October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
critical infrastructure

ICS/OT Security Budgets Are Growing, but Critical Infrastructure Defenses Still Have Gaps

SANS survey data shows rising ICS/OT security budgets alongside gaps in dedicated funding, staffing, visibility and response readiness.

By TheFinanceBase Team 5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ICS/OT cybersecurity budgets are increasing at many organizations, but the growth does not mean operational technology is adequately funded. In a March 2025 SANS Institute survey of more than 180 practitioners, 55% said their ICS/OT security budget had grown over the prior two years. At the same time, 41% said ICS/OT received just 0–25% of their security budget, and only 9% said it received more than 75%. Those respondent-reported figures point to a gap between rising investment and the share of security resources devoted to systems that operate physical processes.

What the budget survey says about spending

The SANS Institute’s 2025 ICS/OT Cybersecurity Budget survey, authored by SANS Principal Instructor Dean Parsons and based on responses from more than 180 professionals working across IT, ICS, SCADA, OT, process control, distributed control and building automation, describes reported trends—not audited spending across all companies. It does not establish an average dollar amount for an ICS/OT security budget.

Survey measure Respondent-reported result
Budget direction over the prior two years 55% reported growth
Share of security budget allocated to ICS/OT 41% allocated 0–25%; 9% allocated more than 75%
Professionals spending all of their time on ICS/OT security 9%

These measures answer different questions. A budget can rise in dollars while remaining a small fraction of an organization’s overall security spending, and a larger allocation does not by itself show whether controls are effective. The survey’s figures support the conclusion that growth is occurring alongside a limited dedicated share of budget and staff time; they do not measure a universal funding shortfall or prove that each respondent’s program is insufficient.

Why increased spending can leave important gaps

ICS/OT environments connect cybersecurity to physical operations. A security failure can affect continuity, safety, environmental outcomes and public trust, while a control that disrupts a process can also carry operational consequences. SANS cautions that “Applying generalized IT security controls directly to ICS/OT environments risks false positives and operational disruption.”

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The leading reported initial attack path illustrates why OT security cannot be assessed as an isolated OT line item: 58% of respondents identified IT compromises spreading into OT/IT networks as an attack vector. Internet-accessible devices were identified by 33%, and transient devices by 27%. These are respondents’ reported attack-vector observations, not probabilities that any particular organization will be breached.

SANS frames the operating reality as: “In an ICS organization, the ICS is the business.” That means security plans and budgets need to account for the engineering and operational context of the systems they protect, not just apply IT controls by default.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

Who controls the OT security budget?

The SANS budget survey found that responsibility is distributed across security, IT and OT functions. Just 27% said CISOs or CSOs lead budget decisions; a larger share reported shared or operational/IT control.

Reported budget decision arrangement Share of respondents
Shared IT/OT control 37%
IT control 31%
OT control 26%
CISO/CSO-led decisions 27%

These percentages describe separate survey responses about governance categories and should not be treated as mutually exclusive portions of a single 100% total. The practical issue is accountability: when budgets and responsibilities are split, organizations need a clear process for deciding who funds cross-domain controls, approves operational changes and owns incident response. SANS recommends engineering-informed controls, with engineering teams leading collaboration and IT teams supporting them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which ICS/OT controls should receive priority?

In the budget report, SANS ranks ICS/OT defensible network architecture as the top prioritized control investment, followed by ICS-specific incident response and architectures that support network visibility. The ranking is a prioritization signal, not a one-size-fits-all sequence: organizations should account for their processes, existing safeguards and operational constraints.

A separate SANS State of ICS/OT Security survey page describes the controls organizations deployed or planned: asset visibility, threat detection and secure remote access were prominent in 2025 deployments and 2026–2027 planned investments. The two sources together suggest evaluating a budget against the defensive capabilities it buys, rather than treating budget growth alone as proof of coverage.

  • Defensible network architecture: prioritize segmentation and architecture that limit unwanted pathways between IT and OT, while preserving required operations.
  • ICS-specific incident response: fund response plans and procedures suited to industrial processes, including coordination between engineering, OT and IT teams.
  • Network and asset visibility: establish what is connected and support monitoring that can identify relevant activity without creating unacceptable operational disruption.
  • Secure remote access: assess how employees, vendors and transient devices connect to OT, and fund controls appropriate to those pathways.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Visibility, detection and cloud monitoring remain uneven

The separate 2025 SANS State of ICS/OT Security survey had 330 respondents. On that survey page, 49% reported having ICS/OT-specific detection; among that group, 26% rated it highly effective. The distinction matters: having a detection capability is not the same as judging it effective.

The same survey page reports that 83% of organizations had some cloud-connected footprint, while 13% had fully integrated cloud monitoring. The figures indicate a potential visibility gap in environments that connect cloud services and operational systems, but they do not establish that every cloud-connected footprint carries the same level of risk.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Incidents and response readiness are separate measures

In the budget survey, 27% of respondents reported one or more ICS/OT security incidents in the prior year. The separate 2025 State of ICS/OT Security survey reported 22% with an incident. These figures come from different SANS surveys and respondent populations, so they should not be combined or read as a year-over-year trend.

Preparedness measures in the separate State survey also show that incident experience and response readiness are not interchangeable: 13% reported full ICS Cyber Kill Chain visibility and 14% felt fully prepared. The budget survey found that 39% tested their incident-response plan annually. Annual testing is one indicator of readiness, but the survey does not establish the quality or scope of each test.

How to judge whether an increase is closing the gap

For an organization reviewing its own program, the useful question is not simply whether spending rose. Compare the allocation and capabilities against operational exposure and ownership:

  • Track budget growth separately from the share allocated to ICS/OT.
  • Identify who controls the budget and who is accountable for decisions spanning IT and OT.
  • Review exposure through IT-to-OT pathways, internet-accessible devices and transient devices.
  • Check whether staffing gives ICS/OT security sufficient dedicated attention.
  • Map spending to architecture, ICS-specific incident response, asset and network visibility, detection and secure remote access.
  • Assess cloud-connected coverage and whether monitoring is integrated where needed.
  • Review incident history and whether the response plan is tested at least annually.

These checks do not prescribe a universal budget share. They help distinguish an increase in funding from an increase in operationally appropriate protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.