Factory floor exposure grows as OT security spending climbs

Share This Post

Manufacturing cybersecurity spending is climbing fast, and the growth is exposing weak factory floor operational technology (OT).

Anyone running production plants are stuck with a decision that doesn’t have a comfortable answer: keep OT isolated and accept that isolation is eroding on its own, or connect it to enterprise IT and inherit a new set of exposures.

Industrial networks used to rely on physical separation from corporate systems. Industrial IoT platforms have made that separation impractical, since plant telemetry now needs to reach enterprise software for the analytics and automation promises that justified the IIoT investment in the first place. A plant manager can’t take a conveyor line offline mid-shift to patch a fifteen-year-old programmable logic controller (PLC) without accepting an output loss.

Vendor demonstrations rarely show that trade-off. Automated patching and instant asset discovery tend to work cleanly in synthetic test environments, where firmware versions are known, network maps are current, and nothing is running a safety-critical process in real-time. Actual plant conditions look different: stale firmware nobody has documented, serial connections nobody mapped, and equipment that cannot tolerate a scheduled reboot because it hasn’t stopped running in three years.

That gap between demonstration and deployment is where most of the money in this market is trulygoing.

Spending data points to a climb through 2030

Research from MarketsandMarkets puts enterprise spending on manufacturing cybersecurity at $10.97 billion in 2025, rising to $17.39 billion by 2030, a compound annual growth rate of 9.7 percent. North American industrial firms account for roughly 36 percent of that 2025 total, according to the research.

The spending isn’t spread evenly across categories either. MarketsandMarkets projects managed security and professional services to expand at an 11.1 percent compound rate through 2030, faster than the market overall.

Pharmaceutical and life sciences manufacturers show the highest rate of expansion among industrial verticals, a pattern the research firm attributes to compliance obligations and the need to protect proprietary chemical formulas from exposure. Cloud security deployments are also expected to outpace on-premises architectures over the same period.

Vendor positioning has settled into two rough camps. Cisco, IBM, Palo Alto Networks, Fortinet, and Microsoft dominate distribution across large industrial accounts with broad enterprise security portfolios. Specialised OT vendors – among them Claroty, Dragos, Nozomi Networks, and Xage Security – have built their businesses around plant-floor monitoring, where the broader IT vendors historically had weaker footing.

Vendors test passive monitoring against production chaos

Deployment cases from the past two years show what enterprise security teams are willing to install on a production line, and what they won’t touch.

Nozomi Networks partnered with Mitsubishi Electric in early 2024 to build threat monitoring into factory automation platforms. The system avoids placing agents on real-time control units and instead processes mirrored traffic pulled from industrial switches, a passive approach that reflects how little tolerance plant operators have for anything that touches a control loop directly.

Cisco expanded its industrial security portfolio in April 2025 with OT telemetry tools designed to extract asset profiles without interrupting low-latency protocols such as Modbus TCP or EtherNet/IP. Engineering teams running these tools in live plants report a recurring problem: legacy devices that were never inventoried and lack basic logging capability, meaning the tool can see traffic from a device it cannot otherwise identify.

Palo Alto Networks has flagged lateral movement between IT and OT networks as the primary risk vector for production plants in its vendor reporting, with attackers exploiting weak boundaries between enterprise resource planning systems and shop-floor execution platforms. Containing that movement typically means layering automated incident response on top of deep packet inspection, rather than relying on either alone.

The physical stakes of active scanning explain a lot of the caution in this market. A standard vulnerability scanner probing a legacy PLC can overflow its buffer and halt a conveyor belt or a safety valve, a potential outcome that plant security teams plan around.

Claroty’s November 2025 update to its risk analytics and remediation workflow restricts active probing to designated maintenance windows, leaning on passive traffic analysis for day-to-day asset mapping instead. Dragos, meanwhile, expanded its OT platform in September 2025 to add cloud telemetry and real-time threat intelligence for operators running multiple plant sites, letting them centralise visibility while keeping containment local to each facility. Fortinet and Check Point supply the firewall integration that ties these distributed sites together at the network edge.

None of this comes cheap in engineering time, and that’s the reason services are outgrowing software licenses in the spending data. Managed security providers absorb the log parsing, incident correlation, and zero-trust proxy configuration that plant technicians don’t have the bandwidth to run themselves, freeing internal staff to focus on keeping equipment running rather than tuning security tooling.

Segmentation and passive taps carry the technical weight

The architecture underneath all of this follows the Purdue Reference Model, which most industrial security teams still use to structure network segmentation. Industrial firewalls and Zero Trust Network Access proxies sit at the Level 3 control boundary, inspecting traffic that crosses between enterprise IT networks and shop-floor manufacturing execution systems.

Passive monitoring engines connect to mirror ports on managed industrial switches at Levels 2 and 3, parsing proprietary protocol payloads down to individual function codes. That level of inspection is what allows a system to flag an unauthorised command write to a PLC before it executes, rather than after a valve has already moved.

Sensitive engineering data crossing into cloud platforms gets encrypted and tokenised in transit, and remote maintenance sessions increasingly run through temporary, identity-verified proxies with session recording, replacing the persistent VPN tunnels that used to leave a standing door open into the plant network.

The tap devices doing the actual capture work are unglamorous by design: passive hardware pulling raw Ethernet frames straight from switches running EtherNet/IP, PROFINET, or Modbus TCP. For plant operators, that passivity is the point. Nothing about the monitoring layer is allowed to touch the control loop it’s watching.

See also: NVIDIA T3000 and T2000 target robotics cost and power limits

Banner for IoT Tech Expo

Want to learn more about the IoT from industry leaders? Check out IoT Tech Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including AI & Big Data Expo and the Cyber Security Expo. Click here for more information.

IoT News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Adblock test (Why?)

More To Explore

  • About
  • Smart Tech
  • Solutions
  • Join Us
  • Contact
  • Contractor’s Hub