Group Purchasing
Group Purchasing

2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future

2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future (PDF, 3.84MB)Published: 03 Mar, 2025
Created by:
Dean Parsons
Dean Parsons

The 2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future survey, published by SANS Institute in March 2025, measured how organizations allocate budget, prioritize controls, and staff their industrial control system (ICS) and operational technology (OT) cybersecurity programs. Written by Dean Parsons, the survey drew on responses from more than 180 professionals working in IT, ICS, SCADA, OT, process control, distributed control, and building automation fields across multiple critical infrastructure sectors worldwide.

Key findings:

  • 58% of respondents identified IT compromises spreading into OT/IT networks as the leading initial attack vector for ICS/OT incidents
  • Only 9% of professionals dedicate 100% of their time to ICS/OT security, despite these systems underpinning critical infrastructure
  • 27% of organizations reported experiencing one or more security incidents involving ICS/OT systems in the past year
  • 55% of respondents reported ICS/OT cybersecurity budget growth over the last two years, but 34% were unsure of their organization's overall security budget allocation
  • Only 27% of budget decisions are led by CISOs or CSOs, even though 65% of respondents view OT cybersecurity as a primary responsibility
  • 37% of organizations share ICS/OT budget control between IT and OT, while 31% have IT controlling the budget and 26% have OT controlling it
  • Only 9% of organizations allocate more than 75% of their security budget to ICS/OT, while 41% allocate just 0–25%
  • 33% of attacks stemmed from internet-accessible devices and 27% from transient devices such as vendor laptops
  • Removable media and transient device security ranks only 4th among prioritized ICS/OT controls, despite 27% of attacks originating from this vector
  • The U.S. (40%) and Europe (38%) allocate 26–50% of their cybersecurity budgets to ICS/OT, while Latin America and the Middle East show the highest concentrations of organizations spending only 0–10%
  • Organizational requirements rank as the top current driver of ICS/OT control implementation, but the evolving threat landscape is expected to become the top driver over the next 12 months
  • ICS/OT defensible network architecture ranks as the #1 prioritized control investment area, followed by ICS-specific incident response

The survey reveals a persistent gap between recognition and resourcing: most organizations acknowledge ICS/OT cybersecurity as important and are increasing budgets, yet relatively few dedicate full-time staff or majority-share budgets to it. Applying generalized IT security controls directly to ICS/OT environments risks false positives and operational disruption, reinforcing the case for engineering-informed, ICS-specific strategies rather than IT-led approaches. Respondents were drawn from more than 180 professionals, concentrated in energy, information technology, government, and other critical infrastructure sectors, spanning organization sizes from under 1,000 to more than 50,000 employees, with the most common roles being ICS/OT cybersecurity manager, security manager or director, security administrator/analyst, and IT manager or director.

FAQ

Meet Your Author

Dean Parsons
Dean Parsons

Dean Parsons

Principal Instructor

Dean Parsons, CEO of ICS Defense Force, teaches ICS515 and co-authors ICS418, emphasizing ICS-specific detection, incident response, and security programs that support OT operations—aligning practitioners and leaders on clear, defensible action.

Read more about Dean Parsons