SMARTFENSE’s own report on the human factor in industrial cybersecurity.
We analyzed +150 industrial and energy clients with over 100,000 users. What we observed about human behavior on the plant floor, and a five-layer framework to build a cybersecurity awareness program that’s genuinely OT-aware.
+150
industrial and energy clients analyzed across LATAM and Europe
9.9%
of industrial employees click a simulated phishing email on average
0 / +400
OT-themed simulations identified as a gap in the SMARTFENSE catalog, closed in May 2026
Verifiable proprietary data and an applicable operational framework. Not a summary of external reports.
Full behavior funnel facing a simulated phishing: opens, clicks, submits credentials, reports. Compared against the office-worker baseline.
The four vectors we actually see in simulations: integrator impersonation, regulator pressure, supply chain BEC, internal urgency.
Why a program designed for the office is not enough for the plant, and what changes when the operator becomes the first line of detection.
Five layers to design a program that works with the industrial sociotechnical system, not against it.
Five movements we expect to see in the sector: regulation, attacker playbooks, governance models, metrics and training.
How the proprietary data was built, what sample it covers, and which neutral external sources we triangulated against (Verizon DBIR, IBM, Dragos, ENISA).
For the roles that make the real decision on how to protect the people inside the plant.
Role 01
Designs the awareness program for the next 12 months and needs quantitative evidence to prioritize where to invest.
Role 02
Brings the human factor to the operational security table and needs quantitative arguments that speak the language of the plant.
Role 03
Understands that the operator is the first line of detection and wants to know which adapted metrics to require from the program.
Fill in the form and we’ll send the PDF to your inbox instantly. No spam, no automatic newsletter.
If you later want to receive future editions, you can subscribe explicitly from the delivery email.
Delivered instantly, together with the permanent shortlink to the report.
Want to discuss how to apply these findings to your industrial security program? Get in touch.