Closing IT security gap to drive critical infrastructure spending
Critical infrastructures are radically transforming on an unprecedented scale, boosted by a rapid adoption of ‘smart’ operational technologies. Cyber security is a growing part of that evolution. ABI Research, a market-foresight advisory firm, forecasts security spending for the protection of critical infrastructures will hit $125bn globally by 2023.
Currently, defence contractors (Lockheed Martin, BAE Systems, Harris, Northrop Grumman), industrial OEMs (Honeywell, Siemens, Airbus, Rockwell, Boeing), tech leaders (IBM, Amazon, Microsoft, Verizon), and energy companies (Shell, Total, Exxon) are the big security spenders.
Three primary drivers are pushing better digital security in sectors such as utilities, transport, and healthcare: digital transformation and increased connectivity of operational technologies; democratisation of cyber attacks targeting critical infrastructure; and a maturing market for industrial and IoT security.
“Connected OT has enabled optimisation and greater efficiency for decades-old legacy systems, cutting costs and vastly improving operations for operators,” said Michela Menting, Research Director at ABI Research. But it has also introduced new vulnerabilities and opened new threat vectors to previously air-gapped technologies.
The first specialised attacks against industrial control systems are over a decade old, and the attack tools and methods are accessible to even the most common cyber criminals. Fortunately, the cyber security industry has been working in parallel to address that security gap between IT and OT. As a result, security solutions for industrial control systems and IoT have been fast maturing, rendering them more widely available and affordable.
Menting, explained: “So, while critical infrastructure operators face an expanding threat landscape, they also have greater choice and support in terms of digital protection of their OT and IT systems. Security budgets have increased significantly, which is encouraging news for those sectors which have long lagged in digital security.”
However, these positive developments face-off against several obstacles plaguing critical infrastructures: a macro-focus slowdown by governments regarding national cyber security strategies, especially in the U.S., and the E.U., continued resistance to cyber security regulation and sectoral information sharing, and cyber threat fatigue leading to general apathy regarding cyber security by the private sector. Many stakeholders view cyber security as a check-box exercise for one-time spending rather than investing on a continuous basis.
Menting concluded: “Consequently, while current security spending levels are significantly higher compared to just a few years ago, there is still significant room for further investment, both from an awareness and an implementation perspective.”
These findings are from ABI Research’s Critical Infrastructure Security report. This report is part of the company’s Digital Security research service, which includes research, data, and Executive Foresights.