Security1 distinct publisher3 min readPublished
Kaspersky's Q2 2026 industrial telemetry puts the global figure at 19.15%, with Africa at 27.9%, Northern Europe at 8.1%, and the biometrics sector worse than every region but one.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The 2.0 percentage points East Asia added over the quarter [3] are not explained by the one category the report singles out in that region. Malicious scripts and phishing pages rose 0.93pp there, to 4.86% [12], which leaves a little under half the regional move sitting in other categories [5]. That arithmetic is deliberately loose: the metric counts ICS computers on which something was blocked, and a single machine can land in several categories, so the parts never sum to the whole. What it does rule out is a reading in which East Asia had a phishing quarter and nothing else, which matches Kaspersky's own note that every threat type except miners rose in the region [4].
Growth rankings and level rankings are also answering different questions. East Asia led the growth tables for scripts and phishing, spyware, viruses and internet-borne threats [4], yet its 4.86% script rate still sits 0.56pp below the 5.42% global average for that category [3]. A region can top the movement charts and remain a below-average place to own an OT asset.
Biometrics is the opposite case: a sector with a level problem. At 26.44% [5] it stands 7.29pp above the global figure [2] and within 1.46pp of Africa, the worst-scoring region in the dataset [8]. It also leads the industry tables for malicious scripts and phishing pages, malicious documents, spyware, ransomware and worms, and it is the only surveyed industry where the email figure exceeds the internet figure [7]. Kaspersky attributes that profile to internet-connected devices, heavy email use for data exchange and approvals such as access granting, and minimal cybersecurity controls at the organisations running the systems [6]. The inverted email-to-web ratio is the part with a budget attached, because it points at the approvals mailbox rather than the browser. Regional and sector effects compound: in East Asia the biometrics script rate reached 9.01%, roughly 1.85 times the regional average for that category [13][4].
Denylisted internet resources are the category to watch structurally. They have risen for two consecutive quarters to 4.31% globally, moving from third place to second and displacing spyware, and they increased in every region [14]. Russia leads at 5.17%, 0.86pp above the global figure [15][6], and inside Russia the concentration is in electric power at 6.61% and in engineering and ICS integration at 5.62% [16]. Those are outbound connections from engineering workstations, not inbound intrusions.
The report states that the global average is falling across all selected industries [8] without offering a cause, so the decline supports no inference about attacker effort. It also coexists with increases in denylisted resources, malicious documents, worms, ransomware and AutoCAD malware [10], and with 10,904 distinct malware families blocked on industrial systems in the quarter [9]. Malicious documents had declined for three straight quarters to a three-year low before turning back up to 1.77% [17], with South America adding 1.35pp to reach 3.56%, its fourth-highest figure in three years [17][18]. The gap between Africa and Northern Europe is 19.8pp, or a factor of about 3.4 [1], which is wider than the global number itself would suggest is possible.
Ranked by verification strength, evidence, and original report placement.
In Q2 2026 the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022.
Regionally the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa.
The figures increased in five regions over the quarter, most notably in East Asia (by 2.0 pp) and Africa (by 0.5 pp).
East Asia saw increases for all threats except miners, and ranked first in growth for malicious scripts and phishing pages, spyware, viruses and threats from the internet; the percentage for blocked email threats also increased.
The biometrics sector, at 26.44%, has traditionally led the rankings of industries and OT infrastructures surveyed in the report.
Biometric systems are characterised by internet access, extensive email use for data exchange and approvals such as access granting, and in many cases minimal cybersecurity controls within the organisations that use them.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary vendor telemetry, granular but unreplicated and methodology-free
The cluster rests on one first-party dataset that is unusually granular and internally consistent: quarter-on-quarter movements, regional ranges, category rankings and industry breakdowns are all stated with figures, and the derived comparisons in the ledger reconcile exactly against the reported numbers. It is nonetheless a single source with no disclosed denominators, sensor counts or sampling method, no third-party replication, and detections rather than confirmed incidents, which caps evidential strength well short of high.
No deployment or installed-base data disclosed
The only adoption-adjacent fact in the cluster is that Kaspersky published telemetry gathered from its own products. The report gives no number of protected ICS computers, sensors, customers or regions covered, and reports no deployments, procurement decisions or operator responses, so there is nothing to measure adoption against without inventing a denominator.
Mildly overstated: precise percentages without a disclosed denominator
The publisher's language is dry and descriptive, and every headline number is tied to its own dataset, so there is no promotional overreach. The modest positive gap reflects that two-decimal precision on global, regional and industry shares implies measurement authority the report does not substantiate - no denominators, sample sizes or methodology - and that the biometrics exposure narrative is presented as explanation while resting on qualitative assertion. Reading the fall to 19.15% as improving ICS security also outruns the evidence, since the metric tracks blocks on one vendor's protected estate.
Vendor measuring its own market
The measuring party sells industrial and endpoint security, the data comes from its own installed products, and the report's structure - rising categories, exposed regions, under-controlled sectors such as biometrics and building automation - maps onto the products it sells. That is a material alignment between the publisher's commercial interest and the framing of the findings, and no conflict disclosure or independent audit accompanies it. The score is not higher because the report also documents a declining aggregate threat rate, which cuts against a purely alarmist incentive.
Moderate: figures are clear, their generalizability is not
Confidence in what the report says is high - the numbers are explicit, internally consistent, and the derived comparisons check out. Confidence in what they mean for the wider ICS population is limited by single-vendor sourcing, absent methodology and denominators, no adoption or incident data, and no external corroboration, so the assessment settles just above the midpoint.
security
CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering1 distinct publisher
security
Tortoiseshell's 'uk1' and 'uk2': Iranian espionage crew now has servers in Britain3 distinct publishers
security
Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing1 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026