Fortinet OT Cybersecurity Report: 53% of Industrial Orgs Under CISO
Fortinet OT Cybersecurity Report: 53% of Industrial Orgs Under CISO
https://www.cybersecurity-insiders.com/fortinet-ot-cybersecurity-report-ciso-ownership/
Publish Date: 2026-06-11 16:06:00
Source Domain: www.cybersecurity-insiders.com
OT security governance has been moving toward the C-suite for four years, but the pace accelerated sharply. Fortinet’s 2026 State of Operational Technology and Cybersecurity Report finds 53% of industrial organizations now place OT cybersecurity under the Chief Information Security Officer (CISO) or Chief Security Officer (CSO), up from 16% in 2022. A global survey of over 700 OT professionals sits underneath that number, and the full picture is more complicated than the governance headline suggests.
- The governance shift is real, but maturity self-assessments have corrected downward sharply: organizations at the highest maturity level (level 4) dropped from 49% to 17% in a single year.
- Intrusions are more visible, not necessarily more frequent: 71% of respondents reported one to nine attacks, up from 47%, with Fortinet attributing much of the jump to improved detection rather than a true volume increase.
- Cost reduction displaced risk reduction as the top cybersecurity performance metric in 2026, surfacing a governance tension the report does not fully resolve.
- 89% of respondents expect new OT regulation within five years, up sharply from 66% in 2025, and four in five organizations intend to bring OT security under CISO oversight within the next 12 months.
OT Cybersecurity Under CISO: Why the Level 4 Maturity Drop Changes the Story
Richard Springer, senior director for marketing OT solutions at Fortinet, wrote in a blog post alongside the report. He noted that industrial organizations now rely on interconnected systems, remote access, cloud-based analytics, and unified IT and OT environments to maintain production. “While this advanced connectivity offers increased efficiency and resilience,” Springer wrote, “it has enlarged the attack surface for cybercriminals, ransomware groups, and nation-state actors.”
The 53% CISO ownership figure is the headline, but the maturity-score recalibration is the operationally consequential…