IoT and OT Security Gaps Create New Risks for MSPs

Quest Technology says MSPs should assess IoT and OT risks, secure legacy devices, and guide customers beyond traditional network defenses as threats grow.

Aug 21, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Industrial ransomware incidents surged in late 2025, increasing pressure on managed service providers to address the operational technology and Internet of Things systems that keep their customers’ physical operations running.

Dragos tracked 1,211 ransomware incidents affecting industrial organizations worldwide during the fourth quarter, up from 742 in the previous quarter. Manufacturing accounted for 819 incidents, or nearly 70% of the total.

For Adam Burke, vice president of sales and partnerships at Quest Technology Management, these attacks carry consequences that extend beyond inaccessible applications or lost data.

“That’s the real world,” Burke told Channel Insider. “That’s where you go beyond the application, and you get to the actual deliverable assets, whether it’s production, manufacturing, power, water.”

Ransomware raises the stakes for operational environments

The threat is becoming increasingly difficult for industrial organizations to ignore.

Dragos tracked 1,211 ransomware incidents affecting industrial entities worldwide during the fourth quarter of 2025, up from 742 in the previous quarter. Manufacturing accounted for 819 incidents, or nearly 70% of the quarter’s total.

Federal agencies have similarly warned about the exposure of operational systems. In guidance issued by CISA, the FBI, EPA, and Department of Energy, agencies said they were aware of cyber incidents affecting U.S. critical infrastructure OT and industrial control systems and urged operators to remove OT connections from the public internet where possible.

For MSPs, Burke said the changing environment requires moving beyond assumptions that segmentation alone will keep operational assets protected.

“The way that you used to set up DMZs between IT and operational IT and maybe hope that no one was going to penetrate that barrier is just not the way threats are coming in anymore,” Burke said, pointing to supply-chain exposure and potentially compromised devices as additional risks.

Legacy devices create persistent security gaps

Advertisement

The challenge is particularly pronounced when organizations rely on older or resource-constrained equipment that cannot support traditional endpoint security tools.

That issue helped drive Quest’s partnership with Crytica Security, which brought Crytica’s IoT and OT security technology into Quest’s managed security portfolio. 

Crytica uses a lightweight endpoint probe designed for resource-constrained environments and to detect abnormal activity without the computing requirements of conventional endpoint protection.

Burke said those capabilities can be important in environments such as healthcare, where legacy systems may perform critical functions while remaining unpatched or unable to support conventional antivirus and detection tools.

MSPs should begin with visibility and risk assessment

Still, Burke cautioned MSPs against treating every security problem as a reason to add another product.

His recommended starting point is an assessment of the customer’s existing vulnerabilities and capabilities, including security investments that may be underused.

“You first have to know where you are in the battlefield,” Burke said. “Understanding where you are from a vulnerability standpoint and from a capability standpoint is the first and foremost, paramount thing you’ve got to do.”

That assessment can also create an opportunity for MSPs to lead broader risk conversations. Rather than immediately recommending a rip-and-replace strategy, Burke said providers should help customers document vulnerabilities, evaluate existing controls and discuss remediation options without beginning from a vendor-specific answer.

Ultimately, he wants OT security to become a more accessible business conversation.

“Everybody’s going to have to deal with it eventually,” Burke said, adding that he hopes to see security leaders widen the conversation to peers across the organization to enable everyone to understand the implications.

From there, Burke added, understanding risk becomes easier, and moving towards remediation can often go faster.

Earlier this year, we spoke with Quest Technology CEO Tim Burke about the risks posed by integrations following a merger or acquisition. Revisit that story for another perspective on security needs impacting MSPs and their customers.

Victoria Durgin

Victoria Durgin is a technology communications professional and editorial leader specializing in channel technology, cloud marketplaces, managed service providers (MSPs), technology distribution, and partner ecosystems. As Managing Editor of Channel Insider, she oversees editorial strategy and content development focused on helping technology vendors, solution providers, and channel partners navigate an evolving IT landscape. With nearly a decade of experience spanning technology journalism, corporate communications, content strategy, and digital publishing, Victoria has developed deep expertise in the business side of technology. Her work includes creating executive thought leadership content, industry analysis, case studies, and channel-focused reporting that helps organizations better understand market trends, partner relationships, and technology buying decisions. Before leading Channel Insider, Victoria built experience across local journalism, business reporting, social media communications, and corporate marketing. She has worked closely with technology vendors, cloud providers, and managed service organizations to develop content that highlights industry innovation, business growth strategies, and successful channel partnerships. Her portfolio includes case studies featuring mid-sized MSPs across the United States, Canada, and Australia. Victoria's work has appeared in Channel Insider, The Valley Ledger, and Medium. She holds a Bachelor of Arts in Communications and Environmental Studies from Susquehanna University. Through her reporting and editorial leadership, she helps technology professionals stay informed about the trends, challenges, and opportunities shaping the global IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.