Mining Expands Cybersecurity Beyond IT Systems

Mining Expands Cybersecurity Beyond IT Systems

Estimated reading time: 5 minutes · Last updated:

Mining cybersecurity has moved from an IT cost centre to an operational imperative as digital controls now run shafts, processing plants and supply chains. As first reported by Mexico Business News, between 2023 and 2024 cyberattacks against the global mining and metals sector tripled, with the Mining and Metals Information Sharing and Analysis Centre (MM-ISAC) documenting 30 incidents in 2024. That spike has miners protecting operational technology (OT), satellite and fibre communications, and downstream partners, because a successful intrusion can halt production rather than just steal data. The primary trend is risk moving off corporate networks and into field systems and remote comms, forcing new governance, vendor controls and incident reporting.

And those are just the ones we know about,

Rob Labbe, CEO and CISO in Residence, MM-ISAC

Key takeaways

  • Incident surge: Between 2023 and 2024, cyberattacks on mining and metals tripled and MM-ISAC recorded 30 incidents in 2024.
  • Industry coalition: More than 100 technology companies, including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, called for stronger AI-related cyber defenses.
  • Vendor signals: CrowdStrike reported US$1.47 billion in revenue for the quarter ended July 31, 2026, and said enterprise demand for AI security helped lift results.
  • Operational control: WSO2 launched a fully self-managed AI Workspace so regulated organisations can control models, agents, access policies and costs.

Why mining’s digital shift makes cyber risk operational

Mines have long treated risk as geological; today the attack surface follows fibre, satellite links and programmable controllers. Modern extraction and processing rely on distributed sensors, remote telemetry and edge compute that tie directly into safety systems and production controls. An intrusion that manipulates an industrial controller can stop conveyors, flood a pit or disable ventilation — outcomes that cause immediate physical harm and lost output, not only data exposure.

The scale of that shift is visible in MM-ISAC’s figures: 30 reported incidents in 2024, up from 10 in 2023, a threefold increase. MM-ISAC’s chief public voice on the issue, Rob Labbe, warned that recorded incidents understate the problem and that many events go unreported. That under-reporting complicates threat analysis because defenders lack a complete view of attacker techniques against OT, remote comms and cloud-integrated control systems.

How vendors and governments are responding

The market reaction is twofold: security vendors are selling AI-enabled detection and preventive controls, while platform providers push options that keep sensitive workloads under customer control. CrowdStrike reported US$1.47 billion in revenue for the quarter ended July 31, 2026, with management saying AI-security demand was a growth driver across its Falcon platform. That demand signal is prompting larger security budgets and more procurement of endpoint and network telemetry tuned for industrial protocols.

At the same time, a coalition of more than 100 technology companies — including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet — issued a call to strengthen defenses against AI-enabled attacks, arguing that governments and organisations have a limited window to fix longstanding infrastructure weaknesses. Vendors such as WSO2 are responding with products aimed at regulated customers: WSO2 announced a fully self-managed AI Workspace that lets organisations control models, agents, access policies and costs from their own infrastructure.

Practical steps miners are taking and where gaps remain

Mining operators are shifting security governance to include OT owners, operations teams and third-party suppliers. Common measures are network segmentation between IT and OT, hardened satellite and fibre endpoints, inventory and isolation of field devices, and stricter access controls for remote agents. The ManageEngine study cited by vendors found that 77% of Mexican organisations fear data leaks from employees using unauthorised generative AI tools, which pushes firms to add model governance and data-loss prevention to supplier contracts.

Gaps persist in incident reporting, supply-chain vetting and recovery planning. Many mine operators still lack playbooks that tie cybersecurity incidents to production continuity and safety procedures, and not all telemetry is retained long enough for forensic work. The combination of under-reporting and dispersed control systems means attackers can dwell inside networks and test the boundaries between IT and OT before causing disruption.

Cases for and against faster operational cybersecurity adoption

The case for

  • Operational disruption risk forces capital discipline: lost production from an OT incident directly hits revenue, creating board-level pressure to fund security projects.
  • Vendor momentum and rising enterprise budgets — signalled by CrowdStrike’s US$1.47 billion quarterly revenue and raised outlook — lower procurement friction for industrial security tools.

The case against

  • Under-reporting of incidents, noted by MM-ISAC and its CEO/CISO-in-Residence Rob Labbe, obscures attacker tactics and reduces the value of shared threat intelligence.
  • Many mines run legacy controllers and bespoke integrations that are costly to replace, so patching and segmentation alone may not close the most consequential vulnerabilities.

What to be careful about

  • Compromise of OT systems could halt production and endanger personnel, not just expose data.
  • Reliance on third-party communications providers (satellite, fibre) creates single points of failure beyond operators’ control.
  • Under-reporting of incidents prevents industry-wide learning and delays effective mitigations.
  • Rapid adoption of AI tools without model governance increases the risk of data leakage and supply-chain exposure.

The bottom line

The shift of risk from corporate systems to operational controls requires miners to treat cybersecurity as part of production and safety management. MM-ISAC’s data — 30 reported incidents in 2024 and a threefold year-over-year rise — makes the case for boards to fund OT controls, hardened remote communications and stronger supplier governance. Vendors and coalitions are responding with AI-enabled detection and self-managed platforms, but under-reporting and legacy equipment mean the work will be incremental. Miners that prioritise segmentation, telemetry and model governance will reduce the window for attackers to cause physical or financial harm.

What to watch

  • Watch for MM-ISAC’s next public incident summary; no date has been set.
  • Watch for further vendor disclosures on AI security features and self-managed options; no date has been set.

Frequently asked questions

How fast did cyberattacks against mining rise?

According to the Mining and Metals Information Sharing and Analysis Centre (MM-ISAC), reported incidents in the mining and metals sector rose from 10 in 2023 to 30 in 2024, a threefold increase.

Which vendors are signalling increased demand for AI security?

CrowdStrike reported US$1.47 billion in revenue for the quarter ended July 31, 2026, and cited accelerating enterprise demand for AI security; WSO2 launched a fully self-managed AI Workspace for regulated customers.

What operational areas should miners prioritise?

Operators should prioritise network segmentation between IT and OT, hardened satellite and fibre endpoints, device inventory and isolation, and telemetry retention for forensics and recovery planning.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

Mining cybersecurity now extends beyond IT to OT, remote links and suppliers after attacks tripled in 2024; MM-ISAC recorded 30...
Hawaiʻi cybersecurity clinic offers a three-session Zoom series for sole proprietors and small businesses, funded by $1 million and Google's...
Darknavy Starlink hack: Darknavy says it gained administrative control of the latest Starlink terminals via hardware attack, per South China...