OT cybersecurity budgets are rarely unlimited.
There is always something else that could be improved. Another system that needs attention. Another site. Another control. Another risk somebody wants addressed.
So one of the most important questions isn’t:
What should we buy next?
It’s:
Where will the next pound actually make a difference?
That sounds obvious.
But security spending can become surprisingly disconnected from the problem it is supposed to solve.
A new monitoring platform.
Another assessment.
More visibility.
Another dashboard.
A new piece of technology because somebody has decided it belongs in the target architecture.
There may be perfectly good reasons for all of those things.
But before spending the money, I think there’s a more basic question to answer:
What risk are we actually trying to reduce?
Spend against the problem, not the product category
One of the traps in cybersecurity is starting with the solution.
“We need better monitoring.”
“We need an OT asset discovery platform.”
“We need network segmentation.”
“We need secure remote access.”
Maybe.
But why?
What problem are we trying to solve?
What operational consequence are we trying to avoid?
And is the thing we’re proposing actually the best use of the money available?
Technology vendors quite reasonably sell technology.
That doesn’t mean every cybersecurity problem is a technology problem.
If third-party access is poorly controlled, perhaps new technology is part of the answer.
But perhaps the first problem is that nobody knows which third parties still require access, who approves it or who is responsible for reviewing it.
If an organisation struggles to respond to OT security alerts, better monitoring might help.
But if nobody has agreed who investigates an alert, when engineering needs to be involved or what happens when something genuinely suspicious is found, adding another source of alerts might simply create more noise.
Before you buy another tool, be clear what problem you’re asking it to solve.
Visibility is useful. What happens next?
Asset visibility is a good example.
Knowing what is connected to an OT environment matters.
But visibility isn’t the outcome.
Imagine spending a significant amount of money discovering thousands of assets across multiple sites.
You now have an impressive inventory.
What happens next?
Which assets actually matter most?
Which ones support critical processes?
Which vulnerabilities deserve attention first?
What communications are expected?
Who owns the systems?
What happens if one becomes unavailable?
Can it be recovered?
That is where information starts becoming useful.
Current NCSC OT guidance makes a similar distinction: assets should be understood in terms of factors such as business and safety criticality, exposure and availability constraints so that the information supports risk-based decisions about controls, maintenance and updates.
I’m not arguing against asset visibility. Quite the opposite.
I’m arguing that we need to think about what we intend to do with the visibility before assuming obtaining more of it is automatically progress.
A dashboard full of assets is still just a dashboard unless somebody can turn the information into better decisions.
If I gave you £100,000 tomorrow…
If an organisation handed me £100,000 and said:
“Improve our OT cybersecurity.”
I wouldn’t start by recommending a product.
I’d want to understand the operation first.
What could stop production or disrupt the service?
What could become unsafe?
What do we already know isn’t working properly?
Where are the important pathways into and across the OT environment?
How dependent are we on vendors and third parties?
Could we respond effectively if something happened tomorrow?
Could we recover?
And perhaps most importantly:
What can we realistically improve?
Because there’s little value in spending £100,000 on something an organisation doesn’t have the people, processes or capacity to implement and operate properly.
Sometimes the answer might be technology.
Sometimes it might be engineering work.
It could be improving access controls, segmentation or recovery capability.
It might be training.
It might be an exercise.
It might be sorting out something fairly basic that everybody has known about for the last two years.
Quite often, it will be a combination.
A security budget should reduce risk, not just increase the number of controls you own
There’s a difference between having more security controls and achieving better security outcomes.
That distinction matters.
You can buy an excellent security product and implement it badly.
You can have a sophisticated monitoring platform without having the people or process to respond effectively to what it finds.
You can invest heavily in backup technology without proving you can restore what the operation actually needs.
You can commission another assessment that produces a very accurate description of problems you already knew existed.
None of those investments are necessarily wrong.
But purchasing the control isn’t the same as achieving the outcome.
I’d rather see an organisation implement a smaller number of sensible controls properly than build an impressive security architecture it cannot operate, maintain or rely upon.
That’s not about lowering ambition.
It’s about making the money count.
Some improvements don’t need another technology purchase
When we talk about OT cybersecurity investment, it’s easy for the conversation to become dominated by products.
But some useful improvements may require little or no new technology expenditure.
Getting IT, cybersecurity, engineering and operations together and agreeing who makes which decisions during an incident.
Introducing appropriate change control where it doesn’t exist.
Reviewing remote-access accounts and understanding whether the access is still required.
Testing whether a backup can actually be restored.
Running an OT incident exercise and challenging the assumptions in the response plan.
Improving cybersecurity awareness amongst engineers and operators.
None of these things are free. They require people, time and effort.
But they don’t necessarily need another platform.
And they may expose weaknesses that buying another platform wouldn’t solve.
NCSC guidance specifically recommends considering controls across people, business processes, physical measures and technology rather than focusing solely on technical controls.
The objective isn’t to own more cybersecurity.
The objective is to reduce risk to the operation.
Don’t spend repeatedly discovering the same problem
Assessments are important.
I say that as someone who works in a business that carries them out.
You need to understand your risks, gaps and priorities.
But eventually assessment has to turn into action.
If an organisation conducts an assessment and discovers that remote access needs improving, that’s useful.
If another assessment twelve months later identifies the same issue, perhaps circumstances have changed and reassessment is justified.
If the third assessment tells you exactly the same thing and nothing has been done in between, you probably don’t have an assessment problem.
You have an execution problem.
That doesn’t mean organisations should stop reviewing their security posture.
Things change. Threats change. Environments change. Controls need to be checked to make sure they remain effective.
But we should be careful not to confuse repeatedly measuring a problem with reducing it.
At some point, some of the budget has to reach the problem itself.
Prevention isn’t the only place to spend
Most organisations understandably want to stop cyber incidents happening in the first place.
So they should.
But no sensible security programme should assume every preventative control will work every time.
Response and recovery matter too.
NIST’s OT guidance explicitly treats response and recovery planning, business continuity and testing as part of securing OT, and recommends considering recovery in terms of the service being provided rather than simply the system that was compromised.
So when deciding where money and effort should go, I think it’s worth asking:
What happens if our preventative controls don’t work?
Can we isolate what needs isolating?
Can we keep operating safely?
Can we restore the systems we depend on?
Are the backups actually usable?
Do the right people know what decisions they may need to make?
Have we practised any of it?
Depending on the organisation and its existing controls, improving recovery capability might reduce more operational risk than adding another preventative control.
That isn’t a universal rule.
It’s precisely why the decision should follow the risk rather than the product category.
Where would I spend the next pound?
There isn’t a universal answer.
And I’d be suspicious of anybody who gave you one without understanding the environment first.
But I would expect a good investment decision to survive a few fairly simple questions:
What problem are we solving?
What operational consequence does it reduce?
Why is this more important than the other things we could spend the money on?
Can we implement, operate and maintain it properly?
How will we know it has actually improved something?
If those questions are difficult to answer, I’d think carefully before signing the purchase order.
That applies whether the investment is £10,000 or £10 million.
Final thought
OT security will always require investment.
There are environments where ageing infrastructure needs replacing, architectures need redesigning and new technology is absolutely justified.
This isn’t an argument for doing everything cheaply.
It’s an argument for spending deliberately.
Start with the consequence.
Understand the problem.
Look at the controls you already have.
Consider people, process, engineering and technology.
Think about response and recovery as well as prevention.
Then decide where the money will make the biggest difference.
Because a security budget should do more than increase the number of controls you own.
It should reduce risk to the operation.
And if you can’t explain how the next pound is going to do that, perhaps you’re not ready to spend it yet.
About the author
Serkan Yusuf is Director of Professional Services at OTIFYD, working with organisations to understand and manage cybersecurity risk across operational technology and industrial environments. OTIFYD helps organisations improve OT cybersecurity and operational resilience through practical, engineering-aware security services.












