Industrial Vulnerabilities Remained Unpatched for Years
New research shows that critical operational technology security flaws often persist for over three years due to strict maintenance protocols.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust that industrial companies are adequately securing their critical infrastructure against digital vulnerabilities?
Holm Security released research finding that critical vulnerabilities in industrial operational technology (OT) environments typically remain unpatched for more than three years. These persistent risks often reside alongside active ransomware-exploitable vulnerabilities on connected IT networks.
Why it matters
The findings highlight the disconnect between cybersecurity best practices and the rigid operational requirements of industrial infrastructure. Because production systems cannot be patched on demand, security gaps persist significantly longer than in traditional IT environments.
Industrial and SCADA (Supervisory Control and Data Acquisition) environments frequently leave critical vulnerabilities open for over three years. This duration significantly exceeds standard software patching timelines due to system-wide reliance on infrequent maintenance windows.
The players
Holm Security
A Stockholm-based company founded in 2015 that provides a platform for assessing security risks across IT and operational technology environments for over 1,500 organizations.
The details
Industrial systems are constrained by production uptime requirements, meaning they cannot be taken offline for security maintenance without authorization. Because vendor certification dictates when changes can be applied to these environments, operators are unable to implement patches on demand. This creates a permanent gap where known exploits remain active in production systems far longer than in standard IT environments, where automated patching is common.
Timeline
2015: Holm Security was founded in Stockholm.
September 29, 2026: Holm Security released its research findings on industrial OT vulnerabilities.
The Tech Race
This research highlights a growing divide between modern IT security expectations and the legacy constraints of operational technology environments. While IT security platforms move toward rapid, automated deployment, industrial infrastructure remains tethered to rigid vendor certification processes.
Organizations relying on industrial or SCADA environments must account for extended risk exposure windows during their internal security assessments. Security teams should prioritize compensating controls for known vulnerabilities that cannot be patched due to vendor certification requirements.
The takeaway
Industrial operators face a persistent security lag that standard patching schedules cannot resolve. Security leaders should look to the next update from Holm Security regarding risk assessment benchmarks for OT environments to better quantify their local exposure.
Further reading
For more on the challenges of securing critical systems, visit Cybersecurity.
Live Poll
Do you trust that industrial companies are adequately securing their critical infrastructure against digital vulnerabilities?







