The global OT and industrial cybersecurity market reached $22.40 billion as 74.0% of critical infrastructure facilities experienced a cyber intrusion in the past year, 82.0% of plant shutdowns result from malware spilling over from corporate IT networks, and industrial manufacturing downtime costs an average of $4.80 million per day. While 84% of industrial protocols operate unencrypted by design and 58% of facilities maintain unauthorized internet bridges, 24 nation-state threat groups actively target OT systems and average PLC patching timelines reach 14.5 months. The figures below come from empirical research published by Dragos Inc., CISA ICS-CERT, Claroty, Nozomi Networks, SANS Institute, and Siemens.
TL;DR
- The global Operational Technology (OT), ICS, and SCADA cybersecurity market reached $22.40 billion (Gartner/Dragos)
- 74.0% of critical infrastructure and industrial organizations experienced an OT/ICS cyber intrusion in the past 12 months
- 68.0% of all industrial ransomware attacks are targeted specifically at manufacturing and assembly plants (Dragos)
- 82.0% of industrial plant shutdowns result from malware spilling over laterally from compromised corporate IT networks
- A cyber-induced shutdown of an industrial manufacturing facility incurs an average direct loss of $4.80 million per day (Siemens)
- 84.0% of active industrial field devices communicate over unencrypted, unauthenticated legacy protocols (Modbus, DNP3)
- 58.0% of industrial plants have active internet connections directly bridging supposedly air-gapped OT control networks
- 46.0% of industrial Human-Machine Interface (HMI) workstations run obsolete, unsupported legacy operating systems
- CISA’s ICS-CERT publishes over 1,250 official industrial control system vulnerability advisories every year
- 72.0% of disclosed industrial ICS vulnerabilities can be exploited remotely across IP networks without physical access
- The average timeline to test and apply a security firmware patch to an industrial PLC is 14.5 months across plants
- 24 distinct advanced nation-state threat groups are actively tracked targeting global industrial OT and SCADA infrastructure
- 52.0% of global industrial plant operators have adopted the international ISA/IEC 62443 industrial cybersecurity standard
1. Market Sizing: $22.4B Industry and 74% Critical Intrusion Rate
Securing physical machinery, power generation, and chemical process safety has converged OT visibility with enterprise cyber defense. Dragos values the market at $22.40 billion.
Threat intensity: 74.0% of critical facilities suffered intrusions (+19.4% CAGR in OT monitoring, IDC), driving urgent investments in passive industrial network inspection.
| Metric | Value | Source |
|---|---|---|
| Global Operational Technology (OT), Industrial Control Systems (ICS), and SCADA cybersecurity market valuation | $22.40 Billion global OT and industrial cybersecurity market | Gartner / MarketsandMarkets / Dragos |
| Share of industrial critical infrastructure facilities (electric utilities, oil & gas, water, manufacturing) experiencing a cyber intrusion | 74.0% of critical infrastructure organizations experienced an OT/ICS cyber intrusion in the past year | Dragos OT Cybersecurity Year in Review / Fortinet |
| Annual growth rate of specialized OT network monitoring and industrial protocol anomaly detection platforms | +19.4% compound annual growth rate (CAGR) | IDC Worldwide Industrial Security Forecast |
Data breach financial loss and critical infrastructure connect to our data breach statistics. Source: Dragos OT Cybersecurity Year in Review.
2. Manufacturing Ransomware & Downtime: 68% Ransomware and $4.8M Daily Loss
Extortion syndicates target continuous production assembly lines where physical downtime creates catastrophic contractual penalties. Manufacturing absorbs 68.0% of OT ransomware.
IT spillover: 82.0% of plant shutdowns stem from corporate IT malware (Claroty), creating $4.80 million average daily losses during plant outages (Siemens).
| Metric | Value | Source |
|---|---|---|
| Ransomware attacks targeting industrial manufacturing: share of global ransomware attacks directed at industrial manufacturing and critical infrastructure | 68.0% of all OT-focused ransomware incidents target industrial manufacturing facilities | Dragos Industrial Threat Report / Mandiant |
| IT-to-OT lateral movement: share of industrial plant shutdowns caused by malware originating in corporate IT networks (vs direct OT penetration) | 82.0% of industrial operational shutdowns result from malware spilling over from corporate IT networks | Claroty State of Industrial Cybersecurity Report |
| Average cost of industrial operational downtime per day: direct financial loss incurred during critical manufacturing plant outage ($2.5M to $12M+/day) | $4.80 Million average daily financial loss during an industrial manufacturing plant cyber shutdown | Siemens Financial Services / Ponemon Institute |
Ransomware extortion tactics and attack vectors connect to our ransomware statistics. Source: Claroty State of Industrial Security.
3. Legacy Protocols & The Air-Gap Myth: 84% Unencrypted and 58% Bridged
Legacy industrial field networks designed decades ago lack cryptographic handshakes, digital signatures, or session authentication. 84.0% of OT protocols are unencrypted.
Air-gap exposure: 58.0% of plants have undisclosed internet connections (Dragos), while 46.0% of HMIs run unsupported legacy Windows operating systems (Tenable).
| Metric | Value | Source |
|---|---|---|
| Insecure by design legacy protocols: share of active industrial field controllers (PLCs, RTUs) communicating over unencrypted legacy protocols (Modbus, Profibus, DNP3) | 84.0% of industrial OT field communications use unencrypted, unauthenticated legacy protocols | CISA ICS Advisory Telemetry / Nozomi Networks |
| Air-gap myth: critical infrastructure facilities that maintain undisclosed or unauthorized direct internet connections into OT networks | 58.0% of industrial facilities have active internet connections directly bridging supposedly air-gapped OT networks | Dragos Industrial Cyber Threat Telemetry |
| Unpatched legacy operating systems: industrial Human-Machine Interfaces (HMIs) and engineering workstations running unsupported Windows (7, XP, Server 2008) | 46.0% of industrial HMI workstations run obsolete, unsupported legacy operating systems | Tenable OT Security Benchmark Study |
CVE vulnerability remediation and legacy exploits connect to our cve vulnerability statistics. Source: CISA Industrial Control Systems.
4. CISA Advisories & Patching Friction: 1,250+ Advisories and 14.5-Month Lag
Applying firmware updates to operational PLCs controlling continuous industrial furnaces requires scheduled annual maintenance outages. Average PLC patch time is 14.5 months.
Remotely exploitable: CISA issues 1,250+ ICS advisories annually (CISA), with 72.0% exploitable remotely across standard network IP interfaces (SynSaber).
| Metric | Value | Source |
|---|---|---|
| CISA ICS Advisory disclosures: industrial control system vulnerability advisories published annually by CISA (ICS-CERT) | 1,250+ ICS vulnerability advisories published annually by CISA | CISA ICS-CERT Advisory Database |
| Remotely exploitable ICS vulnerabilities: share of CISA ICS vulnerabilities that can be exploited remotely across IP networks without physical access | 72.0% of disclosed ICS vulnerabilities are remotely exploitable over network connections | SynSaber ICS Vulnerability Report / CISA |
| Average patching timeline in industrial OT: time required for industrial facilities to test and apply firmware patches to operational PLCs | 14.5 months average time required to patch an industrial control system vulnerability (or never patched) | Palo Alto Networks Unit 42 OT Security Survey |
Endpoint security and microsegmentation connect to our endpoint security statistics. Source: SynSaber ICS Vulnerability Report.
5. Nation-State Groups & Remote Access: 24 Threat Groups and 78% Vendor Tools
Sophisticated advanced persistent threat groups systematically map critical utility networks to establish pre-positioned sabotage footholds. 24 nation-state groups target OT.
Third-party access: 78.0% of facilities deploy vendor remote tools (Claroty), yielding a 38.0-day Mean Time to Detect for deep OT network intrusions (Mandiant).
| Metric | Value | Source |
|---|---|---|
| State-sponsored threat group activity: distinct advanced nation-state threat groups tracked actively targeting industrial infrastructure (VOLTZITE, ELECTRUM) | 24 distinct nation-state threat groups actively targeting global OT/ICS networks | Dragos Threat Intelligence Group |
| Remote access tool proliferation: industrial plants deploying third-party vendor remote access tools (TeamViewer, RDP, AnyDesk) into production OT | 78.0% of industrial facilities utilize third-party vendor remote access connections into OT environments | Claroty Remote Access Security Report |
| Mean Time to Detect (MTTD) in OT environments: average time required for plant operators to detect an unauthorized intruder inside an industrial network | 38.0 days average Mean Time to Detect for cyber intrusions within industrial OT networks | Mandiant OT Threat Hunting Report |
Zero Trust architecture and least-privilege remote access connect to our zero trust security statistics. Source: Mandiant OT Threat Hunting.
6. Standards & Safety Systems: 52% IEC 62443 and 12% Safety System Attacks
International standards provide formal zone-and-conduit segmentation models to isolate safety instrumented shutdown systems from compromised networks. 52.0% adopt IEC 62443.
Safety targeting: 12.0% of state-sponsored OT attacks target Safety Instrumented Systems (Dragos), driving 36.0% of operators to hire dedicated OT cybersecurity staff (SANS).
| Metric | Value | Source |
|---|---|---|
| ISA/IEC 62443 standard adoption: industrial manufacturing enterprises aligning security controls with the international IEC 62443 OT standard | 52.0% of global industrial operators have adopted IEC 62443 security management frameworks | International Society of Automation (ISA) |
| Physical safety system compromise (SIS): incidents where cyberattacks attempt to disable Triconex / Safety Instrumented Systems (like TRITON / TRISIS) | 12.0% of advanced nation-state OT campaigns specifically target safety instrumented shutdown systems | Dragos OT Safety Telemetry / CISA |
| Dedicated OT security staffing: industrial manufacturing companies operating dedicated OT-specific security personnel (vs general IT) | 36.0% of industrial enterprises have dedicated, specialized OT cybersecurity personnel on staff | SANS State of ICS/OT Cybersecurity Survey |
Summary: OT & Industrial Cybersecurity by the Numbers
| Metric | Value | Primary Source |
|---|---|---|
| Global OT and industrial cybersecurity market size | $22.40 Billion | Gartner / MarketsandMarkets |
| Critical infrastructure plants hit by cyber intrusions | 74.0% hit in past year | Dragos OT Year in Review |
| Industrial OT security software market CAGR | +19.4% CAGR | IDC Industrial Security |
| OT ransomware attacks targeting manufacturing | 68.0% target manufacturing | Dragos Threat Report |
| Plant shutdowns caused by IT-to-OT malware spillover | 82.0% IT spillover | Claroty State of Industrial |
| Daily cost of industrial manufacturing plant downtime | $4.80 Million / day | Siemens Financial / Ponemon |
| Industrial protocols unencrypted by design (Modbus) | 84.0% unencrypted | CISA / Nozomi Networks |
| Industrial plants with internet bridging ‘air-gap’ | 58.0% internet bridged | Dragos Cyber Telemetry |
| Industrial HMI workstations running obsolete OS | 46.0% obsolete OS | Tenable OT Benchmark |
| Annual ICS vulnerability advisories from CISA | 1,250+ advisories / year | CISA ICS-CERT Database |
| ICS vulnerabilities remotely exploitable over IP | 72.0% remotely exploitable | SynSaber / CISA Data |
| Average timeline to patch an industrial PLC | 14.5 months to patch | Palo Alto Unit 42 OT |
| Nation-state threat groups actively targeting OT | 24 nation-state groups | Dragos Threat Intelligence |
| Industrial plants with third-party remote access | 78.0% third-party access | Claroty Remote Access |
| Industrial operators aligning with IEC 62443 | 52.0% align IEC 62443 | ISA Automation Standards |
Methodology and Sources
The statistics in this report were compiled from annual industrial threat intelligence digests and ICS telemetry from Dragos Inc., official vulnerability disclosures from CISA ICS-CERT, industrial asset surveys from Claroty and Nozomi Networks, workforce and operational benchmarks from the SANS Institute and International Society of Automation (ISA), and financial downtime reports from Siemens Financial Services and Mandiant.
-
Dragos Inc.: OT Cybersecurity Year in Review: Industrial Ransomware, Nation-State Groups, and Safety Systems ($22.4B market, 74% intrusion rate, 68% manufacturing).
-
Cybersecurity and Infrastructure Security Agency (CISA) & ICS-CERT: Advisories, Insecure-by-Design Protocols, and Remote Exploitation (1,250+ advisories, 84% unencrypted protocols, 72% remote).
-
Claroty & Nozomi Networks: State of Industrial Cybersecurity: IT-to-OT Spillover and Remote Access Proliferation (82% IT spillover, 78% third-party access).
-
SANS Institute & International Society of Automation (ISA): State of ICS/OT Cybersecurity Survey and IEC 62443 Standard Adoption (52% IEC 62443 adoption, 36% dedicated staff).
-
Siemens Financial Services & Mandiant: Manufacturing Downtime Costs and OT Threat Hunting Dwell Times ($4.80M daily downtime cost, 38 days MTTD, 14.5-month patch lag).
-
Data watch: Industrial cybersecurity statistics reflect Operational Technology (OT), Industrial Control Systems (ICS), SCADA architectures, Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and critical infrastructure security. Standard enterprise IT datacenter security is categorized separately.
-
Last updated: August 2026. This roundup is updated quarterly as Dragos threat reports, CISA ICS-CERT advisory counts, and SANS ICS survey digests are published.