Historical intelligence backfill. This assessment covers reporting originally published on 2026-02-17 and was added to the RWP archive on 2026-09-07.
Dragos's 2026 Year in Review is control-loop mapping — ransomware counted as OT by consequence
Ninth annual report — three new groups (AZURITE, PYROXENE, SYLVANITE), 119 ransomware brands against 3,300 industrial orgs in 2025, and a visibility gap Dragos puts at 30 percent of OT networks.
Bottom line up front
CONFIRMED Dragos launched its ninth OT Year in Review on 17 February 2026. Thesis: 2025 adversaries moved from pre-positioning toward mapping control loops. New groups: AZURITE (engineering workstations), PYROXENE (multi-year supply-chain / ops social engineering; June 2025 wiper vs Israeli targets in Dragos's telling), SYLVANITE (rapid exploitation broker enabling VOLTZITE). KAMACITE recon of US industrial devices Mar–Jul 2025; ELECTRUM against Polish DER (wind/solar) in December 2025. Ransomware: 119 groups, 3,300 industrial organizations, manufacturing more than two-thirds; 49 percent more groups than 2024. Dragos IR: significant operational disruption in all OT ransomware cases they responded to — often via ESXi/Windows hosting SCADA, not PLC malware. Visibility: 30 percent of OT networks have visibility; 56 percent cannot see below the IT/OT boundary (Dragos marketing page). SANS restates: disruption often without touching controllers. Process-level ICS Stage 2: ASSESSED for named state groups' intent; ransomware Stage 2: not the default in this report.
Historical backfill of 17 February 2026 reporting; added 7 September 2026.
What happened
Annual dataset, not a single intrusion. Companion landscape post (March) is separate.
Why it mattered
If your board still files plant downtime as "IT ransomware," you are using the misclassification Dragos is yelling about.
Who / what was affected
Industrial orgs globally in Dragos's 2025 set. Named groups as Dragos tracks them.
Technical context
Hunt VPN/jump hosts (Dragos: large share of IR cases). Segment hypervisors that host OT apps. Do not wait for ICS-specific malware.
Exploitation / threat status at the time
CONFIRMED Dragos telemetry/IR as stated.
REPORTED group narratives (ELECTRUM Poland, etc.) via Dragos, not independently re-litigated here.
What defenders should have done
- OT visibility below the boundary.
- Treat ESXi that hosts historians as OT.
- Tabletop control-loop mapping, not just phishing.
RWP assessment
Confidence: High on the dataset shape. New group names are Dragos designations.
Defensive actions
- SANS Five ICS Critical Controls as the floor.
- Incident classification that records process impact.
- Read quarterly ransomware posts as the numbers layer under this YIR.
Sources
- Dragos — 2026 OT Cybersecurity Year in Review
- SANS Institute — Top takeaways from the Dragos 2026 OT report
- CyberSecurityStats — 2026 OT Cybersecurity Year in Review findings