Industrial ransomware incidents surged in late 2025, increasing pressure on managed service providers to address the operational technology and Internet of Things systems that keep their customers’ physical operations running.
Dragos tracked 1,211 ransomware incidents affecting industrial organizations worldwide during the fourth quarter, up from 742 in the previous quarter. Manufacturing accounted for 819 incidents, or nearly 70% of the total.
For Adam Burke, vice president of sales and partnerships at Quest Technology Management, these attacks carry consequences that extend beyond inaccessible applications or lost data.
“That’s the real world,” Burke told Channel Insider. “That’s where you go beyond the application, and you get to the actual deliverable assets, whether it’s production, manufacturing, power, water.”
Ransomware raises the stakes for operational environments
The threat is becoming increasingly difficult for industrial organizations to ignore.
Dragos tracked 1,211 ransomware incidents affecting industrial entities worldwide during the fourth quarter of 2025, up from 742 in the previous quarter. Manufacturing accounted for 819 incidents, or nearly 70% of the quarter’s total.
Federal agencies have similarly warned about the exposure of operational systems. In guidance issued by CISA, the FBI, EPA, and Department of Energy, agencies said they were aware of cyber incidents affecting U.S. critical infrastructure OT and industrial control systems and urged operators to remove OT connections from the public internet where possible.
For MSPs, Burke said the changing environment requires moving beyond assumptions that segmentation alone will keep operational assets protected.
“The way that you used to set up DMZs between IT and operational IT and maybe hope that no one was going to penetrate that barrier is just not the way threats are coming in anymore,” Burke said, pointing to supply-chain exposure and potentially compromised devices as additional risks.
Legacy devices create persistent security gaps
The challenge is particularly pronounced when organizations rely on older or resource-constrained equipment that cannot support traditional endpoint security tools.
That issue helped drive Quest’s partnership with Crytica Security, which brought Crytica’s IoT and OT security technology into Quest’s managed security portfolio.
Crytica uses a lightweight endpoint probe designed for resource-constrained environments and to detect abnormal activity without the computing requirements of conventional endpoint protection.
Burke said those capabilities can be important in environments such as healthcare, where legacy systems may perform critical functions while remaining unpatched or unable to support conventional antivirus and detection tools.
MSPs should begin with visibility and risk assessment
Still, Burke cautioned MSPs against treating every security problem as a reason to add another product.
His recommended starting point is an assessment of the customer’s existing vulnerabilities and capabilities, including security investments that may be underused.
“You first have to know where you are in the battlefield,” Burke said. “Understanding where you are from a vulnerability standpoint and from a capability standpoint is the first and foremost, paramount thing you’ve got to do.”
That assessment can also create an opportunity for MSPs to lead broader risk conversations. Rather than immediately recommending a rip-and-replace strategy, Burke said providers should help customers document vulnerabilities, evaluate existing controls and discuss remediation options without beginning from a vendor-specific answer.
Ultimately, he wants OT security to become a more accessible business conversation.
“Everybody’s going to have to deal with it eventually,” Burke said, adding that he hopes to see security leaders widen the conversation to peers across the organization to enable everyone to understand the implications.
From there, Burke added, understanding risk becomes easier, and moving towards remediation can often go faster.
Earlier this year, we spoke with Quest Technology CEO Tim Burke about the risks posed by integrations following a merger or acquisition. Revisit that story for another perspective on security needs impacting MSPs and their customers.





