// 4 CVE · 3 EXPLOIT IN THE LAST 24H
In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022. Yet the biometric sector remains the most affected at 26.44%, driven by internet exposure, heavy email use, and minimal security controls.

On August 27, 2026, Kaspersky released its quarterly threat landscape report for industrial automation: in the second quarter, the global percentage of ICS computers on which malicious objects were blocked dropped to 19.15%, the lowest level since 2022. The figure does not signal a structural improvement, however. Attack vectors have narrowed but sharpened, with measured growth in denylisted internet resources, malicious documents, worms, ransomware, and AutoCAD malware, while the biometric sector — paradoxically the one that should guarantee physical identity — remains the most affected, with 26.44% of systems impacted.

Key Takeaways
  • In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022; Northern Europe recorded 8.1%, Africa 27.9%
  • Eastern Asia showed the sharpest quarterly increase (+2.0 percentage points), with 9.01% script/phishing in the biometric sector
  • The biometric sector is the most affected among analyzed industries (26.44%), characterized by internet access, extensive email use, and minimal cybersecurity controls
  • Denylisted internet resources rose from third to second top threat globally (4.31%), with Russia leading (5.17%, +1.33 pp) and a peak of 6.61% in the energy sector
  • In Q2 2026, 10,904 distinct malware families were blocked on industrial automation systems
"In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022." — Kaspersky, Threat landscape for industrial automation systems. Q2 2026

The Global Drop That Masks a Risk Reconfiguration

The 19.15% figure demands a technical reading, not a surface one. According to Kaspersky's report, the decline is driven mainly by a drop in malicious scripts and phishing, which fell to a global average of 5.42%. This category traditionally represented the bulk of background noise; its contraction pulls the aggregate figure down.

At the same time, more targeted vectors are accelerating. Denylisted internet resources climbed to 4.31% globally, taking the second spot in the threat ranking after previously ranking third. This marks the second consecutive quarter of growth. Malicious documents rebounded to 1.77% after three quarters of decline, peaking in South America (3.56%, the fourth-highest value in three years). Worms, ransomware, and AutoCAD malware all increased quarter-over-quarter.

The dossier does not specify whether the aggregate decline reflects a real contraction of threats or a change in Kaspersky's detection base, nor how many ICS customers and which exact sectors are included in the sampling.

The Biometric Paradox: Physical Identity, Digital Security Gaps

The biometric sector accounts for 26.44% of ICS computers with blocked malicious objects, the highest value among all industries analyzed. The reason lies not in technical flaws of biometric sensors — which the report does not mention — but in the IT/OT architecture surrounding them.

"Biometric systems are characterized by the availability of internet access, extensive email use for data exchange and approvals (e.g. access granting), and, in many cases, minimal cybersecurity controls within the organizations that use them." — Kaspersky, Threat landscape for industrial automation systems. Q2 2026

This configuration is anomalous for two reasons. First, extensive email use for operational processes — including access approvals — exposes these environments to social engineering techniques that would be geometrically more complex in air-gapped settings. Second, the biometric sector is the only one where email threats exceed internet threats, inverting the hierarchy seen in every other vertical. This suggests a distinct risk profile, not merely an intensification of common patterns.

Eastern Asia amplifies the phenomenon: there, the biometric sector reaches 9.01% script/phishing, the second-highest value in three years. The region overall posted the largest quarterly increase (+2.0 pp), with a 0.93 pp rise in the script/phishing category alone.

Russia and Denylisted Resources: A Geographic Risk Pole

Russia leads globally for denylisted resources (5.17%) and records the largest increase in this category (+1.33 pp). The concentration appears in the energy sector, where it hits 6.61%. The risk geography is therefore fragmented: Africa for overall intensity (27.9%), Eastern Asia for accelerating dynamics, Russia for polarization on energy infrastructure and internet resources.

The report does not document specific MITRE ATT&CK ICS tactics, CVEs, or exploits employed, nor does it provide details on concrete impacts such as downtime or production outages. The source states that 10,904 distinct malware families were blocked on industrial automation systems in Q2 2026, a figure that quantifies threat biodiversity but not severity.

What to Do Now

For operators of industrial biometric systems, the report indicates three documented priorities. First: reduce reliance on email for access-approval processes, since this sector is the only one where email threats exceed internet threats. Second: verify countermeasure coverage across the 10,904 malware family profiles detected in Q2 2026, with attention to growing families (worms, ransomware, AutoCAD malware). Third: monitor the denylisted-resource trend, which has risen to 4.31% globally for two consecutive quarters, signaling persistent offensive interest in C2 communications or web-based payload delivery.

For organizations in Eastern Asia, the +2.0 pp quarterly increase and 9.01% script/phishing in the biometric sector warrant a review of web-filtering policies and anti-phishing training. For those in Russia and adjacent markets, the 6.61% in the energy sector signals a concentration of risk on critical infrastructure that merits network segmentation analysis.

The 19.15% drop does not justify budget cuts: the threat has shifted toward more technical vectors that are harder to detect with aggregate metrics.

Frequently Asked Questions

Does the drop to 19.15% mean ICS are less at risk?

No. The metric measures malicious objects blocked on ICS computers monitored by Kaspersky, not the absolute security of plants. The decline is explained mainly by the contraction of scripts/phishing (5.42%), while more targeted vectors are growing.

Why is the biometric sector particularly vulnerable?

According to the report, because it combines internet access, extensive email use for operational processes, and minimal security controls. The vulnerability lies in the IT/OT context, not in the biometric sensors themselves.

What does "denylisted internet resources" mean in the ICS context?

The report does not specify the exact nature of these resources. The term refers to URLs, IPs, or other identifiers blocked by security solutions, but the technical category is not detailed by the source.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. securelist.com