Business Wire

New Research from Cyolo and Ponemon Institute Identifies Significant Gaps in Securing Access to Connected OT Environments

Share

Today, Cyolo, the access company for the digital enterprise, in partnership with Ponemon Institute, released a global study exploring how organizations that operate critical infrastructure, industrial control systems (ICS), and other operational technology (OT) systems are managing access and risk in an era of rising connectivity.

“Our world has become increasingly interconnected, and the findings of this report highlight the vital need for organizations to reevaluate and enhance their strategies for ensuring secure access into OT environments,” said Larry Ponemon, Chairman and Founder of the Ponemon Institute.

The report, “Managing Access & Risk in the Increasingly Connected Operational Technology (OT) Environment,” reveals that many industrial organizations lack the resources, expertise, and collaborative processes to effectively mitigate threats and ensure secure access to OT systems. The report is based on a survey of 1,056 security professionals across the United States and EMEA who work in organizations that run an OT environment and are knowledgeable about their organization’s approach to managing OT security and risk.

Ensuring secure access to OT environments is about more than just cybersecurity. These environments contain highly sensitive systems and critical infrastructure responsible for keeping manufacturing lines running, water and electricity flowing, and performing other tasks vital to the smooth functioning of our communities.

OT systems were historically isolated for security reasons but are now facing increased connectivity to IT networks and the internet (sometimes called IT/OT convergence). At the same time, more third-party vendors and contractors are being given remote access to OT environments. These shifts introduce serious new risks that can leave organizations exposed to safety and security threats if access and connectivity are not properly controlled.

Overall key findings include:

  • Organizations allow dozens of third-party users to access OT environments. 73% permit third-party access to OT environments, with an average of 77 third parties per organization granted such access. Challenges to securing third-party access include preventing unauthorized access (44%), aligning IT and OT security priorities (43%), and giving users too much privileged access (35 percent).
  • Visibility into industrial assets is dismal. 73% lack an authoritative OT asset inventory, putting organizations at significant risk.
  • IT and OT teams share responsibility for OT security but do not communicate enough to achieve optimal outcomes. 71% report that IT or IT and OT together are responsible for securing OT environments. However, collaboration and communication are lacking, with 37% reporting little or no collaboration, and 19% reporting that teams talk about OT security issues only when an incident occurs.
  • Security is seen not only as a goal of IT/OT convergence but also as an obstacle. Reducing security risk is the top objective of companies pursuing IT/OT convergence (59%), and yet one-third (33%) of organizations not pursuing convergence cite security risk as a top factor for their decision.

“We are at a crucial point in the evolution of OT security, and the need to secure access to critical systems from internal and external threats is more urgent than ever. The stakes are exceptionally high, as a breach could jeopardize not just data but also the functioning of critical infrastructure, risking the safety of workers and the environment,” said Joe O'Donnell, Executive Vice President of Corporate Development and General Manager of OT at Cyolo. “This research reveals a pressing need for new approaches, especially in areas like third-party and privileged access, the security of legacy systems, and collaboration between IT and OT teams. Cyolo is dedicated to supporting organizations in navigating these challenges and working towards a secure, resilient future for OT environments.”

Access the full report here.

Register to attend a joint webinar from Cyolo and Ponemon Institute, on Tuesday, March 12 at 11am ET here: Behind the Ponemon Report: Risk & Access Management in the OT Environment.

During this session Dr. Larry Ponemon will share top insights from the research, with industry analysis added by Cyolo’s Joe O’Donnell and Adi Karisik, Global Principal for OT Cybersecurity at Jacobs Engineering.

About Cyolo

Cyolo enables privileged remote operations by connecting verified identities directly to applications with continuous authorization throughout the connection. Purpose-built for deployment in every type of environment, Cyolo’s Remote Privileged Access Management (RPAM) solution combines multiple security functions required to mitigate high risk access, including zero-trust access for users and devices, MFA for the last mile, IdP capabilities, credentials vault, secure file transfer, supervised access, session recording, and much more into a single, cost-effective, easy to deploy, and user-friendly platform.

Consolidate your security stack and experience the power of seamless and secure operations across any application in any environment, from critical infrastructure to cloud. Visit https://cyolo.io/ to learn more.

About Ponemon Institute

Ponemon Institute is dedicated to independent research and education that advances responsible information and privacy management practices within business and government. Our mission is to conduct high quality, empirical studies on critical issues affecting the management and security of sensitive information about people and organizations. We uphold strict data confidentiality, privacy and ethical research standards. We do not collect any personally identifiable information from individuals (or company identifiable information in our business research). Furthermore, we have strict quality standards to ensure that subjects are not asked extraneous, irrelevant or improper questions.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Cyolo Media Inquiries
10Fold
cyolo@10Fold.com

About Business Wire

Business Wire
Business Wire
24 Martin Lane
EC4R 0DR London

+44 20 7626 1982http://www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Incyte Announces European Commission Approval of Minjuvi ® (tafasitamab) for the Treatment of Relapsed or Refractory Follicular Lymphoma17.12.2025 17:20:00 CET | Press Release

Incyte (Nasdaq:INCY) today announced that the European Commission (EC) has approved Minjuvi® (tafasitamab) in combination with lenalidomide and rituximab for the treatment of adult patients with relapsed or refractory follicular lymphoma (FL) (Grade 1-3a) after at least one line of systemic therapy. "The EC approval of Minjuvi addresses a critical need, bringing a new, first-of-its-kind, chemotherapy-free option to patients in Europe with relapsed or refractory FL,” said Bill Meury, President and Chief Executive Officer, Incyte. “Historically, FL patients have had limited treatment options in the second-line setting, and we are proud to drive this important advancement for the lymphoma community as we seek to deliver innovative medicines for patients with cancer.” The EC decision follows the positive opinion received from the European Medicines Agency’s Committee for Medicinal Products for Human Use (CHMP) in November 2025. This marks the second indication for Minjuvi, which was previo

Rigaku Launches ONYX 3200, a Metrology Instrument for Semiconductor Manufacturing17.12.2025 16:00:00 CET | Press Release

Rigaku Corporation, a global solution partner in X-ray analytical systems and a group company of Rigaku Holdings Corporation (headquarters: Akishima, Tokyo; CEO: Jun Kawakami; hereinafter “Rigaku”) announced the launch of the ONYX 3200, a new semiconductor metrology system to measure film thickness, composition and bump* structures for wafer-level processes. The system is engineered to help manufacturers stabilize quality and increase yield in the metal-wiring formation (back-end-of-line (BEOL)) and packaging processes of semiconductor chips. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251216597402/en/ ONYX 3200 Due to accelerating demands for AI, high-performance computing, data centers, mobile devices, and other devices, chip wiring and interconnect structures have grown increasingly delicate and complex. As a result, the ability to accurately and non-destructively measure metal layers thinner than a human hair and bump

Taylor Wessing Diversifies Its International Strategy17.12.2025 15:05:00 CET | Press Release

International law firm Taylor Wessing is set to diversify its strategy within its international alliance, in order to push international growth and innovation. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251217415857/en/ Dr. Oliver Bertram, Global Co-Chair at Taylor Wessing The English part of the partnership is seeking a merger with US law firm Winston & Strawn and would – depending on a corresponding partner decision, which is still pending – leave the Taylor Wessing alliance at the end of April 2026. Both parties wish to continue their successful joint international client work unchanged. Therefore, collaboration between Taylor Wessing and future Anglo-American firm Winston Taylor will continue seamlessly based on a cooperation agreement, ensuring that clients will not experience any change in their collaboration with Taylor Wessing. With the firm’s new open strategy, Taylor Wessing equally meets the strategic requirem

ISACA to Lead Global Credentialing for CMMC Cybersecurity Framework as International Cyber Readiness Standards Rise17.12.2025 15:00:00 CET | Press Release

As cyber threats escalate and governments raise expectations around operational resilience, ISACA has been appointed to lead the global credentialing programme for the U.S. DoW’s Cybersecurity Maturity Model Certification (CMMC) program. The appointment positions ISACA – the international association for cybersecurity, audit and digital trust – as the exclusive CMMC Assessor and Instructor Certification Organization (CAICO), responsible for training, examining and certifying professionals, assessors, and instructors across the CMMC ecosystem. Originally developed by the U.S. DoW to protect sensitive unclassified information within its global supply chain, CMMC is increasingly relevant to European defence, aerospace, engineering and high-technology companies participating in transatlantic programmes. As the framework is phased into U.S. procurement from 2025 to 2028, many European organisations that handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI),

ASN Bank Signs a Contract With HCLTech to Accelerate Digital Transformation and Enhance Customer Experience17.12.2025 14:43:00 CET | Press Release

HCLTech, a leading global technology company, today announced that it has been selected as a strategic partner by ASN Bank (formerly de Volksbank), the fourth-largest retail bank in the Netherlands. As part of its new strategy ‘Simplify and Grow’, ASN Bank aims to modernise and standardise its IT architecture, which will involve consolidating IT services, simplifying the vendor landscape and building a future-ready organisation. Under the multi-year agreement, HCLTech will support ASN Bank’s enterprise applications, and streamline services through a distributed delivery model to enhance efficiency and customer experience. Michel Ruijterman, Chief Information Officer, ASN Bank: “By signing this agreement , HCLTech’s proven track record in delivering scalable, innovative solutions tailored to the financial services sector means we can now confidently press on with streamlining our business by reducing the number of existing products and aligning the underlying processes and systems under

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye