggedized next-generation firewalls (NGFWs) and enhanced OT defense features including microsegmentation and attack path mapping. Additionally, the new Frontier AI Critical Defense Program enables leaders across operational technology (OT), healthcare, commercial software and open-source communities to coordinate with Palo Alto Networks to deploy proactive "virtual patches," neutralizing vulnerabilities at the network-level before attackers can exploit them. Because AI should do more than just flag risks – it should actively resolve them.
Critical infrastructure was built to run safely and resiliently for decades. We are building the security to ensure it does.