Mining cybersecurity shifts beyond IT systems

Mining cybersecurity shifts beyond IT systems

Estimated reading time: 5 minutes · Last updated:

Mining operators now face cyber risk that extends beyond corporate IT into operational technology and communications. The Mining and Metals Information Sharing and Analysis Centre recorded 30 reported incidents in 2024, up from 10 in 2023, and MM-ISAC leadership says many attacks go unreported. At the same time, a coalition of more than 100 technology companies and vendors, including CrowdStrike and WSO2, is pressing for stronger defences against AI-enabled attacks and for tools that let organisations keep models and agents under their control.

And those are just the ones we know about,

Rob Labbe, CEO and CISO in Residence, MM-ISAC

Key takeaways

  • Incident trend: MM-ISAC documented 30 reported cyber incidents in the global mining and metals sector in 2024, up from 10 in 2023.
  • Industry call to action: A coalition of more than 100 companies including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet urged governments and organisations to strengthen defences against AI-enabled attacks.
  • Vendor signals: CrowdStrike reported US$1.47 billion revenue for the quarter ended 31 July 2026 and raised its fiscal 2027 outlook as demand for AI security accelerated.
  • Control over AI: WSO2 launched a fully self-managed version of its AI Workspace and ManageEngine found 77% of Mexican organisations fear data leaks from unauthorised generative AI.

Why mines are becoming operational cyber targets

Modern mines depend on digital links that reach from control rooms to remote sites. Fibre-optic backbones, satellite connections and automated control systems now carry the signals that keep crushers, conveyors and processing plants running; that widening attack surface places operational technology — OT — in the line of fire, not only office networks.

The Mining and Metals Information Sharing and Analysis Centre recorded a sharp rise in reported incidents: 30 in 2024 versus 10 in 2023, a change MM-ISAC highlights as partly visible only because of reporting. Rob Labbe, CEO and CISO in Residence at MM-ISAC, said, "And those are just the ones we know about," underscoring the organisation's view that many events remain hidden.

That combination of increasing connectivity and limited visibility raises a particular risk for miners because disruptions on OT can stop production, damage equipment or create safety hazards. The shift from geological and physical hazards to attacks arriving over cables and space links means cyber risk now maps directly to operational continuity and worker safety.

How AI and vendors are reshaping defensive choices

Security vendors and large technology firms are signalling two linked trends: more investment in AI-purpose security, and demand for self-managed tools that keep models and data within an organisation's control. A coalition of more than 100 companies urged governments and organisations to address weaknesses before AI-capable systems expand the scale and sophistication of attacks.

CrowdStrike's latest quarter illustrates rising enterprise spending on AI security: the company reported US$1.47 billion in revenue for the quarter ended 31 July 2026, a 26% increase from US$1.17 billion a year earlier, while annual recurring revenue reached US$5.84 billion and net new ARR was US$333 million. Those figures are the clearest commercial signal in the public record that customers are prioritising AI-enabled defence capabilities.

At the same time WSO2 released a fully self-managed version of its AI Workspace inside the WSO2 API Platform so regulated firms can operate models, agents, access controls and costs on their own infrastructure. That release sits alongside a ManageEngine study showing 77% of Mexican organisations fear data leaks tied to unauthorised generative AI, a concern that pushes regulated operators toward on‑premises control.

What operators and policy makers now face

Mining companies must treat cyber risk as an operational priority rather than an IT-only problem. Where control systems, remote telemetry and vendor-supplied agents interface with production, security decisions affect uptime and safety; the materials and vendors now cited in public reporting point to integration of AI-aware controls and tighter model governance as likely responses.

Policy makers and regulators are also in scope because the coalition singled out essential services at risk — hospitals, water treatment facilities and the infrastructure that supports the internet — and asked for broader action to strengthen defences. That call implies a role for standards and guidance covering AI-enabled threats, incident reporting and minimum OT protections.

Exactly how miners respond will vary by region and by the plant’s technology stack, but the public signals are clear: vendors will offer both cloud and self‑managed options, operators will need to inventory OT links and vendor agents, and governance over AI models and data flows will be a procurement and compliance issue for many firms.

Named actors, their role and the finding or product cited
Entity Type Figure or date Note
MM-ISAC Information sharing body 30 reported incidents in 2024 Recorded mining and metals incidents rising from 10 in 2023 to 30 in 2024
Coalition of technology companies Industry group more than 100 companies Open letter urging stronger defences against AI-enabled attacks
CrowdStrike Security vendor US$1.47 billion revenue (quarter ended 31 July 2026) Raised fiscal 2027 outlook; ARR US$5.84 billion; net new ARR US$333 million
WSO2 / ManageEngine Vendor / study WSO2 launch; 77% (ManageEngine) WSO2 released self-managed AI Workspace; ManageEngine found 77% fear data leaks from unauthorised generative AI

Bull and bear cases for mining cybersecurity

The case for

  • CrowdStrike's quarterly results indicate rising enterprise budgets for AI-aware security tools, which could increase investment in OT protections across mining operations.
  • Self-managed AI platforms such as WSO2's release give regulated firms a technical route to keep models, agents and access policies inside their own infrastructure, reducing leak vectors noted by ManageEngine.

The case against

  • The coalition warns that AI-enabled attacks could expand the scale and sophistication of cyber threats, raising the bar for defenders and increasing the cost of adequate protection.
  • MM-ISAC's note on under-reporting — summed by Rob Labbe's comment that many incidents are unknown — suggests the sector's visible incident count may understate true risk, complicating prioritisation.

What to be careful about

  • Critical infrastructure exposure: the coalition specifically identified hospitals, water treatment facilities and internet-supporting infrastructure as at risk from scaled AI-enabled attacks.
  • Visibility gap: MM-ISAC leadership warns of 'massive under-reporting' which reduces the sector's ability to learn from incidents and allocate resources effectively.
  • Data leakage via unauthorised generative AI: ManageEngine found 77% of Mexican organisations fear leaks, a disclosure risk for operators handling reserves, contracts and employee data.

The bottom line

Public records now connect two developments: a rise in visible security incidents in mining and a vendor-driven market shift toward AI-aware defensive tools and self-managed platforms, as first reported by Mexico Business News. For miners the implication is stark: the security perimeter now covers remote links and the control plane, which requires the same inventory, governance and resilience practices applied to safety-critical plant systems. Operators should prioritise visibility, incident reporting and choices that keep sensitive models and data under effective control.

What to watch

  • Watch for any government or regulator response to the open letter from more than 100 technology companies; no date has been set.
  • Watch for MM-ISAC to publish follow-up bulletins or consolidated incident totals for the mining and metals sector; no date has been set.
  • Watch for vendors such as CrowdStrike and WSO2 to announce mining‑specific AI‑security or self‑managed offerings; no date has been set.

Frequently asked questions

How much did cyber incidents in mining change between 2023 and 2024?

MM-ISAC documented 30 reported incidents in 2024, up from 10 in 2023, a threefold increase in the visible incident count for the mining and metals sector.

Who is calling for action on AI-enabled cyberattacks?

A coalition of more than 100 companies, including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, published an open letter urging governments and organisations to strengthen defences.

What commercial signals show rising demand for AI security?

CrowdStrike reported US$1.47 billion revenue for the quarter ended 31 July 2026, a 26% year‑on‑year rise, with annual recurring revenue at US$5.84 billion and net new ARR of US$333 million, which the company links to accelerating enterprise demand for AI security.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

Hawaiʻi cybersecurity clinic offers a three-session Zoom series for sole proprietors and small businesses, funded by $1 million and Google's...
Darknavy Starlink hack: Darknavy says it gained administrative control of the latest Starlink terminals via hardware attack, per South China...
Mining cybersecurity now targets operational systems after MM-ISAC found 30 reported incidents in 2024; vendors and 100+ tech firms call...