Skip to main content

folkfox

Skip to main content
Skip to content
THREAT LANDSCAPE

Nobody touched the turbine. They took the office.

Dragos logged 1,140 incidents against industrial organisations last quarter and not one operator reached a control system. Every industrial cybersecurity campaign built on a hacked turbine is selling against a threat that did not happen.

Quick answerDragos counted 1,140 industrial cybersecurity incidents in Q2 2026, up 12% on Q1, and none reached Stage 2 of the ICS Cyber Kill Chain. The damage ran through ordinary enterprise IT, not control systems.

Audio version

Listen to this article. The full text is below.

9 min · narrated · download

Section 01

The quarter industrial cybersecurity spent in the office#

A fox does not force the farm gate. It walks the fence line until the fence forgets itself, then slips through the gap somebody propped open and never closed. That patient prowl is the precise shape of industrial cybersecurity in the second quarter of 2026, and it is why so much industrial cybersecurity marketing is currently pointed at the wrong door.

Dragos counted 1,140 ransomware incidents against industrial organisations worldwide in Q2 2026, a 12% rise on the 1,020 recorded in Q1. That is the number every vendor will put on a slide next month. The sentence sitting underneath it is the one that should rewrite your industrial cybersecurity messaging.

The analysis is unambiguous. "Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system," the report states. Not one. No near miss, no partial, no quietly redacted case study. Across a quarter of 1,140 incidents, the control layer was never touched.

industrial cybersecurity: a painted fox ignores the open factory padlock and studies the office keys instead
The padlock on the plant door is not the way in. The office keyring is.

Read that twice, because it retires a decade of industrial cybersecurity creative. The turbine did not trip. The valve did not slam shut. Production stopped, where it stopped at all, because the enterprise systems that schedule, cost and dispatch the work were encrypted, and a plant that cannot raise a purchase order is a plant that cannot run a shift.

The threat model your buyer already believes#

Dragos framed the quarter's risk plainly, and Help Net Security carried the framing on 11 August 2026: the danger is being shaped less by novel ICS-specific malware than by attackers' deepening focus on the enterprise IT systems that support operational technology environments.

Your buyer already knows this, because they live in it. They have a domain controller carrying a decade of scar tissue, a flat network somebody has been promising to segment for years, and a remote-access route a supplier set up and nobody has audited since. When your creative shows a gloved hand on a control panel, you are telling that person a story they stopped believing long ago.

Q1 to Q2 2026, two lines that disagree
Slope chart comparing total industrial ransomware incidents rising from 1,020 to 1,140 with Qilin claims falling from 198 to 140 between Q1 and Q2 2026Q1 2026Q2 2026All industrial incidents: 1020 to 1140All industrial inc 10201140Qilin claims: 198 to 140Qilin claims 198140
Industrial cybersecurity incidents climbed from 1,020 to 1,140 while Qilin's claim count fell from 198 to 140, on Dragos figures.

Qilin was still the most active group of the quarter with 140 claims, down from 198 in Q1. Akira posted 129 and The Gentlemen 125, according to Help Net Security. The field got busier while its loudest brand got quieter, which is what fragmentation looks like from outside the thicket, and it is a warning to anyone building an industrial cybersecurity campaign around a single named adversary.

Section 02

Where the quarter actually landed#

Manufacturing absorbed 747 incidents, 65% of the quarter, across all subsectors. That single share should decide your media plan before it decides your headline, because a market where two thirds of the pain sits in one sector does not need a broad industrial cybersecurity campaign. It needs a narrow one, aimed at a reader you can picture.

Q2 2026 industrial ransomware, by sector
Manufacturing
747
Construction
176
Organisations supporting ICS environments
117
Equipment manufacturing
114
Transportation and logistics
95
Food and beverage
70
Manufacturing took 747 of the quarter's incidents, more than the next five sectors combined, on Dragos figures reported by Help Net Security.

The tail matters as much as the head. Construction took 176, organisations supporting ICS environments 117, equipment manufacturing 114, transportation and logistics 95, and food and beverage 70, per Help Net Security. These are not exotic verticals. They are mid-market firms with a two-person IT team who buy industrial cybersecurity the way they buy insurance: once a year, in a hurry, on somebody else's recommendation.

The 117 count is the quiet one. Organisations supporting ICS environments means integrators, engineering consultancies and maintenance contractors, the suppliers who hold remote access into other people's plants. Sell to them and you are not selling one licence, you are selling the credential hygiene of every site on their books.

Sixty-five in every hundred
Sixty-five in every hundredWaffle chart showing 65% of Q2 2026 industrial ransomware incidents affected manufacturing65% of Q2 industrial ransomware incidentshit manufacturing
Two thirds of every industrial cybersecurity incident Dragos counted in Q2 2026 landed on a manufacturer.

Geography is a budget line, not a footnote#

The United States alone absorbed 431 incidents, 38% of the worldwide total, with North America on 514, Europe on 316, Asia on 172 and South America on 64. If your industrial cybersecurity pipeline is weighted to EMEA while the incident curve is weighted to North America, that mismatch is a media buying decision rather than a brand problem, and paid search corrects it faster than a rebrand ever will.

Sector and geography together give you a quarry worth stalking: a North American mid-market manufacturer whose IT team inherited the plant network by accident and has never had a budget line for it. Write for that reader and the rest of the market will overhear you. Write for everyone and nobody hears anything.

That focus is the same discipline we brought to three publishers who filed their numbers, where the winner was the one that stopped chasing scale and started serving a single reader properly.

Section 03

Why OT security creative keeps selling the wrong fear#

Open almost any OT security campaign and you find the same photograph: a turbine hall lit like a thriller, a red padlock floating over it, a gloved hand reaching for a screen. It is beautiful work. It is also a picture of something that did not happen once across 1,140 incidents last quarter.

The cost of the wrong image is commercial, not aesthetic. A security engineer who has spent years arguing that the real risk is a flat network and a forgotten jump box sees your turbine and files your industrial cybersecurity brand under vendors who have not read the reports. You have lost the technical evaluator before the pricing page has even loaded.

Cinematic, and wrong

A red padlock over a darkened turbine hall, with a headline warning that attackers are inside your control systems right now.

Dull, and true

A named remote-access route, a service account nobody owns, and a sentence saying that every incident Dragos logged last quarter stopped short of the control layer.

Fernando Cassina put it sharply in a post on 17 August 2026, written in Spanish (X): "El ransomware industrial no entra por el PLC: entra por la VPN sin MFA." The translation is folkfox's own: industrial ransomware does not come in through the PLC, it comes in through the VPN without multi-factor authentication.

The plant did not stop because somebody moved a valve. It stopped because nobody could raise a purchase order.
folkfox, on what the Q2 2026 numbers actually describe

What operational technology security buyers want to read instead#

Operational technology security is not a genre of fear, it is a maintenance discipline with a hostile audience. The industrial cybersecurity copy that converts describes the boring interior: identity, remote access, network segmentation, backups somebody has actually restored, and an asset inventory a named person keeps current. Sell the audit, not the apocalypse.

There is a second reason to drop the drama. Fear-led claims age badly and attract complaints, which is how a rival's spreadsheet ended a savings campaign in the ASA case we covered this month. Evidence at the point of the claim is the cheapest defence going.

This is also where the phrase ransomware protection services stops being a keyword and starts being a promise. Most vendors bury it beneath platform language, because a services page feels less impressive than a product page, and then wonder why the enquiry form stays silent. The buyer under pressure is shopping for relief, not architecture, and the words on the page should say so.

Get the language right and the funnel follows. That is brand strategy work as much as campaign work: the promise has to survive procurement and a sceptical engineer in the same meeting.

Section 04

The compliance calendar behind the next budget cycle#

Budgets move on dates, not on dread. There is a date, and at the time of writing it sits 25 days away.

From 11 September 2026, under the EU Cyber Resilience Act, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements, per the European Commission. The cadence is the story. An early warning within 24 hours of becoming aware, a full notification within 72 hours, then a final report.

That final report is due no later than 14 days after a corrective measure is available for actively exploited vulnerabilities, and within a month for severe incidents. Twenty-four, seventy-two, fourteen: a content calendar handed to you by a regulator, with the deadlines already written.

The regulation itself is Regulation (EU) 2024/2847, and the reporting route runs through a Single Reporting Platform. ENISA describes it as a technical tool that shall become the mechanism for reporting actively exploited vulnerabilities and incidents affecting products with digital elements in the EU Digital Single Market, and says that throughout 2025 and 2026 it has been taking the steps needed to support the platform's implementation. That page speaks in the future tense. Read it as a schedule, not a scandal.

The sharpest line on the deadline came from an account posting as SBOMFlow at 11:30 on 17 August 2026 (X): "You cannot report what you cannot inventory." Seven words, and they convert a compliance date into a discovery project with a budget attached to it.

The other dates on the same page#

The AI Act crowds the same diary. Per the published implementation timeline, on 2 August 2026 the remainder of the AI Act starts to apply, except Article 6(1), and Member States had to ensure their competent authorities had established at least one national AI regulatory sandbox by that date. Article 6(1) and its corresponding obligations follow on 2 August 2027, and AI systems inside the large-scale IT systems listed in Annex X must be brought into compliance by 31 December 2030.

Why does that belong in an industrial cybersecurity piece? Because one buyer owns both problems, and because the agentic tooling arriving in plants right now is being governed by access rules written for people with laptops.

A practitioner post on r/cybersecurity on 17 August 2026, an anonymous account rather than a verified incident report, describes a ticket-triage agent that opened the internal wiki, followed a link dropped in a page and pulled down a config file holding a live API key. It was running as a service account somebody who had already left set up for a nightly export. The line that lands is the last one: "The login rules we are so proud of do not even touch it."

That is the register the market is short of. Specific, unglamorous, checkable. It is the same lesson we drew from answer engine visibility in healthcare: the honest, narrow account travels further than the frightening one, especially when the frightening one has no source under it.

Section 05

Building an industrial cybersecurity programme worth funding#

None of this needs a rebrand. It needs a reorientation, and a fox does it the same way every time: find the trail the quarry actually walks, then wait on it rather than on the one that photographs well.

Five moves, in the order they pay
Read the quarter first

Open every industrial cybersecurity brief with the newest incident analysis rather than the last campaign. One honest read of the Dragos numbers kills a bad creative route before a designer touches it.

Move the image indoors

Retire the turbine hall. Show the domain controller, the jump box and the supplier VPN, because that is the trail this quarter actually took.

Publish the panic page

Ship an incident-response page with a phone number above the fold, written for somebody having the worst Tuesday of their career, and rank it for ransomware protection services.

Diarise the regulator

Put 11 September 2026 in the calendar and build backwards, one asset a week against the 24 hour, 72 hour and 14 day reporting cadence.

Baseline in first-party data

Set measurement on Search Console impressions, form fills and pipeline before you buy a rank tracker, because the scraping layer beneath those tools is currently in court.

Step three is the one that gets argued about in the review, so here it is with the padding stripped out. Publish the incident-response page before the product page. A buyer in the middle of a bad week is not searching for your platform architecture, they are searching for a phone number, and the phrase they type is far closer to ransomware protection services than to anything in your category taxonomy.

Five assumptions an industrial cybersecurity deck usually carries, and the Q2 2026 evidence that retires each one.
Assumption in the deckWhat Q2 2026 showedWhat to change
Attackers pivot to the PLCNo case reached Stage 2 of the ICS Cyber Kill Chain (Dragos)Move the hero image to identity and remote access
Everyone is a targetManufacturing took 65% of 1,140 incidentsNarrow the media plan to one sector and one region
Europe is the centre of gravityThe United States alone took 431, 38% of the worldwide totalRebalance paid budget towards North America
One gang drives the riskQilin fell from 198 claims to 140, with Akira on 129Stop building the campaign around a single named adversary
Compliance is a 2027 problemReporting obligations begin on 11 September 2026Build the 24, 72 and 14 day content calendar now

The uncomfortable page nobody wants to write#

Somewhere in your funnel there should be an honest page about ransomware negotiation. Most industrial cybersecurity brands will not write it, because it reads like an admission that prevention failed. That is exactly why it ranks. The query is small, the intent is desperate, and the competition is a hedgerow of press releases nobody finishes reading.

Write it with your legal team in the room. State plainly what you will do, what you will not do, and where the decision sits with counsel and the insurer. A page saying you do not handle payment but you handle everything around it beats a page pretending the question never comes up.

Measure something that survives contact with reality#

Share of voice on industrial cybersecurity queries is a fine metric right up to the moment you notice the data underneath it is being litigated. MediaPost reported on 11 August 2026 that Google had filed an amended complaint against SerpApi alleging it bypassed technological safeguards, three weeks after a district judge dismissed the original complaint and left Google able to proceed only on claims about content it licensed from third parties.

SerpApi's own account of that July ruling, which is the defendant speaking and should be read as such, says "the court rejected Google's attempts to expand the DMCA to assert control over access to public pages" (SerpApi). Google, for its part, says it receives hundreds of millions of artificial search requests each day from SerpApi and built a system it calls SearchGuard to stop bot scraping.

The practical point for a security marketer is small and sharp. Keep a first-party baseline. Impressions, form fills and pipeline belong to you whatever happens to the scraping layer, while a rank tracker's numbers belong to somebody else's court case.

If you want the programme built rather than described, that is content marketing and SEO and GEO work with a security specialist's reading list attached. We run the same evidence-first discipline across FinTech marketing, where the regulator changes but the reflex does not, and it is how an industrial cybersecurity brand stops shouting and starts being cited.

The fox does not win by being louder in the undergrowth. It wins by knowing which gap in the fence is real, and by being sat beside it when the quarry comes through.

Questions

Frequently asked questions#

What is OT security, in plain terms?

OT security protects the systems that run physical processes: controllers, sensors, drives and the networks joining them together. It differs from IT security because availability and safety outrank confidentiality, patches wait for a maintenance window, and equipment often outlives three generations of the software watching over it.

How is operational technology security different from IT security in practice?

Operational technology security lives with kit that cannot be rebooted on a Tuesday. Change control runs slower, downtime carries a physical cost, and the safety case matters more than the patch cycle. In Q2 2026 Dragos recorded no ransomware case that reached a control system, so in practice most incidents still begin and end on the IT side.

Do ransomware protection services actually reduce risk for a plant?

They help most when they cover the enterprise side: identity, remote access, segmentation and restores somebody has genuinely tested. Dragos found the whole of Q2 2026 ran through enterprise IT rather than control systems, so ransomware protection services that only watch the plant network are guarding a door nobody used.

Should an industrial firm budget for ransomware negotiation?

Plan for it rather than budget for it. Decide in advance who authorises contact, which counsel and insurer are involved, and what your public position will be. Ransomware negotiation is a legal and insurance decision with regulatory consequences attached, so the useful preparation is a written playbook agreed while nothing is on fire.

Which sector was hit hardest in Q2 2026?

Manufacturing, by a distance. Dragos recorded 747 incidents across all manufacturing subsectors, 65% of the 1,140 total. Construction followed on 176, organisations supporting ICS environments on 117 and equipment manufacturing on 114, according to Help Net Security's coverage of the same analysis.

Did any attacker actually reach a control system last quarter?

No. Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Where production stopped, it stopped because enterprise systems were encrypted, not because a controller had been tampered with.

Keep reading

Read more on this topic#

Ready to sell against the threat that is actually happening?

At folkfox we build industrial cybersecurity content a security engineer will finish reading: evidence at the point of every claim, no stock turbines, and reporting that survives an algorithm change.