Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-24 and was added to the RWP archive on 2026-09-07.
Dragos's 2026 landscape brief is the defender translation of the Year in Review — same groups, sharper access-path advice
24 March companion to the February YIR — AZURITE, PYROXENE, SYLVANITE plus ELECTRUM/KAMACITE/VOLTZITE/BAUXITE, and the instruction to prioritize remote access and identity over "the PLC itself."
Bottom line up front
CONFIRMED 24 March 2026 Dragos blog is not a second dataset. It is the operator FAQ on the February Year in Review. Industrial targeting now includes state groups, RaaS, and hacktivists. Named: AZURITE, PYROXENE, SYLVANITE (new); ELECTRUM, KAMACITE, VOLTZITE, BAUXITE (continued). Takeaway Dragos wants in the SOC: prioritize remote access, identity, and internet-facing edge — the doors into OT — because the landscape is dynamic and the working defenses are not novel. Visibility gap is still the story. Keep separate from the YIR post: different URL, date, and "what to do Monday" framing. Not merged.
Historical backfill of 24 March 2026 reporting; added 7 September 2026.
What happened
A briefing, not a leak-site dump. Oil-and-gas sector follow-on in April is a third derivative — not this article.
Why it mattered
YIR PDFs do not change jump-host configs. This post is the one CISOs can paste into a backlog.
Who / what was affected
Same industrial population as the YIR. No new victim census here.
Technical context
Inventory VPN, cellular gateways, vendor jump boxes. Monitor identity into the DMZ. Do not confuse "no PLC malware" with "no OT risk."
Exploitation / threat status at the time
CONFIRMED Dragos's own framing of their 2025 data.
UNKNOWN additional 2026 activity beyond the YIR cutoff.
What defenders should have done
- Access-path program, not a new SIEM use-case.
- Assume state and crime share the same edge devices.
- Measure detection inside OT, not only at the IT SOC.
RWP assessment
Confidence: High as a Dragos-authored recap. Thin as a standalone incident.
Defensive actions
- Close internet-facing HMIs/PLCs (see FBI water PSA already in this archive).
- Vendor PAM.
- Pair with quarterly ransomware counts, not instead of them.
Sources
- Dragos — OT Threat Landscape 2026
- Dragos — 2026 OT Cybersecurity Year in Review
- SANS Institute — Takeaways from the Dragos 2026 OT report