The global operational technology (OT) security market is projected to grow from $44.34 billion in 2025 to $178.93 billion by 2035, according to new research from SNS Insider, representing an annual growth rate of nearly 15%.
The growth is being driven by increasing cyberattacks against critical infrastructure and industrial control systems, along with the rapid adoption of industrial IoT, smart manufacturing and increasingly interconnected IT and OT environments.
Power, transportation, manufacturing, energy and utilities are among the sectors increasing investment in technologies designed to protect mission-critical operational systems. North America accounted for approximately 42% of the global OT security market in 2025.
Security solutions, including threat detection, monitoring, vulnerability management and incident response, represented nearly 72% of the market in 2025. Managed and professional security services are expected to be the fastest-growing segment as organizations seek additional expertise to secure increasingly complex industrial environments.
Denis Calderone, CTO, Suzu Labs:
“The projected growth tracks with what we’ve been living through lately. The last several months have been a steady stream of attacks on operational technology, from Iran-linked activity against water and fuel-monitoring systems to the wave of PLC compromises that had water utilities scrambling this summer. When CISA is telling the entire water sector to pull PLCs off the public internet and the FBI is documenting lost pressure and actual flooding, budgets catching up to the threat isn’t hype, it’s just an inevitable fact.
“We strongly suspect that the speed in growth of these types of attacks are likely in line with the increased use of offensive AI. The August advisory from NSA, CISA, the FBI, DOE, and EPA on Siemens S7 controllers spelled it out pretty clearly. Attackers are using AI-generated scripts, dressed up to look like legitimate monitoring tools, to build working ICS capability with far less expertise and in far less time than this used to take. That compresses the learning curve that used to keep casual actors out of OT, which means more people can credibly threaten these environments. Executive Order 14306 last summer named this directly, calling out China, Iran, and others targeting critical infrastructure and steering federal cyber efforts toward AI-era threats. The forecast is really just the market responding to conditions.”
Damon Small, Board of Directors, Xcape Inc.:
“Rapidly converging IT and operational technology (OT) environments expose legacy industrial control systems to direct cyber risks, threatening revenue, physical safety, and operational continuity. Driven by aggressive digital transformation across power, manufacturing, and utilities, this market expansion highlights a growing operational vulnerability rather than simple tech adoption. Paradoxically, investment in OT security is surging alongside rising cybersecurity unemployment, revealing a structural mismatch: the skilled, experienced professionals required to protect complex physical assets remain scarce. Because legacy control systems frequently lack basic authentication controls, traditional perimeter security fails. To bridge this acute talent gap and secure legacy assets, security leaders must deploy AI-assisted tooling, enforce strict network segmentation between IT and OT domains, and mandate strong access governance for third-party maintenance connections.
Critical Takeaways
- Convergence of IT and OT exposes legacy control systems to physical safety and operational continuity risks that traditional enterprise tools cannot address.
- A shortage of specialized OT security talent makes pure headcount expansion unfeasible, driving adoption toward AI-assisted tooling for anomaly detection.
- Immediate risk reduction requires strict network segmentation between IT and OT domains alongside tight access governance for third-party connections.
“If your OT security strategy relies entirely on hiring unicorns, prepare to explain your next outage to the board using hand puppets.”
Doc McConnell, Head of Policy and Compliance, Finite State:
“Until recently, operational technology was considered a niche specialty within the field of cybersecurity. A market projection like this shows that’s no longer the case.
“There are two drivers for this rapid expansion. First, we’re increasingly seeing adversaries targeting operational technology. In April, CISA, the FBI, and EPA warned that Iran-linked actors were reaching programmable logic controllers at U.S. water and energy utilities, and in July the FBI documented attackers changing addresses, passwords, and ladder logic on internet-exposed PLCs at water systems in at least seven states. These attacks have had real operational consequences, including pressure loss and flooding.
“And second, we’re seeing a trend toward OT protection in US policy. Last month’s executive order on bulk-power supply chain security puts the origin and security of grid equipment under federal scrutiny, and the Water Cyber Shield Act proposed in Congress would direct EPA to set tiered security standards for drinking water and wastewater systems.
“But OT operators can’t wait for policy to catch up, which is why we’re seeing particular growth in the services segment. Buying new security tooling is straightforward. Finding people who understand how a control system actually behaves, and who can build security into equipment without risking downtime or disruption is harder. In these environments, interruption in service is a life-safety issue, so that expertise is worth hiring for.”
The time to spend is now. Because it is a matter of when and not if you will get attacked.
Related
This entry was posted on September 16, 2026 at 4:35 pm and is filed under Commentary with tags OT Securiity. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
OT security market projected to quadruple as critical infrastructure threats grow
The global operational technology (OT) security market is projected to grow from $44.34 billion in 2025 to $178.93 billion by 2035, according to new research from SNS Insider, representing an annual growth rate of nearly 15%.
The growth is being driven by increasing cyberattacks against critical infrastructure and industrial control systems, along with the rapid adoption of industrial IoT, smart manufacturing and increasingly interconnected IT and OT environments.
Power, transportation, manufacturing, energy and utilities are among the sectors increasing investment in technologies designed to protect mission-critical operational systems. North America accounted for approximately 42% of the global OT security market in 2025.
Security solutions, including threat detection, monitoring, vulnerability management and incident response, represented nearly 72% of the market in 2025. Managed and professional security services are expected to be the fastest-growing segment as organizations seek additional expertise to secure increasingly complex industrial environments.
Denis Calderone, CTO, Suzu Labs:
“The projected growth tracks with what we’ve been living through lately. The last several months have been a steady stream of attacks on operational technology, from Iran-linked activity against water and fuel-monitoring systems to the wave of PLC compromises that had water utilities scrambling this summer. When CISA is telling the entire water sector to pull PLCs off the public internet and the FBI is documenting lost pressure and actual flooding, budgets catching up to the threat isn’t hype, it’s just an inevitable fact.
“We strongly suspect that the speed in growth of these types of attacks are likely in line with the increased use of offensive AI. The August advisory from NSA, CISA, the FBI, DOE, and EPA on Siemens S7 controllers spelled it out pretty clearly. Attackers are using AI-generated scripts, dressed up to look like legitimate monitoring tools, to build working ICS capability with far less expertise and in far less time than this used to take. That compresses the learning curve that used to keep casual actors out of OT, which means more people can credibly threaten these environments. Executive Order 14306 last summer named this directly, calling out China, Iran, and others targeting critical infrastructure and steering federal cyber efforts toward AI-era threats. The forecast is really just the market responding to conditions.”
Damon Small, Board of Directors, Xcape Inc.:
“Rapidly converging IT and operational technology (OT) environments expose legacy industrial control systems to direct cyber risks, threatening revenue, physical safety, and operational continuity. Driven by aggressive digital transformation across power, manufacturing, and utilities, this market expansion highlights a growing operational vulnerability rather than simple tech adoption. Paradoxically, investment in OT security is surging alongside rising cybersecurity unemployment, revealing a structural mismatch: the skilled, experienced professionals required to protect complex physical assets remain scarce. Because legacy control systems frequently lack basic authentication controls, traditional perimeter security fails. To bridge this acute talent gap and secure legacy assets, security leaders must deploy AI-assisted tooling, enforce strict network segmentation between IT and OT domains, and mandate strong access governance for third-party maintenance connections.
Critical Takeaways
“If your OT security strategy relies entirely on hiring unicorns, prepare to explain your next outage to the board using hand puppets.”
Doc McConnell, Head of Policy and Compliance, Finite State:
“Until recently, operational technology was considered a niche specialty within the field of cybersecurity. A market projection like this shows that’s no longer the case.
“There are two drivers for this rapid expansion. First, we’re increasingly seeing adversaries targeting operational technology. In April, CISA, the FBI, and EPA warned that Iran-linked actors were reaching programmable logic controllers at U.S. water and energy utilities, and in July the FBI documented attackers changing addresses, passwords, and ladder logic on internet-exposed PLCs at water systems in at least seven states. These attacks have had real operational consequences, including pressure loss and flooding.
“And second, we’re seeing a trend toward OT protection in US policy. Last month’s executive order on bulk-power supply chain security puts the origin and security of grid equipment under federal scrutiny, and the Water Cyber Shield Act proposed in Congress would direct EPA to set tiered security standards for drinking water and wastewater systems.
“But OT operators can’t wait for policy to catch up, which is why we’re seeing particular growth in the services segment. Buying new security tooling is straightforward. Finding people who understand how a control system actually behaves, and who can build security into equipment without risking downtime or disruption is harder. In these environments, interruption in service is a life-safety issue, so that expertise is worth hiring for.”
The time to spend is now. Because it is a matter of when and not if you will get attacked.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 4:35 pm and is filed under Commentary with tags OT Securiity. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.