Research: over 80% of critical infrastructure organisations invest less than half their cybersecurity budgets in operational technology
Industrial control systems (ICS) and operational technology (OT) are essential to critical infrastructure sectors. Effective ICS/OT security helps prevent potentially catastrophic incidents and protects public trust, economic stability and national security. Yet more than 80% of organisations invest less than half of their cybersecurity budgets in protecting the operational technology underpinning critical infrastructure. At the same time, 55% of companies and organisations report that their cybersecurity budgets have grown over the past two years. Only 9%, however, focus exclusively on ICS/OT security, suggesting a potential gap between financial and human resources. These findings come from Czech cybersecurity company ComSource and research by global security company OPSWAT.
“Securing industrial control systems and operational technology is essential because they form the backbone of critical infrastructure, including energy grids, water treatment and manufacturing processes. Any disruption can cause physical damage, safety risks, operational outages or loss of life, with serious consequences for public safety, economic stability and public trust,” says Michal Štusák, co-owner of ComSource, one of the most experienced implementers of OPSWAT solutions in Czechia. “ICS/OT teams operate under principles and constraints that differ fundamentally from those of IT staff. These differences must be understood and respected: applying conventional security processes, technologies and practices can inadvertently disrupt systems and have negative safety implications.”
The research shows that 41% of critical infrastructure companies and organisations allocate no more than a quarter of their total budget to ICS/OT security, while a further 40% allocate only 26–50%. Just 9% invest more than 75% of their total budget. “Overall, the figures suggest that many organisations recognise the importance of ICS/OT cybersecurity, but relatively few dedicate more than half of their budgets to it. This can increase operational and security risks. The situation in Europe, including Czechia, is somewhat better, but larger budget allocations are still rare,” says Michal Štusák, co-owner of ComSource.
The research also revealed other important insights into ICS/OT cybersecurity. For example, 27% of critical infrastructure organisations reported experiencing one or more security incidents involving ICS/OT systems during the previous year. For 58% of respondents, an IT compromise was the main entry point for an ICS/OT attack, reflecting the interconnected nature of these systems. A further 33% identified internet-accessible devices as an entry point.
More than 180 professionals from a range of critical infrastructure sectors worldwide took part in the research. Respondents were security and technology specialists working in areas including IT, ICS, SCADA, OT, process control systems (PCS), distributed control systems (DCS) and automation systems.