LOGIC TELECOM
Tech worldJuly 21, 20262 min read

Cyberattacks on Russian industry increased by 31%

Kaspersky reported a 31% rise in security incidents affecting Russian industry. We examine the operational risks and practical defensive controls.

A protected digital perimeter around an industrial facility
Contents

On 7 July 2026, Kaspersky reported that the number of security incidents detected and prevented at Russian industrial organisations had increased by almost 31% year on year in the first half of 2026. Transport and logistics saw the sharpest change: attacks increased by 75%, while high-severity incidents rose by 30%.

How the threat picture changed

According to the primary source, the share of high-severity incidents in industry was about 50% above the Russian average. In the first quarter, the share of industrial-control-system computers on which ransomware was blocked increased by 97% year on year. The combined share of spyware, backdoors and keyloggers rose by 50%.

These figures should not be treated as a measurement of every industrial company because they reflect one security vendor’s observations. They nevertheless point to an operational risk for environments where downtime interrupts production, logistics or equipment control.

Why a single security tool is not enough

An industrial environment combines office networks, remote access, contractors, servers and technology segments with different life cycles. Some equipment cannot be patched immediately, so protection needs layers: segmentation, least privilege, multi-factor authentication, controlled remote access, centralised logging and a rehearsed response plan.

Copies of critical configurations and data should be isolated from the main administrative domain. Our guide to backup and fault tolerance explains how to define RPO and RTO and test recovery.

A practical review checklist

  1. Maintain a current map of office, server and industrial network connections.
  2. Close unused remote-access paths and contractor accounts.
  3. Apply available patches or compensating controls to legacy nodes.
  4. Collect security events in a central monitoring system.
  5. Test the restoration of configurations and data.
  6. Assign incident owners and backup communication channels.

Regulated information systems also need controls mapped to their threat model and applicable requirements. Our overview of FSTEC and data protection explains the contractor and documentation checks.

Takeaway

Rising industrial attacks are a reason to review the complete chain rather than purchase one more isolated product: network boundaries, access, logging, recoverability and team readiness. A useful starting point is an inventory of critical services and the failure scenario each service must survive.

Source: Kaspersky’s 7 July 2026 announcement.

Primary source: Kaspersky: cyberattacks on Russian industry in the first half of 2026

SecurityIndustryInfrastructure

Read also