WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Security Awareness – Recent SANS Survey Finds Cyber Defenses are Getting Stronger as Threats to OT/ICS Environments Remain High
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Recent SANS Survey Finds Cyber Defenses are Getting Stronger as Threats to OT/ICS Environments Remain High

Author: Alec Davison

Created: Thursday, November 3, 2022 - 18:38

Categories: Cybersecurity, OT-ICS Security

Last week, the SANS Institute in collaboration with Nozomi Networks released a new report, The State of OT/ICS Cybersecurity in 2022 and Beyond, analyzing the latest trends in OT/ICS cybersecurity. The study revealed, among other findings, that more than a third of organizations don’t know whether they have been compromised and attacks on engineering workstations doubled in the last 12 months.

The report, based on a survey of 332 individuals representing organizations of all sizes across every continent, found that threats to OT/ICS systems remain high. Specifically, 62 percent of respondents rated the risk to their OT environment as high or severe. Additionally, ransomware and financially motivated attacks topped the list of threat vectors at 40 percent, followed by nation-state attacks at 39 percent. Non-ransomware criminal attacks came in third, cited by 32 percent of respondents, followed closely by hardware/software supply chain risk at 30 percent.

The number of respondents who indicated they had experienced a breach in the last 12 months dropped to 10.5 percent, down from 15 percent in 2021. And 35 percent of respondents who experienced a breach said the engineering workstation was the initial infection vector, doubling from 18.4 percent last year. Consequently, attacks using engineering workstations as an initial access vector are now the third most common vector, after IT compromises and replication through removable media. Despite the increasing threats, OT/ICS cybersecurity postures are maturing. The overwhelming majority of respondents, 83 percent, monitor their OT system security. Eighty-eight (88) percent have conducted a security audit of their OT/ICS environment in the past year. And 66 percent say their control system security budget increased over the past two years. Access the full report at Nozomi Networks or read more at SecurityWeek.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar