The first quarter of 2026 marked a notable continuation of the downward trend in the proportion of industrial control systems (ICS) endpoints that encountered blocked malicious objects, settling at 19.6 % across the global sensor network. This figure represents the lowest point observed in the past three years and is roughly 1.4 times lower than the peak recorded in mid‑2023. While the overall decline suggests that broader defensive measures—such as network segmentation, improved patch management, and heightened user awareness—are beginning to pay off, it also masks significant regional and sector‑specific variations that demand closer scrutiny. Decision‑makers should interpret the aggregate improvement as a baseline rather than a signal of complacency, focusing resources on the pockets where threat activity is actually rising.
Geographic disaggregation reveals a stark contrast between regions. Northern Europe reported the lowest attack intensity at just 9.1 % of ICS computers experiencing a block, reflecting relatively mature cyber‑hygiene practices, strong regulatory frameworks, and lower exposure to high‑value target industries. In stark opposition, Africa registered the highest proportion at 27.4 %, a figure driven by a confluence of factors: expanding industrialization, limited cybersecurity budgets, prevalent legacy equipment, and a growing presence of financially motivated threat actors exploiting weaker defenses. These extremes underline the importance of tailoring security investments to local threat ecosystems rather than applying a one‑size‑fits‑all approach.
During Q1 2026, five regions bucked the global downward trend, most notably Southern Europe, Northern Europe, and Russia. Southern Europe emerged as a hotspot for internet‑ and email‑borne threats, posting the fastest growth in spyware, malicious scripts, and phishing pages. Russia, meanwhile, reversed its recent decline, showing an uptick in internet‑based threats and a modest rise in email‑client threats—making it one of only three regions where the email threat metric did not fall. These regional rebounds suggest that attackers are adapting their tactics to exploit perceived gaps, perhaps leveraging language‑specific lures or targeting supply‑chain links that traverse these areas.
Analyzing threat categories, the most pronounced increases were observed in denylisted internet resources and spyware, both of which are frequently disseminated via web browsing and email channels. Denylisted resources—domains and URLs known to host malware—rebounded after two quarters of decline, indicating that attackers are refreshing their infrastructure or that new malicious sites are evading reputation‑based filters. Spyware, despite a modest overall dip to 3.73 %, retained its position as the second‑most prevalent threat category for the third consecutive quarter, underscoring its utility in intelligence‑gathering operations against industrial environments where operational data can be extremely valuable.
Biometric access control systems continue to stand out as the most heavily targeted OT infrastructure, with 26.4 % of their endpoints experiencing a blocked malicious object in Q1 2026. This prevalence stems from several intrinsic characteristics: these systems typically maintain persistent internet connectivity for remote management, rely heavily on email for approval workflows (such as granting or revoking access), and often operate under relatively lax internal security controls compared with core process‑control networks. Consequently, threat actors view biometric platforms as a low‑hanging fruit that can provide a pivot point into broader industrial networks or serve as a repository for credential harvesting.
While most industry verticals exhibited a declining trend in blocked threats, the manufacturing sector was the sole exception, registering a 1.0‑percentage‑point increase in Q1 2026. This rise was distributed across ten regions, with the most pronounced upticks occurring in Western Europe, Northern Europe, and Russia. The manufacturing uptick may reflect the sector’s rapid adoption of IIoT (Industrial Internet of Things) devices, which often ship with default credentials and limited security hardening, thereby expanding the attack surface. It also hints at possible targeting of intellectual property or production‑line disruption as motives behind the observed activity.
Malicious scripts and phishing pages retained their top ranking among threat categories, with a global average block rate of 6.56 % in Q1 2026. The most significant regional surge occurred in Southern Europe, where the metric climbed to 9.85 %—an increase of 0.94 percentage points—and has now risen for three consecutive quarters. Within Southern Europe, biometric systems and building automation solutions recorded the highest concentrations of these threats, at 19.59 % and 15.43 % respectively. This pattern suggests that attackers are leveraging socially engineered emails and compromised web sites to deliver payloads that can capture credentials, harvest data, or lay the groundwork for later ransomware deployment.
Spyware activity displayed a nuanced picture: although the overall blocked proportion fell to 3.73 %, five regions recorded quarterly growth, led by Southern Europe (5.46 %, +0.35 pp) and Russia (2.84 %, +0.24 pp). In Southern Europe, every industry vertical except manufacturing experienced a rise in spyware detections, with biometric systems again showing the steepest increase. In Russia, spyware growth was pervasive across all sectors save construction, and notable multi‑quarter trends emerged in oil and gas (up 1.63× over six months), engineering and ICS integration, and electric power. These trajectories point to sustained espionage campaigns targeting strategic industries, likely motivated by geopolitical or competitive intelligence objectives.
The proportion of ICS endpoints where denylisted internet resources were blocked climbed to 3.54 % globally, with the most dramatic quarterly jump occurring in Southeast Asia (4.58 %, +0.65 pp). In that region, electric power and construction firms bore the brunt, reflecting the high value of infrastructure data and the prevalence of project‑management web portals that attackers can manipulate. Interestingly, in North America (specifically Canada), denylisted resources showed the largest relative increase among all threat categories, growing by a factor of 1.22 to reach 2.14 %. This underscores that even regions with mature defenses are not immune to shifts in attacker infrastructure or changes in legitimate‑looking web traffic that evade reputation filters.
Ransomware continued its downward trajectory, falling to a mere 0.14 % of blocked ICS endpoints—the lowest figure among all threat categories. modest upticks were observed only in North America (Canada) and Northern Europe, each gaining just a few hundredths of a percentage point. When ransomware did appear, it concentrated in the oil and gas and manufacturing sectors of Central Asia and the South Caucasus, as well as in biometric systems within Russia. The persistently low ransomware prevalence may be attributable to effective backup strategies, network isolation, or a shift by cyber‑criminals toward less noisy, more lucrative operations such as espionage or cryptojacking in industrial settings.
Both traditional file‑based miners and web‑based cryptominers showed declining overall prevalence, yet regional spikes revealed persistent interest in monetizing industrial compute resources. Executable‑file miners dropped to 0.59 % globally, with Africa posting the largest regional increase (0.63 %, +0.16 pp), driven notably by manufacturing and oil‑and‑gas firms. Web miners fell further to 0.22 %, but rose in South Asia, the Middle East, and Africa, with biometric systems in Russia again leading the pack at 0.97 %. These patterns indicate that attackers continue to probe for idle CPU cycles on OT networks, possibly to fund other operations or to test the resilience of monitoring controls.
Looking ahead, organizations responsible for industrial automation should treat the aggregate decline in threat blocks as a starting point for deeper, risk‑based investments. First, prioritize hardening of biometric and building‑automation systems—apply least‑privilege access, enforce multi‑factor authentication, and isolate these assets from corporate email and web traffic where feasible. Second, adopt region‑specific threat intelligence feeds that capture the nuances seen in Southern Europe, Russia, and Southeast Asia, enabling more precise detection of denylisted domains and spyware‑laden emails. Third, reinforce manufacturing environments with rigorous IIoT device onboarding procedures, including credential rotation, firmware integrity checks, and network micro‑segmentation. Finally, maintain continuous monitoring for anomalous script execution and phishing indicators, as these remain the leading precursors to more damaging incidents. By translating the report’s granular insights into focused actions, security leaders can sustain the positive trend while defending against the evolving, targeted threats that persist beneath the surface.