WALLIX
Expert Opinion — March 2026

OT Security Resilience: Before, During and After the Incident

A practical resilience framework for industrial environments — organised across three phases: anticipation, response, and recovery.

Yoann DelomierYoann DELOMIEROT Business Strategic LeaderMarch 202612 min read
OT SecurityPAMNIS2ResilienceManufacturing
$0M

avg. industrial data breach cost (2024)

0%

of all cyberattacks hit manufacturing (2025)

0 days

avg. time to identify an industrial breach

$0K/hr

cost of manufacturing unplanned downtime

Executive Summary

Industrial organisations have spent years building stronger perimeter defences. Yet the threat landscape keeps outpacing those efforts. Manufacturing is the single most targeted sector for ransomware, now for the fifth consecutive year, according to IBM X-Force. The consequences are severe:

Scroll
$0M

avg. industrial data breach cost (2024)

The highest year-on-year increase across all industries — source: IBM Cost of a Data Breach Report

$0K/hr

cost of unplanned manufacturing downtime

Production lines that stop, supply chains that fracture, and revenue that evaporates

These are not abstract numbers. They represent production lines that stop, supply chains that fracture, and revenue that evaporates.

Against this backdrop, boardroom conversations are shifting. Gartner's 2026 cybersecurity trends report identifies cyber resilience as a strategic imperative driven by regulatory volatility, geopolitical tensions, and an accelerating threat landscape. The message is clear: prevention alone is no longer sufficient.

Organisations must build the capacity to:

Before

Anticipate

Harden access controls, segment networks, build complete audit trails.

Before

Withstand

Reduce attack surface so intrusions stay contained, not catastrophic.

During

Respond

Instant containment — kill switches, isolated mode, real-time monitoring.

After

Recover

Forensic analysis, credential rotation, controlled validated recovery.

— whilst keeping production running.

The European regulatory environment reinforces this shift. The NIS2 Directive, now entering active enforcement across EU member states, explicitly requires business continuity planning, crisis management, incident handling, and supply chain security as core compliance obligations. For industrial operators, NIS2 compliance is not just about protecting IT systems. It demands operational resilience across the entire organisation, including OT environments.

This expert opinion presents a resilience framework for OT environments, organised into three phases:

For each phase, we examine the challenge from both a cybersecurity and production perspective, and demonstrate how WALLIX PAM delivers practical resilience capabilities that satisfy regulatory requirements whilst keeping operations alive.

The Case for OT Resilience

Scroll

Why Prevention Is Necessary but Not Sufficient

Manufacturing is firmly established as the most targeted sector for cyberattacks. Attackers exploit sprawling networks, complex legacy systems, and inadequate segmentation between IT and OT environments. These gaps persist even in well-defended organisations that exploit zero-day vulnerabilities, compromised supply chains, and social engineering.

0%

of all cyberattacks hit manufacturing (2025)

The highest share on record — source: IBM X-Force Threat Intelligence Index 2026

0 years

consecutive #1 most attacked industry

Manufacturing has topped the ranking every year since 2021

IBM X-Force Threat Intelligence Index

Manufacturing: #1 Most Attacked Industry — 2021–2025

2021
#1
1
X-Force 2022

Most targeted sector globally

2022
#1
1
X-Force 2023

Most extorted industry; ~half of Asia attacks

2023
#1
1
X-Force 2024

Enters IBM CODB top 5 costliest industries

2024
#1
1
X-Force 2025

70% of attacks targeted critical infrastructure

2025
27.7%
1
X-Force 2026

27.7% of all global cyberattacks — highest share on record

Data integrity note: The 27.7% share (2025 data) is the only explicitly published percentage figure — sourced directly from IBM X-Force Threat Intelligence Index 2026. Bar heights for 2021–2024 are scaled proportionally to reflect confirmed "#1 ranked" status; IBM did not publish a specific share percentage for those years. "#1 most attacked industry" status for all five years is confirmed by respective X-Force annual editions.
Source: IBM X-Force Threat Intelligence Index 2022–2026.

This is why Gartner now frames cybersecurity through the lens of resilience rather than prevention. Their 2026 trends report notes that "shifting geopolitical landscapes and evolving global mandates have made cybersecurity a critical business risk with direct implications for organisational resilience." In OT environments, this means accepting that an attacker may gain access. The organisations that fare best are those that can contain the damage, maintain critical operations, and recover quickly.

The organisations that fare best are those that can contain the damage, maintain critical operations, and recover quickly.

The Dual Impact: Cybersecurity and Production

What makes OT resilience fundamentally different from IT resilience is the dual impact of every incident. A ransomware attack on a corporate file server causes inconvenience and data loss. The same attack reaching a SCADA system or PLC can halt a production line, create safety hazards, and cascade through an entire supply chain.

Manufacturing downtime costs vary by sector, but the numbers are consistently brutal:

€0M+/hr

automotive unplanned stoppage cost

Manufacturing downtime costs vary by sector — but the numbers are consistently brutal

$0K/hr

avg. industrial unplanned downtime cost

Source: IBM Cost of a Data Breach Report 2024

0 days

avg. time to identify an industrial breach

Source: IBM Cost of a Data Breach Report 2024

0 days

additional days to contain it

Combined: nearly 9 months of exposure before full resolution

IBM Cost of a Data Breach — 2023–2025

Industrial Sector: Average Data Breach Cost (USD M)

Industrial sector averageGlobal all-industry average
$3.5M$4.0M$4.5M$5.0M$5.5M$6.0M$6.5M202320242025$4.45M$4.88M$4.44M$4.73M$5.56M+18% YoY$5.00M+$0.68M gap
Data integrity note: Chart covers 2023–2025 only. IBM CODB did not publish a standalone industrial-sector figure before 2023 (the sector entered the top 5 ranking in the 2023 report for the first time). No data points have been interpolated or estimated. Industrial 2024 figure ($5.56M) confirmed as the highest year-on-year cost increase across all 17 industries studied.
Industrial sector average data breach cost (USD M), 2023–2025. Sources: IBM Security / Ponemon Institute — Cost of a Data Breach Report (CODB) 2023, 2024, 2025. Full report: ibm.com/reports/data-breach

That is nearly nine months of exposure before an incident is fully resolved — an outcome no operations director can accept. Effective OT resilience must therefore serve two masters simultaneously: the CISO, who needs to contain threats and maintain the security posture, and the Production Head, who needs the line to keep running. Any solution that addresses one at the expense of the other will fail in practice.

Regulatory Drivers: NIS2 and Business Continuity

The NIS2 Directive makes this dual mandate a regulatory requirement. Article 21 explicitly requires covered entities to implement risk management measures encompassing incident handling, business continuity, crisis management, and supply chain security. In January 2026, the European Commission proposed targeted amendments to simplify compliance further while maintaining stringent resilience requirements.

For industrial operators, NIS2 compliance means going beyond IT disaster recovery. It requires continuity of the organisation's business processes as a whole, including OT environments where physical production depends on the availability and integrity of control systems. Management bodies are personally accountable for compliance failures, and essential entities face significant fines:

€0M

max NIS2 fine per violation

0%

of global turnover (alternative penalty)

For essential entities, regulators apply whichever threshold is higher, and management bodies can be held personally accountable. These are statutory maximums; actual enforcement timelines and levels vary by member state. With resilience-oriented investments driving much of the growth, Gartner's global information security spending forecast confirms the market is responding:

$0B

projected global infosec spending in 2026

Source: Gartner Forecast, 4Q25 Update

+0%

year-on-year increase in security spending

Resilience-oriented investments driving the growth

The alignment between regulatory pressure, market spending, and operational reality creates a clear mandate: invest in resilience now, or face compounding risk.

Phase 1

Before the Incident: Anticipation & Preparation

The strongest form of resilience is never being tested. Whilst no defence is impenetrable, the measures organisations put in place before an incident determine whether an intrusion becomes a nuisance or a catastrophe.

Scroll

WALLIX PAM delivers a set of anticipatory controls that serve both cybersecurity and operational objectives.

Cybersecurity Perspective

The goal is clear: reduce the attack surface, harden identity controls, and ensure complete visibility over who accesses what. WALLIX achieves this through several reinforcing mechanisms.

Production Benefit

These same controls translate into resilience advantages that directly strengthen the organisation's ability to anticipate threats, limit their impact, and recover cleanly.

Strong authentication & MFA

Cybersecurity Perspective

Multi-factor authentication, privileged account management, and a dedicated third-party identity provider block identity-based intrusions before they start. Even if attackers steal credentials, they still cannot get in. IBM X-Force 2026 data shows that nearly a third of manufacturing attackers used compromised credentials to access administrative and operational systems once inside, making controlled identity management an essential first line of defence.

Production Benefit

Strong authentication eliminates the credential habits that create silent liability: shared passwords, generic contractor accounts, and credential reuse that destroy accountability when something goes wrong. Every action is traceable to a named individual from the moment they connect. When an incident occurs, you have the evidence to understand it.

Granular access control (RBAC)

Cybersecurity Perspective

Role-based, time-based, and asset-based access restrictions ensure users can access only the systems they are authorised for, nothing more. This limits lateral movement and prevents both accidental and deliberate access to sensitive OT assets.

Production Benefit

There is no risk of third parties exceeding their privileges, which could otherwise lead to misconfigurations or production incidents that are impossible to trace. Access is strictly bound to what each role requires; lateral movement and privilege overreach are blocked at the source.

SRA Bastion (IT/OT segmentation)

Cybersecurity Perspective

The WALLIX Secure Remote Access bastion sits at the IT/OT boundary, creating a clean, enforceable separation with trust zones and conduits aligned to IEC 62443. Attackers struggle to reach the industrial network, and you stay compliant without redesigning your entire infrastructure.

Production Benefit

The WALLIX PAM acts as a proxy in the iDMZ layer, offering a shield approach that preserves OT production: no more shadow VPNs or uncontrolled IT-to-OT access paths. One controlled gateway means fewer unmanaged connections to trace when something goes wrong, and complete traceability across all vendor activity from the moment of connection.

Full session recording & audit

Cybersecurity Perspective

Every remote connection. Every privileged operation. No blind spots, no assumptions. You can prove who did what, when, and why. This is a requirement under both NIS2 and IEC 62443.

Production Benefit

When something goes wrong on the line, you know exactly who was connected and what they did. No more guessing which remote session or recent change caused the issue.

Third-party access governance

Cybersecurity Perspective

Remote vendors connect only through the secure gateway, with no direct PLC/SCADA VPN access. In the event of an incident, there are no unmanaged connections to trace; everything runs through a centralised access platform with full traceability.

Production Benefit

Vendors and contractors reach the systems they need through a controlled, governed pathway rather than an open VPN that bypasses every security control. Every external party is authenticated, their access is scoped to specific assets, and their session is approved before it opens.

Session approval workflows

Cybersecurity Perspective

No external party connects to your operational environment without explicit approval. OT teams review and authorise remote sessions before they are activated. OT teams can approve, deny, and monitor in real time. This closes a critical gap: unknown or forgotten remote sessions that have historically provided attackers with an open door into industrial networks.

Production Benefit

Session approval gives OT teams direct control over who gets in and when. Remote access requests come to you for approval before any connection is established, and only authorised persons can perform maintenance on critical equipment. No more discovering after the fact that someone was inside a control system you did not know about.

SOC/SIEM integration

Cybersecurity Perspective

Detailed access logs feed directly into your SOC. Unusual activity gets spotted earlier, dots get connected faster, and your team responds before an intrusion becomes a production-threatening incident.

Production Benefit

Unusual access patterns are flagged early, before they lead to unplanned downtime or unexpected configuration changes. SOC/SIEM integration means your security team sees the same picture your OT team does, and both can act on it before an anomaly becomes an incident.

Legacy asset protection

Cybersecurity Perspective

Older PLCs, HMIs, and controllers without modern security features need not remain the weakest link. Encrypted, authenticated, supervised access protects these assets without touching the equipment itself, reducing attack surface and buying time before costly upgrades.

Production Benefit

Crucially, legacy equipment stays in production. Older PLCs, HMIs, and controllers can be protected with access controls without requiring costly upgrades or replacements. They remain defensible under governance, bought time before any forced replacement decision.

Credential Governance

Cybersecurity Perspective

Credentials are the keys to your OT environment. A vault stores them securely, rotates them automatically, and revokes them instantly when an incident breaks out or a vendor contract ends. Some legacy assets (field devices, protection relays, certain PLCs) rely on fixed credentials and cannot rotate. For those, controlled access takes over: every request is known, every session recorded, accountability never in question.

Production Benefit

Credentials vaulted and governed. Rotation where assets support it; controlled access and full session recording, where they don't.

Phase 2

During the Incident: Response & Containment

When an intrusion is detected, every second counts. The difference between a contained incident and a full-scale production shutdown often comes down to how quickly and decisively an organisation can respond.

Scroll

WALLIX PAM provides the tools to limit propagation and maintain operational control without forcing a complete shutdown.

Cybersecurity Perspective

The priority is containment: cut off attacker access, preserve forensic evidence, and maintain full visibility over every active session while the threat is neutralised.

Production Benefit

The priority during an incident is to keep the line running, or at a minimum, to control the degradation. WALLIX's response capabilities are designed with this reality in mind.

Centralised kill switch

Cybersecurity Perspective

One control point terminates all remote connections across the entire operational environment. When an intrusion is detected, attacker access is cut in seconds, before they reach critical systems. This is the kind of capability that turns a potential catastrophe into a manageable event.

Production Benefit

Remote access shuts down instantly when needed. You are not waiting on IT to act. Critical systems are protected in seconds, minimising exposure and potential downtime.

Immediate account suspension

Cybersecurity Perspective

Compromised user accounts and third-party credentials get disabled the moment a threat is identified, with no waiting for manual password resets or policy updates. The threat is immediately locked out while your audit trail remains intact.

Production Benefit

Compromised or suspected accounts are locked out without disrupting the rest of the team; the rest of the team keeps working while the threat is contained.

Real-time session monitoring

Cybersecurity Perspective

Suspicious behaviour shows up as it happens: unexpected commands, unusual lateral movement, multiple sessions from the same account, and connections outside standard patterns. Dedicated security team members are alerted and can step in before damage occurs.

Production Benefit

Flags anomalies before they impact the production line. If a remote change caused an issue, you can trace exactly what happened, with no guesswork or finger-pointing, just clear answers.

Isolated mode (Unified Console)

Cybersecurity Perspective

External remote connections can be temporarily turned off via the WALLIX ONE Remote Access Unified Console, while internal monitoring and essential access remain active. Your operational environment is shielded during investigation without losing visibility or forcing a complete shutdown.

Production Benefit

External connections pause while internal operations continue. You investigate without forcing a full production shutdown, maintaining visibility throughout the process.

Encrypted session preservation

Cybersecurity Perspective

Every action taken during an incident is captured and preserved in tamper-proof, encrypted recordings. Evidence is ready for post-incident analysis, compliance reporting, and potential legal proceedings.

Production Benefit

If a remote change caused an issue, you can trace exactly what happened, with no guesswork or finger-pointing, just clear answers.

Automatic SOC alerting

Cybersecurity Perspective

Immediate alerts go to your SOC when suspicious remote activity is detected. No delays, no missed signals. Your response team mobilises the moment something looks wrong.

Production Benefit

Faster awareness means less time lost to escalation. Your response team mobilises the moment something looks wrong.

Break glass mechanism

Cybersecurity Perspective

Emergency access to critical systems remains available even when standard authentication pathways are compromised. Production teams can continue operating safely while the incident remains contained.

Production Benefit

Production is not blocked by its own equipment during an emergency incident, whether a cyber event, fire, or electrical failure. Access to critical systems remains available even when Secure Remote Access is down.

Local control fallback

Cybersecurity Perspective

When remote pathways are under attack, critical production continues only through secure on-site access. Operations do not stop; they revert to the most secure access method until the threat is neutralised.

Production Benefit

When remote access is compromised, operations shift to secure on-site access. The line keeps running while the threat is dealt with.

Phase 3

After the Incident: Recovery & Improvement

How an organisation recovers from an incident determines whether it comes back stronger or remains vulnerable to the next attack. The post-incident phase is where resilience is truly built, through forensic understanding, systematic remediation, and validated recovery.

Scroll

WALLIX PAM ensures that recovery is thorough, controlled, and feeds directly into strengthened defences.

Cybersecurity Perspective

The goal shifts to hardening: trace the full attack path, eliminate every compromised credential, and ensure that restored access is tighter than what existed before the incident.

Production Benefit

The post-incident phase is about getting back to full operations on a stronger footing. WALLIX's recovery capabilities ensure this happens without the chaos that typically follows a security event.

Forensic log & video review

Cybersecurity Perspective

Detailed access logs and video recordings let you trace the complete attack timeline. You understand exactly which credentials were compromised, what systems were accessed, and how the attacker moved through your environment. This is the foundation for every improvement that follows.

Production Benefit

You understand exactly what happened without weeks of forensic investigation. Access logs and session recordings pinpoint which user, remote session, or credential was involved.

Credential & SSH key rotation

Cybersecurity Perspective

Passwords and access keys for all remote accounts get rotated systematically. Any credentials that may have been exposed are eliminated so attackers cannot use them to re-enter your environment.

For legacy OT assets that cannot be rotated, you still gain clean accountability: every credential mapped to a named person, every access right justified, nothing left open by default.

Production Benefit

Rotation where assets support it. For legacy OT assets, clean accountability steps in, credentials mapped, access justified, nothing left open.

Access rights reassessment

Cybersecurity Perspective

Outdated user accounts are removed. Third-party permissions are refined. Excessive privileges discovered during the incident are eliminated.

Every access right is validated against current operational needs and the principle of least privilege.

Production Benefit

Access rights reflect who actually needs access today. Outdated accounts, over-privileged vendors, and forgotten contractor credentials are cleaned out, which reduces future risk.

Controlled reactivation

Cybersecurity Perspective

Remote access is restored progressively, not rushed. Each connection pathway is tested and verified before going live, and only after security validation confirms that vulnerabilities are addressed and monitoring is enhanced.

Production Benefit

Production resumes on a stronger footing, with remote access coming back online progressively and each connection pathway validated before it goes live.

Sectors in scope

OT resilience is a cross-industry imperative

Pipelines, grid, generation

Energy & Utilities

Hospitals & medical devices

Healthcare

Factories & production lines

Manufacturing

WALLIX

PAM Resilience Measures

A unified view of WALLIX PAM capabilities across all three phases of incident resilience.

Phase 1

Before the incident

Strong authentication & MFA

Granular access control (RBAC)

SRA Bastion (IT/OT segmentation)

Full session recording & audit

Third-party access governance

Session approval workflows

SOC/SIEM integration

Legacy asset protection

Credential Governance

Phase 2

During the incident

Centralised kill switch

Immediate account suspension

Real-time session monitoring

Isolated mode (Unified Console)

Encrypted session preservation

Automatic SOC alerting

Break glass mechanism

Local control fallback

Phase 3

After the incident

Forensic log & video review

Credential & SSH key rotation

Access rights reassessment

Controlled reactivation

Regulatory Alignment: NIS2 and IEC 62443

The three-phase resilience framework directly addresses specific regulatory requirements. NIS2 Article 21 mandates risk management measures covering incident handling, business continuity, and supply chain security. IEC 62443-3-3 requires specific capabilities for access control, network segmentation, and audit at each Security Level.

Scroll

NIS2 Directive

Article 21 — Risk management measures

Art. 21(b) — Incident handling

Kill switch, real-time monitoring, SOC alerting, isolated mode

Art. 21(c) — Business continuity

Break glass, local fallback, controlled reactivation of remote access

Art. 21(d) — Supply chain security

Third-party governance, session approval workflows, dedicated IDP

Art. 21(g) — Access control & MFA

Strong authentication, RBAC, privileged account management

IEC 62443

Functional requirements for industrial security

FR1 — Identification & Authentication

MFA, dedicated OT identity provider, session approval workflows

FR5 — Network segmentation

SRA Bastion at IT/OT boundary — trust zones and conduits enforced

FR6 — Audit & accountability

Full session recording, forensic log review, encrypted preservation

Conclusion

The question for industrial organisations in 2026 is no longer whether they will face a cyber incident, but how well they will cope when it happens. With manufacturing firmly established as the most targeted sector for the fifth consecutive year, the average industrial breach taking over nine months to fully identify and contain, and regulators now holding executives personally accountable for resilience failures, the stakes could not be higher.

Scroll

WALLIX PAM addresses this reality with a practical, three-phase resilience framework that works for both the CISO and the Production Head. Before an incident, it hardens access controls, segments networks, and creates complete audit trails. During an incident, it provides instant containment capabilities — from centralised kill switches to isolated mode — without forcing a full production shutdown. After an incident, it enables thorough forensic analysis, systematic credential rotation, and controlled, validated recovery.

What sets this approach apart is the refusal to treat security and operations as competing priorities. Every measure is designed to serve both: the kill switch cuts attacker access and shields production from further damage. Session recordings provide forensic evidence and answer production troubleshooting questions. Legacy asset protection reduces attack surface and keeps critical systems defensible without forcing premature replacement.

For OT environments, those new approaches must be purpose-built. A factory floor is not a server room. Production continuity is non-negotiable. And the best security is security that people actually use — because it does not get in the way of their work. Resilience is not a product feature. It is an operational philosophy. WALLIX PAM gives organisations the tools to make that philosophy real.

0 months

avg. time to fully resolve an industrial breach

199 days to identify + 73 days to contain — source: IBM Cost of a Data Breach Report 2024

0th year

manufacturing ranked #1 most attacked sector

The most targeted sector for ransomware for five consecutive years — source: IBM X-Force 2026

WALLIX

Resilience is an operational philosophy

A factory floor is not a server room. Production continuity is non-negotiable. The best security is security that people actually use — because it does not get in the way of their work. WALLIX PAM gives organisations the tools to make resilience real.

Yoann DELOMIER

OT Business Strategic Leader

References

  1. [1]IBM X-Force (2026). X-Force Threat Intelligence Index 2026. Published February 2026. https://www.ibm.com/reports/threat-intelligence
  2. [2]IBM Security (2024). Cost of a Data Breach Report 2024. Ponemon Institute / IBM. July 2024. https://www.ibm.com/reports/data-breach
  3. [3]Gartner (2026). Top Cybersecurity Trends for 2026. Press Release, 5 February 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026
  4. [4]European Commission (2022). Directive (EU) 2022/2555 — NIS2 Directive. https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
  5. [5]Gartner (2025). Forecast: Information Security, Worldwide, 2023–2029, 4Q25 Update. G00843183, 18 December 2025.

Get started

Ready to get started?

Our experts will assess your current OT environment and recommend a tailored PAM resilience roadmap.

Talk to an OT security expert