Enter your email address below and subscribe to our newsletter

Kaspersky Study Reveals 7% of Industrial Firms Fix Vulnerabilities Only When Urgent

Share your love

A strong cybersecurity strategy begins with complete visibility into an organization’s assets, allowing leaders to understand what assets need protection and assess the highest risk areas.

In environments where IT and OT (Operational Technology) systems converge, this demands more than just a comprehensive asset inventory. Organizations must implement a risk assessment methodology that is aligned with their operational realities—by establishing a clear asset baseline, organizations can engage in meaningful risk assessments that address both corporate risk criteria and the potential physical and cyber consequences of vulnerabilities.

Recent survey findings reveal a concerning trend: a significant number of organizations are not engaging in regular penetration testing or vulnerability assessments. Only 27.1% of respondents perform these critical evaluations on a monthly basis, while the majority—48.4%—conduct assessments every few months. Alarmingly, 16.7% do so only once or twice a year, and 7.4% address vulnerabilities solely as needed. This inconsistent approach can leave organizations vulnerable as they navigate an increasingly complex threat landscape.

Every software platform is inherently vulnerable to bugs, insecure code, and other weaknesses that malicious actors can exploit to compromise IT environments. For industrial companies, effective patch management is therefore crucial to mitigate these risks. However, studies reveal that many organizations encounter significant challenges in this area, often struggling to allocate the necessary time to pause operations for critical updates.

Disturbingly, many organizations patch their OT systems only every few months or even longer, significantly heightening their risk exposure. Specifically, 31.4% apply patches monthly, while 46.9% do so every few months, and 12.4% update only once or twice a year.

These challenges in maintaining effective patch management are exacerbated in OT environments, where limited device visibility, inconsistent vendor patch availability, specialized expertise requirements and regulatory compliance add layers of complexity to the cybersecurity landscape.

As IT and OT systems increasingly converge, there is a pressing need to harmonize these traditionally disparate systems, which have often relied on proprietary technologies rather than open standards. The challenge is further intensified by the rapid proliferation of Internet of Things (IoT) devices—ranging from cameras and smart sensors for asset tracking and health monitoring to advanced climate control systems. This explosion of connected devices broadens the attack surface for industrial organizations, underscoring the urgent need for robust cybersecurity measures.

Kaspersky recommends that industrial organizations adopt the Secure by Design ideology when deploying new OT devices or systems.

“At Kaspersky, we bring the Secure-by-Design concept to life through our Cyber Immunity approach. This means building products that are resilient by architecture—able to withstand attacks, even those exploiting unknown vulnerabilities. Unlike traditional systems, Cyber Immune products don’t rely on constant patching or external security layers. As a result, our clients benefit from stronger protection, simplified maintenance and a lower total cost of ownership—without compromising on security,” says Dmitry Lukiyan, Head of KasperskyOS Business Unit.