Skip to main content

2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future

Industrial Control Systems (ICS) and Operational Technology (OT) environments power critical infrastructure around the globe, from energy grids to transportation networks. This white paper explores the findings of the 2025 SANS Survey on ICS/OT Security Budgets.

SANS_2025_ICS_OT_Cybersecurity_Budget_Spending_Trends_Challenges_Future (PDF, 3.84MB)

3 Mar 2025
ByDean Parsons
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

OT Network Visibility and Detective Controls in a NERC CIP World

Research Paper

As cyber threats grow and regulations evolve, critical infrastructure must balance compliance and innovation.

  • 20 Aug 2025
  • Tim Conway

NERC CIP-015: Monitoring Deep Inside Critical Networks to Keep Adversaries Outside

Research Paper

The North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Standards (hereinafter referred to as the Standards) require preventive controls to establish Electronic Security Perimeters (ESPs) containing Bulk Electric System (BES) Cyber Systems and to control communications in and out of those ESPs.

  • 14 Aug 2025
  • Tim Conway, Robert M. Lee

SANS 2025 Security Awareness Report

Research Paper

Now in its 10th year, the SANS Security Awareness Report remains the definitive, practitioner-built resource for understanding and managing the human side of cybersecurity.

  • 12 Aug 2025
  • Lance Spitzner

Prioritized Industrial Cyber Defense in Oil and Gas

Research Paper

SANS Institute developed a white paper exclusively for ONE-ISAC members to address the urgent cybersecurity challenges facing the oil and gas sector.

  • 13 Jun 2025
  • Dean Parsons

Be a DLP Hero: How to Quickly Deliver Value from Your DLP Program and Set It Up for Future Success

Research Paper

Download this paper and learn how to launch or strengthen your data loss prevention (DLP) program.

  • 3 Jun 2025
  • Kevin Garvey

Resiliency and Business Continuity in the Cloud Era

Research Paper

In this white paper, Dave Shackleford unpacks today’s evolving cloud threat landscape.

  • 21 May 2025
  • Dave Shackleford

SANS 2025 CTI Survey Webcast & Forum: Navigating Uncertainty in Today’s Threat Landscape

Research Paper

This paper explores results from the SANS 2025 CTI Survey, with insights into how cybersecurity...

  • 20 May 2025
  • Rebekah Brown, Andreas Sfakianakis

Collaborative Mobile App Security Development and Analysis

Research Paper

In this tactical, insight-rich review, Jeroen Beckers shares how to overcome mobile app security challenges and modernize your testing with Corellium’s virtual device platform—built for real-world conditions and faster results.

  • 19 May 2025
  • Jeroen Beckers

A Pebble In the Ocean: Maximizing Log Fidelity In Container Environments

Research Paper

Log fidelity is crucial for Incident Response Teams to investigate and contain cyber incidents but can be difficult to optimize in containerized environments.

  • 17 Apr 2025

Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender

Research Paper

Using the SANS ICS Cyber Kill Chain, the research implemented a representative ICS network to evaluate the effectiveness of security controls for use by small ICS defenders.

  • 14 Apr 2025

ARMO’s Behavioral Cloud Application Detection and Response (CADR) Platform

Research Paper

This paper explores how ARMO Platform is attempting to solve the challenge with the industry’s first behavioral cloud application detection and response (CADR) product.

  • 18 Mar 2025
  • Moses Frost

ASPM: Understanding the New Application Security Landscape

Research Paper

Malicious actors continue to prey on the challenges of rapid software development cycles and cloud computing adoption. This paper examines where an application security posture management (ASPM) solution comes in.

  • 18 Mar 2025
  • Chris Edmundson, SANS Institute

2025 SANS Detection Engineering Survey: Evolving Practices in Modern Security Operations

Research Paper

To dive deep into understanding the current state and future trends of this critical field, SANS has partnered with Anvilogic to conduct a comprehensive survey of Detection Engineering professionals across various industries. Dive into the findings in this whitepaper.

  • 24 Feb 2025
  • Terrence Williams

Empowering Responders with Automated Investigation

Research Paper

This white paper investigates how Binalyze’s AIR platform reduces the overhead of forensic investigations by automating the process of collecting artifacts, triaging the data, and identifying next steps.

  • 18 Feb 2025
  • Megan Roddie-Fonseca

Critical Cybersecurity for Safer Water Management

Research Paper

The paper emphasizes the importance of skilled ICS cybersecurity defenders and ICS-specific security controls aligning with the SANS Five ICS Cybersecurity Critical Controls.

  • 28 Jan 2025
  • Dean Parsons

Google SecOps: The SIEM’s Third Act

Research Paper

Discover how SecOps is ushering in the "SIEM's Third Act" by addressing the limitations of traditional SIEMs and empowering security teams with cutting-edge tools for threat-informed defense.

  • 21 Jan 2025
  • Mark Orlando

Unveiling the Dependency on Network Telemetry: Optimizing Lateral Movement Detection

Research Paper

This study investigates the dependency on network and endpoint telemetry for identifying lateral movement attacks, focusing on the Remote Services technique from MITRE ATT&CK.

  • 17 Jan 2025

Beyond Detection: Using Real Phishing Data to Gauge Security Training Program Success

Research Paper

This paper defines one method of network security monitoring in an organization to find these existing indicators.

  • 7 Jan 2025

Protecting the Poor: A Deep Dive into EBT Skimming and Solutions to Combat It

Research Paper

This paper examines why EBT cards are vulnerable to skimming and explores potential preventive measures.

  • 23 Dec 2024

Recover an RSA Private Key from a TLS v1.2 session

Research Paper

Cyberattacks happen every day.Most organizations have administrative and technical controls...

  • 22 Jun 2022

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.