ICS/OT cybersecurity budgets are increasing at many organizations, but the growth does not mean operational technology is adequately funded. In a March 2025 SANS Institute survey of more than 180 practitioners, 55% said their ICS/OT security budget had grown over the prior two years. At the same time, 41% said ICS/OT received just 0–25% of their security budget, and only 9% said it received more than 75%. Those respondent-reported figures point to a gap between rising investment and the share of security resources devoted to systems that operate physical processes.
What the budget survey says about spending
The SANS Institute’s 2025 ICS/OT Cybersecurity Budget survey, authored by SANS Principal Instructor Dean Parsons and based on responses from more than 180 professionals working across IT, ICS, SCADA, OT, process control, distributed control and building automation, describes reported trends—not audited spending across all companies. It does not establish an average dollar amount for an ICS/OT security budget.
| Survey measure | Respondent-reported result |
|---|---|
| Budget direction over the prior two years | 55% reported growth |
| Share of security budget allocated to ICS/OT | 41% allocated 0–25%; 9% allocated more than 75% |
| Professionals spending all of their time on ICS/OT security | 9% |
These measures answer different questions. A budget can rise in dollars while remaining a small fraction of an organization’s overall security spending, and a larger allocation does not by itself show whether controls are effective. The survey’s figures support the conclusion that growth is occurring alongside a limited dedicated share of budget and staff time; they do not measure a universal funding shortfall or prove that each respondent’s program is insufficient.
Why increased spending can leave important gaps
ICS/OT environments connect cybersecurity to physical operations. A security failure can affect continuity, safety, environmental outcomes and public trust, while a control that disrupts a process can also carry operational consequences. SANS cautions that “Applying generalized IT security controls directly to ICS/OT environments risks false positives and operational disruption.”
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The leading reported initial attack path illustrates why OT security cannot be assessed as an isolated OT line item: 58% of respondents identified IT compromises spreading into OT/IT networks as an attack vector. Internet-accessible devices were identified by 33%, and transient devices by 27%. These are respondents’ reported attack-vector observations, not probabilities that any particular organization will be breached.
SANS frames the operating reality as: “In an ICS organization, the ICS is the business.” That means security plans and budgets need to account for the engineering and operational context of the systems they protect, not just apply IT controls by default.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Who controls the OT security budget?
The SANS budget survey found that responsibility is distributed across security, IT and OT functions. Just 27% said CISOs or CSOs lead budget decisions; a larger share reported shared or operational/IT control.
| Reported budget decision arrangement | Share of respondents |
|---|---|
| Shared IT/OT control | 37% |
| IT control | 31% |
| OT control | 26% |
| CISO/CSO-led decisions | 27% |
These percentages describe separate survey responses about governance categories and should not be treated as mutually exclusive portions of a single 100% total. The practical issue is accountability: when budgets and responsibilities are split, organizations need a clear process for deciding who funds cross-domain controls, approves operational changes and owns incident response. SANS recommends engineering-informed controls, with engineering teams leading collaboration and IT teams supporting them.
Rank #3
Which ICS/OT controls should receive priority?
In the budget report, SANS ranks ICS/OT defensible network architecture as the top prioritized control investment, followed by ICS-specific incident response and architectures that support network visibility. The ranking is a prioritization signal, not a one-size-fits-all sequence: organizations should account for their processes, existing safeguards and operational constraints.
A separate SANS State of ICS/OT Security survey page describes the controls organizations deployed or planned: asset visibility, threat detection and secure remote access were prominent in 2025 deployments and 2026–2027 planned investments. The two sources together suggest evaluating a budget against the defensive capabilities it buys, rather than treating budget growth alone as proof of coverage.
Rank #4
- Defensible network architecture: prioritize segmentation and architecture that limit unwanted pathways between IT and OT, while preserving required operations.
- ICS-specific incident response: fund response plans and procedures suited to industrial processes, including coordination between engineering, OT and IT teams.
- Network and asset visibility: establish what is connected and support monitoring that can identify relevant activity without creating unacceptable operational disruption.
- Secure remote access: assess how employees, vendors and transient devices connect to OT, and fund controls appropriate to those pathways.
Visibility, detection and cloud monitoring remain uneven
The separate 2025 SANS State of ICS/OT Security survey had 330 respondents. On that survey page, 49% reported having ICS/OT-specific detection; among that group, 26% rated it highly effective. The distinction matters: having a detection capability is not the same as judging it effective.
The same survey page reports that 83% of organizations had some cloud-connected footprint, while 13% had fully integrated cloud monitoring. The figures indicate a potential visibility gap in environments that connect cloud services and operational systems, but they do not establish that every cloud-connected footprint carries the same level of risk.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Incidents and response readiness are separate measures
In the budget survey, 27% of respondents reported one or more ICS/OT security incidents in the prior year. The separate 2025 State of ICS/OT Security survey reported 22% with an incident. These figures come from different SANS surveys and respondent populations, so they should not be combined or read as a year-over-year trend.
Preparedness measures in the separate State survey also show that incident experience and response readiness are not interchangeable: 13% reported full ICS Cyber Kill Chain visibility and 14% felt fully prepared. The budget survey found that 39% tested their incident-response plan annually. Annual testing is one indicator of readiness, but the survey does not establish the quality or scope of each test.
How to judge whether an increase is closing the gap
For an organization reviewing its own program, the useful question is not simply whether spending rose. Compare the allocation and capabilities against operational exposure and ownership:
- Track budget growth separately from the share allocated to ICS/OT.
- Identify who controls the budget and who is accountable for decisions spanning IT and OT.
- Review exposure through IT-to-OT pathways, internet-accessible devices and transient devices.
- Check whether staffing gives ICS/OT security sufficient dedicated attention.
- Map spending to architecture, ICS-specific incident response, asset and network visibility, detection and secure remote access.
- Assess cloud-connected coverage and whether monitoring is integrated where needed.
- Review incident history and whether the response plan is tested at least annually.
These checks do not prescribe a universal budget share. They help distinguish an increase in funding from an increase in operationally appropriate protection.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




