Every operations manager who has tried to fund an OT security program knows the problem: security has no revenue line, and when it works, nothing happens. Meanwhile the compressor rebuild and the plant expansion have visible payback. This guide is the internal pitch, assembled: what industrial cyber incidents actually cost (honest ranges, not scare-slide numbers), how cyber insurance quietly became a second regulator, how to size a right-fit budget, and how to frame ROI in the language boards actually respond to - downtime days, safety exposure, and compliance dates.
Part of our SCADA security guide library - 60+ articles on securing industrial operations.
Start by being honest about why this pitch keeps losing. It is not that leadership does not care; OT security carries three structural disadvantages into every budget cycle:
There is also an ownership gap: IT owns the security budget but not the control network, and operations owns the control network but has no security budget. OT security falls into the seam, and the seam has no sponsor.
The fix is not louder fear - breach headlines and worst-case slides exhaust their credibility in one budget cycle. The pitch that survives is financial: an honest statement of exposure, a bounded ask, and measurable results. The rest of this guide builds it piece by piece.
First, a caveat your CFO will respect you for making: published figures vary widely, and most headline numbers mix industries, incident types, and methodologies. IBM's Cost of a Data Breach research puts average breach costs generally in the commonly cited 4–5 million USD range in recent years - but that averages all sectors and mostly measures data breaches, not production outages. For industrial operators, the number that matters more is downtime: cost-per-hour figures cited across industry sources run from tens of thousands of dollars for smaller operations to over a million dollars per hour for large automotive, refining, and process facilities. Your own number is calculable from your own production data, and it is the most credible figure you can put in front of a board.
An incident's total cost stacks several distinct components, and the ransom - the number that makes headlines - is rarely the largest:
| Cost Component | What It Covers | Honest Range |
|---|---|---|
| Ransom payment (if paid) | The extortion demand itself; many operators restore from backup instead of paying | Widely variable - published demands run from five figures to multi-millions; paying does not remove recovery cost |
| Downtime and lost production | Halted or manually curtailed operations while systems are rebuilt and trusted again | Commonly cited at tens of thousands to 1M+ USD per hour depending on industry and scale; usually the dominant component |
| Recovery and rebuild | Re-imaging servers and HMIs, restoring historians, revalidating control logic, integrator and overtime labor | Days to weeks of engineering time; often exceeds the ransom demand itself |
| Incident response and forensics | External IR firms, forensic investigation, legal counsel, notification obligations | Typically five to six figures for a serious incident; insurance may cover part |
| Regulatory and legal exposure | Reporting duties, potential penalties, litigation | Highly sector-dependent; NERC CIP penalties can in principle be assessed per violation per day and reach substantial sums |
| Customer and reputational impact | Contract penalties, lost bids, tightened flow-down requirements, insurance repricing | Hard to quantify; effects commonly persist for years after the incident closes |
Two implications follow. Because downtime dominates, recovery capability is the highest-leverage line in the budget - tested backups and a rehearsed restore path shrink the biggest cost component directly; our ransomware protection guide covers what that looks like in OT. And because the components stack, partial protection still pays: a control that cannot prevent an intrusion but halves recovery time has a real, calculable value.
For many operators, the most concrete financial pressure on OT security today comes not from regulators or attackers but from the cyber insurance renewal. After heavy ransomware losses in the early 2020s, insurers hardened underwriting across the market. Premium trends since have varied by year and sector, so state them cautiously in your pitch - but the questionnaire has not relaxed.
Most applications now require detailed attestation, and several controls have effectively become underwriting gates - answer no, and you face higher premiums, ransomware sublimits, coinsurance clauses, coverage exclusions, or a declined application:
Use the questionnaire as a free gap assessment: every "no" answer is a pre-justified budget line, endorsed by a third party the CFO already pays. And accuracy matters - insurers have contested claims where attestations did not match reality, so closing the gap is cheaper than papering over it.
Regulation is the budget lever that converts "we should" into "we must, by this date." The landscape is sector-specific, and you should present it conservatively - requirements evolve, and overstating them costs credibility:
In the internal pitch, regulatory items go first: they carry deadlines, named external enforcers, and consequences that require no probability estimate. Nothing else in the budget defends itself as easily.
A credible OT security budget splits three ways, and the split surprises people: over time, technology is often the smallest slice.
What does a right-sized program cost? The honest answer is it varies - with the consequence of downtime, regulatory scope, and what you already run. As directional guidance: a small operator covering the fundamentals (MFA, closing inbound exposure, tested backups, named accounts, a basic IR plan) can often get there for low five figures per year plus committed staff time, especially when a cloud platform absorbs the platform-security burden. Mid-size operators running their own segmented networks, monitoring, and compliance programs commonly land in six figures annually once people time is counted honestly. Treat these as planning ranges, not quotes - and see our guide to right-sizing security for small operators for the fuller picture.
The deployment model you choose for SCADA quietly decides a large share of your security budget, because it decides who runs the security stack. On-premise, every control is a line item you buy, patch, and staff. On a cloud platform, much of that stack ships with the subscription - the spend shifts from capex plus internal labor to opex carried substantially by the vendor.
| Control Area | On-Premise DIY: You Buy and Run | Cloud Platform: Inherited from Vendor |
|---|---|---|
| Remote access | VPN concentrator licensing, patching, certificate management, exposed endpoint to defend | Outbound-only gateway - no inbound ports or VPN to buy, expose, or patch (verify the architecture) |
| Platform patching | Your staff schedules downtime windows and carries upgrade risk | Vendor patches continuously; your job shifts to verifying their release discipline |
| Security monitoring | SIEM licensing plus someone to build content and watch it | Runtime threat monitoring built into the platform, with event delivery into your SIEM |
| Audit trail | Design, retain, and prove the integrity of logs yourself | Immutable, chained audit records maintained as a platform feature |
| Data integrity | Roll your own transport security and hope the historian is honest | Signed telemetry envelopes with replay detection, plus store-and-forward through outages |
| Compliance evidence | Assemble every control's evidence from scratch for each audit | Vendor supplies platform-layer evidence; the operator layer remains yours |
This is the model Merobix is built on: an outbound-only gateway with no inbound ports or VPN concentrators to fund and defend, TOTP MFA and FIDO2 hardware keys and role-based access as platform behavior, row-level security tenant isolation, signed telemetry envelopes with replay detection, and immutable, chained audit records with runtime threat monitoring delivering events to your SIEM. On the assurance side, Merobix runs a SOC 2 readiness program and maps its controls to IEC 62443, with independent testing part of the ongoing validation program - the engineering detail is on the security page. For operations that require it, the same platform deploys on-premise or air-gapped, which moves the responsibility split back toward you by design.
One honest caveat belongs in every board deck: cloud shifts responsibility, it does not eliminate yours. Identity decisions, field device security, network segmentation, and operational procedures stay on your side of the line under the shared responsibility model - budget for them either way.
Security ROI has a credibility problem: the benefit is a loss that did not happen. The framing that survives CFO scrutiny treats it as avoided-loss expected value, built from ranges rather than false precision:
Then stack the bankable items - benefits that do not depend on probability at all: insurance premium impact and continued insurability, audit effort reduced from weeks of scramble to days of retrieval, compliance deadlines met without emergency spend. And do not leave out the operational dividends of a modern platform, because they often carry the vote: remote visibility that cuts windshield time and truck rolls, faster alarm response, and data engineers can trust. When security spend rides along with an operational upgrade, it stops being a pure cost center - a dynamic explored in our .
When you report back, pick metrics that translate: percentage of accounts with MFA and named identities, inbound firewall exposure (target: zero), last restore test date and result, mean time to detect and respond, open insurance questionnaire gaps, and compliance deadline status. Downtime days, safety exposure, and dates - never CVE counts.
Key takeaway: the business case that wins is not "we might get hacked." It is: this budget converts an unbounded, uninsurable operational risk into a bounded, insurable one - and the same controls pay operational dividends every ordinary day. Present exposure honestly in ranges, let the insurance questionnaire and regulatory deadlines carry the urgency, and put your own downtime cost - not a headline average - at the center of the math.
Boards fund sequenced plans, not wish lists. A three-phase roadmap keeps the first ask small, delivers visible results, and earns the next tranche:
The ordering principle: fund first what attackers and insurers both care about - the two lists overlap almost perfectly, and that overlap is your fastest proof of ROI. To see how much of Phase 1 and 2 a platform can absorb out of the box, pressure-test a guided demo against your requirements list.
Published figures vary widely, and no single number applies to every operation. IBM's Cost of a Data Breach research puts average breach costs for organizations generally in the 4 to 5 million USD range, and industrial downtime is commonly cited at anywhere from tens of thousands to over one million USD per hour depending on the industry and scale of the operation. Total incident cost stacks several components: ransom (if paid), lost production during downtime, recovery and rebuild labor, incident response and forensics, regulatory exposure, and customer trust. For most operators the dominant cost is downtime, not the ransom itself - which is why recovery capability drives the business case more than any other control.
Most cyber insurance applications now include detailed security questionnaires, and several controls have effectively become underwriting gates: multi-factor authentication on remote and privileged access, network segmentation between IT and OT, tested offline or immutable backups, endpoint protection and monitoring, and a documented incident response plan. Operators that cannot attest to these controls increasingly face higher premiums, coverage exclusions, sublimits on ransomware, or declined coverage. Terms and pricing vary by insurer, sector, and year, so treat the questionnaire as a minimum baseline rather than a complete security program.
Translate technical risk into operational and financial language. Frame security spending as avoided-loss expected value: estimate a plausible incident cost range for your operation (downtime days multiplied by production value, plus recovery), pair it with an honest likelihood range, and show how each proposed control reduces that exposure. Add the concrete, bankable items - insurance premium impact, audit effort reduction, compliance obligations with deadlines - and the operational side benefits such as better visibility and fewer site visits. Boards respond to downtime days, safety exposure, and compliance dates far better than CVE counts.
There is no universal number - spend scales with the consequence of downtime, regulatory exposure, and what infrastructure you already run. Small operators often achieve the largest risk reduction from low-cost fundamentals: MFA everywhere, closing inbound firewall exposure, tested backups, and named user accounts with least-privilege roles. A cloud SCADA platform can shift much of the security engineering burden - patching, monitoring, secure architecture - to the vendor for a predictable subscription, which is frequently more realistic for a small team than building and staffing an on-premise security stack. Right-size the program to your risk, and fund the controls that cut off the most common attack paths first.
It shifts them more than it eliminates them. With a cloud platform, the vendor carries platform patching, infrastructure hardening, monitoring, and much of the compliance evidence burden as part of the subscription - costs an on-premise operator must staff and fund directly. The operator still owns identity and access decisions, field device security, network segmentation, and operational procedures under the shared responsibility model. For many small and mid-size operators the total cost of a comparable security posture is lower in the cloud model, but the honest framing is a shift of responsibility and spend, not a disappearance of it.
See how much of your security roadmap a platform can absorb out of the box - outbound-only gateway, MFA and RBAC by default, immutable audit records, SIEM delivery - priced for your operation.