Factories, grids, and finance: Critical infrastructure cyber lessons of 2025

January 2026 Asset Management, Information Security, Industrial (Industry)

Looking back at 2025, South Africa’s industrial operators are reflecting on a year of profound change – and concerns. A significant and welcome development was the end of systemic load shedding, with the grid achieving more than 6 months of stability as the year ended, but as one crisis receded, a more complex, digital-first risk is taking its place.

The primary lesson of 2025 is this: stability has triggered an accelerated, large-scale digitisation of our overall industrial base, and this rapid convergence of IT and operational technology (OT) is happening on a foundation that, in essence, was not designed to be cybersecure.

The ‘air gap’ that once protected factory production lines, power substations, and water treatment plants from the corporate IT network is gone. This convergence is a modern business necessity, enabling remote monitoring, predictive maintenance, and efficiency. The risk, however, comes from connecting modern IT systems to legacy OT – such as SCADA and programmable logic controllers (PLCs) – which were built for physical safety, not cybersecurity. They cannot be easily patched and were never designed to face the (then unforeseen) threats of 2026.

From instability to integration risk

The lesson of 2025 is not about managing reboots from load shedding anymore, but about managing the complex risks of new connections. The new energy stability period has unlocked a green ‘rush’ of both renewable power projects as well as overall digitisation. We are connecting new independent power producers (IPPs) to the grid, rolling out municipal smart metering, and upgrading legacy systems at scale, but the danger lies at the new digital seams emerging.

From the outset of 2025, the public sector has been under siege, with many fending off attacks and others being less lucky. The immense challenges in enforcing the South Africa Critical Infrastructure Protection Act (CIPA) are another signal, with ‘tanker mafias’ and other criminal elements representing a physical threat to water infrastructure that has a direct digital parallel: an unpatched vulnerability in a municipal SCADA system could prove just as catastrophic as physical sabotage.

The factory floor lesson

The manufacturing sector had to learn this lesson in a year it could least afford it. With the Absa Purchasing Managers' Index (PMI) slipping back into contraction at 49,2 in October, the sector remained under intense pressure, leaving no room for a costly digital disruption banging at the gates.

This threat is not abstract for South Africa. The automotive sector, a cornerstone of our manufacturing base, also saw repeated warnings in 2025.

The industrial security posture for 2026

The lessons of 2025 must inform a new industrial security posture. First, unified visibility is paramount. Operators cannot protect what they cannot see. This must start with a comprehensive audit of every single device connected to both the IT and OT networks to eliminate critical blind spots.

Second, network segmentation has become the most powerful defence. This is the modern equivalent of the air gap. A successful breach of the corporate network must be contained. By segmenting networks, an attacker who compromises the finance department is stopped by an internal firewall, completely unable to see or access the factory floor’s control systems.

Finally, operators must adopt a Zero Trust approach for all industrial systems. Every user, device, or application seeking to access the OT network must be verified, every single time. Trust is never assumed.

In 2025, the risk moved from the data centre to physical industrial spaces, and the threat shifted from managing instability to securing integration. The lesson is that digital risks to our physical infrastructure pose a direct threat to economic productivity and public safety. In 2026, our operational resilience will be defined not by how we manage physical assets, but by how we secure the digital convergence that now controls them.

Find out more at www.fortinet.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Connecting access control, logistics and asset tracking
Access Control & Identity Management Asset Management Logistics (Industry)
Physical barriers matter, but a site is not secure just because the gate is strong or the container is locked. True security requires verifying every movement, tracing handovers, making exceptions visible, and allowing intervention before minor issues become major losses.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
SA does not have an AI problem, it has a data problem
AI & Data Analytics Asset Management
Organisations are investing in generative AI, predictive analytics and intelligent automation, driven by the promise of increased productivity, faster decision-making and competitive advantage. Yet many businesses discover AI is not delivering the results expected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.