SEC536: Adversarial AI - Penetration Testing AI Systems

Not all of them: 39% of water facilities are unable to operate manually during an attack or are unsure whether they can, while 61% have tested and confirmed manual operation capability without traditional SCADA or DCS systems.
Only 58% have a dedicated ICS/OT incident response plan, meaning more than 40% are unprepared or unsure they have one, despite 26% of facilities reporting at least one control system security incident in the past year.
The most common attack vector, cited in 41% of incidents, was a compromise that started in the IT network and spread into the ICS/OT environment, rather than a direct attack on control systems themselves.
Over half (52%) of water sector respondents said traditional IT security tools and methods are not designed for control systems and can cause operational disruptions when applied to ICS/OT environments.
Not consistently: nearly 30% of organizations allocate only 0–10% of their total cybersecurity budget to ICS/OT-specific needs, though 40% reported a minor budget increase and 19% a significant increase over the past two years.
Not universally: only 49% of water facilities have a formal remote access policy, leaving a substantial gap even though MFA is considered a critical defense against the stolen-credential attacks common in ICS/OT breaches.