[2026 OT Security Outlook for H2] Engineering Workstations Become the Next OT Target

Jul 27 2026

Image 1. 2026 OT Security Outlook for H2

 

Over the past few years, the primary focus of OT security has been clear. As IT and OT environments have become increasingly connected, manufacturers and critical infrastructure operators have faced growing exposure to cyber threats. In response, organisations have focused on extending proven IT security controls — including VPN, Multi-Factor Authentication (MFA), and Privileged Access Management (PAM) — into industrial environments.

 

This movement has been further accelerated by regulatory frameworks and international standards such as NIS2 and IEC 62443, which place increasing emphasis on identity verification, access control, and security governance. These developments have undoubtedly helped improve the overall security maturity of OT environments

However, threat intelligence and major industrial control system (ICS) incidents observed during the first half of 2026 reveal another important shift. Attackers are moving beyond simply gaining access to industrial networks. Their focus is increasingly shifting towards obtaining the control privileges required to influence physical operations.

This is not simply the emergence of new attack techniques. It represents a fundamental change in what organisations need to prioritise and protect within their OT environments.

 

The Shift from Network Access to Control Privilege

Image 2. The Shift from Network Access to Control Privilege

Traditional ransomware attacks are primarily designed to disrupt IT systems, encrypt data, and create financial pressure. In OT environments, however, the ultimate objective can be far more significant. The most valuable target is not a file server or business application, but the ability to control the industrial processes that keep operations running.

Opening or closing a gas valve, stopping a generator, or modifying the configuration of a protection relay can result in real-world physical consequences. OT attacks are therefore not simply about compromising computer systems; they are about gaining the authority to influence industrial operations.

This shift has already been demonstrated through several major incidents. Industroyer2, which targeted Ukraine’s power infrastructure, was designed to use industrial communication protocols to send commands directly to electrical systems. Triton (Trisis) targeted Safety Instrumented Systems (SIS), attempting to compromise the final safety mechanisms designed to prevent dangerous industrial events. PIPEDREAM (INCONTROLLER) also attracted significant attention because it was not merely designed to exploit a specific vulnerability, but rather to interact directly with multiple industrial control devices.

Although these attacks occurred in different environments, they reveal a common pattern: attackers are not necessarily seeking to compromise PLCs themselves. They are seeking the ability to operate and manipulate the systems that control them.

 

Why Engineering Workstations Matter in OT Security

Recent cybersecurity advisories from government agencies have highlighted that sophisticated threat actors are seeking persistent access to critical infrastructure environments by exploiting weaknesses in internet-facing devices and network infrastructure. This does not mean that attackers will always directly target PLCs. Rather, it demonstrates a broader trend: attackers are increasingly focused on gaining and maintaining access to environments where operational decisions are made.

One of the most valuable assets within these environments is the Engineering Workstation.

Engineering Workstations are among the most critical operational assets in an OT environment. They are used to download PLC programmes, modify parameters, configure industrial equipment, and perform essential maintenance activities. In other words, they are locations where significant levels of operational control authority are concentrated.

If attackers gain access to an Engineering Workstation, they may not need to exploit additional vulnerabilities. Instead, they could attempt to modify programmes or operational settings while appearing to follow legitimate engineering procedures.

This creates a particularly challenging security issue. Because these actions may occur within the boundaries of an authorised user’s privileges, traditional network-based security controls alone may not be sufficient to identify and prevent them.

 

The Changing Nature of OT Attacks in the Second Half of 2026

Image 3. The Changing Nature of OT Attacks in the Second Half of 2026

The security incidents observed during the first half of 2026 raise a fundamental question: What are we actually protecting?

Many organisations have invested heavily in network segmentation, remote access security, VPN protection, and vulnerability management. These measures remain essential components of a strong OT security strategy.

However, if attackers are increasingly focused on obtaining legitimate control privileges, security strategies must evolve accordingly. Knowing who accessed the network is no longer enough. The more important question is who has the authority to control industrial equipment — and whether that authority can be trusted at the moment it is exercised.

 

What Should OT Security Protect Next?

Over recent years, OT security has increasingly incorporated the principles of Identity and Access Management. Verifying user identity and controlling access permissions will continue to be fundamental security requirements.

However, emerging threats indicate that attackers are targeting something beyond access itself. They are seeking the ability to exercise control privilege.

They are not simply looking for PLCs. They are not simply looking for HMIs. They are looking for the authority that allows them to influence industrial operations. For this reason, the future of OT security will extend beyond controlling who can enter the network. Organisations will need to verify trust at the final point where operational authority is exercised — the endpoint where control decisions are actually executed.

 

The key question for OT security teams is no longer only, “Who is accessing the system?” It is also, “Who can control the system, and how do we verify that control privilege at the moment of action?”

 

If the first half of 2026 revealed where attackers are heading, the second half will be the period when organisations must reconsider what they truly need to protect.

The centre of OT security is shifting. It is no longer only about defending networks. It is about protecting control privilege.

 

 

 

--------------------

 

yoV7spyzD5zv6d6nnEVk0-swidch logo 1

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.    

 

Looking to stay up-to-date with our latest news?

Subscribe to our newsletter