Nobody touched the turbine. They took the office.
Dragos logged 1,140 incidents against industrial organisations last quarter and not one operator reached a control system. Every industrial cybersecurity campaign built on a hacked turbine is selling against a threat that did not happen.
By Katie Delaney · 2026-08-17 · 15 min read
The quarter industrial cybersecurity spent in the office#
A fox does not force the farm gate. It walks the fence line until the fence forgets itself, then slips through the gap somebody propped open and never closed. That patient prowl is the precise shape of industrial cybersecurity in the second quarter of 2026, and it is why so much industrial cybersecurity marketing is currently pointed at the wrong door.
Dragos counted 1,140 ransomware incidents against industrial organisations worldwide in Q2 2026, a 12% rise on the 1,020 recorded in Q1. That is the number every vendor will put on a slide next month. The sentence sitting underneath it is the one that should rewrite your industrial cybersecurity messaging.
The analysis is unambiguous. "Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system," the report states. Not one. No near miss, no partial, no quietly redacted case study. Across a quarter of 1,140 incidents, the control layer was never touched.

Read that twice, because it retires a decade of industrial cybersecurity creative. The turbine did not trip. The valve did not slam shut. Production stopped, where it stopped at all, because the enterprise systems that schedule, cost and dispatch the work were encrypted, and a plant that cannot raise a purchase order is a plant that cannot run a shift.
The threat model your buyer already believes#
Dragos framed the quarter's risk plainly, and Help Net Security carried the framing on 11 August 2026: the danger is being shaped less by novel ICS-specific malware than by attackers' deepening focus on the enterprise IT systems that support operational technology environments.
Your buyer already knows this, because they live in it. They have a domain controller carrying a decade of scar tissue, a flat network somebody has been promising to segment for years, and a remote-access route a supplier set up and nobody has audited since. When your creative shows a gloved hand on a control panel, you are telling that person a story they stopped believing long ago.
Qilin was still the most active group of the quarter with 140 claims, down from 198 in Q1. Akira posted 129 and The Gentlemen 125, according to Help Net Security. The field got busier while its loudest brand got quieter, which is what fragmentation looks like from outside the thicket, and it is a warning to anyone building an industrial cybersecurity campaign around a single named adversary.
Where the quarter actually landed#
Manufacturing absorbed 747 incidents, 65% of the quarter, across all subsectors. That single share should decide your media plan before it decides your headline, because a market where two thirds of the pain sits in one sector does not need a broad industrial cybersecurity campaign. It needs a narrow one, aimed at a reader you can picture.
The tail matters as much as the head. Construction took 176, organisations supporting ICS environments 117, equipment manufacturing 114, transportation and logistics 95, and food and beverage 70, per Help Net Security. These are not exotic verticals. They are mid-market firms with a two-person IT team who buy industrial cybersecurity the way they buy insurance: once a year, in a hurry, on somebody else's recommendation.
The 117 count is the quiet one. Organisations supporting ICS environments means integrators, engineering consultancies and maintenance contractors, the suppliers who hold remote access into other people's plants. Sell to them and you are not selling one licence, you are selling the credential hygiene of every site on their books.
Geography is a budget line, not a footnote#
The United States alone absorbed 431 incidents, 38% of the worldwide total, with North America on 514, Europe on 316, Asia on 172 and South America on 64. If your industrial cybersecurity pipeline is weighted to EMEA while the incident curve is weighted to North America, that mismatch is a media buying decision rather than a brand problem, and paid search corrects it faster than a rebrand ever will.
Sector and geography together give you a quarry worth stalking: a North American mid-market manufacturer whose IT team inherited the plant network by accident and has never had a budget line for it. Write for that reader and the rest of the market will overhear you. Write for everyone and nobody hears anything.
That focus is the same discipline we brought to three publishers who filed their numbers, where the winner was the one that stopped chasing scale and started serving a single reader properly.
Why OT security creative keeps selling the wrong fear#
Open almost any OT security campaign and you find the same photograph: a turbine hall lit like a thriller, a red padlock floating over it, a gloved hand reaching for a screen. It is beautiful work. It is also a picture of something that did not happen once across 1,140 incidents last quarter.
The cost of the wrong image is commercial, not aesthetic. A security engineer who has spent years arguing that the real risk is a flat network and a forgotten jump box sees your turbine and files your industrial cybersecurity brand under vendors who have not read the reports. You have lost the technical evaluator before the pricing page has even loaded.
Cinematic, and wrong
A red padlock over a darkened turbine hall, with a headline warning that attackers are inside your control systems right now.
Dull, and true
A named remote-access route, a service account nobody owns, and a sentence saying that every incident Dragos logged last quarter stopped short of the control layer.
Fernando Cassina put it sharply in a post on 17 August 2026, written in Spanish (X): "El ransomware industrial no entra por el PLC: entra por la VPN sin MFA." The translation is folkfox's own: industrial ransomware does not come in through the PLC, it comes in through the VPN without multi-factor authentication.
The plant did not stop because somebody moved a valve. It stopped because nobody could raise a purchase order.
What operational technology security buyers want to read instead#
Operational technology security is not a genre of fear, it is a maintenance discipline with a hostile audience. The industrial cybersecurity copy that converts describes the boring interior: identity, remote access, network segmentation, backups somebody has actually restored, and an asset inventory a named person keeps current. Sell the audit, not the apocalypse.
There is a second reason to drop the drama. Fear-led claims age badly and attract complaints, which is how a rival's spreadsheet ended a savings campaign in the ASA case we covered this month. Evidence at the point of the claim is the cheapest defence going.
This is also where the phrase ransomware protection services stops being a keyword and starts being a promise. Most vendors bury it beneath platform language, because a services page feels less impressive than a product page, and then wonder why the enquiry form stays silent. The buyer under pressure is shopping for relief, not architecture, and the words on the page should say so.
Get the language right and the funnel follows. That is brand strategy work as much as campaign work: the promise has to survive procurement and a sceptical engineer in the same meeting.
The compliance calendar behind the next budget cycle#
Budgets move on dates, not on dread. There is a date, and at the time of writing it sits 25 days away.
From 11 September 2026, under the EU Cyber Resilience Act, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements, per the European Commission. The cadence is the story. An early warning within 24 hours of becoming aware, a full notification within 72 hours, then a final report.
That final report is due no later than 14 days after a corrective measure is available for actively exploited vulnerabilities, and within a month for severe incidents. Twenty-four, seventy-two, fourteen: a content calendar handed to you by a regulator, with the deadlines already written.
The regulation itself is Regulation (EU) 2024/2847, and the reporting route runs through a Single Reporting Platform. ENISA describes it as a technical tool that shall become the mechanism for reporting actively exploited vulnerabilities and incidents affecting products with digital elements in the EU Digital Single Market, and says that throughout 2025 and 2026 it has been taking the steps needed to support the platform's implementation. That page speaks in the future tense. Read it as a schedule, not a scandal.
The sharpest line on the deadline came from an account posting as SBOMFlow at 11:30 on 17 August 2026 (X): "You cannot report what you cannot inventory." Seven words, and they convert a compliance date into a discovery project with a budget attached to it.
The other dates on the same page#
The AI Act crowds the same diary. Per the published implementation timeline, on 2 August 2026 the remainder of the AI Act starts to apply, except Article 6(1), and Member States had to ensure their competent authorities had established at least one national AI regulatory sandbox by that date. Article 6(1) and its corresponding obligations follow on 2 August 2027, and AI systems inside the large-scale IT systems listed in Annex X must be brought into compliance by 31 December 2030.
Why does that belong in an industrial cybersecurity piece? Because one buyer owns both problems, and because the agentic tooling arriving in plants right now is being governed by access rules written for people with laptops.
A practitioner post on r/cybersecurity on 17 August 2026, an anonymous account rather than a verified incident report, describes a ticket-triage agent that opened the internal wiki, followed a link dropped in a page and pulled down a config file holding a live API key. It was running as a service account somebody who had already left set up for a nightly export. The line that lands is the last one: "The login rules we are so proud of do not even touch it."
That is the register the market is short of. Specific, unglamorous, checkable. It is the same lesson we drew from answer engine visibility in healthcare: the honest, narrow account travels further than the frightening one, especially when the frightening one has no source under it.
Building an industrial cybersecurity programme worth funding#
None of this needs a rebrand. It needs a reorientation, and a fox does it the same way every time: find the trail the quarry actually walks, then wait on it rather than on the one that photographs well.
Open every industrial cybersecurity brief with the newest incident analysis rather than the last campaign. One honest read of the Dragos numbers kills a bad creative route before a designer touches it.
Retire the turbine hall. Show the domain controller, the jump box and the supplier VPN, because that is the trail this quarter actually took.
Ship an incident-response page with a phone number above the fold, written for somebody having the worst Tuesday of their career, and rank it for ransomware protection services.
Put 11 September 2026 in the calendar and build backwards, one asset a week against the 24 hour, 72 hour and 14 day reporting cadence.
Set measurement on Search Console impressions, form fills and pipeline before you buy a rank tracker, because the scraping layer beneath those tools is currently in court.
Step three is the one that gets argued about in the review, so here it is with the padding stripped out. Publish the incident-response page before the product page. A buyer in the middle of a bad week is not searching for your platform architecture, they are searching for a phone number, and the phrase they type is far closer to ransomware protection services than to anything in your category taxonomy.
| Assumption in the deck | What Q2 2026 showed | What to change |
|---|---|---|
| Attackers pivot to the PLC | No case reached Stage 2 of the ICS Cyber Kill Chain (Dragos) | Move the hero image to identity and remote access |
| Everyone is a target | Manufacturing took 65% of 1,140 incidents | Narrow the media plan to one sector and one region |
| Europe is the centre of gravity | The United States alone took 431, 38% of the worldwide total | Rebalance paid budget towards North America |
| One gang drives the risk | Qilin fell from 198 claims to 140, with Akira on 129 | Stop building the campaign around a single named adversary |
| Compliance is a 2027 problem | Reporting obligations begin on 11 September 2026 | Build the 24, 72 and 14 day content calendar now |
The uncomfortable page nobody wants to write#
Somewhere in your funnel there should be an honest page about ransomware negotiation. Most industrial cybersecurity brands will not write it, because it reads like an admission that prevention failed. That is exactly why it ranks. The query is small, the intent is desperate, and the competition is a hedgerow of press releases nobody finishes reading.
Write it with your legal team in the room. State plainly what you will do, what you will not do, and where the decision sits with counsel and the insurer. A page saying you do not handle payment but you handle everything around it beats a page pretending the question never comes up.
Measure something that survives contact with reality#
Share of voice on industrial cybersecurity queries is a fine metric right up to the moment you notice the data underneath it is being litigated. MediaPost reported on 11 August 2026 that Google had filed an amended complaint against SerpApi alleging it bypassed technological safeguards, three weeks after a district judge dismissed the original complaint and left Google able to proceed only on claims about content it licensed from third parties.
SerpApi's own account of that July ruling, which is the defendant speaking and should be read as such, says "the court rejected Google's attempts to expand the DMCA to assert control over access to public pages" (SerpApi). Google, for its part, says it receives hundreds of millions of artificial search requests each day from SerpApi and built a system it calls SearchGuard to stop bot scraping.
The practical point for a security marketer is small and sharp. Keep a first-party baseline. Impressions, form fills and pipeline belong to you whatever happens to the scraping layer, while a rank tracker's numbers belong to somebody else's court case.
If you want the programme built rather than described, that is content marketing and SEO and GEO work with a security specialist's reading list attached. We run the same evidence-first discipline across FinTech marketing, where the regulator changes but the reflex does not, and it is how an industrial cybersecurity brand stops shouting and starts being cited.
The fox does not win by being louder in the undergrowth. It wins by knowing which gap in the fence is real, and by being sat beside it when the quarry comes through.
Frequently asked questions#
What is OT security, in plain terms?
OT security protects the systems that run physical processes: controllers, sensors, drives and the networks joining them together. It differs from IT security because availability and safety outrank confidentiality, patches wait for a maintenance window, and equipment often outlives three generations of the software watching over it.
How is operational technology security different from IT security in practice?
Operational technology security lives with kit that cannot be rebooted on a Tuesday. Change control runs slower, downtime carries a physical cost, and the safety case matters more than the patch cycle. In Q2 2026 Dragos recorded no ransomware case that reached a control system, so in practice most incidents still begin and end on the IT side.
Do ransomware protection services actually reduce risk for a plant?
They help most when they cover the enterprise side: identity, remote access, segmentation and restores somebody has genuinely tested. Dragos found the whole of Q2 2026 ran through enterprise IT rather than control systems, so ransomware protection services that only watch the plant network are guarding a door nobody used.
Should an industrial firm budget for ransomware negotiation?
Plan for it rather than budget for it. Decide in advance who authorises contact, which counsel and insurer are involved, and what your public position will be. Ransomware negotiation is a legal and insurance decision with regulatory consequences attached, so the useful preparation is a written playbook agreed while nothing is on fire.
Which sector was hit hardest in Q2 2026?
Manufacturing, by a distance. Dragos recorded 747 incidents across all manufacturing subsectors, 65% of the 1,140 total. Construction followed on 176, organisations supporting ICS environments on 117 and equipment manufacturing on 114, according to Help Net Security's coverage of the same analysis.
Did any attacker actually reach a control system last quarter?
No. Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system. Where production stopped, it stopped because enterprise systems were encrypted, not because a controller had been tampered with.
Read more on this topic#
Answer Engine Optimization for Healthcare: the Quiet Cost of Going Unheard
What happens to a regulated brand when the answer arrives without the click, and how to become the source that gets quoted.
Read the pieceSports betting advertising just met its compliance moment
A dated obligation, a nervous category, and the campaign changes that landed before the deadline rather than after it.
Read the pieceThree publishers filed their numbers. Only one rebuilt the revenue
Filings as evidence: what changed for the publisher that stopped chasing scale and started serving one reader properly.
Read the pieceThe complaint came from a rival, and the maths did the rest
Why evidence at the point of the claim is the cheapest insurance a marketing team can buy.
Read the piece
Ready to sell against the threat that is actually happening?
At folkfox we build industrial cybersecurity content a security engineer will finish reading: evidence at the point of every claim, no stock turbines, and reporting that survives an algorithm change.