As Forbes reports, there has been a significant increase in the military’s cybersecurity spending. In 2023 alone, the sector invested $36.9 billion, and that number is expected to reach $49.4 billion by 2028. This much-needed attention is due to the alarming rise in threats and attacks, especially to ICS, exactly the exposure that purpose-built OT cybersecurity solutions are designed to close. It is also due in part to the mounting risk that state-actors pose, which is further fueled by geopolitical events.
Progressing Cybersecurity Terms
Considering the demand for cybersecurity in defense, the sector has made it a point to highlight the call for advancements in industry events. For instance, National Guard and Department of Defense officials hosted a panel earlier this month in which they discussed topics such as the need to “include cybersecurity measures in the development stage of new components and devices, especially those designed to work specifically on DOD and government networks,” as Sgt. 1st Class Jon Soucy writes for the U.S. Army’s site.
The focus on cybersecurity can also be seen in the progress of the Cybersecurity Maturity Model Certification rule (CMMC). The Defense Federal Acquisition Regulation Supplement rule implementing CMMC, DFARS Case 2019-D041, was published in the Federal Register on 10 September 2025. It took effect on 10 November 2025. However, there is still work to be done. A recent report concluded that much of the defense contracting industry is not prepared to comply with these standards. Josh Luckenbaugh reports for National Defense Magazine that, “Despite the majority of respondents claiming compliance via self-assessment, only 4 percent said they are completely ready for CMMC certification.”
That readiness gap is where cybersecurity for defense contractors has to start, with OT systems built for production environments rather than borrowed from office IT.
What Military OT Is Measured Against
Contract clauses are only part of what defense production has to answer to. A Honeywell study found that ransomware attacks against industrial operators and manufacturers rose 46% in the first quarter of 2025. TXOne’s 2024 Annual OT/ICS Cybersecurity Report found that 85% of organizations do not conduct regular patching, with a majority installing patches quarterly or less often. That leaves those systems exposed for extended periods.
Federal guidance has moved toward that exposure in three places worth knowing.
- In January 2025 the National Security Agency and the Cybersecurity and Infrastructure Security Agency released a guide to help OT operators prioritize security when selecting OT products.
- In April 2025 the NSA published a study on smart controller security within National Security Systems. The NSA states that the convergence of IT and OT has put OT at increased risk.
- A Department of the Air Force report addresses cyber supply chain risk management, the systematic process for managing cybersecurity exposure across the supply chain at every level of an organization.
That Air Force report states military OT is currently aligned with the Risk Management Framework and the Cyber Resilience Engineering Framework. Services will evaluate themselves to NIST Cybersecurity Framework 2.0, which is built to reflect growing complexities of risk, including the rising role of artificial intelligence. The yardstick now reaches past the contract and into the equipment on the floor.
Working Across Sectors to Shore Up Defense Cybersecurity
While contractors work to enhance their cybersecurity practices to meet these evolving expectations, the defense sector is also looking to other industries for assistance. According to TechRadar, the government may be looking to Silicon Valley and the tech industry to step in. The outlet shares that the military may be looking for tech experts to take on part-time reservist officer roles in order to participate in developing solutions to national security challenges, including nation-state-led threats to critical infrastructure such as energy and water systems.
Closing the Readiness Gap on the Production Floor
A 4 percent readiness figure does not get closed in a policy binder. It gets closed in the plant, where the machines that build defense hardware actually run. OT systems for defense production environments should be built for those environments rather than borrowed from office IT.
DYNICS has established a team focused on the defense industry and government sectors, and it develops a range of United States made rugged computer hardware. The range includes the following.
- Rackmount servers
- Panel PCs
- LCD displays
- Switches
- UPS and power management
All of it is manufactured in Ann Arbor, Michigan. DYNICS also provides commercial off the shelf and modified off the shelf solutions, which support shorter lead times, flexibility and vertical integration.
A practical first step is to inventory the OT assets inside your own production environment. Mark which ones were built for that floor and which were carried over from the office. That inventory is where the readiness gap becomes visible, and where OT cybersecurity work has something concrete to act on.
Sources
- “Six Cybersecurity Trends For Defense Contractors As 2024 Concludes” – Neil Lampton, Forbes https://www.forbes.com/councils/forbestechcouncil/2024/10/14/six-cybersecurity-trends-for-defense-contractors-as-2024-concludes/
- “National Guard Bureau Hosts Cybersecurity Awareness Panel” – Sgt. 1st Class Jon Soucy, U.S. Army https://www.army.mil/article/280705/national_guard_bureau_hosts_cybersecurity_awareness_panel
- “Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)” – Federal Register https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
- “DoD ‘fine tunes’ final CMMC program rule, industry turns attention to implementation” – Justin Doubleday, Federal News Network https://federalnewsnetwork.com/acquisition-policy/2024/10/dod-fine-tunes-final-cmmc-program-rule-industry-turns-attention-to-implementation/
- “BREAKING: Few Companies Ready for CMMC Compliance, Study Finds” – Josh Luckenbaugh, National Defense Magazine https://www.nationaldefensemagazine.org/articles/2024/10/1/few-companies-ready-for-cmmc-compliance-study-finds
- “US government wants to recruit tech leaders to help boost security” – Benedict Collins, TechRadar https://www.techradar.com/pro/us-government-wants-to-recruit-tech-leaders-to-help-boost-security










