0% found this document useful (0 votes)
64 views28 pages

Sans OT

Uploaded by

nperna
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
64 views28 pages

Sans OT

Uploaded by

nperna
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Survey

SANS 2024 State of


ICS/OT Cybersecurity
Written by Jason D. Christopher
Foreword by Tim Conway
October 2024

©2024 SANS™ Institute


Foreword

By Tim Conway, Technical Director of ICS and SCADA Programs, SANS Institute

For asset owners and operators of critical infrastructure, staying ahead of emerging
threats and adapting to technological advancements is not just a necessity—it’s a
responsibility. Many of us in the ICS/OT cybersecurity community understand the
immense value of data-driven insights and the power they hold in shaping robust security
programs. This report is more than just a collection of statistics and trends; it’s a potential
roadmap that can help every organization understand where their peers are, strengthen
their defenses, and prepare for the challenges ahead.

The findings in this report offer practical, actionable guidance that can be directly applied
to improve ICS/OT security programs. Whether it’s aligning with industry standards,
enhancing workforce capabilities, or adopting new technologies, the data presented
here provides benchmarks for industrial organizations to measure their progress and
plan for the future. I strongly encourage you to take these insights and use them to drive
meaningful change within your organization, ensuring that your security strategies not
only meet today’s demands but also are poised to tackle tomorrow’s challenges.

I’d like to extend my deepest gratitude to the many professionals who took the time
to contribute to this survey. Your participation is invaluable, not just for the insights it
provides but also for the way it enriches the entire ICS/OT community. It’s through efforts
like these that we continue to grow, learn, and ultimately, secure the critical systems that
underpin our modern world.

SANS 2024 State of ICS/OT Cybersecurity 2


Executive Summary
Since 2017, the annual State of ICS/OT Cybersecurity survey has offered key insights
and benchmarks for industrial cybersecurity programs worldwide. This year’s report
continues that tradition. Based on inputs from over 530 professionals across multiple
critical infrastructure sectors, it provides actionable guidance as to how organizations
can manage industrial cyber risk effectively. The SANS 2024 State of ICS/OT
Cybersecurity report is structured around the SANS Five ICS Cybersecurity Critical
Controls, offering practical insights applicable to ICS/OT programs regardless of size,
budget, or sector.1 As industrial environments evolve, driven by increased threats,
regulatory requirements, and IT–OT integration, the need for a resilient and adaptive
security posture is more critical than ever.

Key Industry-Wide Insights


• Slightly cloudy—26% of respondents are now utilizing cloud technologies for ICS/OT
applications, marking a significant (+15%) increase from previous years.
• Workforce growing pains—51% of respondents do not hold any ICS/OT-specific
certifications, indicating a critical need for access to enhanced training and
certification programs.
• Incident response “haves and have-nots”—56% of organizations have a dedicated
ICS/OT incident response plan, though 28% still lack such a plan.
• MFA for (almost) everyone—75% of respondents have implemented multifactor
authentication (MFA) for remote access to industrial sites, showing steady
improvement in securing access points.
• Limited AI adoption—Only 10% of respondents are currently using AI in their ICS/OT
security strategies, though interest is growing.
• Standards and intel lead maturity—Throughout the report, one thing is clear: the
more organizations use both industry-adopted standards and ICS-specific threat
intelligence, the more mature their overall cyber capabilities are.

1
“The Five ICS Cybersecurity Critical Controls,” November 7, 2022, [Link]/white-papers/five-ics-cybersecurity-critical-controls

SANS 2024 State of ICS/OT Cybersecurity 3


Although advancements in cloud adoption and security technologies are promising, ongoing
workforce development and aligning budget priorities with actual risks remain critical
challenges. This report provides the data and analysis organizations need to refine their
security strategies and better protect critical infrastructure in an increasingly complex cyber
threat landscape. Figure 1 provides a snapshot of respondents’ demographics.

Top 4 Industries Represented Organizational Size


Small
Technology (Up to 1,000)

Small/Medium
(1,001–5,000)
Energy
Medium
(5,001–15,000)

Other Medium/Large
(15,001–50,000)

Large
Government (More than 50,000)
Each building represents 10 respondents.
Each gear represents 10 respondents.

Operations and Headquarters Top 4 Roles Represented


Security administrator/
Ops: 172 security analyst
HQ: 37 Ops: 172
HQ: 40
Ops: 190
HQ: 78 Other

ICS/OT cybersecurity
manager
Ops: 407 Ops: 120
HQ: 328 HQ: 11
Security manager or
Ops: 125 director
Ops: 102 HQ: 13
Ops: 143
HQ: 11
HQ: 14 Each person represents 5 respondents.

Figure 1. Survey Demographics

SANS 2024 State of ICS/OT Cybersecurity 4


2024 Workforce, Governance, and Technology Changes
The 2024 survey examined key shifts in governance, workforce, and technology
within the ICS/OT security landscape. As IT and OT roles further rely on one another,
organizations must adapt their security governance and workforce strategies to address
new challenges. This section focuses on current trends in budget allocation, leadership
priorities, and workforce skills, as well as the adoption of emerging technologies
like cloud computing and artificial intelligence. By analyzing these developments,
organizations can better align their security efforts with industry standards and prepare
for the evolving demands of industrial cybersecurity.

ICS-Specific Workforce Development: The Path to Maturity


The workforce is the beating heart of any ICS/OT security program. A trained and
experienced team can help inform strategies, what technologies to invest in, and the
best approaches for managing industrial cyber risk.
Comparison of Time Spent on ICS Security: 2019 vs. 2024
As industrial environments become more
interconnected, the convergence of IT and OT roles 2019 2024
35% 34.1%
is increasingly common.2 The data shows that 36% of
respondents are responsible for both IT and OT security, 30% 29.4%
27.3% 26.9% 26.1%
reflecting this growing integration. However, this trend is 25%
not universal; 34% of respondents still focus exclusively 20.6%
20% 19.8%
on OT/ICS operations, and 24% are dedicated primarily
15.9%
to IT/business enterprise activities—splitting the “IT vs. 15%

OT” camps into similar populations. 10%

Regardless of their IT/OT placement, respondents 5%


reported that, on average, over half of their time was
0%
spent on ICS cybersecurity. Figure 2 shows how this < 25% 26–50% 51–75% > 76%

has shifted over the past five years. Although ICS/OT Figure 2. Time Spent on ICS Security
cybersecurity is still a “part-time job” for many respondents, over 12% of respondents in
2024 described ICS/OT cybersecurity as taking 100% of their assigned duties.

Over 50% of the ICS workforce has less than five years of experience, highlighting the
urgency for knowledge transfer and mentorship to build deep expertise within the industry.

2
For the purposes of this survey, “convergence” refers to the interdependency and interwoven nature of applying IT and OT controls across industrial
cybersecurity programs—not the more popular marketing use for specific tools in ICS environments.

SANS 2024 State of ICS/OT Cybersecurity 5


The workforce demographics indicate that most
How many years of experience do you have in ICS/OT cybersecurity?
respondents have five or fewer years of experience,
40% 38.7%
as seen in Figure 3. Years working within an industry
does not directly correlate to knowledge and 35%

skills—instead, this statistic highlights the industry’s 30%


“youth” compared to its IT counterpart. This presents
25% 24.1%
opportunities for fresh perspectives but underscores
the need for mentorship to transfer knowledge from 20%
15.6%
seasoned professionals. 15% 13.9%

Certifications can help enable a maturing workforce 10%


7.7%
by providing standardization, a common lexicon
5%
for security concepts, and demonstrative proof of
a foundational understanding required for various 0%
< 1 year 1–5 years 6–10 years 11–20 years > 20 years
jobs and tasks. Unfortunately, roughly half (49%) of Figure 3 ICS Workforce Experience Levels
respondents reported lacking cybersecurity-related
certifications, as seen in Figure 4.

Interestingly, the size of Do you hold or have you held any ICS/OT cybersecurity-related certifications? If so, which ones?
an organization had no Select all that apply.
bearing on this rate of Currently hold Held but expired
certification, indicating that Global Industrial Cyber Security 86.7%
Professional (GICSP) 13.3%
size and budget may not be
Certified Information Systems 84.5%
a direct link to obtaining a Security Professional (CISSP) 15.5%
professional certification. GIAC Response and Industrial 83.8%
Defense (GRID) 16.2%
Notably, those with GIAC 81.8%
Other
Critical Infrastructure 18.2%
ISA Security Compliance
Protection (GCIP), GIAC Institute (ISCI) Embedded Device
81.3%
Security Assurance (EDSA)
18.8%
51.3% 48.7%
Response and Industrial GIAC Critical Infrastructure 80.6%
Defense (GRID), and Protection (GCIP) 19.4%
ISA99/IEC 62443 Cybersecurity 78.9%
System Security Assurance Fundamentals Specialist 21.1%
(SSA) certifications tend Yes No ISA Security Compliance Institute 75.8%
(ISCI) System Security Assurance (SSA) 24.2%
to have more hands-on
GIAC Security Operations 68.6%
ICS experience, spending Certified (GSOC) 31.4%
IACRB’s Certified SCADA 65.7%
over 70% of their time Security Architect (CSSA) 34.3%
on ICS security. That 0% 20% 40% 60% 80% 100%

said, this overall lack of Figure 4. Certifications Across the


ICS Security Workforce
certification suggests that many professionals may be operating
without formalized, industry-specific training. This gap in certification
coverage could undermine the effectiveness of security measures
and contribute to a less resilient ICS security environment.

SANS 2024 State of ICS/OT Cybersecurity 6


The challenges faced by the ICS/OT security workforce are further deepened by
the technical and operational complexities of integrating legacy systems with
modern IT environments. The survey identifies technical integration of aging ICS/OT
technology and IT systems as a major hurdle, with 65% of respondents citing this
as a significant issue. Additionally, the survey highlights a lack of understanding
of ICS/OT operational requirements among IT staff, noted by 50% of respondents,
and a shortage of labor resources, reported by 46%. These challenges point to a
critical need for more specialized training and a deeper appreciation of the unique
demands of ICS environments within the broader cybersecurity workforce.

The need to develop a robust ICS cybersecurity workforce has been recognized
globally, including in regulations like the EU’s NIS 2 Directive3 and policies like
the US’s Call To Action: Building the Cyber Workforce the Nation Needs.4 Although
progress is evident, the industry must address the experience and certification gaps
to foster a resilient, skilled, and unified ICS security community.

ICS-Specific Security Governance: Who in your organization has the primary responsibility
Aligning Priorities with Practice for setting the security policy for control systems?
Chief information security officer (CISO) or
The governance of ICS/OT cybersecurity is chief security officer (CSO) or equivalent
38.5%
Chief information officer (CIO) or
drawing more attention at the executive level, but chief technology officer (CTO)
13.5%

there are still significant gaps between perceived Director-level or manager-level


approval only (no C-suite approvals)
12.1%
risks and actual investments. The 2024 survey No corporate-wide policies are in
7.3%
place—plant/facility-specific
indicates that the responsibility for setting ICS Vice president of engineering
4.0%
(or equivalent)
security policies is increasingly being centralized
Chief operations officer (COO) 3.6%
within the executive leadership, with a clear
Chief risk officer (CRO) 2.4%
emphasis on integrating ICS security into the
Unknown 11.1%
broader corporate security strategy.
Other 7.5%
As Figure 5 shows, CISOs are the main drivers
0% 10% 20% 30% 40%
of ICS security governance (39%), integrating it Figure 5. Roles Responsible for
with corporate security strategy. Respondents also highlighted that CIOs or CTOs ICS/OT Cybersecurity
contribute to ICS security policies (14%), further converging ICS security with IT
governance and indicating most organizations centralize ICS security within the
enterprise. We’ve seen this centralization occur over the past five years, with the
industrial CISO consistently the primary owner of ICS/OT cybersecurity policy, as
Figure 6 illustrates on the next page.

3
“The NIS 2 Directive,” [Link]
4
“Answering the Call to Build the Nation’s Cyber Workforce,”
[Link]/oncd/briefing-room/2023/11/03/answering-the-call-to-build-the-nations-cyber-workforce

SANS 2024 State of ICS/OT Cybersecurity 7


Most organizations (72%) map
CISOs Dominate ICS/OT Security Policy Responsibility (2019–2024)
their control systems to recognized
50%
frameworks, with the NIST CISO
Cybersecurity Framework being CISO remains the primary owner CSO
40%
the most popular (45%). Other CTO
COO
standards, such as International
30% CRO
Society of Automation/
Plant/facility-specific
International Electrotechnical 20% VP engineering
Organization (ISA/IEC) 62443 and  irector-level or
D
manager-level
North American Electric Reliability 10% approval only
Corporation (NERC) Critical Unknown

Infrastructure Protection (CIP), are 0%


Other
2019 2020 2021 2022 2023 2024
also widely used, showing a strong
Figure 6. Trend for Ownership of ICS/OT Cybersecurity
commitment to standardizing
and strengthening ICS security practices. However, standard
mapping depends on who governs ICS security. If a CISO
Governance matters. In cases where the CISO owns ICS security,
owns the governance, 82% of ICS programs follow industry 82% of programs are mapped to standards, compared to 42% if
standards, compared to only 42% if there are no corporate- no corporate-wide policies exist—a nearly 2x difference!
wide policies for ICS.

Meanwhile, there is a significant disconnect between perceived risks and budget


allocation. Although 66% of respondents identified “people”—including employees and
contractors—as the greatest risk to their ICS environments, most budget allocations
continue to prioritize technology. Specifically, 52% of respondents allocate much of their
cybersecurity budget to technology investments, whereas only 25% dedicate a comparable
budget to workforce training, recruitment, and retention. This suggests that although
organizations recognize the importance of addressing human factors in cybersecurity,
their financial investments are geared toward solving this problem with technology. This
shares a common theme with the trends uncovered in the previous section on ICS security
workforce management.

Meanwhile, shared budgets are increasingly common. Some 38% of


respondents reported having a shared IT–OT budget. This increases to Who Has the Money?
48% of respondents if a CISO manages the ICS/OT security program. Over the past five years, budgets have routinely shifted
In 2019, only 29% of respondents indicated that there was a shared “toward the center” and are shared by both IT and OT
IT–OT budget, further cementing the centralization of cybersecurity security teams. In 2019, only 29% of respondents had a
joint IT–OT security budget, compared to 38% in 2024.
governance across industrial organizations. This trend could signal
a growing recognition of the need for a unified approach to securing
both IT and OT environments.

SANS 2024 State of ICS/OT Cybersecurity 8


The 2024 survey data shows that
Rank the following in order of budget allocation
architecture and visibility are the within your ICS/OT cybersecurity program.
top budget priorities among the
Rank #1 Rank #2 Rank #3 Rank #4 Rank #5
SANS Five ICS Cybersecurity Critical
Defensible architecture
Controls. Defensible architecture, 33.1% 30.0% 16.9% 14.3% 5.7%
ICS/OT-specific visibility
which focuses on establishing robust and monitoring 22.9% 22.3% 20.9% 15.7% 17.7%
perimeter defenses and securing the Incident response
21.4% 13.7% 18.9% 23.7% 21.4%
infrastructure, is ranked as the top
Secure remote access
priority by 33% of respondents, as seen 12.9% 18.6% 21.4% 23.1% 23.4%

in Figure 7. Risk-based vulnerability


management 9.1% 15.4% 21.7% 22.9% 30.6%

Respondents value ICS/OT-specific 0% 20% 40% 60% 80% 100%

visibility and monitoring, which Figure 7. Priority Level of the SANS Five ICS Cybersecurity
Critical Controls, Based on Budget Spend
help them see what is happening on their network, identify
vulnerabilities, and spot malicious activities. Interestingly, incident
response received a lower budget priority for organizations,
implying either the tools and methodologies are less expensive—
or there is a potential misalignment in organizational priorities.
After all, without response, what good is detection?

Figure 8 highlights business impact Rank the following in order of business priorities
priorities for industrial organizations— for your industrial cybersecurity program.
respondents place the highest Rank #1 Rank #2 Rank #3 Rank #4 Rank #5 Rank #6 Rank #7
importance on “safety of the industrial Safety of the industrial
process/facility 36.4% 11.6% 10.5% 7.7% 15.6% 11.6% 6.3%
process/facility” and “reliability and
Confidentiality of
availability of the industrial process.” intellectual property 22.4% 13.6% 12.8% 11.6% 12.5% 11.1% 15.9%

In contrast, areas such as “protecting Preventing company


financial loss 13.6% 18.5% 14.8% 17.6% 21.9% 9.4% 4.3%
company reputation and brand” and Reliability and availability
“meeting regulatory compliance” are of the industrial process 12.5% 28.7% 15.3% 16.2% 14.2% 9.7% 3.1%
Meeting regulatory
ranked lower. Respondents in the IT compliance 7.7% 12.2% 19.9% 13.1% 6.0% 10.2% 29.5%
sector, however, ranked “confidentiality Protecting company
reputation and brand 4.0% 8.5% 8.2% 15.6% 13.1% 29.5% 19.6%
of intellectual property” significantly
Limiting negative
higher—in fact, higher than safety and environmental impacts 2.8% 6.8% 18.5% 17.9% 16.5% 17.3% 19.6%
0% 20% 40% 60% 80% 100%
reliability—unfortunately highlighting
Figure 8. Business Impact Priorities
a disconnect compared to industrial
sectors, like energy and manufacturing.

SANS 2024 State of ICS/OT Cybersecurity 9


Technology Adoption in ICS/OT Environments: Cloud and AI
Cloud adoption in ICS/OT environments surged in 2024, with 39% of
respondents using cloud-based services. This marks a major shift from
traditional on-premises solutions, but 45% of respondents still avoid cloud
services due to security and reliability concerns. Interestingly, the industrial
sector matters most when considering
cloud adoption. Energy sector respondents Table 1. ICS Cloud Adoption 2023–2024 Comparison
ICS Cloud Category 2023 Usage 2024 Usage Change
overwhelmingly do not use the cloud (at half
Remote monitoring only of configuration 40.1% 55.8% +15.7%
the adoption rate [18%] of other sectors). This and analysis of operations telemetry
is likely due to regulatory uncertainty with Remote storage of data historian data 39.4% 34.7% –4.7%
Connection for third-party managed ICS/OT services
standards like NERC CIP, which currently do (managed security service provider [MSSP])
32.9% 27.4% –5.5%

not easily allow cloud usage within the North Remote processing of data historian data 29.5% 29.5% —
American Bulk Electric System. Remote control of engineering field devices 25.8% 28.4% +2.6%
Process optimization 22.7% 25.3% +2.6%
Table 1 outlines striking trends in how cloud Business continuity/disaster recovery planning 22.4% 33.7% +11.3%
services are being used compared to last year’s Remote control of engineering operations 22.0% 31.6% +9.6%
(human–machine interface [HMI] in the cloud)
survey. For example, the increase in cloud usage
Virtualized controllers 18.0% 15.8% –2.2%
for remote monitoring of configuration and Other 9.6% 4.2% –5.4%
analysis of engineering operations telemetry
jumped from 40% to 56%, a significant 16% increase. Similarly, there has been
an 11% rise in the use of cloud services for business continuity and disaster
recovery planning, reaching 34% in 2024. The moderate jump (+10%) in HMI
in the cloud may raise some eyebrows across the ICS/OT security community.
That said, despite this increased usage, organizations are taking a cautious
approach. Seventy-nine percent of respondents conduct risk assessments
before cloud deployments, demonstrating a strong focus on risk management
regarding the cloud.

We asked respondents about their use of artificial intelligence (AI) in


ICS/OT environments, a new topic in this year’s survey. The results show
that AI adoption is still nascent, with only 10% of respondents using AI
in both enterprise IT and ICS/OT networks. Another 19% are testing AI in
lab environments, while 27% are limiting AI to enterprise IT environments,
exploring its potential rather than fully integrating it into their industrial
operations. A sizable 33% report no use or testing of AI at all, highlighting
the early stages of AI in the industrial control sector.

SANS 2024 State of ICS/OT Cybersecurity 10


That said, there is considerable interest
What AI technologies or solutions do you currently have in use in your industrial
in AI, with organizations planning to organization? What new AI technologies or solutions is your organization looking to
deploy AI technologies in the next 18 deploy in the next 18 months? Select only those that apply.
months across multiple categories, In Use Planned
as seen in Figure 9. The areas of 70%
65.7%
63.8%
greatest interest include autonomy 60% 58.1%
(64% planned), computer vision 50.3% 49.7% 51.8%
50% 48.2%
(58% planned), and decision science
41.9%
(66% planned). Natural language 40% 36.2%
34.3%
processing (NLP), the common category 30%
of generative AI used for consumer-
20%
grade tools like ChatGPT and Copilot,
is currently in use across 50% of 10%

respondents using AI, with a nearly 0%


Natural language Machine Autonomy Decision science Computer vision
identical set of respondents planning processing learning
future use. This, as well as machine Figure 9. Current and Planned Usage
learning (ML) usage, is arguably the most mature AI technology category. of AI Categories

Despite the limited current use, organizations are proactively establishing AI


cybersecurity policies, with 31% having policies that cover IT use cases and 12%
including both IT and OT. This indicates a growing awareness of the need to
address the cybersecurity implications of AI for industrial organizations.

This year’s survey asked specifically about AI technologies following the


categories from the “AI Index,” which identifies the categories as follows:5
• N
 atural language processing (NLP)—NLP focuses on enabling machines to
understand, interpret, and generate human language. It powers applications
like chatbots, language models, and automated translation systems.
• M
 achine learning (ML)—ML involves training systems to learn patterns from
data to make decisions or predictions. It’s a key driver in AI advancements,
particularly in tasks like recommendation engines and predictive analytics.
• A
 utonomy—Autonomy refers to AI systems’ ability to perform tasks without
human intervention. It is often seen in robotics, self-driving cars, and
autonomous drones.
• D
 ecision science—This area uses AI to support decision making by analyzing
data to provide actionable insights. It’s widely applied in fields like
economics, healthcare, and logistics for optimization and strategy.
• C
 omputer vision—Computer vision enables AI to interpret and understand
visual information from the world. It is used in image recognition, facial
detection, and even self-driving technology.

5
“The AI Index,” [Link]

SANS 2024 State of ICS/OT Cybersecurity 11


The SANS Five ICS Cybersecurity Critical Controls
The SANS Five ICS Cybersecurity Critical Controls, published in November 2022, serve
as foundational guidance for securing ICS and OT environments.6 These controls help
organizations mitigate risks and ensure the safety and reliability of critical infrastructure.
In this report, we use these controls as broad categories to analyze current trends and
guide the enhancement of industrial cybersecurity programs.

The SANS Five ICS Cybersecurity Critical Controls are:

• I CS incident response—Focuses on developing and maintaining a tailored incident


response plan to ensure resilience and swift recovery in ICS environments

• D
 efensible architecture—Emphasizes the design and implementation of robust
ICS architectures that support visibility, segmentation, and process communication
enforcement

• I CS network visibility and monitoring—Advocates for continuous network security


monitoring with protocol-aware tools to enhance visibility into ICS interactions and
identify vulnerabilities

• S
 ecure remote access—Stresses the importance of securing remote access to ICS
networks, particularly against threats from hybrid work structures and supply chain
vulnerabilities

• R
 isk-based vulnerability management—Prioritizes the management of ICS
vulnerabilities based on risk, focusing on those that could enable adversary access
or disrupt operations

Each section of this report will expand on these controls and link them to specific
findings and trends to aid organizations in growing and maintaining their ICS/OT
security programs.

SANS ICS Cybersecurity Critical Control #1:


2024 Incident Response Trends
ICS/OT incident response plans must be customized to the specific facilities, processes,
and impacts of each industrial environment. The US Department of Homeland Security
warned in 2009 that “standard cyber incident remediation actions deployed in IT business
systems may result in ineffective and even disastrous results when applied to ICS cyber
incidents.” Yet, 15 years later, nearly a third (28%) of respondents still lack an ICS-specific
incident response plan (IRP). This statistic is virtually unchanged from last year’s survey.

SANS 2024 State of ICS/OT Cybersecurity 12


For those that do have a plan (56% of respondents), testing of the IRP is commonly on an
annual basis. And those that test annually have largely based their plans on standards
like NERC, ISA/IEC, and the like. Interestingly, respondents that test more often (quarterly
or monthly) represent a small fraction (16% and 8% of
respondents, respectively), and typically have a broader Those that test more often have a broader set of IRP influences,
like standards, threat intelligence, and consequence-driven
set of IRP influences, including standards, threats, and
engineering scenarios, indicating increased maturity.
consequence-driven engineering scenarios.

Regular ICS-specific IRP testing, not surprisingly, correlates to more informed capabilities
for ICS incident response. For example, an impressive number of annual testers have
exercised an ICS network outage resulting in production outages (65%) and are confident
they can operate in manual mode (66%). However, this is dwarfed by those who test
quarterly (75% have exercised an ICS network outage and 72% can operate their ICS in
manual mode). Respondents who tested their IRP monthly were true masters of their
craft, with nearly 90% having exercised such
What do you include in your ICS/OT incident response plan testing?
outages. Those that train regularly clearly
Select all that apply.
have the upper hand in mature ICS incident
Paper-based tabletop exercises 66.7%
response capabilities.
Simulated ICS/OT cyber attack with
technical hands-on experience
57.4%
When asked about what types of exercises
Operational drills 48.2%
are performed, respondents leveraged a
ICS/OT cybersecurity range
environments using active tools
34.4%
large range of capabilities, with paper-based
Other 3.6%
tabletop exercises being the most widely
0% 10% 20% 30% 40% 50% 60% 70%
used, as seen in Figure 10.
Figure 10. IRP Exercise Types
Industrial Impacts from Ransomware in 2024
This year’s survey saw a decrease in respondents reporting ransomware impacts, with only
12% of respondents reporting ransomware incidents in the previous 12 months. Half of
those ransomware attacks impacted ICS/OT networks, and 38% compromised the safety or
reliability of the physical process, as seen in Figure 11. Although the overall trend seems
to have decreased, the impacts are still potentially catastrophic and should be considered
for all ICS/OT-specific incident response programs.

Ransomware Incidents

Ransomware in last 12 months? If yes, systems impacted Was reliability or safety compromised?

11.7% IT network only 38.1% 9.5%


13.9%
Yes Yes
OT/ICS network only 28.6%
38.1%
No No
Both networks 21.4%
 nknown/
U 52.4%  nknown/
U
74.4% unsure unsure
Unknown/unsure 11.9%
0% 10% 20% 30% 40%

Figure 11. Ransomware Incidents over the Past 12 Months

6
“The Five ICS Cybersecurity Critical Controls,” November 7, 2022, [Link]/white-papers/five-ics-cybersecurity-critical-controls/

SANS 2024 State of ICS/OT Cybersecurity 13


Non-Ransomware Incidents What were the initial attack vectors involved in your
Comparatively, there were more reported OT/control systems incidents? Select all that apply.
Compromise in IT allowed
non-ransomware incidents, with 19% of threat(s) into OT/IT network(s)
45.8%

respondents reporting one or more security External remote services 23.7%


incidents over the same period. Internet-accessible device 23.7%

The reported attack vectors have changed Engineering workstation


compromise
20.3%
over the years, as outlined in Figure 12, with Compromised removable media 20.3%
an increased focus on IT-based attack vectors Supply chain compromise 20.3%
allowing threats into ICS/OT networks (which
Drive-by compromise 18.6%
is historically the most commonly reported
Spearphishing attachment 18.6%
attack vector).
Exploit of public-facing application 13.6%
ICS/OT incident response is a team sport with
Data historian compromise 10.2%
multiple stakeholders involved. Over the years,
Wireless compromise 10.2%
the common question of “who would you
Unknown
8.5%
contact during an incident?” has shifted within (sources were unidentified)
Transient cyber asset,
8.5%
the industrial space—specifically for non- including vendor laptops

regulatory government agencies. Unlike other Other 3.4%


0% 10% 20% 30% 40% 50%
stakeholders, there has been a consistent
Figure 12. Initial Attack Vectors
decrease in voluntary reporting and/or
participation with government entities, as seen in Table 2.

Table 2. ICS Incident Response: Who Is Contacted After Detection


2019 2021 2022 2023 2024

Cybersecurity solution provider 35.6% 48.1% 56.5% 43.2% 45.8%

Control system vendor 45.6% 32.7% 34.8% 36.4% 45.8%

Engineering consultant 13.4% 19.2% 34.8% 27.3% 18.6%

Internal resources 59.0% 44.2% 32.6% 37.5% 27.1%

Non-regulatory government organizations 40.6% 32.7% 23.9% 25.0% 11.9%

System integrator 15.1% 11.5% 19.6% 5.7% 25.4%

Security consultant 37.2% 32.7% 17.4% 17.0% 42.4%

IT consultant 18.4% 40.4% 13.0% 20.5% 18.6%

Main automation contractor 8.4% 11.5% 8.7% 13.6% 16.9%

Other 2.1% 3.8% 0.0% 1.1% 5.1%

IT security team 33.0% 50.8%

SANS 2024 State of ICS/OT Cybersecurity 14


Actions an Attacker Takes to Compromise an ICS Facility ICS attack
Attacker IT Attacker action ICS capability Attack ICS attack Attack adjustments execution
entry point pivot to ICS development validation delivery and modifications

ICS Compromise-to-Detection Gap


Detection-to-Containment Gap
Containment-to-
Remediation Gap

Common IT ICS asset hardening ICS threat Incident Recover operational


security controls and controls detection declared integrity
Traditional ICS ICS situational awareness Containment and
perimeter controls and data protection eradication
Actions the Defender Takes and/or is Reliant on to Thwart the Attack

Figure 13. ICS Cyber Incident Timeline

Speaking of detection, our


On average, how much time elapsed between the initial compromise and detection
industry has historically had (i.e., the dwell time)? How long from detection to containment?
difficulty with how long it takes How long from containment to remediation?

to detect a compromise and 36.2% Compromise-to-Detection Gap


remediate. This is partially due
30% 25.9%
to the lack of visibility in the
ICS environment, as well as the 20%

skillsets required to recover from 10.3% 10.3%


10% 6.9%
an ICS cyber incident, which is 5.2% 5.2%
a blend of IT and OT knowledge 0%
< 6 hours 6–24 hours 2–7 days 8–30 days 1–3 months 4–6 months Unknown
and experience. Consider the
timelines in Figure 13 for a Detection-to-Containment Gap
30% 26.8%
traditional IT cyber incident that 25.0%
pivots to OT environments. 20%
14.3% 14.3%
The top timeline identifies the
10% 8.9%
7.1%
steps required by an attacker to 3.6%
execute an ICS cyber attack; the 0%
< 6 hours 6–24 hours 2–7 days 8–30 days 1–3 months 4–6 months Unknown
bottom highlights the potential
defender activities that can be Containment-to-Remediation Gap
30% 26.3%
used to detect, deter, prevent,
21.1%
and recover from such an attack. 20%
19.3%
15.8%
Based on the 2024 survey data,
8.8%
detection occurs relatively 10%
3.5% 3.5%
quickly (often less than 24 0.0% 1.8%
0%
hours), but the later stages of the < 6 hours 6–24 hours 2–7 days 8–30 days 1–3 months 4–6 months 7–12 months > 1 year Unknown

incident response lifecycle take Figure 14. Detection, Containment, and Remediation Gaps for ICS Incidents
considerable effort—with some
remediation times stretching to a
year or more, as seen in Figure 14.

SANS 2024 State of ICS/OT Cybersecurity 15


ICS-specific incident response still proves to be a challenge for industry.
We’re Getting Quicker…
Although many organizations are making progress, a significant portion
still lack adequate preparedness, testing, and integration across IT and OT Over half of respondents that had an incident
reported a compromise-to-detection gap of less
functions. For ICS environments, where the stakes are exceptionally high,
than 24 hours. In 2019, the same number had a
improving incident response capabilities should be a top priority, guided by compromise-to-detection gap of 2–7 days.
industry standards and tailored to the specific risks to safety and reliability.

SANS ICS Cybersecurity Critical Control #2:


2024 Defensible Architecture Trends
As mentioned earlier, technology is the largest budget category for ICS security programs.
After establishing an ICS-specific incident response program based on scenarios and
safety/reliability risks, organizations should deploy defensible architecture technologies
and strategies tailored to the incidents that could affect the industrial process and
human safety.
Rank the following ICS/OT cybersecurity architecture priorities for your organization.
When asked about defensible
Rank #1 Rank #2 Rank #3 Rank #4 Rank #5 Rank #6 Rank #7
architecture priorities,
1.5% 1.5%
Network protections, including
respondents clearly pointed boundary protection 55.6% 23.2% 15.1% 1.9% 1.2%
toward network segmentation Asset hardening and security, 3.9%
including configuration management
14.7% 37.8% 19.7% 15.8% 6.9%
between IT and OT as the top and removable media security 1.2%

concern. Compromised IT systems Software security,


including validation 1.9% 8.1% 20.8% 26.3% 20.5% 15.8% 6.6%
were the top vector for ICS/OT Access controls, including
identity management 10.8% 18.1% 22.4% 12.0% 22.0% 10.0% 4.6%
incidents in 2024, so it makes
Data security, including
sense to see network protections availability and integrity 8.9% 6.6% 10.4% 24.7% 23.9% 12.4% 13.1%

ranked so high. Other priorities Workforce management, including


training and awareness 12.4% 9.7% 15.8% 46.3%
4.6% 3.1% 6.9%
can be seen in Figure 15. Supply chain risk, including
product lifecycle management 14.7% 40.2% 26.6%
Most respondents (64%) based 3.1% 3.1% 4.6% 7.3%
0% 20% 40% 60% 80% 100%
their architecture on standards, Figure 15. Defensible Architecture Ranked Priorities
threats, trends, and scenarios with safety and reliability
impacts. A large majority (74%) documented the IT–OT
22% of respondents had one or more ICS/OT assets dual-homed
boundary for industrial networks. However, nearly a
with IT networks or residing directly on the enterprise IT network.
quarter (22%) had some ICS/OT systems dual-homed
with IT networks or on the enterprise IT network,
exposing them to greater risks. Alarmingly, 34% Please describe your method of connectivity between your
of these respondents also had their safety internal OT/control system network and safety instrumented
systems (SIS) and/or functional safety systems.
instrumented systems (SISs) on the same IT
Restricted network (firewall) 47.9%
network. SIS is the last defense during both
a physical safety event and a potential ICS Air gap or physically isolated 16.5%

cyber incident, and should not be connected Shared network (flat or routed) 14.1%
Restricted to mechanical
to enterprise IT networks due to the potentially and electrical, not logical 8.1%
interconnections between systems
disastrous impacts associated with an SIS failure.
Converged or comingled logic
and safety control functionality 7.4%
Luckily, despite these fringe cases, industry in control components
understands the importance of separating the Other 6.0%

SIS, as seen in Figure 16. 0% 10% 20% 30% 40% 50%

Figure 16. SIS Connectivity

SANS 2024 State of ICS/OT Cybersecurity 16


Boundary protection is just one element of
What security technologies or solutions do you currently have in use
building a defensible ICS architecture. In the in your OT environment? What new technologies or solutions would you
2024 survey, we asked respondents to outline most want to add for control system security in the next 18 months?
Select all that apply or indicate not applicable (N/A).
which technologies they have in place and
which they are planning to implement over In Use Planned

81.3%
the next 18 months. The full list can be found Access controls
13.2%
in the Appendix. Of the nearly 40 technologies Backup and recovery 74.4%
processes and tools 17.6%
outlined in the survey, we captured the top five
Endpoint detection and response 73.3%
currently implemented in Figure 17. (EDR), including traditional antivirus 16.5%
Segmentation between control 66.3%
Over the past five years, several of these systems and higher risk networks 21.2%
categories have seen massive jumps in Secure remote access with 64.8%
multifactor authentication 21.2%
implementation across industry. For example, in
0% 20% 40% 60% 80%
2019, 72% of respondents had access controls in
Figure 17. Top Five In-Use ICS Security Technologies
place for ICS, compared to 81% today. Similarly,
endpoint detection and response (EDR) was
What security technologies or solutions do you currently have in use
reported as being used by 53% of respondents in your OT environment? What new technologies or solutions would you
in 2019; however, by 2024 there was a 20% jump most want to add for control system security in the next 18 months?
to 73% using EDR. Interestingly, due to the larger Select all that apply or indicate not applicable (N/A).

penetration of the technologies in the top five, In Use Planned

most of the planned rates are relatively low in ICS-specific cybersecurity 37.7%
metrics or dashboards 37.0%
relation to other technologies being deployed ICS network security monitoring 52.4%
in ICS/OT environments. In comparison, the and anomaly detection solutions 32.6%
Control system enhancements/ 45.1%
most-planned technologies in Figure 18 tell an upgrade services 31.5%
interesting story for what the next 18 months in ICS-specific cybersecurity training
49.1%
30.8%
ICS security may look like.
ICS-specific incident response 45.8%
tabletops or simulations 30.0%
Figure 18 shows the most-planned ICS
0% 20% 40% 60% 80%
security technologies. Except for ICS-specific
Figure 18. Most-Planned ICS Security Technologies
cybersecurity metrics and dashboards, these
technologies are already in use by nearly half
In 2019, OT-specific monitoring was used by only 33% of
of respondents, but over 30% more plan to use respondents (compared to 52% in 2024), demonstrating a massive
them. This suggests a possible shift toward growth across this technology category in only five years.
non-technology spending, like training and
tabletops. ICS network security monitoring What security technologies or solutions do you currently have in use
stands out as the only highly planned in your OT environment? What new technologies or solutions would you
technology, with over 50% current deployment. most want to add for control system security in the next 18 months?
Select all that apply or indicate not applicable (N/A).
Finally, three technology categories for
In Use Planned
defensible ICS architecture stood out for being
Software bill of materials (SBOM)
25.3%
the least deployed—but with a surprisingly large 27.5%
25.6%
number of respondents planning to use them Industrial cloud security
23.4%
over the next 18 months, as seen in Figure 19. Security orchestration, automation, 28.2%
and response (SOAR) 29.7%
0% 20% 40% 60% 80%

Figure 19. Least Used ICS Security Technologies with High Planned Rates

SANS 2024 State of ICS/OT Cybersecurity 17


Software bill of materials (SBOM), industrial cloud security,
We often describe ICS/OT as the “M&M” model: hard shell,
and security orchestration, automation, and response (SOAR) gooey center. This is why we focus a lot on IT–OT boundaries
were the least used technologies within the 2024 survey—but (i.e., the hard shell). However, security professionals need
each has higher-than-average planned implementations for to also focus on toughening up that gooey center. Recall,
for example, that replication through removable media
the next 18 months, indicating that these technologies may
was a top attack vector in 2024. To combat this, 69% of
become more common across ICS security programs soon. respondents have a formal program for removable media
risks, and 70% have threat detections enabled for removable
SANS ICS Cybersecurity Critical Control #3: media in their ICS/OT environments.
2024 ICS Network Monitoring Trends
Industrial cybersecurity is evolving rapidly, and so are the capabilities of security
operations centers (SOCs) that monitor and respond to threats in ICS environments. This
year’s survey reveals how organizations are integrating IT and OT SOCs, enhancing ICS-
specific network monitoring, and correlating data for comprehensive analysis.

Establishing and Integrating OT-Specific SOCs


Nearly 30% of respondents have integrated their IT and OT SOCs, a sign of convergence
between these domains. This allows for a unified and efficient response to threats,
leveraging both IT and OT strengths. Most merged IT–OT SOCs report to a CISO (58%), map
to standards (84%), and have a shared IT–OT budget (54%).

Many organizations have recognized the importance of a dedicated SOC, with 63% having
one. That said, 45% have no OT SOC capabilities, leaving a significant gap in threat
detection and response for ICS/OT environments, as shown in Figure 20.

Does your organization have what Select the statements that describe your
could be considered a SOC? SOC capabilities.

We have a merged IT and OT SOC. 29.4%

9.6% We have an internal IT SOC. 25.3%

We outsource our IT SOC to an MSSP. 14.7%


Yes

27.7% We outsource our OT SOC to an MSSP. 11.8%


No
62.7% We have an internal OT SOC. 8.8%
Unknown/unsure
We don’t have a dedicated SOC. 5.3%

Other 4.7%
0% 10% 20% 30%

Figure 20. SOC Trends and Capabilities

SANS 2024 State of ICS/OT Cybersecurity 18


Building SOC Capabilities with ICS-Specific Monitoring
Deploying ICS-specific network monitoring appears to
Establishing a SOC is a potential first step for industrial have a real impact on incident response. Respondents
organizations, but expanding capabilities with ICS-specific that had extensive ICS/OT network monitoring capabilities
reported faster-than-average compromise-to-detection
network monitoring is crucial. The survey reveals a wide range
times, with over 50% detecting within 6 hours!
of monitoring capabilities across organizations. Although
52% of respondents have limited ICS/OT network monitoring,
26% have extensive monitoring solutions, reflecting a growing Select the statement that best describes your
ICS/OT network monitoring capabilities.
awareness of the need for ICS visibility.

However, Figure 21 shows that 12% of organizations have


 e have limited
W
no ICS/OT network monitoring capabilities, exposing them 9.8% ICS/OT network
monitoring
to significant risk of undetected cyber threats and severe capabilities.
12.2%
disruptions. For organizations with established SOCs,  e have extensive
W
ICS/OT networking
enhancing network monitoring capabilities is a natural and 51.7% monitoring
capabilities.
necessary progression. 26.2%  e have no ICS/OT
W
network monitoring
Correlating Data for Comprehensive Analysis capabilities.

Unknown/unsure
Data collection and correlation across various ICS
components is key for effective ICS/OT SOCs. The survey
shows that most organizations (70%) collect and correlate Figure 21. ICS-Specific Network Monitoring Coverage
data from ICS server assets, and 64%
from network devices like firewalls From which control system components are you collecting and correlating data?
Select all that apply.
and routers.
ICS server assets running commercial
70.1%
However, as Figure 22 shows, OS (Windows, Unix, Linux)
ICS network devices (management
industrial organizations should also interfaces, printers, firewall, switches, 63.9%
routers, gateways, protocol security)
include less obvious components, ICS operator assets (HMI, workstations)
running commercial OS (Windows, Unix, Linux)
60.6%
such as serial/non-routable networks ICS engineering assets (engineering
workstations, instrumentation laptops,
and embedded controllers, to calibration and test equipment) running
58.5%
commercial OS (Windows, Unix, Linux)
gain deeper visibility and identify
ICS network telemetry (taps/spans) 36.1%
potentially hidden threats in high-
Data historian 34.9%
impact facilities.
Remote access appliances, including modems 33.6%

Physical access systems 32.4%

Wireless communication devices and protocols 29.5%

Removable media 27.0%


Embedded controllers or
components (e.g., PLCs, IEDs)
26.6%

Field communications 20.3%

Serial/non-routable networks 12.4%

Other 4.6%
0% 10% 20% 30% 40% 50% 60% 70%

Figure 22. Data Collection and Correlation Across ICS/OT Components

SANS 2024 State of ICS/OT Cybersecurity 19


Leveraging Threat Intelligence for Active Defense
With monitoring and data correlation in place, the next step is to leverage threat intelligence
to make sense of the data and preemptively address potential threats. To do so, 56% of
organizations use ICS-specific threat intelligence, relying mostly on external sources, with
vendor-provided intelligence being the most common (79%).

Internal data can further refine this threat intelligence, as seen in Figure 23, which can
include a mix of automated and human-driven processes, with 71% of respondents using
threat detection across their ICS/OT security program. Of those, 70% use automated means,
such as asset-based EDR, to detect threats within OT networks. Additionally, 40% utilize ICS
protocol-aware network monitoring solutions, and 48% rely on anomaly-based detection
engines. These tools, combined with trained ICS staff conducting threat hunting (38%), create
a layered defense that can significantly improve threat detection and response capabilities.

Are you implementing any processes to What processes are you using to detect threats within
detect threats within your OT networks? your OT networks? Select all that apply.
We use automated means (like
asset-based EDR) to detect threats.
69.5%

We are using anomaly-based


15.4% 47.5%
detection engines.

Yes We are using ICS protocol-aware


network monitoring solutions.
39.5%
13.9% No We have trained ICS staff to search
for events (threat hunting).
37.9%
70.8% Unknown/unsure
We use a third party to periodically
check our ICS systems.
32.2%

We use a third party to consistently


18.1%
check our ICS systems.
0% 10% 20% 30% 40% 50% 60% 70%

Figure 23. ICS/OT Threat


Third parties can be used to either consistently or periodically check ICS/OT systems, Detection Capabilities
and this year’s survey data shows a healthy use of those opportunities. Even
respondents with extensive monitoring capabilities and a merged IT–OT SOC use these
third parties, implying that there is a benefit in either additional
coverage, external expertise, or both when examining ICS/OT threats. Even respondents that said they have extensive
This year’s survey shows consistent advancements in the monitoring capabilities and a merged IT–OT SOC report using third
parties for help detecting threats, implying that there
of ICS networks, with SOCs playing a central role in this evolution.
is a benefit in either additional coverage, external
Organizations are fostering stronger cybersecurity defenses by expertise, or both when examining ICS/OT threats.
creating ICS-enabled SOCs, improving monitoring tailored to
industrial environments, broadening data correlation, and utilizing threat intelligence.
Nevertheless, the survey identifies that there is room for improvement, especially in
terms of extending monitoring abilities.

SANS 2024 State of ICS/OT Cybersecurity 20


SANS ICS Cybersecurity Critical Control #4:
2024 Secure Remote Access Trends
Remote access has been a difficult topic across ICS/OT security programs. Unlike IT
networks, ICS/OT environments must balance access requirements with potential
reliability and safety impacts. These extra considerations are exacerbated by the
isolated locations of many industrial sites, where support is often limited. Remote
access by vendors, contractors, and internal staff has increased over the past few
years. COVID lockdowns did not help the situation when, for example, many vendors
urgently provided their remote access tools for free. Temporary solutions, however,
can create permanent risks. What was once a carefully planned activity became
reactionary, making the need for secure remote access a top critical control.

Understanding remote access issues begins with recognizing the existing connectivity in
industrial settings. A little over half (53%) of those surveyed have documented all of their
connectivity outside the ICS/OT perimeter. Such documentation
Do you have a remote access policy or program?
increases to 63% if the ICS program is mapped to cybersecurity
standards, and increases even further (79%) if the organization
7.2%
also has extensive ICS network monitoring capabilities (as covered  es, we have a formal
Y
8.7% remote access policy
in Figure 21). This highlights how both governance and technology or program for critical/
high-risk environments.
can aid organizations in their maturity across multiple security
 es, we have an
Y
capabilities, as well as the importance of knowing your industrial 22.0% 62.1% informal remote access
policy or program.
assets and how/why they have external connectivity.
No
Once the network connectivity has been evaluated, organizations
Unknown/unsure
typically invest in a formal remote access policy or program.
As highlighted in Figure 24, 84% of respondents have either an
informal or formal policy in place for remote access. Figure 24. Remote Access Policy and Program Implementation

Policies can only go so far—where the rubber meets


the road is when specific technical capabilities of If an organization maps its ICS cybersecurity program to standards and
the remote access are secure. As seen in Figure has extensive ICS monitoring capabilities, it is 53% more likely to have
documented all external connections to its industrial environment.
25, multifactor authentication (MFA) is the most
popular security control for remote
access, followed by using a jump Which statements describe your remote access capabilities?
Select all that apply.
box to establish a trusted path to
We require multifactor authentication when
the ICS/OT environment. These remotely accessing the ICS/OT environment.
74.9%
Our remote access capabilities include
approaches are largely driven using a jump box to establish trusted 71.0%
paths to the ICS/OT environment.
by external factors, including ICS
We retain logs for all remote access sessions. 63.3%
security standards, cyber insurance,
We have the ability to kill a remote access
54.1%
and regulation—and, architecturally, session if an anomaly is detected.
We regularly (at an organizationally
are recommended best practices. defined time) verify who has remote 48.3%
access rights to ICS/OT networks.
We use next-gen secure remote
access solutions that include session 32.9%
recordings and least-privilege access.
We use dial-up connectivity in
our remote access program.
3.9%

Other 5.3%
0% 20% 40% 60% 80%

Figure 25. Secure Remote Access Capabilities

SANS 2024 State of ICS/OT Cybersecurity 21


Interestingly, one-third (33%) of those surveyed reported having a next-gen secure remote
access platform, and just over half (54%) could terminate a remote access session if an
anomaly were detected. Compared to the technology plans in the Appendix, where a
significant majority of those questioned utilize secure remote access (65%), a moderate
share (21%) plan to deploy it over the next 18 months. This could indicate a potentially
interesting shift as industry evaluates older, legacy remote access platforms for newer
technology with enhanced security capabilities.

SANS ICS Cybersecurity Critical Control #5:


2024 Risk-Based Vulnerability Management Trends
ICS/OT vulnerabilities vary in their severity and Percentage of Respondents Performing an ICS/OT Cybersecurity
exploitability. Vulnerability management does not mean Assessment in the Previous 12-Month Period
“patch management” for many industrial organizations; 80%
77.5%
each vulnerability needs to be assessed for its potential 76.0% 76.2%
74.9%
impact and the attack vector required for exploitation. 75%

To understand these impacts and risks, industrial 70% 69.0%


organizations typically start with some sort of security
assessment. Most organizations (71%) reported having 65%

conducted security assessments of their control systems,


aiding their understanding of system vulnerabilities. Of 60%
2019 2020 2021 2022 2023 2024
those that have performed security assessments, about Figure 26. 2019–2024 Trend of ICS/OT Cybersecurity Assessments
75% had performed the assessment in the past year. This is on
par with previous annual surveys, as seen in Figure 26. Annual ICS/OT cybersecurity assessments appear to be “table
stakes” for any industrial organization; the past five years of
Who performs the assessments has shifted somewhat,
data shows about 75% of respondents regularly perform one.
however. ICS/OT cybersecurity consultants performed more
assessments in 2024, increasing by 7% from
What types of security assessments has your organization performed in the
25% in 2019–2023 to 32% in 2024. Internal
past 36 months in your ICS/OT environment? Select all that apply.
ICS security teams saw a moderate 3%
Paper-based vulnerability assessment:
increase from previous years, implying that evidence review, network diagram
review, configuration management
51.2%
both IT consultants and internal IT teams artifact review, and similar
Internal audit 48.0%
are performing fewer ICS/OT assessments,
Active vulnerability assessment
offset by more subject-matter experts in a production environment
41.0%
Active vulnerability assessment
specific to industrial security. That said, in a test environment
40.6%

the most popular assessment type is a Regulatory audit 38.1%


paper-based vulnerability assessment Penetration test and/or red/purple
25.8%
teaming in a test environment
(as seen in Figure 27), with fewer Penetration test and/or red/purple
25.0%
teaming in a production environment
respondents leveraging more technical
Unknown 9.0%
active vulnerability assessments (in test or
None 5.3%
production) and fewer still performing ICS-
Other 2.0%
specific penetration testing.
0% 10% 20% 30% 40% 50%

Figure 27. ICS/OT Cybersecurity Assessment Types and Popularity

SANS 2024 State of ICS/OT Cybersecurity 22


At what levels of the Purdue Model is the penetration testing being performed against?

26.3%
Yes

73.7%
No

37.7%
Yes
62.3%
No

47.4% 52.6%
No Yes

42.1%
No 57.9%
Yes

52.6% 47.4%
No Yes

35.1%
Yes
64.9%
No

20.2%
Yes

79.8%
No

Figure 28. Penetration Testing


When penetration tests are performed, they are mostly performed across the DMZ or Across the Purdue Model

Level 3 of the Purdue Model, as seen in Figure 28. Although difficult (and requiring ICS-
specific skill sets and knowledge), penetration tests can be performed at lower levels of
the Purdue Model when safety and reliability concerns are taken into consideration.

The benefits of a standards-based ICS/OT cybersecurity program are clear: organizations


that follow any security standard are 15% more likely to conduct a security assessment
and penetration test. The best results, however, come from
combining both a standards-based approach and ICS- Organizations that both use a standards-based approach to
specific threat intelligence; this boosts the rates of security their ICS/OT cybersecurity program and ingest ICS-specific
assessments to 88% (a 1.2x increase) and penetration tests threat intel perform more in-depth cybersecurity assessments.

to 74% (a 1.5x increase).

SANS 2024 State of ICS/OT Cybersecurity 23


There are, of course, other ways to detect
What processes are you using to detect software or hardware vulnerabilities
vulnerabilities. As outlined in Figure 29, within your control system networks? Select all that apply.
the most common technique is continuous Continuous monitoring
for vulnerabilities
51.7%
monitoring across ICS/OT assets (52% of
Passive network monitoring 46.6%
respondents), followed closely by passive
Vendor notifications for vulnerabilities 41.9%
network monitoring (47%). These methods
Collaboration with vendors during
reflect a shift toward more proactive factory acceptance testing (FAT) 41.0%
and site acceptance testing (SAT)
and continuous forms of vulnerability Monitoring public notifications from
vendors, information sharing and
38.5%
management, leveraging both automated analysis centers (ISACs) and computer
emergency readiness teams (CERTs)
tools and collaborative efforts with vendors. Baseline configuration and control
35.0%
logic program comparison
Assessing and tracking detected Passive endpoint analysis (for
31.6%
example, on engineering workstations)
vulnerabilities can take many forms; 46% of Use of active defense techniques for
30.3%
threat protection and detection
respondents use configuration management Periodic vulnerability scanning
during system downtime
29.9%
artifacts for such purposes. When asked Forensic analysis for unusual
20.1%
operations and conditions
about coverage across their ICS/OT
Software bill of materials
(SBOM) monitoring
16.7%
environments, 53% of respondents claimed
Other 4.7%
that their configuration baselines could be
0% 10% 20% 30% 40% 50%
leveraged for at least half of their assets.
Figure 29. Vulnerability Detection
Once detected, organizations have several available options for implementing Techniques
patches or finding a workaround, as outlined in Figure 30 from the U.S.
Department of Homeland Security.

If patching is ultimately pursued, the most popular method used by respondents


(34%) is to pretest and apply vendor-validated patches on a defined schedule.

Figure 30. DHS Patch Urgency Decision Tree7

7
“Recommended Practice for Patch Management of Control Systems,”
[Link]/uscert/sites/default/files/recommended_practices/RP_Patch_Management_S508C.pdf

SANS 2024 State of ICS/OT Cybersecurity 24


Next Steps for Industry
This year’s SANS State of ICS/OT Cybersecurity report highlights both progress and
ongoing challenges in the field. The insights provided should be used to drive tangible
improvements in cybersecurity programs. Organizations are encouraged to benchmark
their own efforts against these findings to inform their strategies for 2025 and beyond—
whether in budgeting, workforce development, or technology adoption.

Adopt a Standards-Based Program with Centralized Governance


and ICS-Specific Threat Intelligence
Data shows that ICS/OT programs that integrate standards-based frameworks, centralized
governance, and ICS-specific threat intelligence are more mature and capable of
managing cybersecurity risks. These programs are better positioned to anticipate, detect,
and respond to threats, leading to a more secure and resilient environment. Organizations
should prioritize adopting these approaches to strengthen their security posture and
address the unique risks within industrial environments.

Prioritize Workforce Development


The maturing ICS/OT cybersecurity workforce requires active leadership to continue its
growth. Leaders must focus on attracting and retaining talent, investing in professional
development, and facilitating knowledge transfer from experienced professionals to newer
team members. This is crucial for building a workforce that is not only technically skilled
but also deeply knowledgeable about the specific challenges of ICS/OT security.

Evaluating Technology Adoption


The pace of technology adoption in the ICS/OT space is another interesting trend
identified in this report. The past five years have seen substantial growth in the
implementation of ICS/OT-specific network monitoring, endpoint protection,
and access control technologies. Although considered slower than traditional IT
deployments, there are not only metrics showing some considerable growth, but also
plans to continue to leverage new technologies for ICS/OT cybersecurity. The rapid
evolution of the ICS/OT cybersecurity landscape demands that organizations remain
agile and proactive in adopting advanced technologies.

SANS 2024 State of ICS/OT Cybersecurity 25


Final Thoughts
The insights from this report should serve as a catalyst for action, not just as data points
to be filed away. Organizations must critically assess their security postures and use
these findings to shape strategic plans for the future. By adopting standards-based
governance, prioritizing workforce development, and embracing advanced technologies,
organizations can effectively manage the complex risks facing critical infrastructure.

The path forward is clear: proactive, informed, and strategic actions are essential to
ensuring the security and resilience of our ICS/OT environments. With the right focus
and resources, organizations can meet today’s challenges and be well-prepared for the
threats of tomorrow.

Sponsor

SANS would like to thank this survey’s sponsor:

SANS 2024 State of ICS/OT Cybersecurity 26


Appendix: 2024 Defensible Architecture Technology

Planned and Used ICS Security Technologies

In Use Planned

Access controls
81.3%
13.2%

Anomaly detection tools


59.0%
26.0%

Application allowlisting
50.5%
26.0%

Asset identification and management


62.6%
28.6%

Backup and recovery processes and tools


74.4%
17.6%

Cloaking device IP addresses


27.8%
20.9%

Continual authentication/authorization
42.9%
27.1%

Control system enhancements/upgrade services


45.1%
31.5%
Control system network security monitoring software and solutions, including internal 50.9%
network security monitoring (INSM) and network detection and response (NDR) 32.2%

Device access controls and policy-based allowlisting


55.7%
20.5%

Device allowlisting
50.2%
20.5%

Endpoint detection and response (EDR), including traditional antivirus


73.3%
16.5%

ICS configuration management


49.1%
28.2%

ICS network security monitoring and anomaly detection solutions


52.4%
32.6%

ICS-specific cybersecurity metrics or dashboards


37.7%
37.0%

ICS-specific cybersecurity training


49.1%
30.8%

ICS-specific incident response tabletops or simulations


45.8%
30.0%

ICS/OT firmware security, including software authentication and/or validation


37.4%
31.5%

ICS/OT-specific cybersecurity assessment and/or audit


54.9%
28.9%

Identity-based policy orchestration


34.8%
27.1%
Impact analysis for ICS/OT cyber incidents, including cyber-informed 31.1%
engineering (CIE) or “materiality” designations for compliance 31.1%

Industrial cloud security


25.6%
23.4%

Industrial data loss prevention (DLP)


32.6%
22.3%

Industrial intrusion prevention systems (IPS)


39.9%
26.4%

Industrial-aware intrusion detection system (IDS)


48.0%
27.1%
0% 10% 20% 30% 40% 50% 60% 70% 80%

CONTINUED

SANS 2024 State of ICS/OT Cybersecurity 27


Planned and Used ICS Security Technologies (continued)

In Use Planned

Monitoring, log analysis, and/or correlation


64.5%
24.2%

Protocol security
49.5%
23.8%

Secure remote access with multifactor authentication


64.8%
21.2%

Security automations and workflows to decrease manual effort and human error
37.4%
31.9%

Security awareness training for staff, contractors, and vendors


64.1%
19.4%

Security orchestration, automation, and response (SOAR)


28.2%
29.7%

Segmentation between control systems and higher risk networks


66.3%
21.2%

SOC for ICS/OT or integration into enterprise SOC


39.9%
29.3%

Software bill of materials (SBOM)


25.3%
27.5%

Software-defined network segmentation


39.9%
18.3%

Unidirectional gateway between control systems and higher risk networks


40.3%
22.7%

User and application access controls


62.3%
18.3%

User behavioral analysis tools


36.3%
23.8%

Vulnerability scanning
61.2%
22.0%

Other
3.7%
2.6%
0% 10% 20% 30% 40% 50% 60% 70% 80%

SANS 2024 State of ICS/OT Cybersecurity 28

You might also like