*The respondents represented companies from various segments, including energy / utilities, healthcare / pharma, transportation / logistics, manufacturing, chemical / petrochemical, oil / gas / refining, or water / wastewater. The companies had more than 1,000 employees, except in South Africa, UAE, Hong Kong, Singapore, Thailand, the Philippines, Malaysia, Indonesia, South Korea, or Israel; in these countries, more than 250 employees. Furthermore, the respondents had operations technology within functional responsibility, reporting responsibility for manufacturing or plant operations, and were involved in cybersecurity purchase decisions.
The survey was conducted in Australia, New Zealand, Argentina, Brazil, Canada, Mainland China, Colombia, Denmark, Egypt, France, Germany, Hong Kong, India, Indonesia, Israel, Italy, Japan, Malaysia, Mexico, Norway, Philippines, Poland, Portugal, Singapore, South Africa, South Korea, Spain, Sweden, Taiwan, Thailand, UAE, the UK, the U.S., and Vietnam.
Citation formats
CISO responsibility for operational technology cyber security 2022-2025
According to a 2025 survey, a consequence of the continued vulnerability of operational technology (OT) networks to cyberattacks is the increased involvement of Chief Information Security Officers (CISOs) in OT cybersecurity decision-making. This trend was confirmed by ** percent of respondents in 2025, up from ** percent in 2024.
An ever-increasing number of attacks
Recent years have witnessed a surge in the number and scale of cyberattacks targeting OT systems, used to monitor, control, and automate physical processes, devices, and infrastructure in crucial, asset-intensive industries, including power grids, transportation and telecommunications systems, and healthcare facilities. The digital transformation experienced in our societies has resulted in the growing connectedness of OT environments, expanding OT owners’ attack surface, but also in growing IT-OT convergence.
Insiders represent the biggest threat
Considering the importance of industrial process continuity and public safety-related impacts, it comes as no surprise that both organized crime and state-sponsored actors see critical infrastructure (CI) as lucrative targets for financial gain, espionage, or cyberwarfare operations. Nevertheless, well-meaning but negligent insiders are considered the biggest threat actors to OT security, with malicious insiders ranking second. When attempting to reduce the attack surface, CI organizations face diverse obstacles, from operational requirements to lack of personnel, depending on their responsibility level.
Profit from the additional features of your individual account
Currently, you are using a shared account. To use individual functions (e.g., mark statistics as favourites, set
statistic alerts) please log in with your personal account.
If you are an admin, please authenticate by logging in again.
Learn more about how ÀÖ²¥´«Ã½app×îа汾 can support your business.
Fortinet. (July 23, 2025). Does your organization plan to roll operational technology cybersecurity underneath the Chief Information Security Officer in the next 12 months? [Graph]. In ÀÖ²¥´«Ã½app×îа汾. Retrieved August 13, 2026, from /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/
Fortinet. "Does your organization plan to roll operational technology cybersecurity underneath the Chief Information Security Officer in the next 12 months?." Chart. July 23, 2025. ÀÖ²¥´«Ã½app×îа汾. Accessed August 13, 2026. /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/
Fortinet. (2025). Does your organization plan to roll operational technology cybersecurity underneath the Chief Information Security Officer in the next 12 months?. ÀÖ²¥´«Ã½app×îа汾. ÀÖ²¥´«Ã½app×îа汾 Inc.. Accessed: August 13, 2026. /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/
Fortinet. "Does Your Organization Plan to Roll Operational Technology Cybersecurity underneath The Chief Information Security Officer in The next 12 Months?." ÀÖ²¥´«Ã½app×îа汾, ÀÖ²¥´«Ã½app×îа汾 Inc., 23 Jul 2025, /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/
Fortinet, Does your organization plan to roll operational technology cybersecurity underneath the Chief Information Security Officer in the next 12 months? ÀÖ²¥´«Ã½app×îа汾, /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/ (last visited August 13, 2026)
Does your organization plan to roll operational technology cybersecurity underneath the Chief Information Security Officer in the next 12 months? [Graph], Fortinet, July 23, 2025. [Online]. Available: /statistics/1419018/ciso-responsibility-for-operational-technology-cyber-security/