GlobeNewswire by notified

Three years and counting: How long critical vulnerabilities survive in industrial systems

29.9.2026 10:00:00 CEST | GlobeNewswire by notified | Press release

Share

Holm Security's Security Research team has found that the typical critical vulnerability in operational technology environments was disclosed more than three years ago, and it rarely sits alone.

STOCKHOLM, Sept. 29, 2026 (GLOBE NEWSWIRE) -- The typical critical vulnerability in operational technology (OT) environments was disclosed more than three years ago, and it rarely sits alone, according to new research released today by Holm Security's Security Research team.

Operational Technology (OT) has a reputation for being difficult to patch, but the scale of the resulting exposure is rarely measured. From what our Security Research team sees across industrial environments, the pattern is clear enough to put numbers to.

The typical critical vulnerability in industrial and SCADA environments has been publicly known for more than three years and is still unresolved. Industrial environments are also considerably more likely than others to carry active, ransomware-exploitable risk on their IT network at the same time.

None of this points to negligence. It reflects the reality of securing systems that can't simply be taken offline and patched. What it shows is how long known industrial risk persists in practice, and why visibility across both IT and OT has become essential.

The typical critical industrial vulnerability was disclosed more than three years ago

Across industrial environments, the typical open critical vulnerability is one whose underlying issue was first publicly disclosed more than three years ago. It's a vulnerability that has been publicly documented, with a fix or mitigation already available. In IT, a three-year-old unresolved critical vulnerability is unusual. In OT, it is the norm.

Detection isn't the obstacle. Production systems often can't be patched on demand, maintenance windows are infrequent, and vendor certification can dictate what can be changed and when. The result is a long tail of known, unaddressed critical risk sitting in environments that are frequently the most sensitive to disruption.

Industrial risk rarely sits alone

Industrial vulnerabilities don't exist in isolation. Where there are active industrial vulnerabilities, the great majority of those environments also carry an active critical or ransomware-exploitable vulnerability on the IT network at the same time. This suggests industrial environments are more likely to be managing serious exposure on both fronts at once.

Why it matters

Industrial risk and IT risk are not separate problems. Yet the two are still routinely managed by different teams, with different tools, on different schedules. Seeing industrial and IT risk through one system, prioritized against each other rather than in isolation, is what turns two partial views into a single picture of where an organization is exposed.

Holm Security assesses IT and OT environments through one platform, bringing exposure and vulnerability management to industrial risk alongside IT risk instead of treating them separately.

About Holm Security

Holm Security is a European leader in exposure and vulnerability management. Founded in 2015 in Stockholm, Holm Security helps more than 1,500 organizations across the public and private sectors see their risk clearly, prioritize what matters, and prove that it is going down. Its Next-Gen Vulnerability Management Platform finds, prioritizes, and helps remediate vulnerabilities across systems and networks, cloud, web applications, APIs, and users, spanning both IT and Operational Technology (OT). Learn more at holmsecurity.com.


Media contacts marketing@holmsecurity.com

Subscribe to releases from GlobeNewswire by notified

Subscribe to all the latest releases from GlobeNewswire by notified by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from GlobeNewswire by notified

Iveco Group signs a 150 million euro term loan facility with Cassa Depositi e Prestiti to support investments in research, development and innovation11.6.2024 12:00:00 CEST | Press release

Turin, 11th June 2024. Iveco Group N.V. (EXM: IVG), a global automotive leader active in the Commercial & Specialty Vehicles, Powertrain and related Financial Services arenas, has successfully signed a term loan facility of 150 million euros with Cassa Depositi e Prestiti (CDP), for the creation of new projects in Italy dedicated to research, development and innovation. In detail, through the resources made available by CDP, Iveco Group will develop innovative technologies and architectures in the field of electric propulsion and further develop solutions for autonomous driving, digitalisation and vehicle connectivity aimed at increasing efficiency, safety, driving comfort and productivity. The financed investments, which will have a 5-year amortising profile, will be made by Iveco Group in Italy by the end of 2025. Iveco Group N.V. (EXM: IVG) is the home of unique people and brands that power your business and mission to advance a more sustainable society. The eight brands are each a

DSV, 1115 - SHARE BUYBACK IN DSV A/S11.6.2024 11:22:17 CEST | Press release

Company Announcement No. 1115 On 24 April 2024, we initiated a share buyback programme, as described in Company Announcement No. 1104. According to the programme, the company will in the period from 24 April 2024 until 23 July 2024 purchase own shares up to a maximum value of DKK 1,000 million, and no more than 1,700,000 shares, corresponding to 0.79% of the share capital at commencement of the programme. The programme has been implemented in accordance with Regulation No. 596/2014 of the European Parliament and Council of 16 April 2014 (“MAR”) (save for the rules on share buyback programmes set out in MAR article 5) and the Commission Delegated Regulation (EU) 2016/1052, also referred to as the Safe Harbour rules. Trading dayNumber of shares bought backAverage transaction priceAmount DKKAccumulated trading for days 1-25478,1001,023.01489,100,86026:3 June 20247,0001,050.597,354,13027:4 June 20245,0001,055.705,278,50028:6 June20243,0001,096.273,288,81029:7 June 20244,0001,106.174,424,68

Landsbankinn hf.: Offering of covered bonds11.6.2024 11:16:36 CEST | Press release

Landsbankinn will offer covered bonds for sale via auction held on Thursday 13 June at 15:00. An inflation-linked series, LBANK CBI 30, will be offered for sale. In connection with the auction, a covered bond exchange offering will take place, where holders of the inflation-linked series LBANK CBI 24 can sell the covered bonds in the series against covered bonds bought in the above-mentioned auction. The clean price of the bonds is predefined at 99,594. Expected settlement date is 20 June 2024. Covered bonds issued by Landsbankinn are rated A+ with stable outlook by S&P Global Ratings. Landsbankinn Capital Markets will manage the auction. For further information, please call +354 410 7330 or email verdbrefamidlun@landsbankinn.is.

Relay42 unlocks customer intelligence with a new insights and reporting module, powered by Amazon QuickSight11.6.2024 11:00:00 CEST | Press release

AMSTERDAM, June 11, 2024 (GLOBE NEWSWIRE) -- Relay42, a leading European Customer Data Platform (CDP), is leveraging Amazon QuickSight to power its new real-time customer intelligence, reporting, and dashboard module. Harnessing the breadth and quality of customer data, the new Insights module empowers marketing teams to dive deep into customer behaviors and gain invaluable insights into the performance of their marketing programs across all online, offline, paid, and owned marketing channels. Preview of the Relay42 Insights module, in pre-beta version Key capabilities of the Relay42 Insights module include: Deep insights into customer behaviors: With the Relay42 Insights module, marketers can ask unlimited questions about their data and gain a deeper understanding of how to serve their customers more effectively. Simplicity with AI-powered querying: Marketers can use artificial intelligence to query their data using natural language search, reducing the reliance on data scientists. Us

Metasphere Labs Announces X Spaces Event on the Topic of Green Bitcoin Mining and Sound Money for Sustainability11.6.2024 10:30:00 CEST | Press release

VANCOUVER, British Columbia, June 11, 2024 (GLOBE NEWSWIRE) -- Metasphere Labs Inc. (formerly Looking Glass Labs Ltd., "Metasphere Labs" or the "Company") (Cboe Canada: LABZ) (OTC: LABZF) (FRA: H1N) is thrilled to announce an engaging Twitter Spaces event on Green Bitcoin mining, energy markets, and sustainability on July 3, 2024 at 2 p.m. ET. Follow us on X at MetasphereLabs for updates and to join the event. What We'll Discuss Bitcoin Mining Basics: Understand the fundamentals of Bitcoin mining.Energy Market Dynamics: Explore how Bitcoin mining interacts with energy markets.Sustainable Innovations: Learn about our efforts to promote sustainability in Bitcoin mining.Sound Money: Discover how tamper-proof currency can enhance stability.Efficient Payment Rails: See how fast, neutral payment systems support humanitarian projects.Carbon Footprint: Compare Bitcoin's environmental impact with traditional banking. "We're excited to host this event and dive into the critical topics of Bitcoin

World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye