The Plant You Can’t Patch: Where Manufacturing’s OT Security Budget Really Goes
Manufacturing security budgets are rising fast, but the number that matters is not the spend. It is the fact that a running production line cannot be taken offline to fix, and that single constraint is quietly deciding where the money lands.
Ask a plant manager to reboot a fifteen-year-old programmable logic controller mid-shift and you get a short answer. It has not stopped in three years, nobody wants to be the person who stops it now, and the lost output is real money. That is the awkward reality sitting underneath every headline about climbing operational technology (OT) security spend. The tools are maturing, but the equipment they are meant to protect was never built to be paused, scanned, or patched on a schedule.
For years, factories leaned on physical separation to stay safe. Plant networks simply did not touch corporate systems. Industrial IoT dissolved that boundary, because the analytics and automation that justified the investment only work once machine telemetry reaches enterprise software. The isolation that once did the security job for free has been trading itself away, one integration at a time, and the budget increase is really an attempt to buy back the protection that connectivity removed.
Services are outgrowing software, and that is the tell
The spending data tracks a steady climb rather than a spike. Research from MarketsandMarkets values manufacturing cybersecurity at roughly 11 billion dollars in 2025, rising to around 17 billion by 2030, an annual growth rate close to 10 percent. North American industrial firms account for about a third of the current total.
The more revealing detail is which categories are growing fastest. Managed security and professional services are expanding quicker than the market as a whole, and cloud-based deployments are set to outpace on-premises ones. Pharmaceutical and life sciences plants lead the pack, pushed by compliance rules and the need to guard proprietary formulations.
| Metric | Figure |
|---|---|
| Manufacturing cybersecurity market, 2025 | ~$11bn |
| Projected market, 2030 | ~$17bn |
| Compound annual growth | ~9.7% |
| North American share of 2025 spend | ~36% |
| Fastest-growing segment | Managed and professional services |
When services outgrow licences, it usually means the hard part is not the software. It is the engineering time to run it. Plant technicians rarely have the bandwidth to parse logs, correlate incidents, and tune zero-trust proxies, so that work is being handed to managed providers.
Why the whole architecture went passive
Because you cannot freeze a production line to secure it, the industry has settled on a design principle: watch everything, touch nothing. Monitoring systems avoid placing agents on real-time control units and instead read mirrored traffic pulled from industrial switches. The control loop stays untouched, which is the entire point.
Recent deployments show where the caution comes from. Nozomi Networks worked with Mitsubishi Electric to fold threat monitoring into factory automation using mirrored traffic rather than on-device agents. Cisco extended its industrial tooling to profile assets without disturbing low-latency protocols such as Modbus TCP and EtherNet/IP. Claroty now confines active probing to scheduled maintenance windows and relies on passive analysis the rest of the time, while Dragos has added centralised cloud visibility for operators running several sites at once.
The reason for all this restraint is physical, not procedural. A routine vulnerability scanner aimed at a legacy PLC can overwhelm it and halt a conveyor or trip a safety valve. On a factory floor, a clumsy security check can cause the very outage it was meant to prevent.
Two kinds of vendor, and a boundary that does the work
The supplier landscape has split into two camps. Broad enterprise security firms such as Cisco, IBM, Palo Alto Networks, Fortinet, and Microsoft own distribution across large industrial accounts. A specialist group built specifically for the plant floor, including Claroty, Dragos, Nozomi Networks, and Xage Security, occupies the monitoring niche where the generalists were historically weaker. Buyers increasingly end up combining both.
Underneath the products, most teams still structure their networks around the Purdue reference model. Industrial firewalls and zero-trust access proxies sit at the control boundary, inspecting anything crossing between corporate IT and shop-floor execution systems. Passive engines tap mirror ports and read proprietary protocols down to individual function codes, which is what lets a system flag an unauthorised command to a controller before it executes rather than after a valve has already moved. Remote maintenance is shifting from always-on VPN tunnels to short-lived, identity-verified sessions with recording attached.
The takeaway for operators: budget alone does not close OT exposure. The plants making progress are the ones that accept the no-downtime constraint up front, segment hard at the IT and OT boundary, and buy visibility through passive taps rather than intrusive scanning.
Market figures attributed to MarketsandMarkets. Vendor deployment details drawn from public reporting on manufacturing OT security through 2024 to 2025.
