drj logo

"*" indicates required fields

Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!
This field is for validation purposes and should be left unchanged.

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
DRJ Fall 2025 Dallas Show
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2025
    • DRJ Spring 2026 Call for Papers
    • DRJ Scholarship
    • Other Industry Events
    • Schedule & Archive
    • Send Your Feedback
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • DRJ ACADEMY
    • DRJ Academy
    • Beginner’s Guide to BC
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • Business Resilience Decoded
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • DEI
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • Glossary Committee
      • Rules and Regulations Committee
  • Podcast

Study: Industry Should Make Cybersecurity a Top Priority for Devices, Machines, and Systems in 2025

by Jon Seals | February 5, 2025 | | 0 comments

  • “OT+IoT Cybersecurity Report”: Companies have too little budget for cybersecurity
  • Jan Wendenburg, CEO ONEKEY: “Companies should be prepared for cyber incidents.”
  • ONEKEY at Embedded World 2025: Hall 5, Booth 5-376

DUESSELDORF– The German Federal Office for Information Security (BSI) has found that an average of more than 2,000 new vulnerabilities are discovered in software every month, of which around 15 percent are classified as “critical”. “In view of this constant threat situation, German industry should further strengthen its cyber resilience in 2025,” advised Jan Wendenburg, CEO of the Duesseldorf-based cybersecurity company ONEKEY. He is referring to his company’s “OT+IoT Cybersecurity Report 2024”, according to which the industry neglected software security in networked devices, machines and systems last year. “The industry has a lot of catching up to do in this area in 2025 compared to last year,” said Jan Wendenburg. The report on security in operational technology (OT) and Internet of Things (IoT) devices is based on a survey of 300 industry executives: https://www.onekey.com/resource/ot-iot-cybersecurity-report-2024

According to the study, around two-thirds of companies surveyed believe that cyber security should be improved. A third of them consider the budget allocated to defending against hackers to be “limited”, meaning that more emphasis should be placed on this area. According to the report, 27% of companies are unsure about the budget situation for cyber security measures. Only 34% of companies surveyed have what they consider to be an “adequate” or even “significant” budget for cyber resilience initiatives. “The other two thirds should clarify their IT security budget in the new year and increase it quickly,” ONEKEY CEO Jan Wendenburg recommended for 2025.

Most Companies Rely on Contractual Security Measures

As part of the survey, ONEKEY also wanted to know what measures companies are using to test their cyber resilience. According to the survey, 36 percent conduct threat assessments, 23 percent initiate penetration tests, 22 percent rely on intrusion detection, i.e. active monitoring of networks, and 15 percent prefer vulnerability assessments (multiple answers were allowed). 19% strengthen security through network segmentation, so that a successful intrusion into one segment does not compromise the entire corporate network.

However, the most commonly used measure against cybercriminals in the survey was not technical protection, but legal protection: 38 percent of companies require their IT service providers and suppliers to contractually guarantee security. Whether this is an effective measure remains questionable, however, as suppliers with “contractually assured security” have also been involved in almost all major security incidents in recent years, such as Cloudflare, Crowdstrike, Cisco and others.

Just under a third (32 percent) of the companies surveyed have processes in place to learn from security incidents and implement necessary improvements. “Pre-defined business processes that define how to deal with hacking attacks, both during and after an attack, should be part of every company’s security repertoire,” said Jan Wendenburg. He explained: “In view of the ongoing threat situation, every company management should be adequately prepared for the worst-case scenario.”

Jan Wendenburg: “Cyber Resilience Should Top the 2025 Agenda.”

Just over a third (34 percent) of organizations make at least some effort to improve security following a hacking incident. According to the survey, these companies make an effort to thoroughly analyse and evaluate the security incident they have survived and derive improvements in terms of measures to ward off cyber criminals. However, the “OT+IoT Cybersecurity Report” finds that about the same number of companies are more or less helpless in the face of cyber attacks. They are largely unaware of how to deal with attacks on connected devices, machines and systems. 16 percent have not developed operational procedures to learn from cyber attacks and implement necessary improvements.

“Business leaders should put cyber resilience at the top of their agenda for 2025,” recommended Jan Wendenburg.

Visit ONEKEY at the Embedded World 2025
Learn more about ONEKEY’s OT and IoT security solutions at Embedded World 2025. ONEKEY will be present with a booth: Hall 5, booth 5-376. For more information please visit our event page: https://www.onekey.com/resource/embeddedworld2025

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of The automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life. 

Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated software bill of materials (SBOM) generation. “Digital Cyber Twins” enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle. 

The patent-pending, integrated Compliance Wizard™ already covers the EU Cyber Resilience Act (CRA) and requirements according to IEC 62443-4-2, ETSI EN 303 645, UNECE R 155 and many others.

The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritisation of vulnerabilities, significantly reducing the time to remediation.

Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform (OCP) and ONEKEY Cybersecurity Experts.

Contact us: ONEKEY GmbH,
Kaiserswerther Str. 45, 40477 Duesseldorf, Germany,
Sara Fortmann, e-mail: sara.fortmann@onekey.com,
website: https://onekey.com

Related Content

  1. Integration of Cybersecurity into Physical Security Realm
  2. Disaster Recovery Journal
    User Involvement in Recovery Planning
  3. Disaster Recovery Journal
    Minimizing Downtime in Critical Power Infrastructure

Recent Posts

Mark43 Expands UK Presence with New Manchester Office

July 17, 2025

Lansweeper Acquires Redjack, Strengthening its Position as the Global Leader in Technology Asset Intelligence

July 17, 2025

Microsoft Highlights Long-Time Partner Visus After it Helps Santa Barbara County Surveyor’s Office Digitize Slow-Moving Paper Processes

July 17, 2025

Zimperium Warns of Surge in Mobile Cyber Threats as Summer Travel Heats Up

July 17, 2025

Strata Identity Introduces Maverics Identity Orchestration for AI Agents to Secure, Control, and Observe Agentic Behaviors

July 17, 2025

Flexential’s 2024 ESG Report Details Advancements Across Data Center Efficiency, Talent Support, and Operational Oversight

July 16, 2025

Archives

  • July 2025 (40)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (91)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2025
    • Spring 2025

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal is the industry’s largest resource for business continuity, disaster recovery, crisis management, and risk management, reaching a global network of more than 138,000 professionals. Offering weekly webinars, the latest industry news, rules and regulations, podcasts, the industry’s only official mentoring program, a quarterly magazine, and two annual live conferences, DRJ is leading the way to keep professionals up-to-date and connected in an ever-changing world.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2025 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Fall 2025 | Building Resiliency Through Innovation

    Leave your details below for a chance to win a free pass to DRJ Fall 2025 | Building Resiliency Through Innovation. The winner will be announced on July 11. Join us for DRJ’s 73rd Conference!

    Enter Now