
Over the past two years, three distinct trends have emerged that have transformed the way industry views cybersecurity, also known as OT security. OTORIO exactly these trends in its new study on OT cybersecurity.
The first trend is the accelerated evolution towards connected manufacturing, particularly in relation to remote operations and supply chain management. Driven by the pandemic and in the hope of becoming increasingly efficient and cost-effective, companies are being forced to digitize their processes. As a result, formerly isolated industrial environments are now exposed to the Internet.
The second trend is the general increase in cybercrime. Just a few years ago, the industry was mainly targeted by state attackers. Only they have the resources to attack critical infrastructure, energy and industrial companies. Today, cybercriminal organizations are using sophisticated tools that were once only available to nation states, causing significant damage. These criminals target industrial environments that they consider “low-hanging fruit” due to accelerated digitization.
The latest trend is tightening laws and regulations, driven by governments taking an increasingly active role in cyber defence. The energy, utilities and transportation sectors are critical to both the economy and national security, driving governments to introduce new regulations and update and evolve existing ones.
To gain better insight into these OT cybersecurity drivers and assess the impact of these trends, OTORIO is conducting a survey of 200 senior cybersecurity leaders. The goal was to find out: Have the companies changed their processes or best practices? How do the new regulations affect them and do they compare to previous new analyses? And most importantly, what are their plans for the future, and will increasing connectivity, OT-related cyber threats, and regulatory interventions herald the art of protecting their business?
The most important results of the study:
98 percent of the responses provided indicated that the level of digital and cyber risks to their operations has increased over the past three years. Concerns about OT cybersecurity are well founded. 67 percent of the responses provided say that risks have increased significantly since 2019, and 31 percent see a smaller increase. Only 2% are likely to have seen no difference in cyber risk levels over the past three years.
53 percent of actual counted supply chain attacks are among their top three cybersecurity concerns, with 99 percent reporting a supply chain attack in the last 12 months (at the time of the survey). Especially in the OT area, there is a very long supply chain and a strong dependency on suppliers. No matter how strong a company’s security measures are, they are only as strong as their weakest link.
Compliance is the key driver of OT cybersecurity. Regulations and external threats are high on the agenda of decision makers tasked with securing production environments. The top three drivers of cybersecurity are compliance (86 percent), growth (83 percent), and cyber attacks (82 percent). These are the real issues that concern decision makers today.
Organizations are currently getting minimal value from their existing OT security solutions. The biggest challenges with existing OT cybersecurity systems are a skills gap (57 percent), unworkable mitigation proposals (49 percent), alert fatigue (44 percent), and complexity (33 percent). The OT market has been patchy for so long that the right security measures are difficult to assess. Many solutions for OT today are retrofitted IT solutions – with protection measures that are unsuitable for OT and patches or workarounds that add to the complexity.
Responsibility for OT security is shared between engineering, IT and senior management. According to the survey, the top three roles responsible for managing OT cybersecurity are the VP/Head of Manufacturing/Engineering (31 percent), the CISO (30 percent), and the CEO (23 percent). The result is that in many cases, those responsible for OT security are not cybersecurity experts.
Less than 50 percent of organizations manage their OT cybersecurity in-house. While 47 percent reported having an in-house team to manage OT cybersecurity, 53 percent rely heavily on managed services. 41 percent fully outsource OT cybersecurity, and 12 percent say they use a mix of outsourced and in-house teams.
Most companies plan to increase their cybersecurity budget by more than 50 percent in 2022. This is understandable given a significant increase in cybercrime, more regulation than ever, digital transformation and the shift to connected manufacturing. More than half of those wanting (54 percent) invest in increasing their cybersecurity budget by more than 50 percent for 2022. 92 percent will increase it by at least 10 percent.


Methodology:
Respondents were selected and approached through a global B2B research panel, invited to take the survey via email, and responses were collected in Q4 2021. The employees were C-level managers, directors or heads of cyber security from companies with 250 to 10,000+ employees. They hail from North America, Latin America and Europe and came from industries such as energy and utilities, oil and gas, coal mining and alternative energy.
Check out the full 2022 OT Cybersecurity Survey Report today.
www.otorio.co