Only a quarter of organisations in Asia Pacific (APAC) perform regular cybersecurity assessments, leaving them exposed to unplanned downtime, production losses, and reputational and financial damages that can result from cyber breaches. This alarming trend was highlighted in a recent joint survey conducted by VDC Research and Kaspersky.
The study, Securing OT with Purpose-built Solutions, conducted by Kaspersky in collaboration with VDC Research, illuminates the shifting cybersecurity landscape within the industrial sector. Focusing on key industries such as energy, utilities, manufacturing, and transportation, the research surveyed over 250 decision-makers to uncover vital trends and challenges in securing industrial environments against cyber threats.
A robust cybersecurity strategy begins with complete visibility into an organisation’s assets. This enables leaders to identify which assets require protection and assess the most critical risk areas. In environments where IT and operational technology (OT) systems converge, this requires more than just an inventory. Organisations must adopt a risk assessment methodology tailored to their operational context—by establishing a clear asset baseline, they can conduct meaningful risk assessments that account for both corporate risk criteria and the physical and cyber consequences of vulnerabilities.
Survey findings reveal a concerning trend: many organisations are not performing regular penetration testing or vulnerability assessments. In APAC, only 26.7% of respondents conduct these evaluations monthly. The majority—42.7%—carry them out every few months, while 20% do so only once or twice a year, and 10.7% assess vulnerabilities solely as needed. This puts the region roughly 6% behind the global average, leaving organisations ill-prepared in an increasingly complex threat environment.
Every software platform is inherently susceptible to bugs, insecure code, and other weaknesses that bad actors can exploit. For industrial companies, effective patch management is essential to mitigate these risks. However, many organisations struggle to allocate time for critical updates due to operational constraints. In APAC, only 21.3% apply patches monthly, 52% every few months, and 16% only once or twice a year—substantially increasing their exposure.
These difficulties are amplified in OT environments, where patching is complicated by limited device visibility, inconsistent vendor support, specialised expertise, and regulatory compliance requirements.
As IT and OT systems continue to converge, harmonising these traditionally distinct infrastructures becomes increasingly important. This is further complicated by the rapid rise of Internet of Things (IoT) devices—from smart sensors and asset trackers to climate control systems—broadening the attack surface and reinforcing the need for comprehensive cybersecurity measures.