![]() |
½ÃÀ庸°í¼
»óǰÄÚµå
1568195
°Ç¹°¿ë OT »çÀ̹ö º¸¾È »ê¾÷ ºÐ¼®(2024-2030³â)Buildings OT Cybersecurity Industry Analysis 2024-2030 |
°Ç¹°¿ë OT »çÀ̹ö º¸¾È¿¡ ´ëÇÑ ÅõÀÚ°¡ Áõ°¡Çϰí ÀÖÁö¸¸ »ó´ëÀûÀ¸·Î ³·Àº ¼öÁØ¿¡¼ ½ÃÀÛÇÏ¿© ¾÷°è Àü¹ÝÀÇ ¸¹Àº »çÀ̹ö º¸¾È ÇÁ·Î±×·¥ÀÌ Àü¹ÝÀûÀ¸·Î ¹Ì°³¹ß »óÅÂÀÓÀ» °Á¶Çϰí ÀÖ½À´Ï´Ù. 2024³â ¼¼°è ÅõÀÚ¾×Àº 37¾ï ´Þ·¯¿¡ ´ÞÇÒ °ÍÀ¸·Î ¿¹»óµÇ¸ç, »çÀ̹ö º¸¾È¿¡ ´ëÇÑ À§Çè ÀνÄÀÌ ³ô¾ÆÁü¿¡ µû¶ó 2023-2031³â CAGRÀº 16%·Î ¼ºÀåÇÕ´Ï´Ù. 2024-2031³â TAMÀº 517¾ï ´Þ·¯À̸ç, ÀÌ ÅõÀÚÀÇ 80% ÀÌ»óÀº ¼±Áø±¹ÀÌ Áß½ÉÀÔ´Ï´Ù. WA´Â ºÏ¹Ì, À¯·´, ¾Æ½Ã¾ÆÅÂÆò¾ç ¼±Áø±¹À» Á¦¿ÜÇÑ Áö¿ª¿¡¼´Â 2030³â±îÁö ÅõÀÚ°¡ Á¦ÇÑÀûÀÌ°í ¼ºÀå·üµµ ³·À» °ÍÀ¸·Î ¿¹ÃøÇß½À´Ï´Ù.
¼±Áø±¹¿¡´Â °·ÂÇÑ ½ÃÀå ¼ºÀå ÃËÁø¿äÀÎÀÌ ÀÖ½À´Ï´Ù. °æÁ¦ÀÇ ºÒÈ®½Ç¼º¿¡µµ ºÒ±¸Çϰí, 2025³â ÀÌÈÄ °ÇÃ๰ÀÇ °Ç¼³ ¼ºÀåÀº °ÈµÉ °ÍÀ¸·Î ¿¹»óµË´Ï´Ù. °Ç¹° ÀÚ»ê ¼ÒÀ¯ÁÖµéÀÌ EPBD(¿¡³ÊÁö ¼º´É °Ç¹° Áöħ), ¹Ì±¹ EO 14057(2045³â±îÁö ¹Ì±¹ ¿¬¹æ °Ç¹°¿¡¼ ¼ø ¹èÃâ·® Á¦·Î ¸ñÇ¥), Àεµ ¿¡³ÊÁö Àý¾à¹ý, ÀϺ» °ÇÃ๰ ¿¡³ÊÁö Àý¾à¹ý µî ´Ù¾çÇÑ ¿¡³ÊÁö ¼º´É ¸ñÇ¥¸¦ ´Þ¼ºÇϱâ À§ÇØ ³ë·ÂÇϰí ÀÖÀ¸¹Ç·Î Áö¼Ó°¡´É¼º ¸ñÇ¥µµ ¸®³ëº£ÀÌ¼Ç ½ÃÀåÀ» ÃËÁøÇÒ °ÍÀÔ´Ï´Ù. µµ ¸®³ëº£ÀÌ¼Ç ½ÃÀåÀ» ÃËÁøÇÒ °ÍÀ¸·Î º¸ÀÔ´Ï´Ù. ºôµù °ü¸® Ç÷§Æû, ½º¸¶Æ® ¼¾¼, Ä¿³ØÆ¼ºñƼ °È¿¡ ´ëÇÑ ´ë±Ô¸ð ÅõÀÚ´Â ÀÌ·¯ÇÑ Áö¼Ó°¡´É¼º ¸ñÇ¥¸¦ ´Þ¼ºÇÏ´Â µ¥ µµ¿òÀÌ µÉ °ÍÀ¸·Î ¿¹»óµË´Ï´Ù. ±â¼ú ¹ßÀüÀº ¿¡³ÊÁö ºñ¿ë Àý°¨°ú Áö¼Ó°¡´É¼º Çâ»ó»Ó¸¸ ¾Æ´Ï¶ó °ÅÁÖÀÚÀÇ °æÇèÀ» °³¼±ÇÏ´Â µ¥¿¡µµ µµ¿òÀÌ µÉ °ÍÀÔ´Ï´Ù. ±×·¯³ª ¿¬°á¼º°ú ½º¸¶Æ® ±â±â Áõ°¡´Â »õ·Î¿î Ãë¾àÁ¡À» ¾ß±âÇÏ°í °ø°ÝÀÇ ´ë»óÀÌ µÇ´Â ¿µ¿ªÀ» ³ÐÈ÷±â ¶§¹®¿¡ ÀÚ»ê ¼ÒÀ¯ÀÚ´Â »çÀ̹ö º¸¾È ÇÁ·Î±×·¥À» Á¶Á¤Çϰí ÁøÈ½ÃÄÑ¾ß ÇÕ´Ï´Ù.
°Ç¹°¿¡¸¸ ±¹ÇÑµÈ °ÍÀº ¾Æ´ÏÁö¸¸, NIS2¿Í °°Àº »çÀ̹ö º¸¾È ±ÔÁ¤Àº ÀνÄÀ» ³ôÀÌ°í »çÀ̹ö À§Çè ÇÁ·Î±×·¥À» °³¼±ÇÏ´Â µ¥ µµ¿òÀÌ µÉ °ÍÀ¸·Î ±â´ëµÇ¸ç, NIS2´Â ÀÌÀü ¹öÀü(NIS)º¸´Ù Å©°Ô È®´ëµÇ¾úÁö¸¸, °·ÂÇÑ ½ÃÇà ¾øÀÌ´Â º¯È°¡ ´õµð´Ù´Â °ÍÀ» ÀÔÁõÇϰí ÀÖ½À´Ï´Ù. WA´Â °Ç¹° ÀÚ»êÀÇ µðÁöÅÐÈ¿Í ÀÌ»çȸÀÇ »çÀ̹ö º¸¾È À§Çè¿¡ ´ëÇÑ ÀǽÄÀÇ Çâ»ó°¡ ÇöÀç¿Í ¹Ì·¡ÀÇ »çÀ̹ö º¸¾È ±ÔÁ¦º¸´Ù ´õ Áß¿äÇÑ ÅõÀÚ ÃËÁø¿äÀÎÀ̶ó°í »ý°¢ÇÕ´Ï´Ù.
»çÀ̹ö º¸¾È ±â¼úÀÌ ºÎÁ·Çϰí, º¹ÀâÇÑ º¥´õ ¹× ¼ºñ½º °ø±Þ¾÷ü »ýŰ谡 Á¸ÀçÇϸç, °æ¿µÁøÀÇ Çå½Åµµ°¡ ³·°í, ¿¹»ê Á¦¾àÀÌ ÀÖ´Â ºÐ¾ß¿¡¼´Â ÀÏ¹Ý °Ç¹° »ç¾÷ÀÚÀÇ »çÀ̹ö À§Çè ÇÁ·ÎÆÄÀÏÀ» ³·Ã߱Ⱑ ½±Áö ¾Ê½À´Ï´Ù. ÀÌ·¯ÇÑ À庮Àº ¾÷°è ±³À° ¹× Çù·Â °È¸¦ ÅëÇØ ±Øº¹ÇØ¾ß ÇÕ´Ï´Ù.
WA´Â DX µ¿Çâ¿¡ µû¶ó »çÀ̹ö º¸¾È¿¡ ´ëÇÑ »ý°¢µµ Á¡Â÷ º¯ÈÇϰí ÀÖ´Ù°í º¾´Ï´Ù. Á¶Á÷ÀÌ Á¦·Î Æ®·¯½ºÆ® ¾ÆÅ°ÅØÃ³¸¦ ÁöÇâÇÏ¸é¼ ÀÚ»ê ¹× µð¹ÙÀ̽º °ü¸®, Ãë¾à¼º °ü¸®, ³×Æ®¿öÅ© ¼¼ºÐÈ, À§Çù ŽÁö, º¸¾È ¿ø°Ý ¾×¼¼½º °ü¸®¿¡ ´ëÇÑ °ü½ÉÀÌ ³ô¾ÆÁö°í ÀÖ½À´Ï´Ù. ±×·¯³ª µ¥ÀÌÅͰ¡ ¿§Áö µð¹ÙÀ̽º¿¡¼ ó¸®µÈ ÈÄ ÀúÀå ¹× ºÐ¼®À» À§ÇØ Å¬¶ó¿ìµå Ç÷§ÆûÀ¸·Î Àü¼ÛµÇ´Â °æ¿ì°¡ Áõ°¡ÇÔ¿¡ µû¶ó ÀÚ»ê ¼ÒÀ¯ÀÚ´Â OT µð¹ÙÀ̽º¿Í ³×Æ®¿öÅ© º¸È£¿¡ ÁýÁßÇØ¾ß Çϸç, µ¿½Ã¿¡ ¿§Áö µð¹ÙÀ̽º¿Í Ŭ¶ó¿ìµå °£ÀÇ µ¥ÀÌÅÍ º¸È£¸¦ º¸ÀåÇÒ ¼ö ÀÖµµ·Ï ÇØ¾ß ÇÕ´Ï´Ù. º¸È£ÇÒ ¼ö ÀÖµµ·Ï ÇØ¾ß ÇÕ´Ï´Ù. Á¶Á÷ÀÌ ÃÖ¼ÒÇÑÀÇ È¥¶õÀ¸·Î »ç°í¿¡ ´ëÀÀÇÏ°í º¹±¸ÇÒ ¼ö ÀÖµµ·Ï Çϱâ À§Çؼ´Â ȸº¹Åº·Â¼º(resilience)¿¡ ´õ¿í ÁßÁ¡À» µÎ¾î¾ß ÇÕ´Ï´Ù. ¿©±â¿¡´Â »ç¶÷, ÇÁ·Î¼¼½º, ±â¼ú¿¡ ÁßÁ¡À» µÎ°í »çÀ̹ö º¸¾ÈÀ» ±â¾÷ ¸ñÇ¥ ¹× ±ÔÁ¦ ¿ä°Ç°ú ÀÏÄ¡½ÃŰ´Â °Å¹ö³Í½º ÇÁ·¹ÀÓ¿öÅ©°¡ Æ÷ÇԵ˴ϴÙ.
ÀÌ ºÐ¼®¿¡¼´Â °Ç¹°¿ë OT »çÀ̹ö º¸¾È ½ÃÀåÀ» °ËÅäÇϰí, ÀÚ»ê ¼ÒÀ¯ÀÚ¿Í º¸¾È ¸®´õ¿¡°Ô ¿µÇâÀ» ¹ÌÄ¡´Â µ¿ÇâÀ» »ìÆìº¸°í, ÇöÀç¿Í ¹Ì·¡ÀÇ OT »çÀ̹ö º¸¾È ÁöÃâÀ» Æò°¡ÇÕ´Ï´Ù.
OT ³×Æ®¿öÅ© ¹× Àåºñ º¸È£¿¡ »ç¿ëµÇ´Â ±â¼ú°ú ¼ºñ½º¸¦ ´ë»óÀ¸·Î ÇÕ´Ï´Ù. ÆÛµà ¸ðµ¨¿¡¼´Â ·¹º§ 3 ÀÌÇÏÀ̸ç, ÷ºÎµÈ Â÷Æ®¿¡ ¼³¸íµÈ °¨µ¶ °èÃþ, ÀÚµ¿È °èÃþ, ÇöÀå °èÃþÀ» Æ÷ÇÔÇÕ´Ï´Ù.
ºôµùÀÇ ¿ë¾î´Â Á¾Á¾ °°Àº Àǹ̷Π¾²ÀÌ´Â °æ¿ì°¡ ¸¹½À´Ï´Ù. ºôµù °ü¸® ½Ã½ºÅÛ(BMS), ºôµù ÀÚµ¿È ½Ã½ºÅÛ(BAS), ºôµù Á¦¾î ½Ã½ºÅÛ(BCS), ¼³ºñ °ü·Ã Á¦¾î ½Ã½ºÅÛ(FRCS)Àº ¸ðµÎ Áߺ¹µÇ¾î ÇÁ·ÎÁ§Æ® ¹üÀ§¿¡ Æ÷ÇԵ˴ϴÙ.
½Ã½ºÅÛ ¹× Àåºñ¿Í °ü·Ã ÄÁÆ®·Ñ·¯¿¡´Â HVAC, ¿¡³ÊÁö °ü¸®, ¿¤¸®º£ÀÌÅÍ, ÈÀç ¹× ¾ÈÀü, Á¶¸í, ÀüÀÚ º¸¾È(¹°¸®Àû ÃâÀÔ ÅëÁ¦, °¨½Ã Ä«¸Þ¶ó), ±â°è ½Ã½ºÅÛ(±Þ¼ö ÆßÇÁ µî), ÁÖÂ÷ ½Ã½ºÅÛ µîÀÌ Æ÷ÇԵ˴ϴÙ.
ÀÌ ÇÁ·ÎÁ§Æ®¿¡´Â NIST 2.0 ÇÁ·¹ÀÓ¿öÅ©(°Å¹ö³Í½º, ½Äº°, º¸È£, ŽÁö, ´ëÀÀ, º¹±¸) Àü¹Ý¿¡ °ÉÃÄ °Ç¹° OT¸¦ º¸È£ÇÏ´Â µ¥ »ç¿ëµÇ´Â ±â¼ú ¹× °ü¸®Àû »çÀ̹ö º¸¾È °ü¸®°¡ Æ÷ÇԵ˴ϴÙ. À¯ÀÏÇÑ ¿¹¿Ü´Â ºÐ¼®¿¡¼ Á¦¿ÜµÈ ¹é¾÷ ¹× ÀçÇØº¹±¸ ±â¼úÀÔ´Ï´Ù.
¿¬±¸ ´ë»ó ÇÁ·ÎÁ§Æ®´Â Àü ¼¼°è¸¦ ´ë»óÀ¸·Î Çϸç, ¿¬±¸ ±â°£Àº 2023-2031³âÀ̸ç, 2023³âÀº ±âÁØ ¿¬µµ, 2024³âÀº ¿¹ÃøÄ¡À̹ǷΠÀÌÈÄ º¸°í¼¿¡¼ º¯°æµÉ ¼ö ÀÖ½À´Ï´Ù. ÃÑ °¡¿ë ½ÃÀå(TAM)Àº 2024-2031³â, CAGRÀº 2023-2031³âÀÔ´Ï´Ù.
Investment in buildings OT cybersecurity is increasing although it is starting from a relatively low base, highlighting the overall underdeveloped state of many cybersecurity programs across the industry. Global investment is forecast to reach $3.7B in 2024 and will grow at a CAGR of 16% from 2023-2031 as cybersecurity risk awareness improves. The TAM from 2024 to 2031 is $51.7B with over 80% of this investment spread across developed nations. Outside of NA, Europe and developed countries in Asia Pacific, WA expects limited investment and low growth to 2030.
There are strong market drivers in developed economies. Despite economic uncertainties, the construction growth for buildings is expected to strengthen post-2025. Sustainability goals will also drive the renovation market as building asset owners aim to meet energy performance targets such as the Energy Performance Buildings Directive (EPBD), the US EO 14057 which targets net-zero emissions from federal buildings by 2045, India's Energy Conservation Act and Japan's Building Energy Conservation Act, among others. Significant investment in building management platforms, smart sensors, and enhanced connectivity are expected to help reach these sustainability goals. Technological advancements will not only reduce energy costs and improve sustainability but also enhance occupant experiences. However, growing connectivity and smart devices introduce new vulnerabilities and expands the attack surface requiring assets owners to adapt and evolve cybersecurity programs.
Although not specific to buildings, cybersecurity regulations such as NIS2 are expected to enhance awareness and improve cyber risk programs although WA expects the impact to be limited to incremental improvements to current programs rather than large and widespread investment. Although NIS2 has been significantly expanded from its predecessor (NIS), history highlights that without strong enforcement change is slow. WA believes that digital transformation of building assets and growing board awareness of cybersecurity risk are more significant investment drivers than current and forthcoming cybersecurity regulation.
Lowering the typical building operators cyber risk profile is challenging in a sector that lacks cybersecurity skills, has a complex ecosystem of vendors and service companies, limited board commitment, and budget constraints. These barriers need to be overcome through greater industry education and collaboration.
WA believes that attitudes to cybersecurity are slowly changing in response to digital transformation trends. This includes a growing focus on asset and device management, vulnerability management, network segmentation, threat detection and Secure Remote Access Management as organisations move towards zero-trust architectures. However, as data is increasingly processed by edge devices, and forwarded to cloud platforms for storage and analysis, asset owners need to focus on protecting OT devices and networks, whilst ensuring that edge devices and data is protected to and from the cloud. A greater focus on resilience is required, ensuring that organisations can respond and recover from incidents with minimal disruption. This includes a focus on people, processes and technology and a governance framework that aligns cybersecurity with company goals and regulatory requirements.
This analysis reviews the Building OT Cybersecurity market, exploring the trends impacting asset owners and security leaders, and evaluates current and future OT cybersecurity expenditure.
The project covers the technologies and services used to protect OT networks and devices. In the Purdue Model this is level 3 and below, covering the supervisory layer, automation layer and field layer described in the accompanying chart.
Building terminologies are often used interchangeably. Building Management Systems (BMS), Building Automation Systems (BAS), Building Control Systems (BCS) and Facility Related Control Systems (FRCS) all overlap and are included within the scope of the project.
Systems, devices and related controllers includes HVAC, energy management, elevators, fire and safety, lighting, electronic security (physical access control, surveillance cameras), mechanical systems (e.g. water pumps) and parking systems.
The project includes technical and administrative cybersecurity controls used to protect buildings OT across the NIST 2.0 framework (Govern, Identity, Protect, Detect, Respond, Recover). The only exception is back-up and disaster recovery technology which has been excluded from the analysis.
The project is global and covers the period 2023 to 2031. The base year is 2023 and 2024 is a forecasted number that may change in subsequent editions of the report. The Total Available Market (TAM) is often quoted for the period 2024-2031 whilst the CAGR for the period covers 2023-2031.