By Carlos Marques, VP Business Development, Africa
For decades, industrial systems ran on a comforting assumption: the plant floor was physically separate from the corporate network, so whatever happened in IT stayed in IT. That assumption is gone. As manufacturing and logistics operations across Africa digitise to compete globally, operational technology, the systems that run production lines, water treatment, ports, and power distribution, is connecting to corporate networks that were never designed to protect it. The air gap didn’t get breached. It dissolved, quietly, one integration project at a time.
A converged network is a shared attack surface
Once IT and OT share a network, a threat that starts in email or a compromised laptop has a path to the factory floor. Dragos’s 2026 OT/ICS Cybersecurity Report tracked 119 ransomware groups actively targeting industrial organisations in 2025, up from 80 the year before, a 49% increase that collectively impacted 3,300 organisations globally. Manufacturing alone accounted for more than two-thirds of the victims. These aren’t attacks that stayed contained to a server room. Dragos found that its incident response teams observed significant operational disruption in every single OT ransomware case they responded to during the year.
Legacy equipment can’t be patched, so it has to be compensated for
Here’s the uncomfortable part of industrial digitisation: much of the equipment doing the actual work, programmable logic controllers, SCADA systems, decades-old sensors, was never built with security in mind and often can’t be updated without risking the production line itself. Dragos found that 26% of vendor advisories for known industrial vulnerabilities came with no patch or mitigation available at all. When you can’t fix the vulnerability, the only option left is compensating controls: network segmentation, strict access boundaries, and monitoring tuned to catch what shouldn’t be happening, because the equipment itself will keep quietly running exposed.
You can’t defend what you can’t see
Ask most industrial organisations for a complete asset inventory of their OT environment and watch the pause that follows. That pause is the real vulnerability. SANS’s 2025 ICS/OT security survey found that unauthorised external access accounted for half of all reported incidents, yet only 13% of organisations had fully implemented advanced access controls like session recording or OT-aware monitoring. Just 14% of respondents said they felt fully prepared for emerging threats. Without visibility into what’s actually connected and what it’s doing, anomaly detection isn’t a capability an organisation has. It’s a capability an organisation hopes it has.
When OT fails, the consequences aren’t just financial
A breached database is a business problem. A breached industrial control system can stop a production line, disable safety instrumentation, or put people in physical danger. INTERPOL’s 2025 Africa Cyberthreat Assessment flagged this shift directly, warning that ransomware targeting critical infrastructure, energy, mining, telecom, transportation, and manufacturing carries the potential to disrupt essential services and cause serious economic damage across the continent. This is no longer a hypothetical. As African manufacturing and logistics scale to meet demand, the systems keeping people safe are increasingly the same systems attackers are learning to target.
Regulation is arriving, but enforcement is uneven
The regulatory picture is moving in the right direction, just not consistently. Kenya’s Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, enacted in 2024, formally elevated the protection of critical infrastructure as a national priority. Nigeria’s telecoms regulator is working toward a national cybersecurity framework targeted for 2026. That’s real progress, but it’s happening market by market, at different speeds, with different enforcement capacity. An organisation operating across three or four African countries can’t assume the same baseline of regulatory protection or oversight in each one. Compliance has to be treated as a floor, not a strategy.
AI just gave every attacker an OT specialist on staff
The skills gap that used to protect industrial systems is closing, and not on the defenders’ side. In August 2025, operators at Uganda’s Electricity Transmission Company Limited watched their monitoring screens freeze as a ransomware variant compromised systems governing the national power grid; service was only restored through backup protocols. INTERPOL’s African Cyberthreat Assessment Report 2026 puts this in context: AI now drives more than 55% of reported cybercrime across the continent, automating reconnaissance, phishing, and evasion at a scale no human-run campaign could match. Separately, Dragos documented a real case of a commercial AI model identifying an industrial interface as a high-value target and recommending it as a path into OT during an intrusion, without the attacker needing any specialist ICS knowledge. For defenders, this collapses a timeline that used to buy time. Reconnaissance that once took a skilled team weeks can now be assembled by a generalist attacker in minutes, and an under-resourced team that was already struggling with visibility is now facing adversaries who no longer need years of OT expertise to find the door.
No single vendor sees the whole picture anymore
This is the uncomfortable part for the industry itself: AI-scaled attacks don’t respect the line between IT and OT, so defending against them can’t either. Specialist OT security vendors understand control systems, protocols, and physical process risk in ways traditional IT vendors never will. But the entry point in cases like Uganda’s is still an IT-side compromise, which means the telemetry that would catch an AI-assisted attacker early often sits with the IT security stack, not the OT one. Analysts are converging on the same conclusion from a different angle: IoT Analytics’ OT Cybersecurity Insights Report 2026 argues that the integration of AI into OT has forced a fundamental rethink of industrial security by vendors and enterprises alike, while industry commentary on next-generation OT security operations centres points to the same structural fix, merging siloed IT and OT teams into a single function with shared visibility and shared workflows rather than two teams comparing notes after the fact. A segmented approach to AI-era threats is really just a slower version of the segmentation problem this article started with.
What good looks like
None of this requires ripping out functioning industrial equipment. It requires knowing what’s connected, segmenting IT from OT deliberately rather than by accident, monitoring for behaviour that doesn’t belong, and building compensating controls around the equipment that can’t be patched. At DataGroupIT, we’re increasingly working with partners and manufacturers across the continent who are having this conversation for the first time, not because they’ve been breached, but because they’ve finally asked the question of what’s actually running on their industrial network. That question is the right place to start.
Africa’s industrial growth is real and it’s accelerating. The organisations that treat OT security as foundational, not an afterthought bolted on after the fact, are the ones whose growth won’t get interrupted by an attacker who found the gap first.
Carlos Marques is VP Business Development, Africa, at DataGroupIT (DGIT), a pan-African cybersecurity value-added distributor helping organisations build security architecture across identity, data, cloud, network, and managed security services.
