Industrial manufacturers are connecting more machines, controllers, networks, cloud platforms, and enterprise applications than ever before. This connectivity supports smarter production and broader use of AI, but it also creates new dependencies across information technology (IT) and operational technology (OT).
Rockwell Automation’s latest report, “Operational Resilience in the Age of Connectivity,” examines this changing environment through responses from 1,560 manufacturing and industrial decision-makers across 17 major manufacturing countries. The findings point to an important industry issue: confidence in cybersecurity capabilities does not always match actual operational exposure.
Cybersecurity Is Becoming a Direct Manufacturing Risk
More than one-third of industrial organizations identify cybersecurity risk as one of the major external obstacles to business growth. This reflects a broader change in how manufacturers view cyber threats.
In a traditional automation environment, cybersecurity was often treated as an IT responsibility. However, modern plants rely on connected PLCs, DCS platforms, SCADA systems, industrial Ethernet, remote access, engineering workstations, historians, MES platforms, and cloud services.
A cyber event can therefore move beyond data loss. It can interrupt production sequences, affect equipment availability, delay maintenance activities, or disrupt the flow of operational information.
From an automation engineering perspective, cybersecurity should be evaluated together with availability, process safety, maintenance, and production continuity.
Incident Exposure Remains Significant Despite High Confidence
The study reports that 46% of organizations experienced a cyber incident during the previous year, while 90% expressed confidence in their ability to prevent, contain, or recover from such an incident.
This difference deserves attention.
High confidence does not necessarily mean low operational risk. A plant may have firewalls, endpoint protection, network segmentation, backup systems, and monitoring tools while still having weaknesses in legacy controllers, engineering workstations, remote connections, or undocumented assets.
In industrial environments, the question is not simply whether security technology has been installed. Engineers also need to ask whether the organization can detect an abnormal condition, isolate the affected asset, maintain safe operation, and restore production within an acceptable time.
That is the practical meaning of operational resilience.
Cybersecurity Investment Must Translate Into Operational Capability
Rockwell Automation reports that 62% of organizations have already invested in cybersecurity platforms, while cybersecurity ranks among the higher-ROI technology investments reported by respondents. (罗克韦尔自动化)
However, purchasing security technology is only one part of the process.
For example, an OT cybersecurity platform may provide asset visibility and vulnerability information, but the plant still needs defined ownership and response procedures. Someone must determine which vulnerabilities affect production, which systems can be patched, and which systems require compensating controls because they cannot be taken offline.
This is particularly important for legacy automation equipment. A controller that has operated continuously for years may not support modern security mechanisms. Replacing it immediately may also create unacceptable production downtime.
Therefore, risk-based prioritization is often more practical than attempting to modernize every asset simultaneously.
IT/OT Convergence Expands the Industrial Attack Surface
The integration of IT and OT creates significant operational benefits. Production data can move into enterprise analytics platforms, maintenance teams can access equipment information remotely, and AI systems can process larger volumes of operational data.
At the same time, every new connection creates another dependency.
Rockwell Automation identifies IT/OT integration points as the second-most vulnerable area for cyber incidents, while 37% of respondents expect secure IT/OT architecture to contribute to positive business outcomes over the next five years.
This creates an important engineering balance.
IT and OT should not be viewed as completely isolated environments, but neither should they be connected without architectural controls. Network segmentation, controlled remote access, identity management, asset inventory, secure communication, and monitored data flows become increasingly important as connectivity expands.
AI Is Moving Into the Cybersecurity Workflow
The research also indicates that 45% of industrial organizations plan to apply AI and machine learning to cybersecurity initiatives during the next 12 months.
AI can help security teams analyze large volumes of network events, identify unusual behavior, prioritize alerts, and support faster investigation.
However, industrial cybersecurity introduces a different requirement from conventional enterprise IT security: production context matters.
An unusual network event does not automatically represent an attack. A maintenance engineer may be downloading a controller program, changing a PLC configuration, or accessing a drive during a planned shutdown.
For this reason, AI-based security systems should be connected to accurate OT asset information and operational context. Otherwise, organizations may generate excessive alerts without improving response quality.
Resilience Requires More Than Security Tools
One of the strongest lessons from the report is that cybersecurity technology alone does not create operational resilience. Rockwell Automation emphasizes visibility, governance, prioritization, and continuous improvement as parts of a resilient OT security program.
In practical plant engineering, resilience can be considered across several layers:
- Asset visibility: Know which PLCs, HMIs, servers, switches, drives, and engineering stations exist.
- Network visibility: Understand how OT assets communicate and where critical dependencies exist.
- Access control: Limit remote and privileged access according to operational requirements.
- Segmentation: Reduce unnecessary communication between production zones and enterprise systems.
- Backup and recovery: Maintain tested backups for configurations, applications, and critical engineering data.
- Incident response: Define what operators, engineers, IT teams, and management should do during an incident.
- Continuous assessment: Reevaluate risks when equipment, software, networks, or production processes change.
This approach shifts cybersecurity from a one-time project toward an ongoing engineering process.
The Legacy Automation Problem Cannot Be Ignored
Digital transformation often focuses on new technologies such as AI, cloud computing, digital twins, edge computing, and connected production systems. Yet many factories still depend on automation equipment designed years or even decades ago.
These legacy systems may have limited authentication, outdated operating systems, unsupported firmware, or restricted patching options.
Replacing all legacy equipment is rarely practical.
A more realistic strategy is to identify the assets that can create the greatest operational impact and then apply appropriate compensating measures. Network segmentation, application allowlisting, controlled engineering access, monitoring, offline backups, and restricted remote connections can reduce exposure without immediately replacing every controller.
Cybersecurity Should Be Part of Automation Architecture
From an industrial automation engineering perspective, cybersecurity should increasingly become an architectural consideration rather than an additional layer added after commissioning.
When engineers design a new control system, they can consider security zones, communication paths, remote-access requirements, backup strategies, and recovery procedures alongside control performance and system availability.
Standards and frameworks such as IEC 62443, NIST CSF, and NIS2-related requirements can provide structured references for developing this approach. Rockwell Automation also highlights these frameworks in its current OT cybersecurity strategy.
The objective is not to make an industrial network impossible to access. The objective is to make access intentional, observable, controlled, and recoverable.
My Engineering View: Resilience Should Be Measured at the Production Level
A useful way to evaluate industrial cybersecurity is to move beyond the question, “How many security tools have we deployed?”
A better engineering question is:
“If a cyber incident affects this production system today, how quickly can we detect it, contain it, maintain safe operation, and restore the required production function?”
This perspective connects cybersecurity directly with plant performance.
For example, a security control that generates thousands of alerts but does not help operators identify the affected production asset may have limited practical value. Conversely, accurate asset visibility combined with clear response procedures can provide measurable operational benefits even when legacy equipment remains in service.
In my view, the next stage of industrial cybersecurity will therefore depend less on simply adding security products and more on integrating cybersecurity with automation engineering, maintenance, network architecture, and business continuity planning.
Connectivity Will Continue to Change the Risk Profile
Manufacturers are unlikely to reduce connectivity. AI, industrial analytics, remote services, cloud platforms, and connected equipment will continue to expand across production environments.
Rockwell Automation’s wider 2026 manufacturing research also shows that manufacturers are moving from experimentation toward broader execution of digital technologies, while cybersecurity remains an important part of scaling connected and AI-supported operations.
The engineering challenge is therefore not whether factories should become connected. Instead, organizations need to determine how to make connectivity manageable, observable, secure, and recoverable.
Operational resilience will increasingly depend on that balance.
Conclusion
Rockwell Automation’s research highlights a clear relationship between digital transformation and industrial cybersecurity. As IT and OT systems become more interconnected, cybersecurity increasingly affects production continuity, operational risk, and the ability to scale digital technologies.
The reported 46% incident exposure rate, 90% confidence level, 62% cybersecurity-platform investment rate, and 45% planned AI/ML adoption for cybersecurity show an industry that is investing heavily while still adapting to a changing risk environment.
For industrial organizations, the next step is not simply to purchase more cybersecurity technology. It is to connect security strategy with real plant architecture, asset visibility, operational procedures, recovery planning, and continuous risk assessment.
That is where cybersecurity investment can become measurable operational resilience.