Two-thirds (65%) of UK organisations that manage cyber-physical systems (CPS) have had their operations impacted by a cyberattack in the past 12 months, according to new research from Claroty, the cyber-physical systems protection company. That compares with 58% globally and 56% across EMEA.
The findings come from ‘The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability’, a survey of 2,000 business and technology leaders whose organisations manage CPS, including 200 in the UK. The research shows UK organisations are more exposed than their global peers, feel the impact in business terms and face the twin pressures of legacy technology and fast-moving regulation.
The business cost of operational attacks
When incidents happen, UK organisations feel it where it hurts, with 38% of those affected reporting reputational damage from their most significant incident – the highest of any market surveyed and above the global average (30%). UK organisations also reported financial loss (42% vs 35% globally), operational downtime (49% vs 43%) and regulatory scrutiny (36% vs 30%) more often than their global peers.
The threat UK leaders rank highest is disruption that starts in IT and spills into operational systems (44% vs 37% globally). Ransomware remains a bigger concern in the UK than globally (35% vs 27%), sitting level with AI-powered attacks (36%).
CIOs own operational security, but governance is lagging
Nearly half (48%) of UK organisations say the CIO is ultimately accountable for operational security, compared with 39% globally and UK CIOs are also more likely to control the budget (36% vs 28%). Yet only 14% of UK organisations have fully integrated IT and operational security governance.
Confidence in recovery is also shallow. While most UK leaders believe their operations are covered by business continuity and disaster recovery plans, only one in five (19%) is very confident – despite two-thirds having already been hit.
Legacy technology and moving regulation
Legacy systems are the single biggest barrier to full compliance for UK organisations (31% vs 26% globally), and UK leaders are more likely to rank vulnerable legacy OT among their top threats (28% vs 21%).
Nearly half (47%) say keeping up with evolving regulations, mandates and frameworks is a top compliance challenge, the joint highest of all markets surveyed. Regulation is also a stronger driver of operational security investment in the UK than globally (32% vs 26%).
Fighting AI with AI
Three-quarters (74%) of UK organisations are using AI in operational environments, and the same proportion are investing in AI-powered security to counter AI-powered attacks (68% globally). More than half (56%) say AI has improved operational efficiency (48% globally), but 41% say it has introduced new cybersecurity, compliance or operational risks.
“UK organisations are being hit more often than their global peers and they’re feeling it in their reputation, their revenue and their relationship with regulators,” said Nick Haan, Field CTO at Claroty.
“Attacks that start in IT are spilling into the systems that keep production lines, hospitals and utilities running. CIOs have taken on responsibility for protecting those operations, but too few organisations have joined up how they govern IT and operational security. With legacy systems that can’t simply be patched and regulation that keeps moving, UK boards need to treat operational resilience as a core business capability – one they own, fund and regularly test.”


