The SANS ICS/OT Cybersecurity Survey: 2023's Challenges and Tomorrow's Defenses, published by SANS Institute in September 2023, examined how industrial control system and operational technology facilities are defending against a changing threat landscape. The survey drew more than 700 responses from professionals across more than 60 industrial subcategories, including energy, chemical, critical manufacturing, nuclear, and water management, and mapped its findings to the SANS Five ICS Cybersecurity Critical Controls.
Key findings:
- When an ICS incident occurs, only 25% of organizations would consult their own internal ICS-specific security team, ranking it eighth among response resources behind cybersecurity solution providers (43%) and internal resources generally (38%)
- The most widely used source of ICS threat intelligence is publicly available threat intel (61%), even though it is often the least timely and accurate
- Just 52% of organizations have a dedicated ICS/OT incident response plan, and 17% are unsure whether they have one at all
- Organizations with no dedicated budget for ICS/OT security nearly tripled year over year, jumping from 8% in 2022 to 22% in 2023
- 38% of respondents now handle both ICS and IT security in their role, up sharply from just 20% in 2022
- Facilities report high confidence (around 80%) that their ICS networks are segregated from IT and the internet, yet only 25% are actually collecting and correlating remote access logs to verify it
- Fewer than 30% of facilities pre-test and apply vendor-validated patches on a defined schedule, and only 15% apply patches during routine maintenance windows
- 44% of respondents now rate current threats to ICS as "high," continuing a steady climb from 38% in 2019, 40% in 2021, and 41% in 2022
- Compromise in IT systems that allowed threats to pivot into OT/IT networks is the top initial attack vector reported (38%), ahead of engineering workstation compromise (30%)
- 45% of organizations are leveraging the MITRE ATT&CK ICS framework, and 57% of those use it to complete a formal attack-technique coverage assessment
- The top three ICS/OT certifications held by respondents are GICSP (47%), GRID (28%), and GCIP (22%)
- 56% of organizations have an exercised, documented plan to run ICS engineering systems in a reduced or manual capacity during a cyber incident
The survey's throughline is a gap between confidence and verification. Facilities report strong belief that their networks are segmented and defended, but the data on remote access logging, patch cadence, and incident response planning suggests that confidence often outpaces actual practice. The steady year-over-year rise in perceived threat severity, paired with a sharp jump in organizations with zero ICS/OT security budget, points to security teams being asked to do more with fewer resources at exactly the moment risk is increasing.
Respondents worked across a wide range of industrial verticals, led by energy, information technology, and government, with electricity, oil and gas, and equipment manufacturing among the most common subcategories. The top roles represented were security administrator/security analyst, security manager or director, and ICS/OT cybersecurity analyst.