Last year, Dragos handled more operational technology cyber incident response cases than in the prior three years combined. A consistent pattern emerged across every engagement: organizations struggled to obtain the correct data to investigate what actually happened.
Sometimes the struggle is operational: individual log extraction instead of automated collection. More often, significant time is spent identifying which data sources could prove or disprove investigative hypotheses. These sources are incomplete or missing entirely. Most operational technology (OT) and industrial control system (ICS) asset owners do not invest meaningful resources into OT monitoring, detection, and response capabilities.
We know why. The cybersecurity standards they rely on as the source of truth favor prevention over everything else.
For two decades, industry standards specific to cybersecurity have centered on prevention: perimeter protection, preventative security countermeasures, and hardening the systems inside the boundary. They include detection, response, and recovery, but without equal weight or practical examples. This bias matters. It inhibits an organization’s ability to respond when preventative controls fail, and they always fail eventually.
There is also more to fail than there used to be. Defining extended operational technology (xOT), Dragos CEO Robert M. Lee draws the boundary around every system that can influence a control loop or physical process, regardless of classification, ownership, or protocol. OT was never a device category. It was the connection between digital systems and the physical world, and xOT applies that same test to an environment that now includes building automation, cloud-connected analytics, and the Windows HMI your asset inventory files under IT. As xOT environments expand and adversaries move faster, using AI to find and exploit vulnerabilities, the standards struggle to keep pace. The ones analyzed in this piece were written for the narrower definition. 
The National Institute of Standards and Technology (NIST) built its Cybersecurity Framework around six core functions. Five of them define outcomes: Identify, Protect, Detect, Respond, and Recover. The sixth, Govern, was added in CSF 2.0 and sets out the strategy, roles, policy, and oversight that shape how the other five get implemented.
Figure 1: Preventative vs. active functions, with Govern as cross-cutting (NIST CSF 2.0)
We analyzed dozens of standards and mapped how controls distribute across the five outcome functions. Controls aligned with Identify and Protect count as preventative. Those supporting Detect, Respond, and Recover count as active.
We scored Govern separately rather than counting it on either side. It does not execute controls, so folding it into the preventative column would have inflated the imbalance this analysis set out to measure. What Govern determines is whether the controls an organization already has stay effective over time, which becomes the central issue later in this piece.
Percentages throughout reflect the share of controls in each standard mapped to preventative or active functions, weighted by control count. Controls supporting both are scored separately.
What we found: every standard has a prevention bias.
Dragos analyzed numerous cybersecurity standards, regulations, and guidelines across OT and IT contexts. We reviewed those actively used in electric, chemical, manufacturing, pharmaceutical, metals & mining, oil & gas, transportation, water, building automation, and nuclear.
The analysis was clear. Every standard overweights preventative function.
Figure 2: Distribution of preventative and active controls across cybersecurity standards
The NIST Cybersecurity Framework treats its five outcome functions as equally important, which suggests a 20% distribution per function. Instead, Identify and Protect make up 60% of the controls. The remaining 40% splits between Detect, Respond, and Recover.
NIST SP 800-53 shows the extreme: 95% preventative, 3% active, and 2% mapping to both. While SP 800-53 is not an OT standard, it forms the basis for OT and sector-specific frameworks such as NIST SP 800-82 and NEI 08-09. The ISA/IEC 62443 series mirrors the same imbalance, averaging 75% prevention against 25% detection, response, and recovery across its parts, though individual parts vary widely.
Figure 3: Preventative and active control distribution across individual ISA/IEC 62443 parts
This explains what we document in our last five Year in Review reports: the OT/ICS industry is not adequately prepared to detect or respond to incidents.
Prevention is ideal. It is not guaranteed.
Preventative countermeasures atrophy. Configurations drift, and once-secure systems become vulnerable as firmware updates go unapplied, certificates expire, and device resets restore factory-default passwords. ISA/IEC 62443-1-1 illustrates this through a graph showing the relative security level of an Industrial Automation and Control System (IACS) over time. It refutes the notion that cybersecurity has a start and end date. It shows why controls become significantly less effective over time as new vulnerabilities emerge, and adversaries develop new tactics, techniques, and procedures (TTPs).
Without continuous evaluation, security controls will degrade. With periodic evaluation, they remain effective.
Figure 4: Relative security level of an IACS over time. Adapted from ISA/IEC 62443-1-1.
Last year, adversaries weaponized exploits in a median of 24 days. Multiple threat groups independently, and across geopolitical alignments, moved into actively mapping control loops and executing code to cause physical disruption. This is the removal of the last practical barrier between having network access and being able to cause operational disruption. It indicates teams behind these operations are being told to prepare to act, not just to maintain options.
In our rapid-response work, we routinely found asset owners with limited or no detection capabilities in OT network segments. They remained unaware of failed preventative controls until operational impact occurred.
In a typical architecture review of an oil and gas facility, we discovered a “Permit Any” firewall rule that completely negated the organization’s segmentation efforts. The rule was labeled temporary and included “temp” in its name. Evidence showed that it had been in place for months. The protection was effective when first installed. Over time, rules like this have accumulated and severely diminished the firewall’s effectiveness.
Prevention is one piece. Detection acts as continuous validation that other countermeasures function as expected. It provides early warning when they do not. But all countermeasures, preventative and active, must undergo periodic evaluation of effectiveness.
No organization is exempt from OT cyber threats. Having established, well-thought incident response plans that execute immediately after threat detection is critical to limiting impact and cost.
The need for resilient xOT cybersecurity programs is greater than ever. Dragos tracks 26+ named OT threat groups. Ransomware groups impacted over 3,300 industrial organizations, a ~49% increase from the prior year. Vulnerabilities continue to compound. Most organizations created their cybersecurity programs with prevention bias when they implemented standards shown in industry frameworks.
This bias underdeveloped their detection, response, and recovery capabilities.
This gap is not theoretical. In November 2022, Robert M. Lee and Tim Conway published the Five ICS Cybersecurity Critical Controls: ICS Incident Response, Defensible Architecture, Network Visibility and Monitoring, Secure Remote Access, and Risk-Based Vulnerability Management. This research on prevention bias was one of the contributing factors behind that work. The controls exist because the industry needed a practical answer to the imbalance this analysis identified.
#1: Adopt a Continuous Improvement Mindset
Cybersecurity is not a project. It is an iterative process that must be constantly nurtured. Think of each core capability not as another defense layer, but as a force multiplier that strengthens the others.
To Protect assets, you must first Identify them. When, not if, protections fail, you must Detect those failures, Respond to consequences, and Recover operations. As you examine each core capability within your cybersecurity program, outline approaches that enhance security posture beyond standards limitations. Iteratively review existing cybersecurity documents. Clarify expectations and procedural changes among stakeholders.
#2: Increase Visibility into OT Assets
Visibility enables detection and is the most critical step on the path to operational readiness and cyber risk management. Visibility can’t stop at knowing an asset exists. On average, Dragos finds that organizations fail to account for nearly 30% of the connected devices on their networks, and true readiness means knowing every one of them and their security posture, from default credentials and out-of-date firmware to expired certificates and risky configurations, so teams can proactively harden and remediate those vulnerabilities before an adversary finds them first.
Dragos estimates fewer than 10% of OT networks worldwide have visibility and monitoring in place. Yet visibility of your network provides the sight picture for how processes and workflows actually execute. Understanding “normal” for your OT environment contributes to the higher-fidelity information needed to accelerate situational awareness and change detection.
xOT is the standard for defining that environment. The Dragos Platform is what organizations use to see it.
#3: Test Your Incident Response Capabilities Regularly Through Tabletop Exercises
Detection is only useful if it enables response. Rehearsing incident response plans during routine exercises uncovers procedural gaps and issues with roles, responsibilities, accountabilities, and authorities necessary for effective response.
Crafting realistic xOT scenarios is crucial for identifying insufficient data sources or poor data quality that defenders need during an incident to make critical decisions. These decisions are unnecessarily complex if there is confusion about where data lives, how to access it, how long it is retained, and its usefulness.
Adversaries targeting operational environments are crossing a line that had previously been limited to a small number of well-known attacks. Multiple independent threat groups began actively mapping control loops and preparing to cause operational disruption. The timeline from compromise to operational readiness compressed dramatically, in some cases from months to weeks to days.
Two things are moving at once. The standards that define most cybersecurity programs underweight detection, response, and recovery. And the environment those programs cover keeps expanding. Every system that crosses the xOT boundary arrives without a detection requirement attached, because the standards were scoped to a narrower definition of OT than the one operations run on.
Prevention remains necessary. It is no longer sufficient.
The gap between what adversaries can do and what defenders can see is widening, and the xOT boundary is where it widens fastest. Closing it requires treating detection, response, and recovery with the same rigor and investment that standards have long afforded prevention.
The standards bias is real. The consequences are measurable. The solution is within reach. Organizations that build balanced cybersecurity programs, ones that invest equally in prevention, detection, response, and recovery, will be the ones that survive 2026 and beyond.
If your incident response plan has not been tested against a real OT scenario, Dragos runs tabletop exercises tailored to your environment. Explore Dragos tabletop exercises.