Sans OT
Sans OT
By Tim Conway, Technical Director of ICS and SCADA Programs, SANS Institute
For asset owners and operators of critical infrastructure, staying ahead of emerging
threats and adapting to technological advancements is not just a necessity—it’s a
responsibility. Many of us in the ICS/OT cybersecurity community understand the
immense value of data-driven insights and the power they hold in shaping robust security
programs. This report is more than just a collection of statistics and trends; it’s a potential
roadmap that can help every organization understand where their peers are, strengthen
their defenses, and prepare for the challenges ahead.
The findings in this report offer practical, actionable guidance that can be directly applied
to improve ICS/OT security programs. Whether it’s aligning with industry standards,
enhancing workforce capabilities, or adopting new technologies, the data presented
here provides benchmarks for industrial organizations to measure their progress and
plan for the future. I strongly encourage you to take these insights and use them to drive
meaningful change within your organization, ensuring that your security strategies not
only meet today’s demands but also are poised to tackle tomorrow’s challenges.
I’d like to extend my deepest gratitude to the many professionals who took the time
to contribute to this survey. Your participation is invaluable, not just for the insights it
provides but also for the way it enriches the entire ICS/OT community. It’s through efforts
like these that we continue to grow, learn, and ultimately, secure the critical systems that
underpin our modern world.
1
“The Five ICS Cybersecurity Critical Controls,” November 7, 2022, [Link]/white-papers/five-ics-cybersecurity-critical-controls
Small/Medium
(1,001–5,000)
Energy
Medium
(5,001–15,000)
Other Medium/Large
(15,001–50,000)
Large
Government (More than 50,000)
Each building represents 10 respondents.
Each gear represents 10 respondents.
ICS/OT cybersecurity
manager
Ops: 407 Ops: 120
HQ: 328 HQ: 11
Security manager or
Ops: 125 director
Ops: 102 HQ: 13
Ops: 143
HQ: 11
HQ: 14 Each person represents 5 respondents.
has shifted over the past five years. Although ICS/OT Figure 2. Time Spent on ICS Security
cybersecurity is still a “part-time job” for many respondents, over 12% of respondents in
2024 described ICS/OT cybersecurity as taking 100% of their assigned duties.
Over 50% of the ICS workforce has less than five years of experience, highlighting the
urgency for knowledge transfer and mentorship to build deep expertise within the industry.
2
For the purposes of this survey, “convergence” refers to the interdependency and interwoven nature of applying IT and OT controls across industrial
cybersecurity programs—not the more popular marketing use for specific tools in ICS environments.
Interestingly, the size of Do you hold or have you held any ICS/OT cybersecurity-related certifications? If so, which ones?
an organization had no Select all that apply.
bearing on this rate of Currently hold Held but expired
certification, indicating that Global Industrial Cyber Security 86.7%
Professional (GICSP) 13.3%
size and budget may not be
Certified Information Systems 84.5%
a direct link to obtaining a Security Professional (CISSP) 15.5%
professional certification. GIAC Response and Industrial 83.8%
Defense (GRID) 16.2%
Notably, those with GIAC 81.8%
Other
Critical Infrastructure 18.2%
ISA Security Compliance
Protection (GCIP), GIAC Institute (ISCI) Embedded Device
81.3%
Security Assurance (EDSA)
18.8%
51.3% 48.7%
Response and Industrial GIAC Critical Infrastructure 80.6%
Defense (GRID), and Protection (GCIP) 19.4%
ISA99/IEC 62443 Cybersecurity 78.9%
System Security Assurance Fundamentals Specialist 21.1%
(SSA) certifications tend Yes No ISA Security Compliance Institute 75.8%
(ISCI) System Security Assurance (SSA) 24.2%
to have more hands-on
GIAC Security Operations 68.6%
ICS experience, spending Certified (GSOC) 31.4%
IACRB’s Certified SCADA 65.7%
over 70% of their time Security Architect (CSSA) 34.3%
on ICS security. That 0% 20% 40% 60% 80% 100%
The need to develop a robust ICS cybersecurity workforce has been recognized
globally, including in regulations like the EU’s NIS 2 Directive3 and policies like
the US’s Call To Action: Building the Cyber Workforce the Nation Needs.4 Although
progress is evident, the industry must address the experience and certification gaps
to foster a resilient, skilled, and unified ICS security community.
ICS-Specific Security Governance: Who in your organization has the primary responsibility
Aligning Priorities with Practice for setting the security policy for control systems?
Chief information security officer (CISO) or
The governance of ICS/OT cybersecurity is chief security officer (CSO) or equivalent
38.5%
Chief information officer (CIO) or
drawing more attention at the executive level, but chief technology officer (CTO)
13.5%
3
“The NIS 2 Directive,” [Link]
4
“Answering the Call to Build the Nation’s Cyber Workforce,”
[Link]/oncd/briefing-room/2023/11/03/answering-the-call-to-build-the-nations-cyber-workforce
visibility and monitoring, which Figure 7. Priority Level of the SANS Five ICS Cybersecurity
Critical Controls, Based on Budget Spend
help them see what is happening on their network, identify
vulnerabilities, and spot malicious activities. Interestingly, incident
response received a lower budget priority for organizations,
implying either the tools and methodologies are less expensive—
or there is a potential misalignment in organizational priorities.
After all, without response, what good is detection?
Figure 8 highlights business impact Rank the following in order of business priorities
priorities for industrial organizations— for your industrial cybersecurity program.
respondents place the highest Rank #1 Rank #2 Rank #3 Rank #4 Rank #5 Rank #6 Rank #7
importance on “safety of the industrial Safety of the industrial
process/facility 36.4% 11.6% 10.5% 7.7% 15.6% 11.6% 6.3%
process/facility” and “reliability and
Confidentiality of
availability of the industrial process.” intellectual property 22.4% 13.6% 12.8% 11.6% 12.5% 11.1% 15.9%
not easily allow cloud usage within the North Remote processing of data historian data 29.5% 29.5% —
American Bulk Electric System. Remote control of engineering field devices 25.8% 28.4% +2.6%
Process optimization 22.7% 25.3% +2.6%
Table 1 outlines striking trends in how cloud Business continuity/disaster recovery planning 22.4% 33.7% +11.3%
services are being used compared to last year’s Remote control of engineering operations 22.0% 31.6% +9.6%
(human–machine interface [HMI] in the cloud)
survey. For example, the increase in cloud usage
Virtualized controllers 18.0% 15.8% –2.2%
for remote monitoring of configuration and Other 9.6% 4.2% –5.4%
analysis of engineering operations telemetry
jumped from 40% to 56%, a significant 16% increase. Similarly, there has been
an 11% rise in the use of cloud services for business continuity and disaster
recovery planning, reaching 34% in 2024. The moderate jump (+10%) in HMI
in the cloud may raise some eyebrows across the ICS/OT security community.
That said, despite this increased usage, organizations are taking a cautious
approach. Seventy-nine percent of respondents conduct risk assessments
before cloud deployments, demonstrating a strong focus on risk management
regarding the cloud.
5
“The AI Index,” [Link]
• D
efensible architecture—Emphasizes the design and implementation of robust
ICS architectures that support visibility, segmentation, and process communication
enforcement
• S
ecure remote access—Stresses the importance of securing remote access to ICS
networks, particularly against threats from hybrid work structures and supply chain
vulnerabilities
• R
isk-based vulnerability management—Prioritizes the management of ICS
vulnerabilities based on risk, focusing on those that could enable adversary access
or disrupt operations
Each section of this report will expand on these controls and link them to specific
findings and trends to aid organizations in growing and maintaining their ICS/OT
security programs.
Regular ICS-specific IRP testing, not surprisingly, correlates to more informed capabilities
for ICS incident response. For example, an impressive number of annual testers have
exercised an ICS network outage resulting in production outages (65%) and are confident
they can operate in manual mode (66%). However, this is dwarfed by those who test
quarterly (75% have exercised an ICS network outage and 72% can operate their ICS in
manual mode). Respondents who tested their IRP monthly were true masters of their
craft, with nearly 90% having exercised such
What do you include in your ICS/OT incident response plan testing?
outages. Those that train regularly clearly
Select all that apply.
have the upper hand in mature ICS incident
Paper-based tabletop exercises 66.7%
response capabilities.
Simulated ICS/OT cyber attack with
technical hands-on experience
57.4%
When asked about what types of exercises
Operational drills 48.2%
are performed, respondents leveraged a
ICS/OT cybersecurity range
environments using active tools
34.4%
large range of capabilities, with paper-based
Other 3.6%
tabletop exercises being the most widely
0% 10% 20% 30% 40% 50% 60% 70%
used, as seen in Figure 10.
Figure 10. IRP Exercise Types
Industrial Impacts from Ransomware in 2024
This year’s survey saw a decrease in respondents reporting ransomware impacts, with only
12% of respondents reporting ransomware incidents in the previous 12 months. Half of
those ransomware attacks impacted ICS/OT networks, and 38% compromised the safety or
reliability of the physical process, as seen in Figure 11. Although the overall trend seems
to have decreased, the impacts are still potentially catastrophic and should be considered
for all ICS/OT-specific incident response programs.
Ransomware Incidents
Ransomware in last 12 months? If yes, systems impacted Was reliability or safety compromised?
6
“The Five ICS Cybersecurity Critical Controls,” November 7, 2022, [Link]/white-papers/five-ics-cybersecurity-critical-controls/
incident response lifecycle take Figure 14. Detection, Containment, and Remediation Gaps for ICS Incidents
considerable effort—with some
remediation times stretching to a
year or more, as seen in Figure 14.
cyber incident, and should not be connected Shared network (flat or routed) 14.1%
Restricted to mechanical
to enterprise IT networks due to the potentially and electrical, not logical 8.1%
interconnections between systems
disastrous impacts associated with an SIS failure.
Converged or comingled logic
and safety control functionality 7.4%
Luckily, despite these fringe cases, industry in control components
understands the importance of separating the Other 6.0%
81.3%
the next 18 months. The full list can be found Access controls
13.2%
in the Appendix. Of the nearly 40 technologies Backup and recovery 74.4%
processes and tools 17.6%
outlined in the survey, we captured the top five
Endpoint detection and response 73.3%
currently implemented in Figure 17. (EDR), including traditional antivirus 16.5%
Segmentation between control 66.3%
Over the past five years, several of these systems and higher risk networks 21.2%
categories have seen massive jumps in Secure remote access with 64.8%
multifactor authentication 21.2%
implementation across industry. For example, in
0% 20% 40% 60% 80%
2019, 72% of respondents had access controls in
Figure 17. Top Five In-Use ICS Security Technologies
place for ICS, compared to 81% today. Similarly,
endpoint detection and response (EDR) was
What security technologies or solutions do you currently have in use
reported as being used by 53% of respondents in your OT environment? What new technologies or solutions would you
in 2019; however, by 2024 there was a 20% jump most want to add for control system security in the next 18 months?
to 73% using EDR. Interestingly, due to the larger Select all that apply or indicate not applicable (N/A).
most of the planned rates are relatively low in ICS-specific cybersecurity 37.7%
metrics or dashboards 37.0%
relation to other technologies being deployed ICS network security monitoring 52.4%
in ICS/OT environments. In comparison, the and anomaly detection solutions 32.6%
Control system enhancements/ 45.1%
most-planned technologies in Figure 18 tell an upgrade services 31.5%
interesting story for what the next 18 months in ICS-specific cybersecurity training
49.1%
30.8%
ICS security may look like.
ICS-specific incident response 45.8%
tabletops or simulations 30.0%
Figure 18 shows the most-planned ICS
0% 20% 40% 60% 80%
security technologies. Except for ICS-specific
Figure 18. Most-Planned ICS Security Technologies
cybersecurity metrics and dashboards, these
technologies are already in use by nearly half
In 2019, OT-specific monitoring was used by only 33% of
of respondents, but over 30% more plan to use respondents (compared to 52% in 2024), demonstrating a massive
them. This suggests a possible shift toward growth across this technology category in only five years.
non-technology spending, like training and
tabletops. ICS network security monitoring What security technologies or solutions do you currently have in use
stands out as the only highly planned in your OT environment? What new technologies or solutions would you
technology, with over 50% current deployment. most want to add for control system security in the next 18 months?
Select all that apply or indicate not applicable (N/A).
Finally, three technology categories for
In Use Planned
defensible ICS architecture stood out for being
Software bill of materials (SBOM)
25.3%
the least deployed—but with a surprisingly large 27.5%
25.6%
number of respondents planning to use them Industrial cloud security
23.4%
over the next 18 months, as seen in Figure 19. Security orchestration, automation, 28.2%
and response (SOAR) 29.7%
0% 20% 40% 60% 80%
Figure 19. Least Used ICS Security Technologies with High Planned Rates
Many organizations have recognized the importance of a dedicated SOC, with 63% having
one. That said, 45% have no OT SOC capabilities, leaving a significant gap in threat
detection and response for ICS/OT environments, as shown in Figure 20.
Does your organization have what Select the statements that describe your
could be considered a SOC? SOC capabilities.
Other 4.7%
0% 10% 20% 30%
Unknown/unsure
Data collection and correlation across various ICS
components is key for effective ICS/OT SOCs. The survey
shows that most organizations (70%) collect and correlate Figure 21. ICS-Specific Network Monitoring Coverage
data from ICS server assets, and 64%
from network devices like firewalls From which control system components are you collecting and correlating data?
Select all that apply.
and routers.
ICS server assets running commercial
70.1%
However, as Figure 22 shows, OS (Windows, Unix, Linux)
ICS network devices (management
industrial organizations should also interfaces, printers, firewall, switches, 63.9%
routers, gateways, protocol security)
include less obvious components, ICS operator assets (HMI, workstations)
running commercial OS (Windows, Unix, Linux)
60.6%
such as serial/non-routable networks ICS engineering assets (engineering
workstations, instrumentation laptops,
and embedded controllers, to calibration and test equipment) running
58.5%
commercial OS (Windows, Unix, Linux)
gain deeper visibility and identify
ICS network telemetry (taps/spans) 36.1%
potentially hidden threats in high-
Data historian 34.9%
impact facilities.
Remote access appliances, including modems 33.6%
Other 4.6%
0% 10% 20% 30% 40% 50% 60% 70%
Internal data can further refine this threat intelligence, as seen in Figure 23, which can
include a mix of automated and human-driven processes, with 71% of respondents using
threat detection across their ICS/OT security program. Of those, 70% use automated means,
such as asset-based EDR, to detect threats within OT networks. Additionally, 40% utilize ICS
protocol-aware network monitoring solutions, and 48% rely on anomaly-based detection
engines. These tools, combined with trained ICS staff conducting threat hunting (38%), create
a layered defense that can significantly improve threat detection and response capabilities.
Are you implementing any processes to What processes are you using to detect threats within
detect threats within your OT networks? your OT networks? Select all that apply.
We use automated means (like
asset-based EDR) to detect threats.
69.5%
Understanding remote access issues begins with recognizing the existing connectivity in
industrial settings. A little over half (53%) of those surveyed have documented all of their
connectivity outside the ICS/OT perimeter. Such documentation
Do you have a remote access policy or program?
increases to 63% if the ICS program is mapped to cybersecurity
standards, and increases even further (79%) if the organization
7.2%
also has extensive ICS network monitoring capabilities (as covered es, we have a formal
Y
8.7% remote access policy
in Figure 21). This highlights how both governance and technology or program for critical/
high-risk environments.
can aid organizations in their maturity across multiple security
es, we have an
Y
capabilities, as well as the importance of knowing your industrial 22.0% 62.1% informal remote access
policy or program.
assets and how/why they have external connectivity.
No
Once the network connectivity has been evaluated, organizations
Unknown/unsure
typically invest in a formal remote access policy or program.
As highlighted in Figure 24, 84% of respondents have either an
informal or formal policy in place for remote access. Figure 24. Remote Access Policy and Program Implementation
Other 5.3%
0% 20% 40% 60% 80%
26.3%
Yes
73.7%
No
37.7%
Yes
62.3%
No
47.4% 52.6%
No Yes
42.1%
No 57.9%
Yes
52.6% 47.4%
No Yes
35.1%
Yes
64.9%
No
20.2%
Yes
79.8%
No
Level 3 of the Purdue Model, as seen in Figure 28. Although difficult (and requiring ICS-
specific skill sets and knowledge), penetration tests can be performed at lower levels of
the Purdue Model when safety and reliability concerns are taken into consideration.
7
“Recommended Practice for Patch Management of Control Systems,”
[Link]/uscert/sites/default/files/recommended_practices/RP_Patch_Management_S508C.pdf
The path forward is clear: proactive, informed, and strategic actions are essential to
ensuring the security and resilience of our ICS/OT environments. With the right focus
and resources, organizations can meet today’s challenges and be well-prepared for the
threats of tomorrow.
Sponsor
In Use Planned
Access controls
81.3%
13.2%
Application allowlisting
50.5%
26.0%
Continual authentication/authorization
42.9%
27.1%
Device allowlisting
50.2%
20.5%
CONTINUED
In Use Planned
Protocol security
49.5%
23.8%
Security automations and workflows to decrease manual effort and human error
37.4%
31.9%
Vulnerability scanning
61.2%
22.0%
Other
3.7%
2.6%
0% 10% 20% 30% 40% 50% 60% 70% 80%