Industrial cybersecurity: 5 tips to follow in 2026

  • Defence
  • Cyber
  • Cybersecurity

© Ercom et Adobe stock

  • Type Insight
  • Published

Faced with a record number of cyber incidents last year, industrial companies in Europe are under mounting pressure to protect their operations. As cybercriminal tactics evolve and regulations tighten, securing your systems is no longer just a technical challenge—it’s a cornerstone of productivity and compliance. Ready to strengthen your company’s defences? Discover five expert tips to future-proof your industrial cybersecurity in 2026.

With 1,318 incidents recorded in Europe, industry was the sector most targeted by cybercriminals in 2025. These incidents often have serious consequences and can bring the entire industrial sector to a standstill.

Industrial players face several challenges. They must secure their IT and OT systems, address vulnerabilities in their aging legacy environments, and protect ever-increasing volumes of data. Added to this is a regulatory imperative with the entry into force of the NIS2 directive.

Cybersecurity is therefore a matter of compliance, productivity, and long-term viability for industrial companies. Discover our expert's 5 tips to improve your organisation's cybersecurity.

1. Strengthen Access Control

According to Palo Alto Networks' Global Incident Response Report 2026, 90% of cybersecurity incidents in 2025 were linked to inadequate identity controls. The first action to take is therefore to strengthen access control to your systems.

This involves simple measures, such as implementing a password management policy with a minimum required complexity, regular password changes, or using a password manager to prevent risky practices. Strong authentication is another measure to implement to verify the identity of users wishing to access your systems.

Network segmentation naturally fits into this control framework. Separating IT (computer systems) and OT (operational technology) environments mechanically limits the spread of an attack from one system to another.

2. Maintain and Secure Digital and Industrial Assets

An application, infrastructure, or automated system that is not regularly maintained becomes a vulnerability exploitable by cybercriminals. These individuals use tools to automatically detect vulnerabilities that companies have not patched. It is therefore crucial to systematically deploy updates and security patches to close these gaps.

Beyond patch management, the data flowing between your machines, software, and systems must be protected by end-to-end encryption. If intercepted by a malicious third party, your data becomes unreadable.

In sensitive industrial environments, it is strongly recommended to use solutions certified by the French National Cybersecurity Agency (ANSSI). This is the case, for example, with the Cryptobox collaborative solution which secures file sharing at a Restricted Distribution level, Cryptosmart Mobile which guarantees the security of terminals and mobile communications with a government-level security level, Cryptosmart PC, which protects the connections of your remote computers by integrating the technological building blocks of Cryptosmart Mobile, and Citadel Team, a collaborative solution which ensures end-to-end encryption of messaging and calls, and which also secures audio/video conferences.

3. Anticipate Risks

To avoid a complete production shutdown in the event of an incident, anticipating risks plays a key role. The first step is to map and prioritise the risks that could affect your IT and OT environments.

This preliminary work will then allow you to develop a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP). These documents describe the steps to take to react effectively in the event of a cyberattack. They define everyone's role, the people to contact in an emergency, and the technical and human resources to be mobilized. They include a resilient communication tool to facilitate the coordination of mobilised teams, such as Citadel Team, a solution designed to ensure the continuity and confidentiality of communications in the event of a cyber incident.

These procedures must be tested through crisis management exercises. An annual review of the plans ensures their relevance in the face of constantly evolving threats.

4. Regularly Raise Staff Awareness

60% of security incidents involve human error. To limit risks, it is therefore essential to train all employees on cybersecurity issues and best practices in cyber hygiene. It is also important to raise their awareness of attackers' methods.

This training must be regularly updated to reflect the evolving nature of cyber threats and must be systematically provided to new employees. Beyond theory, it is important to offer practical exercises or simulations, such as sending fake phishing emails. An informed and empowered employee becomes an effective early warning system: they will often be the first to detect a suspicious anomaly.

5. Establish a Culture of Lessons Learned

In the industrial sector, cybersecurity must be part of a continuous improvement approach. Every incident, every thwarted attack attempt, should become a learning opportunity and enrich your cybersecurity strategy.

To achieve this, it is essential to establish a "no-blame culture": employees must be able to report any anomaly or error without fear of reprisal. Each piece of information can then be analysed, leading to the correction of procedures or the strengthening of existing systems.

Lessons learned can be shared during team meetings, via an internal security newsletter, or by organising post-incident debriefing sessions. In this way, cybersecurity gradually becomes embedded in the company culture.

Access control, the maintenance of digital and industrial assets, incident anticipation, awareness, and a culture of learning from experience are the five pillars of a sustainable, compliant, and effective cybersecurity strategy. Ercom supports industrial companies in their security efforts with sovereign solutions such as Citadel Team, the secure professional communication solution that encrypts your messages, audio conversations, and video conferences; Cryptobox, the secure file sharing and collaboration solution; Cryptosmart Mobile, which secures your endpoints, communications, and data; and Cryptosmart PC, the turnkey VPN solution for PCs with government-grade security.

La cybersécurité n’est plus une option, mais une priorité stratégique. Seules des solutions sécurisées de bout en bout garantissent une protection réelle des systèmes d’information. Investir aujourd’hui, c’est construire la résilience de demain. Dans l’industrie, cette exigence est indispensable pour assurer la continuité, la sûreté et la performance des opérations.

Nicolas Mostacchi - Sales director at Ercom by Thales

  • Defence

Frugal AI: the key to embedding artificial intelligence in combat optronics

Insight
  • Research & innovation

Thales and ELI-NP Renew their partnership with a new maintenance support contract for the World-Class 10-Petawatt Laser System

Insight
  • Cybersecurity

Thales researchers explain why the defence against the quantum threat starts now

Insight
  • Cybersecurity

Game On: How Bot Attacks Are Threatening the Digital Fan Experience

Insight
  • Research & innovation

From Mars to nuclear fusion, Thales stretches the frontiers of high-power laser technology

Insight
  • Defence

How to stop the use of unsecured attachments without hampering your teams’ productivity

Insight
  • Air defence

On Thales’ missile optronics and electronics repair lines, augmented maintenance is becoming a reality

Insight
  • Defence

Remote access: Which VPN can balance security and user experience?

Insight
  • Surveillance and intelligence

Collaborating with advanced airborne autonomy, the new paradigm for land operations

Insight