Who’s winning the cybersecurity arms race? A region-by-region scorecard
What you’ll learn:
- Global information security spending is tracking toward roughly $249 billion in 2026, up close to 13% year-on-year.
- North America is absorbing roughly 44% of global security spending.
- Europe writes the best rules. North America holds the strongest procurement lever and the deepest tooling budget. Asia-Pacific manufactures the most and is closing the investment gap fastest.
There is a number that should end every boardroom argument about industrial cybersecurity budgets. Unplanned downtime on an automated assembly line runs at roughly $2.4 million per hour. Not per day. Per hour.
See also: U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs
For a plant producing defense-related sensor assemblies, avionics subsystems or precision components against a contracted delivery schedule, a four-day outage becomes a nine-figure event before anyone counts the reputational damage or the penalty clauses that can follow.
That arithmetic explains where capital is moving. Global information security spending is tracking toward roughly $249 billion in 2026, up close to 13% year-on-year, with a credible path beyond $370 billion by 2030.
The OT slice of that is expanding considerably faster than the enterprise average, growing at mid-teens compound rates as manufacturers discover that the controls protecting their email were never designed to protect their production lines.
The defense-adjacent segment tells the same story in miniature. According to Acumen Research & Consulting, the global military sensors cybersecurity solutions market size was valued at $4.3 billion in 2025. The market is observed to reach $9.4 billion by 2035, while growing at a CAGR of 8% during the forecast period of 2026 to 2035.
Sensors are the revealing case, because they are built in commercial plants, moved through commercial supply chains, and then asked to perform under adversarial conditions.
The factory that produces the component and the theaters of war that consume it now share a single threat surface. So which region is handling that surface best? Nobody is winning outright, and the reasons differ by column.
When the assembly line became the target
- The threat data leaves little room for interpretation. Industrial threat tracking published in early 2026 counted 119 ransomware groups targeting industrial organizations during 2025, a 49% jump from the 80 active a year earlier. Those groups reached roughly 3,300 industrial organizations, up from 1,693 in 2024. Manufacturing absorbed more than two thirds of all victims.
- The momentum has carried forward. The second quarter of 2026 produced 1,140 industrial ransomware incidents, a 12% increase over the 1,020 logged in the first quarter.
- Manufacturing accounted for 747 of those, or 65% of the total. Engineering firms, system integrators and equipment makers, which is to say the industrial supply chain itself, took another 117.
- Three operational numbers explain why these campaigns keep succeeding. Average ransomware dwell time inside OT environments runs to 42 days. Around 88 percent of OT networks still lack effective detection and response capability. And unsecured remote access, through VPN portals, firewall interfaces and vendor tunnels, remains the most common route into a plant network.
- Attackers are not defeating industrial control protocols. They are walking through maintenance doors that were propped open for convenience.
- The financial exposure compounds it. Average ransom demands against manufacturers reached $1.16 million in 2025, more than doubling in 12 months, and 2026 breach investigation data found ransomware involved in 61% of manufacturing breaches against 48% across all sectors.
North America: Fortress with an unlocked loading dock
North America remains the commercial center of gravity, absorbing roughly 44% of global security spending. The weakness is distribution, not volume. Tier-one primes run mature OT programs with dedicated plant security teams and hardware-level segmentation. Their tier-three suppliers frequently cannot produce a complete asset inventory.
See also: IT-OT convergence: When ransomware hits the factory floor
“Only 9% of North American organizations expect security budget increases above 10% this year, the lowest figure of the three major regions. Having spent early, the region is now spending slowest.”
The victim data skews heavily toward the mid-market, which is precisely where defense programmes source their machined housings, wiring harnesses and optical subassemblies.
There is a complacency signal in the budget numbers, too.
Washington's most effective cyber instrument is not a statute; it’s a contract clause.
The U.S. Department of Defense requested $14.32 billion for cyberspace activities in fiscal 2026, an increase of $967.6 million over the FY 2025 enacted level of $13.36 billion and the largest such request in the department's history.
Tier-one primes run mature OT programs with dedicated plant security teams and hardware-level segmentation. Their tier-three suppliers frequently cannot produce a complete asset inventory.
The composition matters more than the headline. The defensive cybersecurity portfolio took $8.31 billion, up 15.47% year-on-year, while cyberspace operations fell 2.07% to $5.40 billion. Money is shifting from offence toward hardening. Federal civilian agencies added roughly $11.7 billion, pushing the total federal request past $20 billion.
Perspective is worth keeping! Cyber remains 1.69% of an $848.3 billion defense budget request, which says something about the scale of ambition relative to the scale of the institution.
The real leverage sits in the Cybersecurity Maturity Model Certification program, which converts security posture into bid eligibility for roughly 200,000 defense industrial base companies. Execution is the bottleneck.
See also: Hackers exploit PLMs in recent cyberattacks at Shell, GE, Philips
Government audit reporting published in March 2026 found only 92 authorized third-party assessment organizations as of December 2025, working out to around 3.17 certified assessors per 1,000 defense suppliers. For a midsize firm machining housings for infrared sensor modules, the obstacle is no longer willingness to comply. It’s finding somebody qualified to sign off.
Private capital has moved into that vacuum faster than policy did. Cyber insurers now underwrite on documented evidence of IT and OT segmentation. Industrial buyers increasingly write IEC 62443 (standards that define requirements and processes for securing industrial automation and control systems and OT) conformance directly into supplier terms. Federal rulemaking moves in years. Procurement terms move in quarters.
Is AI arming the defenders or the intruders?
Both, and the balance has not settled!
The investment case is unambiguous. According to Cervicorn Consulting, the global AI in cybersecurity market size was valued at $28.38 billion in 2025 and is expected to be worth around $228.64 billion by 2035, expanding at a compound annual growth rate of 23.2% over the forecast period from 2026 to 2035.
That is roughly an eightfold expansion in a decade, and industrial environments are among its strongest applications, because plant traffic is far more predictable than corporate traffic.
See also: AI is superpowering cyberattacks, but manufacturers can cut their exposure
A pump does not spontaneously open an encrypted session with an unfamiliar host. Behavioral models flag that deviation in seconds, which is the only useful timescale when downtime costs $2.4 million an hour. Brussels has formalized the connection.
The EU Action Plan on Cybersecurity and AI, published in July 2026, is the first European document to treat AI-assisted threat detection as an expected operational practice under NIS2 rather than a discretionary upgrade.
The counterweight is that AI has collapsed the cost of a convincing attack. Phishing aimed at plant engineers now arrives in fluent local language referencing genuine purchase orders and real supplier contacts.
Europe: The rulebook grows teeth
Europe legislates harder than anyone and has finally started enforcing. As of mid-2026, 23 of 27 EU member states had fully transposed NIS2, bringing roughly 160,000 entities into scope with maximum penalties of 10 million euro ($11.5 million) or 2% of global turnover, plus personal liability for management bodies.
The European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice in July 2026 over incomplete transposition, with financial sanctions requested.
Germany's federal cybersecurity authority is auditing some 29,000 entities.
See also: AI ‘governance gap’ persists across industries as security incidents continue to rise
The behavioral effect is measurable. European Union agency estimates put the EU-wide rise in cybersecurity spending across 2025 and 2026 at 34%, with essential entities now allocating an average 9.8% of IT budget to security against 6.7% before NIS2, which is the expanded EU law that sets strict cybersecurity and incident reporting rules across 18 critical industrial sectors. The European industrial cybersecurity market stood near $5.8 billion in 2025 and is compounding at roughly 9.5%.
Asia-Pacific: Is the “world's factory” guarding Its own door?
Asia-Pacific builds the components that everyone else's defense programs depend on, and it’s now spending most aggressively to catch up. Some 22% of organizations across the region expect security budget increases above 10% this year, more than double the North American figure and comfortably ahead of Europe's 14%.
A leading Japanese or Korean facility matches anything in Bavaria. A contract assembler three tiers down may run no passive monitoring at all, and it appears on the same bill of materials.
Consolidation signals how seriously the industrial base is taking it. Mitsubishi Electric acquired OT security platform Nozomi Networks for $883 million in September 2025, an automation manufacturer buying detection capability outright rather than partnering for it. On the policy side, Japan's Active Cyberdefense Law, Singapore's amended Cybersecurity Act and India's six-hour incident reporting window under CERT-In all push in the same direction.
See also: Black Kite: Ransomware increasing across all metrics in 2026
Variance is the risk. Asia logged 172 industrial ransomware incidents in the second quarter of 2026 against Europe's 316, though regional disclosure norms in Asia almost certainly understate the real total. A leading Japanese or Korean facility matches anything in Bavaria. A contract assembler three tiers down may run no passive monitoring at all, and it appears on the same bill of materials.
Nobody wins from the top down
Europe writes the best rules. North America holds the strongest procurement lever and the deepest tooling budget. Asia-Pacific manufactures the most and is closing the investment gap fastest. None of that produces a winner. The decisive variable is not regional. It is depth.
Ransomware operators nearly doubled their industrial victim count in a single year without needing to touch a single programmable logic controller, because compromising an ERP platform or a hypervisor hosting SCADA software halts production just as effectively as manipulating a control loop. Every scorecard above measures the top of the pyramid. The exposure lives in the three tiers underneath it.
For executives with manufacturing exposure, the practical question for the next 12 months is narrow and unglamorous: Can you name every remote access path into your plant network, including the ones your vendors use?
Given that 82% of OT environments still carry unsecured remote access, most cannot. That gap, not the regional balance of power, decides whether the next incident becomes a headline.
About the Author
Mahima SambreMahima Sambre
Mahima Sambre, a trained business journalist, is a market research writer and insights expert for Acumen Research and Consulting. She specializes in emerging technologies, industrial automation, artificial intelligence, robotics, and advanced manufacturing. She’s analyzing the rise of physical AI, tracking automation trends, or exploring the next wave of smart manufacturing.
