In the second quarter of 2026, the overall share of industrial control systems (ICS) endpoints on which security tools blocked malicious objects continued its downward trajectory, settling at 19.15% – the lowest point observed since 2022. This decline suggests that baseline hygiene improvements, network segmentation, and broader adoption of application‑control policies are beginning to pay off across many manufacturing and critical‑infrastructure sites. However, the aggregate figure masks significant regional and sectoral variations that warrant closer scrutiny. While the global trend is encouraging, threat actors are shifting focus to niches where legacy systems, limited security budgets, or high‑value data exchanges create fertile ground for infection. Decision‑makers should interpret the falling percentage not as a signal to relax vigilance, but as an invitation to reallocate resources toward the emerging hotspots highlighted in the report. By understanding where the pressure is mounting, organizations can prioritize patching, user‑training, and network‑monitoring initiatives that yield the greatest risk reduction per dollar spent.

Regionally, the picture is anything but uniform. Northern Europe posted the lowest infection pressure at a mere 8.1% of ICS computers encountering blocked threats, reflecting mature cyber‑risk frameworks, strong regulatory oversight, and widespread adoption of zero‑trust architectures. In stark contrast, Africa registered the highest regional figure at 27.9%, driven by a combination of expanding industrial automation in mining and energy sectors, uneven cybersecurity maturity, and increased exposure to internet‑based threat vectors. East Asia demonstrated the most notable quarter‑over‑quarter increase, climbing 2.0 percentage points, while Africa added a modest 0.5 points. These shifts indicate that threat actors are re‑targeting geographically diverse supply chains, exploiting regional disparities in security investment. For multinational operators, the data underscores the necessity of a differentiated risk‑management approach: reinforcing baseline controls in low‑risk zones while deploying advanced threat‑intelligence, managed detection and response (MDR), and regular red‑team exercises in high‑exposure locales.

The biometrics sector continues to occupy an outsized position in the threat landscape, with 26.44% of its ICS assets encountering blocked malicious objects – the highest proportion among all surveyed industries. This persistent vulnerability stems from three interlocking factors: ubiquitous internet connectivity required for cloud‑based matching services, heavy reliance on email for credential distribution and access‑approval workflows, and, in many deployments, a legacy‑first mindset that leaves critical authentication servers inadequately hardened. Because biometric databases often serve as gatekeepers to physical and logical assets, a successful compromise can cascade into broader operational disruption, fraud, or intellectual‑property theft. Organizations utilizing biometric access controls should therefore prioritize network‑level isolation, enforce multi‑factor authentication for administrative interfaces, and implement stringent email‑security gateways that sandbox attachments and disable macros by default.

Malicious scripts and phishing pages retained their crown as the most frequently blocked threat category worldwide, even as the global average slipped to 5.42% in Q2 2026. The modest decline suggests that browser‑based protections and user‑awareness campaigns are gradually curbing drive‑by infections. Yet the story diverges sharply in East Asia, where the same metric rose by 0.93 percentage points to 4.86% – the second‑highest level observed in the region over the past three years. Notably, every industry surveyed in East Asia experienced an uptick except construction, with biometrics (9.01%) and building automation (6.49%) posting the highest numbers. This pattern points to targeted social‑engineering campaigns that lure engineers and facility managers into clicking malicious links embedded in project‑coordination emails or shared design files. To counter this, firms should enforce URL‑filtering at the perimeter, deploy browser isolation for external‑facing workstations, and conduct regular simulated‑phishing drills tailored to OT‑focused personnel.

Denylisted internet resources climbed from third to second place in the threat‑category hierarchy, reaching a global blocked‑percentage of 4.31% after two consecutive quarters of growth. Russia led this surge, with a 1.33‑point increase that pushed its regional figure to 5.17%, reclaiming the top spot it previously held in Q2 2022 and Q2 2024. Within Russia, the electric‑power sector (6.61%) and engineering/ICS‑integration firms (5.62%) bore the brunt, likely reflecting adversaries’ interest in disrupting energy distribution and gaining insight into critical‑infrastructure designs. The rise underscores the value of maintaining dynamic, threat‑intelligence‑fed blocklists that encompass newly observed command‑and‑control domains, malicious file‑hosting sites, and compromised legitimate services. Companies should integrate automated feed updates into their firewalls and proxy servers, while also conducting periodic passive‑DNS audits to detect beaconing to newly registered malicious domains.

Malicious documents, after three quarters of decline, rebounded to a global blocked‑percentage of 1.77% in Q2 2026. The revival was most pronounced in South America (+1.35 pp) and Southern Europe (+0.48 pp), both of which now rank among the top three regions for this threat. In South America, the biometrics vertical again topped the list with 6.67% of its ICS endpoints encountering blocked malicious docs, while Southern Europe’s biometrics segment reached a striking 11.48%. This resurgence likely reflects attackers’ renewed reliance on weaponized Office files and PDFs to deliver ransomware or espionage payloads via supply‑chain‑related correspondence. Mitigation strategies include disabling automatic macro execution, leveraging document‑sanitization platforms that strip active content, and enforcing strict application‑whitelisting for programs that can parse untrusted files.

Spyware continued its downward slide, reaching a global low of 3.30% – the lowest level since 2022 – yet regional nuances reveal pockets of resurgence. East Asia (+0.53 pp) and Southeast Asia (+0.42 pp) drove the modest uptick, with mainland China leading the regional tally at 6.61% and the electric‑power (11.75%) and manufacturing (5.87%) sectors therein showing the highest exposure. Southeast Asia’s biometrics (8.93%) and manufacturing (7.32%) industries also experienced notable increases, suggesting that adversaries are harvesting operational data, intellectual property, and credential harvests from environments where monitoring may be less intensive. Organizations should consider deploying endpoint detection and response (EDR) solutions capable of detecting credential‑dumping and keystroke‑logging behaviors, coupled with network traffic analysis that spots exfiltration to atypical destinations.

Ransomware activity, while still relatively rare on ICS networks, showed a modest quarterly uptick to a global blocked‑percentage of 0.16%. Notably, the increase was universal except in Western and Southern Europe and Canada, with Africa spearheading the growth curve. In Q2 2026, Africa claimed the top regional spot at 0.29%, approaching its Q2 2025 peak of 0.31%. Within Africa, the electric‑power industry (0.72%) and biometrics (0.52%) recorded the highest ransomware‑related blocks, and Russia’s biometric segment experienced three consecutive quarters of growth, culminating in a striking 1.22% – the highest ransomware figure observed across all industries and regions. This trajectory indicates that ransomware gangs are increasingly viewing biometric authentication systems as high‑value targets capable of facilitating lateral movement or denying access to critical facilities. Defensive priorities should include immutable backups of authentication databases, strict separation of OT and IT credential stores, and deployment of ransomware‑specific behavior‑blocking tools that detect rapid file‑encryption patterns.

Cryptocurrency miners continued their decline, hitting historic lows for both Windows‑executable miners (0.48%) and browser‑based web miners (0.14%) – the lowest levels since 2021. The downward trend was uniform across all regions except Africa, where Windows‑executable miner activity ticked upward slightly. On average, the oil‑and‑gas sector remained the most attractive host for miners, registering 0.66% for executable miners and 0.34% for web miners, likely due to the abundant computational cycles available on under‑utilized SCADA servers and the sector’s historically relaxed endpoint controls. While mining malware is less destructive than ransomware, its presence signals weak host hardening and can degrade controller performance, potentially impacting real‑time processes. Companies should enforce baseline hardening – disabling unnecessary services, applying least‑privilege accounts, and utilizing application‑control whitelists – to deny miners a foothold.

Worm propagation demonstrated a clear quarterly rise, with the global blocked‑percentage climbing to 1.43%. The Middle East emerged as the second‑most affected region after Africa, posting a 2.11% figure that displaced Central Asia and the South Caucasus from the runner‑up position. Within the Middle East, building‑automation systems were the hardest hit, registering 2.90% of endpoints with blocked worm activity, and all surveyed industries in the region experienced growth. Australia and New Zealand, while ranking 12th overall at 0.41%, revealed a striking anomaly: the electric‑power sector there saw a 4.3‑fold increase, jumping from 0.29% to 1.24% despite the region’s overall low threat exposure. This suggests that specific worm variants are exploiting protocol‑implementation flaws in power‑grid RTUs or leveraging shared engineering workstations. Mitigation strategies include disabling unnecessary SMB/v1 services, enforcing strict network segmentation between engineering LANs and operational OT, and deploying intrusion‑prevention signatures that target known worm propagation techniques.

Virus detection slipped to a global blocked‑percentage of 1.29%, yet the regional hierarchy remained stable: Southeast Asia (6.03%), Africa (4.22%), and East Asia (3.14%) continued to lead. These same three regions also dominate the rankings for malware targeting AutoCAD, underscoring a persistent threat to engineering design workflows. In Africa, the construction vertical recorded the highest virus prevalence at 5.47%, while East Asia’s construction sector topped the list at 5.93% – a clear indication that attackers are weaponizing malicious DWG or DXF files to infiltrate design environments. In Australia and New Zealand, the electric‑power sector’s virus rate surged from 0.29% to 1.24%, a change driven primarily by a single variant that exploits legacy OPC‑DA implementations. For organizations reliant on CAD or engineering software, recommendations include implementing file‑type whitelisting, scanning all incoming design files with sandboxed antivirus engines, and restricting macro or script execution within CAD plugins.

Malware targeting AutoCAD crept upward to a global blocked‑percentage of 0.31%, with Africa showing the most dramatic trajectory after more than doubling in the previous quarter and reaching 1.02% in Q2 2026. The highest regional concentrations were found in construction projects across East Asia (6.38%) and Southeast Asia (4.05%), reflecting adversaries’ interest in compromising building‑information‑modeling (BIM) data, stealing proprietary designs, or inserting backdoors that could later facilitate sabotage. The concurrent rise in email‑based threats – the sole threat source that increased globally – further amplifies the risk, as phishing lures often carry malicious attachments masquerading as project updates or RFQs. To defend against this convergence, firms should enforce strict email attachment policies, deploy URL rewriting and attachment sandboxing at the mail gateway, and maintain isolated, air‑gapped workstations for high‑sensitivity design tasks.

Across all threat vectors, email emerged as the only source that registered a quarterly increase, pushing the global blocked‑percentage of email‑borne threats to 2.84%. Notable regional jumps occurred in South America (+1.00 pp to 5.20%) and Africa (+0.70 pp to 4.30%). The biometrics sector again bore the brunt, with 19.14% of its ICS endpoints encountering blocked email threats, closely followed by building‑automation systems in Southern Europe at 12.49%. This concentration highlights how email remains a preferred conduit for delivering malicious documents, links to exploit kits, and social‑engineering ploys aimed at credential harvesting. Practical steps for hardening email channels include enforcing DMARC, DKIM, and SPF authentication; disabling external content loading in email clients; employing time‑of‑click URL protection; and conducting regular, role‑based phishing simulations that mirror OT‑specific scenarios such as fake maintenance‑work orders or access‑request notifications.

In synthesizing the Q2 2026 findings, three overarching imperatives emerge for leaders responsible for industrial cybersecurity. First, maintain a risk‑based, region‑specific posture: apply baseline hardening universally while allocating advanced threat‑intelligence, managed detection, and red‑team resources to the hotspots identified in Africa, East Asia, and sectors like biometrics and building automation. Second, prioritize email and web‑based attack vectors, which remain the dominant delivery mechanisms for scripts, documents, and ransomware; invest in gateway sandboxing, macro disabling, and user‑training calibrated to OT workflows. Third, ensure that critical engineering and design environments – particularly those handling AutoCAD, BIM, and biometric templates – are isolated from general‑purpose networks, subjected to strict application whitelisting, and scanned with behavior‑based detection tools capable of catching zero‑day exploits. By translating these insights into concrete actions – such as updating blocklists, reviewing remote‑access policies, and scheduling periodic compromise assessments – organizations can turn the encouraging downward trend in overall threat prevalence into a sustained resilience advantage.