Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—ICS/OT security budgets are growing at many organizations, but growth does not mean the systems are adequately protected. In SANS Institute’s March 2025 survey of more than 180 practitioners, 55% reported budget growth over the prior two years. At the same time, 41% said only 0–25% of their security budget goes to ICS/OT, and just 9% said the share exceeds 75%. The gap is between recognizing the need to spend and dedicating enough money, people and operational attention to cover it.

What the budget figures do—and do not—show

The March 2025 SANS Institute 2025 ICS/OT Cybersecurity Budget survey, authored by SANS Principal Instructor Dean Parsons, records practitioners’ reports about their organizations. It is not an audit of enterprise spending, and it does not establish a dollar-denominated average ICS/OT budget. Its figures show the direction and allocation respondents described, not whether any particular organization spends enough.

That distinction matters: a larger budget can still leave ICS/OT competing with other security needs, while staffing and incident readiness lag behind. The percentages below refer to respondents in this budget survey unless a separate SANS survey is explicitly identified.

Measure Reported result What it indicates
ICS/OT budget trend 55% reported growth over the prior two years (SANS Institute, 2025 ICS/OT Cybersecurity Budget survey) More organizations report increasing investment, but the figure does not state the dollar amount or prove that the increase closes a funding gap.
Share of security budget allocated to ICS/OT 41% allocated 0–25%; 9% allocated more than 75% (same survey) Growth can coexist with a relatively small ICS/OT share.
Dedicated ICS/OT security time 9% of professionals said they spend 100% of their time on ICS/OT security (same survey) Budget allocation is only part of capacity; specialist staff time is limited for many respondents.

Why can funding rise while critical areas remain underfunded?

ICS and OT systems operate physical processes, so a security decision can affect operational continuity, worker and public safety, environmental outcomes and trust. Controls that are routine in enterprise IT may behave differently in a production environment. SANS warns that applying generalized IT security controls directly to ICS/OT can cause false positives and operational disruption. Funding must therefore support controls designed with engineering knowledge and operational constraints, not simply transfer an IT checklist to industrial systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The leading reported attack path also crosses organizational boundaries: 58% identified an IT compromise spreading into OT/IT networks as the leading initial attack vector. That makes an IT-only view of the risk incomplete. SANS’s operational framing is, “In an ICS organization, the ICS is the business.” Security planning must account for the business process and the people responsible for running it.

Who controls the ICS/OT security budget?

Respondents described budget authority as distributed across security, IT and operational functions. Only 27% said CISOs or CSOs led budget decisions; shared IT/OT control was most common among the listed arrangements.

Reported budget control Share of respondents
Shared IT/OT control 37% (SANS Institute, 2025 ICS/OT Cybersecurity Budget survey)
IT control 31% (same survey)
OT control 26% (same survey)
CISO or CSO leads budget decisions 27% (same survey; leadership measure, not an additional mutually exclusive control category)

These figures describe different aspects of governance: the first three identify reported control arrangements, while the CISO/CSO figure concerns who leads decisions. They should not be added together. Shared ownership can help connect enterprise security resources with operational expertise, but it also calls for clear responsibility: who sets priorities, who approves operational changes, and who verifies that funded controls work in the plant or facility.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Which investments should come first?

SANS ranks ICS/OT defensible network architecture as the top prioritized control investment, followed by ICS-specific incident response and architectures that support network visibility. This ordering focuses on separating and understanding industrial environments, then preparing for incidents in ways suited to them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Build defensible network architecture

Make network architecture the first funding discussion, rather than treating it as a one-time equipment purchase. The aim is to establish boundaries and access paths that reflect how the industrial environment operates. Engineering and OT teams should shape the design and change process, with IT security supporting them; this reduces the risk that a well-intended control disrupts essential operations.

2. Fund ICS-specific incident response

Incident plans and response capabilities need to account for the systems, process dependencies and operational decisions involved in an ICS event. SANS reports that only 39% test their incident-response plan annually. A plan that has not been exercised may leave teams uncertain about roles and response steps when timing and safe operations matter.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

3. Support network visibility and detection

Visibility architecture is among SANS’s top investment priorities. The separate 2025 SANS State of ICS/OT Security survey also points to capability gaps: 49% reported having ICS/OT-specific detection, and 26% of that group rated it highly effective. In that survey, asset visibility, threat detection and secure remote access were the most common areas of 2025 deployment and planned investment for 2026–2027. These figures come from a different survey population and should not be treated as budget-survey results.

4. Treat remote access and cloud connections as part of the boundary

The separate State of ICS/OT Security survey found that 83% reported some cloud-connected footprint, while 13% said cloud monitoring was fully integrated. That makes it important to include cloud-connected systems and remote-access pathways in asset and network visibility plans. The survey’s figures describe respondents’ reported environments; they do not establish that every organization has the same exposure or needs the same design.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What attack paths should shape the plan?

The budget survey’s attack-vector responses offer a practical way to test whether proposed spending addresses routes into the environment, rather than only adding controls at the perimeter.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Reported initial attack vector Share identifying it Funding implication
IT compromise spreading into OT/IT networks 58% (SANS Institute, 2025 ICS/OT Cybersecurity Budget survey) Coordinate IT and OT security planning around cross-domain pathways.
Internet-accessible devices 33% (same survey) Include exposed devices in asset visibility and access-control work.
Transient devices 27% (same survey) Account for devices that connect temporarily, rather than relying only on a static asset picture.

These are respondent-identified vectors, not a ranking of the likelihood of compromise at every site. A useful budget review maps each relevant pathway to an accountable owner and a funded control, then checks that the control can be operated safely.

How should leaders tell whether more spending is closing the gap?

Track budget growth alongside the share allocated to ICS/OT, dedicated staff capacity, incident frequency, detection and visibility coverage, remote-access and cloud monitoring, and incident-response exercises. SANS’s separate 2025 State of ICS/OT Security survey found that 22% reported an incident, 13% reported full ICS Cyber Kill Chain visibility, and 14% felt fully prepared. Those figures are not directly comparable to the budget survey’s 27% incident figure: the State survey had 330 respondents and is a distinct survey.

Use measures that reveal whether investment has changed operational capability, not just whether a budget line increased. For example, leaders can review whether the critical network paths are understood, whether ICS-specific response plans have been exercised, and whether detection covers the assets and connections the organization actually operates. The survey results do not prescribe a universal spending threshold; the right allocation depends on the organization’s systems, exposure and operational requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.