What Investors & Analysts are getting wrong about the OT Market

Ted Gutierrez

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

In his S4x24 talk, "What Investors & Analysts are getting wrong about the OT Market," Ted Gutierrez delivers a compelling and critical analysis of the current state of the Operational Technology (OT) cybersecurity market. Drawing from extensive experience within the asset owner world and numerous interactions with investors, Gutierrez argues that a fundamental misunderstanding of OT operational realities is driving a dysfunctional market. He highlights a significant disconnect between the expectations of investors and product companies—who seek rapid scalability and high valuations—and the actual purchasing behaviors and needs of OT asset owners, whose priorities are rooted in safe, reliable operations and long-term maintenance cycles.

Watch on YouTube

Visual summary for What Investors & Analysts are getting wrong about the OT Market by Ted Gutierrez
Visual summary for What Investors & Analysts are getting wrong about the OT Market by Ted Gutierrez

Key moments

  1. 0:40 Initial doubts about the OT market's Total Addressable Market
  2. 1:30 OT cyber journey is longer, more expensive, and tougher
  3. 2:30 Unveiling three critical myths affecting the OT market
  4. 5:00 Analyst feedback loop broken: The 'Chinese whispers' effect
  5. 6:00 Critique: Analysts lack real OT operational experience
  6. 7:00 Investor capital misaligned with OT's long buying cycles
  7. 8:00 Excessively high valuations distorting the OT cybersecurity market

What Investors & Analysts are getting wrong about the OT Market

Speakers: Ted Gutierrez

Conference: S4

YouTube: https://www.youtube.com/watch?v=UW2ibQeSMgo

Overview

In his S4x24 talk, "What Investors & Analysts are getting wrong about the OT Market," Ted Gutierrez delivers a compelling and critical analysis of the current state of the Operational Technology (OT) cybersecurity market. Drawing from extensive experience within the asset owner world and numerous interactions with investors, Gutierrez argues that a fundamental misunderstanding of OT operational realities is driving a dysfunctional market. He highlights a significant disconnect between the expectations of investors and product companies—who seek rapid scalability and high valuations—and the actual purchasing behaviors and needs of OT asset owners, whose priorities are rooted in safe, reliable operations and long-term maintenance cycles.

Gutierrez challenges the prevailing narratives around the OT cybersecurity market, asserting that its total addressable market (TAM) is often overestimated and that traditional IT growth models do not apply. This misalignment, he contends, creates a "rock up the hill" scenario where various stakeholders are pushing and pulling in different directions, leading to frustration for asset owners, financial difficulties for product companies, and unmet return expectations for investors. The talk serves as a crucial call to action for the industry to realign its understanding with the unique characteristics and demands of critical infrastructure environments, advocating for a more grounded and operationally focused approach to OT cybersecurity.

Background

▶ Watch: Initial doubts about the OT market's Total Addressable Market (0:40)

The genesis of this market misalignment, as Gutierrez explains, lies in the fundamental differences between the Information Technology (IT) and Operational Technology (OT) domains. Investors, accustomed to the rapid growth and scalability of IT markets, approach OT cybersecurity with similar expectations. They seek solutions with a vast Total Addressable Market (TAM) that can scale "to the moon," justifying significant capital deployment. However, Gutierrez, speaking from the perspective of an asset owner, quickly realized this premise was flawed. OT asset owners simply do not acquire products and services at the same pace or with the same motivations as their IT counterparts.

The OT cyber journey is characterized as "longer, more expensive, and tougher" than often perceived. This is due to several factors: organizational changes, budget cuts, and the inherent operational constraints within critical infrastructure. Unlike IT, where rapid upgrades and software-as-a-service models are common, OT environments prioritize safe, reliable operations above all else. Purchasing decisions are tied to maintenance cycles—often spanning years—rather than annual budget allocations or immediate perceived threats. This foundational difference means that products not directly contributing to operational uptime or safety are difficult to justify.

Furthermore, Gutierrez highlights a broken feedback loop within the industry. In an ideal scenario, asset owners communicate their needs to market analysts, who then inform investors, leading to capital deployment for relevant product development. These products then meet asset owner demands, reinforcing the market. However, in OT, this loop is distorted, resembling a game of "Chinese whispers." Analysts often lack practical, "steel toes or hard hats" experience on the shop floor, instead basing their market insights on the amount of capital raised by investors. These investors, often new to OT, deploy capital with a short 18-month expectation for returns, creating pressure for rapid growth and inflated valuations that are out of sync with OT's reality. This influx of "liquidity" into the market, driven by IT-centric investment models, has inadvertently made it tougher for genuine OT solutions to thrive sustainably.

Key Findings

▶ Watch: Unveiling three critical myths affecting the OT market (2:30)

Gutierrez identifies three core myths that are fundamentally distorting the OT cybersecurity market and preventing sustainable growth:

  1. Distorted Feedback Loops: The traditional market feedback loop, where asset owner needs drive analyst reports, which in turn inform investor capital and product development, is broken in OT. Many market analysts lack on-the-ground experience in operational environments, relying instead on the volume of venture capital raised by companies. This means that investor activity, often driven by IT-centric growth models, is inadvertently validating market narratives that do not accurately reflect the practical demands of asset owners. This creates a supply of products and services that may not genuinely align with the slow, deliberate, and safety-focused purchasing cycles of OT organizations.
  1. Overestimated Market Size and Misaligned Valuations: Gutierrez argues that the concept of OT cybersecurity as a massive, standalone market is fundamentally flawed. Instead, he proposes that OT cyber should be a subsegment of revenue-oriented investments necessary to achieve safe, reliable uptime. Asset owners integrate safety and security within their existing operational and maintenance frameworks, not as separate, high-growth IT-style purchases. The prevailing high valuations placed on OT cybersecurity startups by investors are forcing asset owners into a position where they are pressured to buy products they may not truly need or cannot integrate within their operational budgets and timelines. This creates an artificial demand driven by investor expectations for high returns, rather than genuine operational necessity.
  1. Ineffective "Land-and-Expand" Strategy: The common IT sales strategy of "land in one part of the organization and expand to others" does not translate effectively to OT environments. OT organizations have distinct silos, different operational priorities, and longer, more complex procurement processes. Gaining a foothold in one area does not guarantee broader adoption at the same rate seen in IT, leading to slower growth and higher customer acquisition costs for product companies, further exacerbating the challenge for venture-backed firms aiming for rapid scaling.

Gutierrez substantiates these findings with compelling data points. Examining employment and revenue growth over two years, he notes that public cyber companies, industrials, and IT sectors generally showed flat or declining trends. However, a "diamond in the rough" emerged: Original Equipment Manufacturers (OEMs). These companies, deeply embedded in industrial operations, possess significant cash reserves and trade on different multiples. While other sectors experienced reductions in force, OEMs demonstrated consistent growth, acquiring thousands of industrial clients. Crucially, the speaker highlights that OEMs are actively acquiring OT cybersecurity companies, but at valuations significantly lower than typical venture capital expectations. The last eight deals observed were between $25 million and $125 million, which is a "third of the average amount of capital raised by some of the industry juggernauts." These acquisitions are primarily by industrial players, with only a few by IT companies, indicating a divergence in how value is perceived and realized in the OT market. This data suggests that the true sustainable path for OT cybersecurity companies often lies with integration into established industrial ecosystems rather than pursuing independent, high-valuation public offerings or large IT acquisitions.

Technical Deep Dive

▶ Watch: Analyst feedback loop broken: The 'Chinese whispers' effect (5:00)

While this talk does not delve into specific code exploits or protocol vulnerabilities, its "technical deep dive" lies in dissecting the mechanisms of market failure within the highly specialized context of Operational Technology (OT). The core technical misunderstanding that Gutierrez exposes is the application of IT-centric business and investment models to environments governed by entirely different technical and operational imperatives.

The operational technology landscape is fundamentally distinct from IT. OT systems, such as Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) systems, and Distributed Control Systems (DCS), are designed for long lifecycles, often decades, prioritizing safety, reliability, and deterministic operations. Unlike IT, where patching cycles are frequent and downtime is often tolerable, OT systems require extreme uptime, and any changes, including security updates, must be meticulously planned, tested, and integrated into existing maintenance cycles. These cycles can be infrequent, sometimes occurring only during scheduled shutdowns every few years.

The technical implications of the distorted feedback loops are profound. When market analysts and investors, lacking "steel toes" experience, base their understanding on IT investment trends, they inadvertently encourage the development of OT cybersecurity products that may be technically ill-suited for the environment. These products might:

  • Lack native integration: Many solutions are developed with IT architectures in mind, struggling to integrate seamlessly with proprietary OT protocols (e.g., Modbus, DNP3, OPC UA), legacy hardware, and air-gapped or heavily segmented networks.
  • Introduce unacceptable risk: Deploying IT-style agents or intrusive scanning tools can disrupt delicate OT processes, leading to instability, downtime, or even safety hazards. The primary concern in OT is preventing operational disruption, even if it means slower adoption of security measures.
  • Fail to align with operational workflows: OT cybersecurity is not a standalone function but must be deeply embedded within existing operational processes, maintenance schedules, and engineering workflows. Solutions that require separate management consoles, new skill sets not possessed by OT engineers, or demand frequent updates are often rejected.
  • Overlook the "human element": OT environments often have a smaller, highly specialized workforce, where "tribal knowledge" is critical. Technical solutions must be intuitive and augment existing staff capabilities rather than requiring extensive retraining or new hires in an already constrained talent pool.

Gutierrez's argument that "OT cyber should be a subsegment of the revenue-oriented investments necessary to achieve safe, reliable uptime" is a critical technical insight. It implies that cybersecurity in OT is not merely about preventing breaches but about ensuring the continuous, secure operation of physical processes. Technical solutions must therefore demonstrate a clear, quantifiable contribution to operational resilience, rather than simply offering a list of security features. This includes considerations for asset inventory solutions that can map complex, heterogeneous OT networks without disruption, vulnerability management that accounts for legacy systems and extended patching cycles, and risk assessments that factor in physical consequences and safety integrity levels. The technical viability of an OT cybersecurity solution is thus inextricably linked to its ability to function within these unique operational constraints, a factor often overlooked by those applying an IT investment lens.

Demo / Proof of Concept

▶ Watch: Investor capital misaligned with OT's long buying cycles (7:00)

This talk focused on market analysis and strategic insights into the OT cybersecurity market rather than demonstrating specific tools, vulnerabilities, or proof-of-concept exploits. Therefore, a dedicated demo section is not applicable.

Defensive Implications

▶ Watch: Excessively high valuations distorting the OT cybersecurity market (8:00)

Ted Gutierrez's insights offer critical defensive implications for OT asset owners, product companies, and the broader industrial cybersecurity community. The primary takeaway for asset owners is to be highly discerning and grounded in their operational realities when evaluating cybersecurity solutions.

  1. Prioritize Operational Reality: Asset owners must continue to prioritize safe, reliable operations as the bedrock of their cybersecurity strategy. Cybersecurity is not an isolated IT function but an integral part of maintaining uptime and safety. Solutions should be evaluated based on how they enhance, not disrupt, these core objectives. This means integrating security within existing maintenance cycles and operational workflows, rather than adopting products that demand rapid, IT-style deployment.
  2. Question Market Hype and Valuations: Be wary of products and services driven by inflated investor valuations and market hype. Asset owners should buy based on genuine operational needs, proven efficacy in OT environments, and clear return on investment in terms of enhanced reliability and safety, not because a company has raised a large amount of capital or promises a "kinetic attack" prevention. Question whether a product truly aligns with the long-term, deliberate nature of OT procurement.
  3. Demand OT-Native Solutions: Seek solutions from vendors who demonstrate a deep understanding of OT environments, including proprietary protocols, legacy systems, and the unique constraints of industrial operations. The "steel toes or hard hats" experience is paramount. This often means looking towards Original Equipment Manufacturers (OEMs) or specialized industrial players, which Gutierrez identifies as showing sustainable growth and sensible acquisition strategies. These entities are more likely to offer solutions that integrate seamlessly and do not introduce undue risk to critical processes.
  4. Influence the Feedback Loop: Asset owners have a crucial role to play in correcting the distorted feedback loop. Engage with analysts, but critically evaluate their understanding of OT. Provide candid feedback on genuine needs and challenges, pushing back against narratives that do not reflect on-the-ground reality. This helps to create more accurate market documentation and guides investor capital towards truly valuable solutions.
  5. Focus on Foundational Elements: Concentrate on fundamental cybersecurity practices that align with OT operational needs, such as accurate asset inventory solutions, pragmatic vulnerability management adapted for long patch cycles, and risk assessments that consider physical consequences. These foundational elements, integrated into existing processes, provide more value than chasing every new, high-tech solution.
  6. Budget Realistically: Understand that the OT cyber journey is "longer, more expensive, and tougher." Budget for long-term integration, ongoing maintenance, and the necessary specialized skill sets, rather than expecting quick, IT-style wins.

For product companies, the defensive implication is to pivot from an IT-centric growth mindset to one that truly serves the OT market's unique characteristics. This means developing solutions that deeply integrate with operational workflows, demonstrate clear value in maintaining uptime and safety, and embrace a longer, more patient sales cycle. For investors, the message is clear: adjust expectations regarding TAM, valuation, and return timelines. Sustainable success in OT lies in backing companies that understand and respect the operational realities, often through partnerships or acquisitions by established industrial players, rather than aiming for rapid, IT-style exits.

Key Takeaways

  • The OT cybersecurity market is fundamentally misunderstood by many investors and analysts, leading to misaligned expectations and unsustainable business models.
  • Asset owners operate on long maintenance cycles and prioritize safe, reliable operations, making their purchasing behavior distinct from IT and resistant to rapid "land-and-expand" strategies.
  • Market feedback loops are distorted; many analysts lack practical OT experience and base their insights on investor capital rather than genuine asset owner needs.
  • Valuations for OT cybersecurity companies are often inflated by IT-centric investment models, pressuring asset owners to buy products they may not truly need.
  • Original Equipment Manufacturers (OEMs) represent a "diamond in the rough," showing consistent growth and acquiring OT cybersecurity companies at more realistic valuations ($25M-$125M), indicating a more sustainable path for the industry.
  • Asset owners should be discerning, prioritize solutions that enhance operational resilience, and integrate cybersecurity within their existing operational and maintenance frameworks, rather than chasing market hype.

About the Speaker(s)

Ted Gutierrez, the speaker for "What Investors & Analysts are getting wrong about the OT Market," brings a unique and highly informed perspective to the discussion. His insights are rooted in extensive experience "coming from the asset owner world," providing him with a deep, on-the-ground understanding of the operational realities, purchasing behaviors, and core priorities within critical infrastructure environments. This background has given him a critical lens through which to evaluate the broader OT cybersecurity market. Furthermore, Gutierrez has engaged in "150 different meetings with investors," affording him direct exposure to their expectations, investment strategies, and the challenges faced by product companies seeking capital. This dual perspective—from both the demand side (asset owner) and the supply/funding side (investor interactions)—makes him a credible and authoritative voice on the disconnects and opportunities within the OT market.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk is a brutal, yet essential, exposé on the fundamental misalignments driving the Operational Technology (OT) cybersecurity market. Gutierrez, with unparalleled "steel toes" credibility, dismantles pervasive myths around market size, investor expectations, and asset owner behavior. His analysis, backed by concrete observations on OEM acquisitions, provides critical, actionable intelligence for anyone navigating the OT space, cutting through the hype to reveal the true operational realities and sustainable pathways for growth. This is the kind of hard-hitting market intelligence that actually matters.

Heather Calloway (CISO) — MUST SEE

Ted Gutierrez's S4x24 talk offers a sharp, unsentimental diagnosis of the fundamental market dysfunction in OT cybersecurity. He clearly articulates how IT-centric investment models misalign with the operational realities of critical infrastructure, leading to wasted capital and ineffective solutions. This is a crucial strategic message for any CISO, board member, or policymaker involved with OT, providing actionable insights on how to navigate a misinformed market and prioritize genuine operational resilience over hype.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference