Industrial OT Vulnerabilities Remained Unpatched for Years

New research shows that critical security flaws in industrial operational technology often persist for over three years.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of a heavy industrial relay module with thick power cables, symbolizing long-term security gaps in critical infrastructure.
New research from Holm Security indicates that critical vulnerabilities in industrial control systems often remain unpatched for more than three years due to complex maintenance requirements. AI Illustration. Upload story photo >

Live Poll

Do you trust that industrial companies are adequately securing their critical infrastructure against digital vulnerabilities?

Holm Security released data revealing that critical vulnerabilities within industrial and SCADA environments go unresolved for more than three years after disclosure. These systems frequently remain exposed to ransomware risks due to the complexity of industrial maintenance cycles.

Why it matters

Industrial environments rely on systems that cannot be patched on demand due to strict vendor certification requirements and the difficulty of taking production systems offline. This creates a dangerous security gap where known exploits persist in critical infrastructure.

The typical critical vulnerability in operational technology remains unaddressed for more than three years following initial disclosure. Holm Security maintains a platform tracking these risks across its base of more than 1,500 client organizations.

The players

Holm Security

Founded in 2015 and based in Stockholm, this company provides platforms for assessing risk across IT and OT environments for over 1,500 organizations.

The details

Production systems in industrial environments face unique challenges, as infrequent maintenance windows prevent rapid patching. Consequently, many industrial environments continue to operate with active, ransomware-exploitable risks present on their IT networks.

Timeline

  1. 2015: Holm Security was founded in Stockholm.

  2. September 29, 2026: Holm Security released its latest research findings regarding OT vulnerabilities.

The Tech Race

This research highlights the widening divide between rapid IT security cycles and the stagnant reality of industrial control system protection. The inability to patch critical infrastructure in real-time continues to pose a significant challenge compared to standard corporate network security.

Organizations relying on industrial technology must account for prolonged vulnerability windows when planning security budgets and network architecture. Security teams should prioritize compensating controls to mitigate risks since immediate software patching is often not feasible.

The takeaway

Legacy industrial systems require specialized security strategies that do not depend on traditional software patching cadences. Businesses should integrate proactive risk assessment platforms to identify and isolate vulnerable OT components within their networks.

Further reading

Learn more about the latest threats in Cybersecurity.

Live Poll

Do you trust that industrial companies are adequately securing their critical infrastructure against digital vulnerabilities?