Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security firms report different ICS vulnerability totals because they may use different source collections, include different product categories, and count different things: CVEs, individual flaws, or advisories. For calendar year 2022, the figures reported by five firms ranged from 457 CISA advisories to 2,170 CVEs. They are not a like-for-like ranking.

What the 2022 figures count

The comparison below summarizes figures published by SecurityWeek on March 13, 2023. The periods are calendar years unless noted; the unit and scope differ by publisher.

Publisher 2022 figure 2021 comparison What was counted or included
Dragos 2,170 CVEs; reported as 27% above 2021 Not stated in the comparison Dragos drew from CISA, CERT@VDE, JP-CERT, individual vendor advisories, raw NIST data, and vulnerabilities found by its researchers. (SecurityWeek, March 13, 2023)
SynSaber 1,342 vulnerabilities 1,191 Limited to CISA ICS advisories and excluded ICS medical vulnerabilities covered by those advisories. (SecurityWeek, March 13, 2023)
Claroty 940 ICS/OT vulnerabilities 826 ICS/OT-only count. Claroty’s broader XIoT series has a different scope. (SecurityWeek, March 13, 2023)
IBM 457 CISA advisories 715 CISA advisories IBM clarified to SecurityWeek that the figure counted advisories, not individual flaws. (SecurityWeek, March 13, 2023)
Nozomi Networks 778 ICS vulnerabilities 1,188 Nozomi said its method changed in the second half of 2022. SecurityWeek suggested this may have shifted the count from vulnerabilities to advisories; that was the publication’s interpretation, not a confirmed explanation from Nozomi. (SecurityWeek, March 13, 2023)

The units matter. A single advisory can describe multiple flaws, so an advisory count cannot be compared directly with a count of CVEs or individual vulnerabilities. IBM’s 457, for example, is not evidence that it found fewer flaws than a firm reporting thousands of CVEs.

Why the totals diverge

Source coverage

A firm that gathers reports from government CERTs, vendors, independent researchers, and its own researchers can find issues absent from a tally restricted to one source. Dragos vulnerability analyst Reid Wightman told SecurityWeek: “We include many individual vendors and research organizations. Several of these vendors do not coordinate with the main government-run CERTs, so we end up with CVEs that are not covered in other lists.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SynSaber’s 2022 count, by contrast, was limited to CISA ICS advisories. A narrower source list can yield a smaller total without implying that the omitted issues do not exist.

Product categories and shared components

“ICS” does not always define the same boundary. Claroty reported 940 ICS/OT vulnerabilities for 2022, while its broader XIoT series included some medical, IT, and IoT issues, as well as flaws affecting multiple product types. Those XIoT half-year figures were 819 issues in H2 2021, 747 in H1 2022, and 688 in H2 2022; they are not interchangeable with the ICS/OT-only annual figure.

Inclusion rules can also differ for third-party components. One publisher may count every issue listed in an advisory; another may exclude an issue if it affects a shared component rather than being specific to the ICS/OT product. Claroty’s Team82 researcher Bar Ofner described the company’s approach to SecurityWeek: “We chose to only look at these publicly available sources in order to understand the market with an eagle-eye perspective. We wanted to look only at publicly disclosed vulnerabilities in relevant security advisories that usually reflect the vendor’s perspective on new vulnerabilities.”

Method changes over time

A year-over-year change can reflect a changed method as well as a changed set of disclosures. Nozomi told SecurityWeek its methodology changed in H2 2022. Because the article’s suggestion that the change may have shifted the unit to advisories was an interpretation, readers should not treat it as a confirmed explanation for the decline from 1,188 to 778.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Claroty’s separate March 2022 announcement reported 797 vulnerabilities in H2 2021 versus 637 in H1 2021, and said 34% of its H2 2021 findings affected IoT, IoMT, and IT assets. Those figures further illustrate how category and reporting-period labels shape a total; they do not independently validate the 2022 cross-firm comparison. (Claroty, March 2, 2022)

How to compare two reports fairly

Before drawing a conclusion from two totals, align the basic definitions:

  • Reporting period: Check whether each number covers a calendar year, half-year, or another interval.
  • Source universe: Identify whether the tally includes CISA and other government CERTs, NVD, vendor notices, independent researchers, or the firm’s own discoveries.
  • Product scope: Determine whether it covers ICS/OT alone or also medical, IT, IoT, or other XIoT categories, and how shared components are treated.
  • Counting unit: Establish whether the figure means advisories, CVEs, or individual vulnerabilities, including how multiple flaws in one advisory are counted.
  • Method version: Look for collection or counting-rule changes during the period, which can make year-over-year comparisons misleading.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a vulnerability count can—and cannot—tell you

These totals describe issues recorded under each publisher’s methodology. The figures do not share a reconciled cross-firm dataset or common denominator, and a larger tally does not by itself mean a more dangerous environment, more exploitable flaws, or a less secure vendor.

For operational decisions, a raw total needs to be supplemented with information about severity, exploitability, affected product versions, exposure, and available mitigations. Dragos’s later 2025 OT Cybersecurity Report says its 2024 vulnerability assessment draws on reports from independent researchers, vendors, Dragos, and ICS-CERT. That demonstrates continued multi-source analysis, but does not provide a directly comparable current cross-firm table.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Claroty vice president of research Amir Preminger summarized the practical need for useful context in the company’s March 2022 announcement: “As more cyber-physical systems become connected, accessibility to these networks from the internet and the cloud requires defenders to have timely, useful vulnerability information to inform risk decisions.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.