Declining Threats in Industrial Control Systems: A Q2 2026 Overview
In a notable shift within the cybersecurity landscape, the percentage of Industrial Control Systems (ICS) computers on which malicious objects were blocked has dropped to 19.15% in Q2 2026, marking the lowest level since 2022. This decline suggests a potential improvement in the security posture of industrial environments, as reported by Kaspersky’s latest Industrial Threat Report.
Regionally, the data reveals significant disparities, with Northern Europe experiencing the lowest block rate at 8.1%, while Africa reported the highest at 27.9%. This variance highlights the differing levels of cybersecurity maturity and threat exposure across regions.
Regional Threat Trends
Despite the overall decline, certain regions have seen an uptick in malicious activity. East Asia, for instance, recorded a 2.0 percentage point increase in blocked threats, particularly in categories such as malicious scripts, phishing pages, and spyware. This region has emerged as a focal point for various cyber threats, with the percentage of ICS computers affected by email threats also on the rise.
In contrast, the biometrics sector remains particularly vulnerable, with 26.44% of its ICS computers encountering malicious objects. The sector’s reliance on internet connectivity and email for operational processes, combined with often minimal cybersecurity controls, contributes to its high exposure to threats.
Threat Categories and Their Implications
The report identifies several key categories of threats that have evolved over the quarter. Notably, malicious scripts and phishing pages continue to dominate, with a global average of 5.42% of ICS computers affected. East Asia leads in this category, particularly within the biometrics and building automation industries.
Additionally, the rise of denylisted internet resources has pushed this category to second place in the threat rankings, with a global block rate of 4.31%. Russia has notably seen a significant increase in this area, indicating a potential shift in threat vectors that organizations need to monitor closely.
Malicious documents, while previously on a downward trend, saw a resurgence in Q2 2026, particularly in South America and Southern Europe. This uptick underscores the need for organizations to remain vigilant against document-based threats, which can often bypass traditional security measures.
Emerging Threat Sources
Interestingly, the report indicates that the only source of threats that increased in Q2 2026 was email, with a block rate of 2.84%. This highlights the ongoing risk posed by phishing and other email-based attacks, which continue to evolve and adapt to security measures. In Southern Europe, the biometrics sector reported the highest percentage of email threats blocked at 19.14%, emphasizing the critical need for enhanced email security protocols.
Conversely, threats from the internet and removable media have decreased, with the latter reaching a record low of 0.24%. This decline may reflect improved security practices and awareness among organizations, particularly in managing removable media risks.
As the cybersecurity landscape continues to evolve, the findings from Kaspersky’s report serve as a reminder of the dynamic nature of threats facing industrial environments. Organizations must remain proactive in their cybersecurity strategies, adapting to emerging threats while reinforcing their defenses against established vulnerabilities.
Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.



