As the World Economic Forum reported earlier this year, more than 600 residential buildings in Ukraine experienced heating disruption when attacked by malware known as FrostyGoop malware. This came as experts became aware of PIPEDREAM, which World Economic Forum author Robert M. Lee described as “the first ICS malware with the ability to scale attacks across systems and sectors.” Both FrostyGoop and PIPEDREAM solidified what was already increasingly apparent, OT and ICS systems are now on the frontline of cybersecurity warfare.
While geopolitics and international escalations are a major factor in the cyberattack landscape, there are also other elements increasing the vulnerability of OT and ICS systems. A significant contributor is that OT is no longer separated from the rest of enterprise networks as it once was. This means that OT isn’t limited to “elite attackers,” as Kevin Townsend at Security Week explained. To address these changes, the approach to OT and ICS cybersecurity has had to evolve accordingly.
The Rise of OT Cybersecurity Commandments
The need for OT cybersecurity started bubbling in the 1990s with demand-driven supply chains, but it really became a reality in 2007 with DHS’s Project Aurora. As a response to this growing need, the Purdue Model was adopted. The Purdue Model came with what were labeled commandments. But as OT cybersecurity defenses and attacks have become more sophisticated, the commandments didn’t necessarily keep up. Of them, though, there is one that remains relevant.
According to Rafael Maman at Sygnia: “Out of the Four Commandments in the by-then-obsolete Purdue Bible, only the first one – promoting network segregation & segmentation – will survive; albeit further nuanced to cover a true and complete segmentation (rather than a Perimeter Security based merely on IT/OT separation), and somewhat downgraded from being the core methodology to a very important best-practice.”
Zero Trust Enters the OT Conversation
Segmentation survived because it answered a question operators still ask, which is who gets to reach what. Zero trust extends that same logic to every request on the network. Research shows many operators either are adopting or intend to adopt zero-trust models, though the approach remains debated in OT settings. Much of that debate, as a piece published by SC Media argues, comes down to misconceptions rather than to the technology itself.
Two objections come up repeatedly.
- That zero trust cannot be paired with existing measures such as defense in depth, when combining the two can establish a stronger shield
- That zero trust demands a lengthy and burdensome restructuring of legacy technology, when zero-trust models can be put in place over systems already running
That layering approach is described as forming a cyber mesh, where controls sit above the plant floor rather than replacing it. For operators, the practical first step is to check whether segmentation and identity controls already exist on the network, and where the gaps between them sit. Dynics works in both areas, through OT network segmentation and through identity and access control.
The Introduction of New OT Cybersecurity Frameworks
Along with the commandment of network segregation and segmentation, other frameworks have been developed to better address the evolving OT cybersecurity space. For instance, the SANS Institute established the “five critical controls” for OT Cybersecurity, which consist of developing an incident response plan, building a defensible architecture, gaining network visibility and monitoring, using secure remote access, and conducting risk-based vulnerability management. “Software Defined Networking in the OT space offers an excellent way to simplify network management while enabling microsegmentation and significantly enhancing OT cybersecurity,” says Jeff Smith, CTO of Dynics.
As OT and ICS cybersecurity approaches shift to meet today’s demands, we’re also seeing shifts in budgets. “Cybersecurity budgets across operational technology (OT) infrastructure are firmly moving toward long-term strategy, resilience, and regulatory readiness rather than merely patching legacy systems and purchasing tools,” writes Anna Ribeiro at Industrial Cyber.
Current industrial control system security combines network segmentation, secure remote access, protocol visibility, and identity controls.
What the Numbers Show About the Shift
The spending changes track the threat data closely. Dragos, in its ICS/OT Cybersecurity Year in Review for 2022, found that ransomware attacks targeting industrial organizations increased by 87%, tracking 605 cases in that year alone. TechTarget’s coverage of that report noted several Conti victims in the automotive industry, along with multiple LockBit variants affecting victims across construction, electric and manufacturing. Forbes later reported that cyberattacks against critical infrastructure surged in 2024, increasing by 30% from the prior year.
Spending moved in the same direction. ABI Research projects enterprise spending on OT cybersecurity will reach $21.6 billion globally by 2028, and Cybersecurity Dive reported that much of it will focus on network security and segmentation. The broader industrial control systems market was reported as expected to rise from $16.7 billion in 2022 to $23.7 billion by 2027, with North America hosting the largest portion of that growth.
Where that money lands is the operator’s decision. Engineering workstations have been identified as a point of access in OT environments, which makes them a reasonable place to start an inventory. Map which workstations reach which cells, then check what the network switch between them actually permits.
Sources
- “Why using IT cybersecurity to protect OT puts industrial organizations at risk” – Robert M. Lee, World Economic Forum
https://www.weforum.org/stories/2025/01/cybersecurity-protect-ot-industrial-organizations-risk-it/
- “Cyber Insights 2025: OT Security” – Kevin Townsend, Security Week
https://www.securityweek.com/cyber-insights-2025-ot-security/
- “The Future of OT Security” – Rafael Maman, Sygnia
https://www.sygnia.co/blog/the-future-of-ot-security/
- “Making it easier to deploy zero-trust for operational technology systems” – Roman Arutyunov, SC Media
- “Dragos: ICS/OT ransomware attacks up 87%” – Alexander Culafi, TechTarget
https://www.techtarget.com/cybersecurity/news/365531080/Dragos-ICS-OT-ransomware-attacks-up-87
- “Industrial cyberattacks fuel surge in OT cybersecurity spending” – Matt Kapko, Cybersecurity Dive
https://www.cybersecuritydive.com/news/industrial-ot-cybersecurity-spending-growth/720172/
- “OT/ICS Engineering Workstations Face Barrage of Fresh Malware” – Becky Bracken, Dark Reading
https://www.darkreading.com/vulnerabilities-threats/ot-ics-engineering-workstations-malware
- “OT cybersecurity budgets shift toward strategy and resilience to meet rising threats, compliance demands” – Anna Ribeiro, Industrial Cyber










