Malicious object blocks on ICS computers drop to 19.15% in Q2 2026, lowest since 2022.

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Declining Threats in Industrial Control Systems: A Q2 2026 Overview

In a notable shift within the cybersecurity landscape, the percentage of Industrial Control Systems (ICS) computers on which malicious objects were blocked has dropped to 19.15% in Q2 2026, marking the lowest level since 2022. This decline suggests a potential improvement in the security posture of industrial environments, as reported by Kaspersky’s latest Industrial Threat Report.

Regionally, the data reveals significant disparities, with Northern Europe experiencing the lowest block rate at 8.1%, while Africa reported the highest at 27.9%. This variance highlights the differing levels of cybersecurity maturity and threat exposure across regions.

Regional Threat Trends

Despite the overall decline, certain regions have seen an uptick in malicious activity. East Asia, for instance, recorded a 2.0 percentage point increase in blocked threats, particularly in categories such as malicious scripts, phishing pages, and spyware. This region has emerged as a focal point for various cyber threats, with the percentage of ICS computers affected by email threats also on the rise.

In contrast, the biometrics sector remains particularly vulnerable, with 26.44% of its ICS computers encountering malicious objects. The sector’s reliance on internet connectivity and email for operational processes, combined with often minimal cybersecurity controls, contributes to its high exposure to threats.

Threat Categories and Their Implications

The report identifies several key categories of threats that have evolved over the quarter. Notably, malicious scripts and phishing pages continue to dominate, with a global average of 5.42% of ICS computers affected. East Asia leads in this category, particularly within the biometrics and building automation industries.

Additionally, the rise of denylisted internet resources has pushed this category to second place in the threat rankings, with a global block rate of 4.31%. Russia has notably seen a significant increase in this area, indicating a potential shift in threat vectors that organizations need to monitor closely.

Malicious documents, while previously on a downward trend, saw a resurgence in Q2 2026, particularly in South America and Southern Europe. This uptick underscores the need for organizations to remain vigilant against document-based threats, which can often bypass traditional security measures.

Emerging Threat Sources

Interestingly, the report indicates that the only source of threats that increased in Q2 2026 was email, with a block rate of 2.84%. This highlights the ongoing risk posed by phishing and other email-based attacks, which continue to evolve and adapt to security measures. In Southern Europe, the biometrics sector reported the highest percentage of email threats blocked at 19.14%, emphasizing the critical need for enhanced email security protocols.

Conversely, threats from the internet and removable media have decreased, with the latter reaching a record low of 0.24%. This decline may reflect improved security practices and awareness among organizations, particularly in managing removable media risks.

As the cybersecurity landscape continues to evolve, the findings from Kaspersky’s report serve as a reminder of the dynamic nature of threats facing industrial environments. Organizations must remain proactive in their cybersecurity strategies, adapting to emerging threats while reinforcing their defenses against established vulnerabilities.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Air Force retires EC-130H Compass Call, replacing it with EA-37B

WASHINGTON — The Air Force has formally retired the EC-130H Compass Call, concluding over 40 years of operations for this electronic attack aircraft. The...

AI-Driven Research Uncovers HEIF Heist Vulnerability in Popular Software Decoders

Researchers have identified a significant vulnerability, dubbed the "HEIF Heist," in popular software decoding tools that could expose major internet platforms and enterprise services...

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...