Rockwell Automation Report Reveals Cybersecurity as Top Growth Obstacle for Industrial Organizations
More than one-third of industrial organizations worldwide now view cybersecurity risk as a top obstacle to business growth, according to Rockwell Automation's newly released "operational resilience in the Age of Connectivity" report. The Milwaukee-based automation giant's comprehensive study, published in September 2026, highlights how the rapid expansion of connected operations, artificial intelligence adoption, and IT/OT convergence has fundamentally altered the risk landscape for manufacturers and process industries.
The report's findings reflect a fundamental shift in how industrial companies perceive and manage cybersecurity. No longer viewed as merely an IT concern, cyber risk now ranks alongside supply chain disruption, talent shortage, and regulatory compliance as a strategic business challenge requiring executive-level attention and investment. This recognition comes as industrial operations become increasingly interconnected, with traditional air-gapped control systems giving way to networked architectures that enable remote monitoring, predictive maintenance, and data-driven optimization.
Rockwell Automation's research reveals that the convergence of information technology and operational technology, while delivering significant operational benefits, has simultaneously expanded the attack surface available to malicious actors. Modern industrial facilities integrate distributed control systems, programmable logic controllers, SCADA systems, and industrial Internet of Things devices across vast networks, many of which connect to corporate IT infrastructure and cloud platforms. Each connection point represents a potential vulnerability that must be secured against increasingly sophisticated threats.
The report identifies several key factors driving heightened cybersecurity concerns in industrial environments. First, the proliferation of connected devices has grown exponentially, with modern facilities hosting thousands of sensors, actuators, and intelligent devices that communicate continuously. Second, the adoption of artificial intelligence and machine learning for process optimization requires extensive data collection and analysis, creating additional pathways for potential compromise. Third, the increasing sophistication of cyber attacks, including ransomware targeting industrial operations, has demonstrated the real-world consequences of inadequate protection.
For industrial organizations, the consequences of cybersecurity failures extend far beyond traditional IT concerns such as data breaches or financial losses. Attacks on operational technology can result in production downtime, equipment damage, environmental incidents, and even safety hazards for personnel. The 2021 Colonial Pipeline ransomware attack, which disrupted fuel supply across the US East Coast, demonstrated how cyber incidents in industrial infrastructure can cascade into broader economic and social impacts.
Rockwell Automation's report emphasizes that achieving operational resilience requires a comprehensive approach spanning technology, processes, and people. On the technology front, industrial organizations must implement defense-in-depth architectures that include network segmentation, access control, encryption, and continuous monitoring. Safety instrumented systems must be designed with cybersecurity considerations from the outset, ensuring that safety functions remain reliable even under cyber attack conditions.
The report also highlights the importance of establishing robust incident response capabilities. Industrial organizations cannot assume they will prevent all cyber attacks; instead, they must prepare to detect, contain, and recover from incidents quickly and effectively. This preparation requires regular testing of response plans, coordination with external partners including law enforcement and industry information sharing centers, and investment in forensic capabilities to understand attack methods and prevent recurrence.
workforce development emerges as another critical theme in Rockwell Automation's findings. The report notes that many industrial organizations struggle to find personnel with the specialized skills needed to secure complex OT environments. Traditional IT security professionals often lack understanding of industrial processes and real-time operational requirements, while OT engineers may not possess deep cybersecurity expertise. Bridging this skills gap requires targeted training programs and collaboration between IT and OT teams.
The report's release coincides with evolving regulatory requirements for industrial cybersecurity. Regulations such as the EU's NIS2 Directive, the US Transportation Security Administration's security directives for critical infrastructure, and sector-specific standards in energy, water, and transportation impose increasingly stringent requirements on industrial operators. Compliance demands not only technical controls but also documented risk assessments, incident reporting procedures, and supply chain security measures.
Rockwell Automation's own response to these challenges includes expanded cybersecurity offerings integrated into its automation platforms. The company's FactoryTalk security solutions provide capabilities for asset discovery, vulnerability management, network monitoring, and incident response specifically designed for industrial environments. These tools integrate with Rockwell's industrial automation hardware and software, enabling unified management of operational and security functions.
The report also addresses the role of artificial intelligence in both creating cybersecurity challenges and providing solutions. While AI-powered systems require protection against adversarial attacks and data poisoning, they also offer capabilities for detecting anomalous behavior, predicting potential vulnerabilities, and automating response actions. Industrial organizations that successfully harness AI for defensive purposes can achieve security outcomes beyond what manual processes alone can deliver.
Supply chain security represents another area of growing concern highlighted in the report. Industrial organizations depend on complex supply chains for equipment, components, and software, each representing a potential vector for cyber compromise. The report recommends implementing supplier security assessments, requiring secure development practices, and establishing procedures for validating the integrity of delivered products and updates.
Industry analysts note that Rockwell Automation's findings align with broader trends observed across the industrial sector. As digital transformation initiatives accelerate, cybersecurity has moved from a technical afterthought to a strategic imperative. Organizations that fail to address cyber risks adequately face not only potential operational disruptions but also competitive disadvantages as customers and partners demand assurance of secure operations.
The report's emphasis on operational resilience rather than mere prevention reflects a mature understanding of the cybersecurity challenge. Complete prevention of all cyber attacks remains impossible; instead, organizations must build capabilities to continue operating despite attacks, recover quickly when incidents occur, and continuously improve their defenses based on evolving threats. This resilience mindset requires investment not only in technology but also in organizational culture, training, and continuous improvement processes.
For industrial automation professionals, the report's findings underscore the importance of integrating security considerations into every aspect of system design and operation. From initial architecture decisions through ongoing maintenance and upgrades, cybersecurity must be treated as a fundamental requirement rather than an add-on feature. This integration requires collaboration across disciplines, with automation engineers, IT security professionals, and operational managers working together to achieve comprehensive protection.
As industrial organizations continue their digital transformation journeys, the challenges identified in Rockwell Automation's report will only intensify. The convergence of IT and OT, adoption of advanced technologies, and evolution of threat landscapes all point to cybersecurity remaining a critical concern for years to come. Organizations that proactively address these challenges through comprehensive strategies spanning technology, processes, and people will be best positioned to achieve their growth objectives while maintaining operational resilience.
Written by: Maxwell, with over a decade of experience in industrial automation and cybersecurity. Maxwell has worked extensively on securing industrial control systems, specializing in IT/OT convergence, safety system integrity, and development of comprehensive cybersecurity programs for critical infrastructure. The report underscores the urgent need for industrial organizations to elevate cybersecurity from a technical concern to a strategic business priority. As operational technology becomes increasingly connected and automated, the potential impact of cyber incidents grows exponentially. Organizations must invest not only in technology solutions but also in people, processes, and culture to build genuine operational resilience against evolving cyber threats.