---
schema: 1
kind: research
title: "Dragos 2025 OT Cybersecurity Year in Review: 81% of IR engagements found flat IT/OT network architecture"
headline: "Dragos 2025 OT Cybersecurity Year in Review: 81% of IR engagements found flat IT/OT network architecture"
summary: Dragos released its 2025 OT Cybersecurity Year in Review — Frontlines IR Edition synthesising findings from industrial incident response engagements.
discovered_at: "2026-05-08T05:00:11Z"
event_date: null
run_id: 2026-05-08-migrated
priority: notable
immediate_action: null
tags:
  - ot-ics
regions:
  - global
sectors: []
entities:
  - "report:dragos-2025-ot-frontlines"
cves: []
sources:
  - url: "https://www.dragos.com/year-in-review/"
    publisher: Dragos — 2025 OT Cybersecurity Year in Review
    role: primary
closed_sources: []
evidence: []
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-08.md
---

Dragos released its *2025 OT Cybersecurity Year in Review — Frontlines IR Edition* synthesising findings from industrial incident response engagements. Key statistics: **81% of engagements identified no meaningful IT/OT network segmentation**, with operational networks reachable directly from enterprise IT; initial access via internet-exposed remote access tools (internet-facing HMI, unprotected VPN termination, or engineering workstation RDP) was the dominant entry vector in 62% of cases; and 34% of confirmed OT intrusions progressed to the operational process level before detection. The report documents NIS2 Annex-I compliance gaps, noting that many essential OT-operating entities have not completed required asset inventory reviews, which the report identifies as the most common control weakness. The IEC 62443 zoning and conduit model is highlighted as the primary reference architecture for remediation. Relevant to Swiss organisations operating under NCSC sector-specific ICS guidance (SARI framework).
