Lessons for New Zealand from the Fortinet 2026 State of OT Cybersecurity Report
Greater visibility, IT and OT convergence, and longer attacker dwell times are reshaping operational cybersecurity
Fortinet has released its 2026 State of Operational Technology and Cybersecurity Report, its eighth annual study examining how organisations are securing operational technology (OT) environments.
Based on a global survey of more than 700 OT-related professionals, including respondents from Australia and New Zealand, the report shows that organisations are taking OT cybersecurity more seriously, but significant gaps remain. Attackers are remaining undetected for longer, regulatory expectations are accelerating, and organisations are reassessing how mature their OT security programmes really are.
For New Zealand organisations operating critical infrastructure, manufacturing, transport, utilities, healthcare, and other operational environments, the findings provide several important lessons.

IT and OT can no longer be secured in isolation
One of the underlying themes of the 2026 report is the continuing convergence of information technology and operational technology.
Many OT systems were originally designed as isolated environments, without connections to corporate networks, cloud platforms, remote users, or the internet. Today, that model has changed.
As organisations digitise operations, Fortinet notes that OT and IT threats are now inextricably linked. Connecting OT, IT, and cloud environments can improve efficiency, visibility, analytics, and automation, but it also creates new pathways for cyber threats to reach mission-critical operational systems.
For New Zealand organisations, this means OT security can no longer sit entirely apart from the wider cybersecurity programme. IT and OT teams need shared visibility, coordinated governance, and an architecture that enables connectivity without creating uncontrolled pathways between business and operational systems.
Organisations are getting more realistic about security maturity
One of the most striking findings in the 2026 report is the decline in organisations rating themselves at Fortinet’s highest level of cybersecurity process maturity.
Fortinet measures maturity from Level 0, where cybersecurity processes are largely reactive and unorganised, through to Level 4, where processes are continually improved through optimisation, automation, threat intelligence, and mature incident management.
In 2025, 49% of respondents assessed themselves at Level 4. In 2026, that dropped to just 17%.
Rather than representing a major decline in security, Fortinet suggests improved tools, stronger IT and OT collaboration, and better visibility are revealing weaknesses that previously went unnoticed. Organisations are gaining a more realistic understanding of their exposure.
The lesson is that cybersecurity maturity should not be treated as a static score. Genuine maturity means continuously identifying weaknesses and improving controls as the environment and threat landscape evolve.
Better visibility is revealing more attacks, but dwell times are increasing
The 2026 report shows a substantial increase in organisations detecting multiple intrusions. 71% of respondents reported between one and nine intrusions, up from 47% in 2025.
Fortinet cautions that this does not necessarily mean attacks have become dramatically more successful. Improved monitoring may simply be revealing malicious activity that would previously have gone undetected.
However, attacker dwell time remains concerning.
In 2026, the proportion of incidents where attackers remained undetected for weeks increased from 6% to 13%, while incidents involving dwell times measured in months increased from 5% to 7%.
For OT operators, this reinforces the importance of asset visibility, continuous monitoring, and understanding normal communication patterns. The objective is not only to prevent attacks at the perimeter, but to identify and contain malicious activity quickly when an attacker does gain access.
Segmentation is becoming fundamental to OT resilience
One of the more encouraging findings is the significant reduction in intrusions affecting both enterprise IT and OT systems.
In 2025, 60% of respondents who experienced an intrusion reported that both environments were affected. In 2026, this fell to 24%, the lowest figure since 2022. Fortinet suggests increased segmentation between IT and OT environments is likely contributing to the improvement.
Accordingly, Fortinet’s first recommended best practice is to segment and microsegment IT and OT networks to limit the impact of attacks.

Segmentation restricts which systems, devices, and users can communicate with one another. This is particularly important in OT environments, where legacy devices, flat networks, and limited patching opportunities are common. Proper segmentation can restrict lateral movement, isolate higher-risk assets, improve visibility, and reduce the operational impact of a compromise.
For critical infrastructure operators, segmentation should increasingly be considered part of the underlying OT architecture rather than an optional security layer.
Remote access and incident response need to reflect OT risk
The convergence of IT and OT also creates new requirements around remote access and incident response.
Equipment manufacturers, maintenance providers, integrators, and engineering teams often require remote access to operational systems. Fortinet recommends purpose-built secure remote access controls that apply zero-trust principles, providing temporary and granular access to only the systems required while monitoring and recording sessions.
Incident response also needs to account for the realities of OT.
In a traditional IT environment, a compromised server may simply be isolated or shut down. In OT, the same action could interrupt production, affect critical infrastructure availability, or create safety consequences.
Fortinet therefore recommends incorporating OT directly into security operations and incident response planning, including playbooks that account for operational systems, production processes, roles, system dependencies, and recovery priorities.

Regulatory pressure is accelerating
Fortinet found that 89% of respondents expect increased cybersecurity regulation within five years, up from 66% in 2025.
New Zealand does not yet have the same comprehensive mandatory critical infrastructure cybersecurity regime seen in some overseas markets. However, this is beginning to change. In 2026, the Department of the Prime Minister and Cabinet proposed new mandatory cybersecurity requirements for New Zealand’s most significant critical infrastructure entities, potentially covering sectors including energy, transport, communications, health, finance, defence, and water.
Australia provides a useful indication of where regulatory expectations can lead. Under its Security of Critical Infrastructure (SOCI) Act, covered organisations can be required to maintain formal risk management programmes and report cybersecurity incidents, while designated systems of national significance can face additional requirements around incident response planning, cybersecurity exercises, and vulnerability assessments.
For New Zealand critical infrastructure operators, the gap is becoming harder to ignore. Compared with Australia, New Zealand is still behind in formalising critical infrastructure cybersecurity obligations. Organisations therefore need to take responsibility for their own resilience rather than wait for regulation to catch up, while also preparing for a future in which mandatory cyber governance, incident reporting, risk management, and resilience requirements are likely to become part of the operating environment.
Legacy OT remains a challenge
Fortinet also reports encouraging signs of industrial systems being modernised. 40% of respondents now operate ICS environments less than five years old, compared with 20% in 2025.
However, 47% still operate systems between six and ten years old, while around 13% have systems more than 11 years old.
Replacing every older system is rarely realistic. Where modernisation is not practical, organisations need compensating controls such as segmentation, restricted access, continuous monitoring, and OT-specific threat intelligence.
Lessons for New Zealand leaders
Fortinet’s 2026 report shows that OT cybersecurity is becoming more demanding as IT and OT environments converge, attackers remain undetected for longer, and regulatory expectations increase.
For New Zealand organisations, there is an additional challenge. Compared with markets such as Australia, our formal critical infrastructure cybersecurity requirements remain less developed. Organisations cannot rely on regulation to define what an appropriate level of resilience looks like or wait for legislation before addressing known risks.
Fortinet’s recommended best practices for 2026 focus on five areas:
- Segmenting and microsegmenting IT and OT networks
- Implementing secure remote access
- Integrating OT into security operations and incident response
- Investing in OT-specific threat intelligence
- Taking a platform-based approach to security architecture
For New Zealand organisations responsible for critical operations, the lesson is not simply to deploy more cybersecurity technology. It is to understand how IT and OT systems interact, identify and monitor the assets that matter, control the pathways between them, restrict remote access, and prepare for incidents before they occur.
As IT and OT continue to converge, cyber resilience and operational resilience are increasingly becoming the same conversation.
Contact Nextro today to discuss how your organisation can improve OT visibility, strengthen IT and OT segmentation, secure remote access, and build a more resilient cybersecurity architecture for critical operational environments.
