80% of ANZ operational systems hit with a cyber attack in the past year

Claroty

Thursday, 08 October, 2026


80% of ANZ operational systems hit with a cyber attack in the past year

OT cybersecurity company Claroty has announced new research revealing 80% of organisations in Australia and New Zealand have experienced a cyber attack on their operational environments in the past 12 months.

The research forms part of an independent global survey of 2000 business and technology leaders in over 40 countries, titled ‘The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability’. It seeks to understand how enterprise technology leaders are protecting their most valuable operational environments — from cyber-physical systems (CPS), to operational technology (OT), the Internet of Things (IoT), the Internet of Medical Things (IoMT), and building management systems (BMS) — amid the rapid rise of AI and an increasingly complex threat landscape.

Cyber attacks are having significant operational and financial consequences

The report finds that cyber attacks on operational environments are having tangible consequences for organisations in ANZ. When respondents were asked to identify the most significant impacts, the top responses were operational downtime (41%), safety incidents or hazards (37%), and reputational damage (32%). On average, organisations experienced approximately two hours of operational downtime as a result of their most significant cyber incident. However, for some organisations the disruption was considerably longer, with 18% reporting operational downtime lasting more than three days. The financial impact was also significant: organisations in ANZ reported an average loss of approximately $2.04 million from cyber incidents, almost double the global average of $1.04 million.

Insecure third-party access remains one of the most significant cyber risk factors in operational environments, with 88% of ANZ organisations experiencing at least one cybersecurity incident originating from third-party access in the past 12 months. Overall, organisations reported an average of more than three cyber incidents caused by third-party access. This is alarming given over half (52%) of organisations said they had only partial or no monitoring of third-party connections into their CPS/OT environments. Given the obvious exposure that remote access creates, technology leaders must have clear visibility and control over every remote session accessing their networks.

“In operational environments, uptime isn’t simply a metric — it is directly connected to business continuity, productivity, profitability, customer trust and, in many critical environments, safety,” said Jason Pearce, Field CTO, APJ at Claroty. “Even a relatively short disruption to physical operations can create significant downstream consequences across production, supply chains and essential services.

“The ANZ findings are particularly significant because organisations across Australia and New Zealand are experiencing an average financial impact from cyber incidents that is almost twice the global average. This reinforces why operational resilience needs to be treated as a business priority, not simply a cybersecurity objective. The question is no longer just whether an organisation can prevent an incident, but whether it understands its operational exposure, can contain disruption and recover critical operations safely and predictably.”

Digital transformation must be matched with cybersecurity investment

Manufacturing, health care and other critical infrastructure organisations are rapidly introducing AI into their operational environments as they pursue digital transformation, with 83% of organisations across ANZ already using the technology in some capacity. However, technology leaders acknowledge that AI carries many risks as well as opportunities. While 49% say AI has improved operational efficiency and productivity and 46% say it has improved decision-making, 45% also say AI has introduced a range of new cybersecurity and compliance risks. Those concerns are also reflected in the threats technology leaders see emerging. When asked to identify the biggest threats currently facing their operational environments, 32% pointed to AI-powered cyber attacks, followed closely by vulnerable legacy OT systems (30%).

In response to these increased risks, organisations are investing more in cybersecurity, acknowledging that digital transformation success and operational security investments must go hand-in-hand.

Transitioning from compliance to operational resilience is key

ANZ organisations are relatively mature when it comes to cybersecurity compliance, with three-quarters (74%) saying they take a proactive or structured approach to cybersecurity compliance in their operational environments. However, there are still many barriers blocking them from achieving full compliance. Specifically, 31% of organisations said a lack of IT/OT alignment was their biggest operational barrier to achieving full CPS compliance, followed closely by limited visibility (23%) and third-party risk (23%).

Almost half (45%) of respondents also said that keeping pace with constantly evolving cybersecurity regulations, standards and frameworks is their biggest challenge when it comes to maintaining compliance, while a third (36%) highlighted the difficulty of managing compliance across multiple sites or business units. These responses demonstrate the inherently complex nature of operational environments, which makes it difficult for many organisations to achieve full compliance.

These challenges also underscore a broader shift in how organisations need to think about operational cybersecurity. Compliance alone does not guarantee that an organisation can withstand a cyber attack. Therefore, as cyber risk in operational environments continues to increase, technology leaders in ANZ must shift their focus away from tick-box compliance towards operational resilience instead, ensuring that their critical systems can recover effectively from attacks.

The full report can be found here.

Image credit: iStock.com/metamorworks

Related Articles

Why quantum is our next big bet after AI

Equating 'quantum' with only 'quantum computing' risks missing out on the...

IMARC 2026 will bring the mining world to Sydney

Now is the time for robust conversations and new thinking as we seek solutions to support mining...

A high-speed, real-time optical data connection for industrial applications

Fraunhofer IPMS has introduced a new industrial communication technology called...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd