Skip to content

Risk Management

The OT Cybersecurity Budget: How to Build the Business Case and Measure ROI

The OT cybersecurity budget is often an afterthought next to IT, even when operational risk is far higher. How to build a convincing business case and measure the ROI of industrial security investments.

4 min read
OT cybersecurity business case with ROI and investment roadmap

The OT budget problem: why it is always an afterthought

In many industrial organizations, the cybersecurity budget follows a well-established logic: the IT team has a defined budget that includes the information security component. OT lives in a separate world, with operations budgets that cover maintenance, technology upgrades, and spare parts. OT cybersecurity falls between these two worlds with no clear ownership of the budget.

The result is that OT security investments are often:

  • Reactive: they arrive after an incident, not before
  • Insufficient: sized against the IT budget, not against OT risk
  • Unmeasured: with no effectiveness metrics, and therefore no basis for renewal

The CISO who wants to build a structured OT security program must first solve the budget governance problem, and to do that they must build a credible business case.

Building the business case: from risk to number

An effective business case does not start with "we need to buy this tool". It starts with quantifying the risk you want to reduce.

Risk scenario: define realistic incident scenarios for the specific organization. Not "a generic ransomware" but "a ransomware that encrypts the SCADA workstations on line 3, causing a production stoppage of X hours or days". Specific, with concrete operational impacts.

Impact quantification: for each scenario, estimate the economic impact. Typical components:

  • Cost of production downtime (loss of margin per unit of time)
  • Recovery cost (system restoration, staff overtime, vendor support)
  • Potential damage to the physical plant (in sabotage scenarios)
  • Cost of notifications and regulatory penalties (NIS2, DORA)
  • Reputational damage (hard to quantify, but not zero)
  • Insurance cost (the lack of controls raises the premium or rules out coverage)

Probability: estimate the annualized probability of the risk scenarios. It is not exact, but even a conservative estimate documents that the risk is real and not negligible. The industrial sector has a growing body of public data on ransomware incidents and OT attacks that supports this estimate.

Expected risk calculation: probability x impact = expected annualized risk. This is the number against which the security investment must be compared.

The maturity model as an investment roadmap

Presenting the budget as "we want to buy X, Y, Z" is less effective than presenting it as "we are at this level of maturity, we want to reach this level, here is what it takes and how much it costs".

OT maturity frameworks (such as C2M2, CMMC, or models based on IEC 62443) define progressive levels of capability, from ad hoc processes (level 1) to optimized and measured programs (level 5). Positioning the organization on this spectrum and defining the target level justifies the investments in a structured way.

The maturity model has another advantage too: it allows investments to be spread over time, with multi-year roadmaps instead of one-off requests that are hard to approve. A budget spread over three years, with verifiable milestones, is easier to obtain than a concentrated investment.

OT cybersecurity ROI: how it is really measured

Security ROI is notoriously hard to measure: "thanks to our investments, we were not attacked" is not measurable in the traditional sense. But more rigorous approaches do exist:

Reduction in expected risk: the main KPI is the reduction of quantified risk before and after the investments. If the expected annualized risk was 2M euros and after the investments it is 500K euros, the risk reduction is 1.5M euros per year. Compared with the cost of the investment, this is a calculable ROI.

Comparison with the cost of an incident: the cost of a real incident in the same sector or in a comparable organization is a powerful benchmark. "The ransomware incident at company X in our sector cost Y. Our investment in OT security costs Z. The ratio is convincing."

Reduction in the insurance premium: if implementing specific controls reduces the premium of the cyber policy, this is a measurable cost reduction directly attributable to the investments.

Operational metrics: the number of critical vulnerabilities left without compensating controls, the average time to detect network anomalies, the coverage of critical assets in monitoring: metrics that show how the posture improves over time.

Presenting to the board: language and metrics that work

The boards of directors of industrial companies think in terms of production, revenue, operational continuity, and regulatory compliance. They do not think in terms of CVE and CVSS.

Board presentations on OT cybersecurity budgets work best when:

You talk about operations, not technology: "risk of a production stoppage of X days" is more concrete than "critical vulnerability in the SCADA protocol". "NIS2 compliance at risk, potential penalties of up to X euros" is more immediate than "gap in access controls".

You use the sector benchmark: "35% of manufacturing companies in our sector have suffered at least one significant incident in the last 12 months" is more convincing than general cybersecurity statistics.

You quantify the unmanaged residual risk: do not present only what you are asking for, but also what remains exposed if the budget is not approved. The board's decision must be informed about the risk it is accepting, not just the cost it is avoiding.

You show verifiable milestones: not "we will improve OT security" but "by Q2 we will have full visibility into the OT network; by Q4 we will have implemented secure remote access with MFA for all vendors". Measurable objectives build credibility and make subsequent reporting easier.

An OT cybersecurity budget obtained with a rigorous business case is more solid than one obtained after an incident. The latter always comes eventually: but with the former, the goal is that the incident never has to happen at all.

The MON5 angle

MON5's modular path stems from the same logic described in this article: instead of a monolithic budget request, you start with the assessment in the DISCOVER phase, which produces the concrete numbers (exposed assets, critical vulnerabilities, uncontrolled access) on which to build the business case for management.

The subsequent capabilities, ANALYZE and PROTECT, are activated in phases, with verifiable milestones that make reporting to the board easier and support the defense of the budget in the years that follow. If you need to quantify the risk before asking for the investment, the OT assessment is the natural starting point.

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna