OT Cybersecurity: Ireland’s Challenges and Opportunities 

On 18th November, the OT Cybersecurity Conference 2025, organised by ISA Ireland Section in partnership with Cyber Ireland, brought together over 200 attendees in Mullingar to examine Ireland’s operational technology cybersecurity landscape. Participants from critical infrastructure, manufacturing, energy, and the broader cybersecurity community took part in a full day of discussions, case studies, and practical insights. 

The agenda included sessions from a range of organisations working across Ireland’s cybersecurity and industrial sectors. The National Cyber Security Centre (NCSC) opened Session 1 with an overview of cyber fundamentals, followed by contributions from RDJArmis, Deloitte Ireland, Security Risk Advisors, and others on topics such as OT insurance considerations, incident response planning, evolving OT security approaches, and applied security testing. 

With a steady emphasis on collaboration, resilience, and upcoming regulatory requirements, the conference provided a clear overview of the challenges facing OT environments and the shared efforts underway to strengthen Ireland’s preparedness in this area.

As Conference Chair, I’d like to provide some perspectives on OT Cybersecurity: Ireland’s Challenges and Opportunities. 

OT security is a significant and rising problem for organisations, for society for national and global security. Business trends and needs such as IT/OT convergence, digital transformation, increasing need for an use of cloud, AI, big data, IoT in OT markets is being impeded by the increasing cyber security risk. However, as it is progressing, the risk to OT verticals such as manufacturing, utilities, healthcare, etc. is increasing due to increased IT/OT convergence resulting in increased attack surface areas. OT cyber security practices are typically less mature and are about 5-10 years behind where IT cyber security practice is today, due mainly to the different business drivers of prioritising manufacturing or utility services availability and safety over other typical cyber security needs such as integrity and confidentiality.  

Specialist OT cyber criminal groups focusing not just on OT but on specific verticals in OT are emerging. Overall ransomware groups focusing on OT grew by 60% in the last year. We have witnessed nation states actively targeting and successfully exploiting OT as part of hybrid warfare in Ukraine/Russia and in the Middle East. There is an active “cold war” in OT going on globally, in non kinetic “peacetime”.  Europe has recognised the risk to European security and prosperity by bringing in a wide ranging set of cyber security legislation to protect critical sectors and to address a significant risk to societal, economic and political risk to European Area members, specifically EU Cyber Security Act, EU Cyber Solidarity Act, DORA, NIS2 and CRA. 

NIS 2 is soon to be transposed in Ireland and will bring both IT and OT in scope for improving resilience and security of critical and important service providers. It’s estimated that NIS2 now brings into scope over 4,500 organisations in Ireland, a lot of whom have OT or Cyber Physical systems. 

Cyber Ireland have been collaborating with ISA for three years now on organising their annual conference, which aims to build out the expertise of Cyber Ireland and ISA Ireland members in the areas of practical and best practice OT and IT security. The goal is ultimately to increase the pool of converged IT and OT cyber security experts to service ISA member OT cyber security needs and to help Cyber Ireland members grow into the emerging OT cyber Security market.

 

A recent Marsh McClellan Dragos report identified the potential risk of OT security at USD 329.5BN, modelled off cyber risk intelligence data. A recent Frost Sullivan report identified the Cyber Physical Security market and OT+ market to be USD 32BN in 2024 forecasted to grow to USD 74.15BN by 2030. So, as we can see the financial risk to the industries using OT is very significant whilst the opportunity to help address and remediate that risk is also very significant. The CPS (OT+) market is approximately 13% of the IT Cyber Security market today. 

The pool of resources to service the OT or CPS need is currently very small. Ireland’s  success in attracting FDI in key areas such as Life Sciences, Pharmaceutical along with our indigenous success in Agri Food,Information Technology and digital services provision in Information technology manufacturing means that many Irish organisations have OT Cyber Security needs. Ireland has the opportunity to rapidly grow our OT services and solutions capabilities and establish a first mover advantage is this newly maturing segement. To do so, we need to invest in talent and skills, research, development and innovation and scaling up service providers to become a world leader in this segment. It needs active collaboration of the cyber security sector with other key sectors such as manufacturing, healthcare, telecoms and technology sectors. It also needs government economic and national security agency supports. The challenge is clear but so is the opportunity if we can collaborate to make Ireland an OT cyber security centre of excellence. 

Photo Gallery

Join Cyber Ireland's OTSec Special Interest Group

Cyber Ireland’s Operational Technology Cybersecurity (OTSec) Special Interest Group (SIG) provides a forum for industry end-users, integrators and vendors to share information, best practices and support capability building in operational technology cyber security across organisations and sectors.

If interested in joining or supporting the OTSec SIG activities, please fill out the OTSec SIG Application Form