Holm Security's Security Research team has found that the typical critical vulnerability in Operational Technology (OT) environments was disclosed more than three years ago, and it rarely sits alone.
Operational Technology has a reputation for being difficult to patch, but the scale of the resulting exposure is rarely measured. From what our Security Research team sees across industrial environments, the pattern is clear enough to put numbers to.
The typical critical vulnerability in industrial and SCADA environments has been publicly known for more than three years and is still unresolved. Industrial environments are also considerably more likely than others to carry active, ransomware-exploitable risk on their IT network at the same time.
None of this points to negligence. It reflects the reality of securing systems that can't simply be taken offline and patched. What it shows is how long known industrial risk persists in practice, and why visibility across both IT and OT has become essential.
The typical critical industrial vulnerability was disclosed more than three years ago
Across industrial environments, the typical open critical vulnerability is one whose underlying issue was first publicly disclosed more than three years ago. It's a vulnerability that has been publicly documented, with a fix or mitigation already available. In IT, a three-year-old unresolved critical vulnerability is unusual. In OT, it is the norm.
Detection isn't the obstacle. Production systems often can't be patched on demand, maintenance windows are infrequent, and vendor certification can dictate what can be changed and when. The result is a long tail of known, unaddressed critical risk sitting in environments that are frequently the most sensitive to disruption.
Industrial risk rarely sits alone
Industrial vulnerabilities don't exist in isolation. Where there are active industrial vulnerabilities, the great majority of those environments also carry an active critical or ransomware-exploitable vulnerability on the IT network at the same time. This suggests industrial environments are more likely to be managing serious exposure on both fronts at once.
Why it matters
Industrial risk and IT risk are not separate problems. Yet the two are still routinely managed by different teams, with different tools, on different schedules. Seeing industrial and IT risk through one system, prioritized against each other rather than in isolation, is what turns two partial views into a single picture of where an organization is exposed.
Holm Security assesses IT and OT environments through one platform, bringing exposure and vulnerability management to industrial risk alongside IT risk instead of treating them separately.
About this research
These findings come from Holm Security's Security Research team. They're based on what the team observes across industrial environments, combined with public vulnerability data such as disclosure dates. The findings describe the broader threat landscape, not the security posture of any individual organization.
Head of Security Research
Mihail has extensive expertise in vulnerability management and over 10 years’ experience in IT and cybersecurity. With a strong foundation in software development, including automation and automotive industries, he leads the Security Research team and is responsible for all vulnerability tests across the company’s suite of vulnerability scanners.




