Gen. partnerAlgotech

SCADA Security 2026: Cyberattacks are no longer just an IT problem. They impact the real world

The one-day professional conference focused on the security of industrial control systems (ICS/OT) offered not only a technological perspective but also a broader context: from legislation through crisis management to the real-world impacts of cyber incidents.

|
April 5, 2026

The one-day professional conference focused on the security of industrial control systems (ICS/OT) offered not only a technological perspective but also a broader context: from legislation through crisis management to the real-world impacts of cyber incidents.

"We see an increase in attacks and their impacts"

At the very start of the conference a strong appeal came from the director of Národního úřadu pro kybernetickou a informační bezpečnost, Lukáše Kintra.

"We see a continuous increase in the number of cyberattacks and incidents, but above all in their impacts."

Kintr pointed out that cybercrime today, according to some studies, reaches an economic volume that would rank it among the largest "economies of the world." He also pointed to a fundamental problem:

"We see how difficult it is for many institutions to cope with such attacks."

According to him, not only technology plays a crucial role, but above all the organizations' approach — the willingness to implement rules, to cooperate and to be proactive.

NIS2, strategy... and the reality of implementation

According to Kintr, the Czech Republic ranks among the better-prepared states in the European context — partly thanks to the implementation of the NIS2 directive.

But the key problem is not the legislation itself, but its implementation in practice:

"It's all about implementing those new rules. And about our willingness to deal with them."

The new national cybersecurity strategy stands on three pillars: protection of critical infrastructure, development of societal preparedness, and international cooperation.

Without an active approach from organizations, however, it will remain only on paper, according to him.

OT infrastructure: old technologies, new threats

One of the main topics of the conference was the security of industrial systems (OT), which today face a completely new type of threat.

As Jan Václavík from Fortinet explains in an interview for CZECH CYBER TV:

"Today the entire industry is controlled by software... all technologies are connected to the network or to the cloud."

This fundamentally changes the security situation. While industrial systems used to be isolated, they are nowadays often directly accessible from the IT environment — and thus to attackers.

Their longevity is also a big problem:

"A PLC device can operate for 20 or 30 years... but the firmware is often not updated."

The result is systems that contain known vulnerabilities, are insufficiently monitored, and at the same time control physical processes.

And that is precisely the crucial difference compared to classic IT:

"These systems interact with the physical world — they can cause damage to property, health and lives."

Security doesn't start in software, but at the cable

An interesting perspective was also brought by a second interview at the conference, which highlighted the often overlooked layer — the physical infrastructure.

As was said:

"Security is not just about IT — it is also about the passive network infrastructure."

Modern approaches today allow monitoring the physical network connections in real time, detecting unauthorized manipulations and responding to incidents directly at the physical layer.

For example using RFID tagging of cabling or intelligent patch management.

The biggest risk? A false sense of security

A strong theme throughout the conference was the gap between "paper security" and the real preparedness of organizations.

The panel discussion agreed on one thing:

a secured infrastructure does not automatically mean a prepared organization

What matters is the ability to respond in a crisis, clearly defined processes, and people's readiness.

It is the human factor and decision-making under pressure that remain the weakest link.

AI, regulation and new obligations

The afternoon session focused on regulation and the new challenges brought by the NIS2 directive, the AI Act, and the growing use of artificial intelligence.

It was said that the biggest risk today is not AI itself, but its uncontrolled deployment without a clear governance model.

Cybersecurity as a shared responsibility

One common message ran through the entire conference: security is not just a technical problem.

"None of us will succeed without the other."

Without information sharing, cooperation between the state and the private sector, and an active approach by organizations, it will not be possible to face the growing threats.

Bonus for subscribers

In CCTV+ you can find the complete recording of the lecture: "Events and trends in cyberspace in 2026"

Treat yourself. Try CZECH CYBER TV for just 125 CZK per month

Already a subscriber?

Sign in
  • •CZECH CYBER TV subscription from 125 CZK per month with annual payment.
  • •You save 75 CZK per month.
  • •You can cancel the automatic renewal at any time.
Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.