What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Yes—but the figure applies to a small share of respondents, not to the typical incident. In Ponemon Institute’s 2021 survey, 1% of respondents whose organizations confirmed an ICS/OT cybersecurity incident said its total cost exceeded $100 million. The survey’s modeled average was about $3 million per incident. Both figures are historical survey findings, not current estimates or predictions for every industrial company.
What the 2021 survey says about incident costs
Ponemon Institute’s 2021 report estimated an average total cost of $2,989,550 per ICS/OT cybersecurity incident. It calculated that estimate from $963,168 in detection, investigation, and remediation labor and $2,026,382 in fixed costs, which included equipment replacement, downtime, legal costs, and regulatory fines. The labor calculation assumed a six-person team. The report’s estimate is a modeled survey figure, not an audited universal average. Ponemon Institute’s November 2021 report was sponsored by Dragos.
SecurityWeek’s November 10, 2021 account of the survey said that, among respondents whose organizations confirmed an incident, 1% reported a total cost above $100 million and 2% reported costs from $10 million to $100 million. Those shares do not mean that 1% of all U.S. firms experienced a $100 million loss. They describe the answers of the incident-confirming respondents in this survey. SecurityWeek’s account is a secondary summary of the findings.
How long incidents took to address
Ponemon Institute’s 2021 survey put the average time to detect, investigate, and remediate an ICS/OT incident at 316 days:
| Incident stage | Average time reported in the 2021 survey |
|---|---|
| Detection | 170 days |
| Investigation | 66 days |
| Remediation | 80 days |
| Total | 316 days |
These are survey-reported timelines, not a forecast of how long a future incident will take. Long response periods can contribute to cost through ongoing operational disruption, but the survey does not establish that a particular delay caused a particular dollar loss.
#1 Best Overall
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
How common incidents and ransomware were among respondents
In Ponemon Institute’s 2021 survey, 63% of respondents said their organization had experienced an ICS/OT cybersecurity incident in the preceding two years. Separately, 29% said their organization had been hit by ransomware during that period. These are respondent-reported shares; they should not be treated as representative rates for all U.S. companies.
SecurityWeek’s account of the 2021 survey said more than half of respondents in the ransomware-hit group reported paying an average ransom above $500,000, and some reported payments above $2 million. These ransom figures are not the same as the survey’s total incident-cost estimate, which included other labor and fixed-cost categories.
What respondents said contributed to incidents
SecurityWeek reported that respondents identified negligent insiders, maintenance-related issues, and IT security incidents spilling into OT environments where network segmentation was poor among common causes. The findings do not identify one cause as responsible for every incident.
Recommended Free Tools
Ponemon Institute’s 2021 report also highlighted organizational differences that can complicate security work. Half of respondents cited cultural differences between IT and OT teams as a challenge; 44% cited technical differences, such as patch-management realities and industrial automation vendor requirements; and 43% cited unclear ownership of industrial cyber risk. The report described additional governance concerns, including limited senior-management understanding of OT risk, inadequate resources, gaps in cross-functional expertise, and unclear reporting and accountability.
Where respondents reported security gaps and capabilities
The report’s findings suggest that incident cost is only one part of the picture: respondents also reported challenges with coordination, visibility, and program maturity. In 2021, 35% said their IT and OT teams had a unified security strategy, while 39% said the teams worked cohesively toward mature security. Just 21% described their ICS/OT program as fully mature.
On visibility, 45% said their organization was effective at maintaining an inventory of devices attached to OT networks, and 46% said it was effective at gathering threat intelligence about ICS/OT. Respondents also reported using several safeguards:
Rank #4
| Reported capability | Share of respondents in the 2021 survey |
|---|---|
| Vulnerability assessments where appropriate | 57% |
| Managing USB devices and maintenance laptops in OT | 55% |
| OT-specific network detection | 52% |
| Physical locking or isolation of sensitive equipment where possible | 52% |
The report also discusses segmentation, asset and patch management, access management, and safety-system isolation. These figures describe reported capabilities; the study did not compare products or demonstrate that a specific control prevents incidents.
What the findings can—and cannot—tell a business
The report frames OT as programmable systems or devices that interact with the physical environment, or manage devices that do. Examples include industrial control systems, building management systems, safety control systems, and physical access controls. ICS covers systems such as SCADA and distributed control systems, as well as components like programmable logic controllers.
Ponemon Institute surveyed 603 U.S. IT, IT security, and OT security practitioners at C-level, manager, and director levels who were familiar with their organizations’ cybersecurity initiatives and ICS/OT security practices. Its executive summary described the need to overcome cultural and technical differences between IT and OT teams as a primary challenge to improving security. The results offer a snapshot of those practitioners’ reports in 2021; they do not prove causation, establish prevalence across all U.S. firms, or rank the effectiveness of safeguards. Since the report was sponsor-supported and dates from 2021, its figures should not be presented as current without newer evidence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




