Industries
Cybersecurity for manufacturing and automation
Europe is a heartland of machine building and industrial automation — and therefore a favoured target for cyberattacks. Connected production and connected products create efficiency, but also new attack surface: from the single machine through the control system to the device shipped to the customer. A successful attack here rarely means only data loss, but a production halt or an unsafe product in the market.
Two roles, one method
Industrial companies are under double pressure. As operators of their production they fall under NIS2. As manufacturers of products with digital elements — connected machines, controllers, components — they fall under the Cyber Resilience Act. Treating the two separately leads to duplicate processes and needless cost. We think both roles together, with IEC 62443 as the common technical framework.
The particular danger of IT/OT convergence
Industry 4.0 lives on the link between production and corporate IT — and that link is the risk. In many plants, production has grown over time and is only inadequately separated from the office network. A phishing message in administration can thus lead to a production outage; malware that first hits IT jumps across to a poorly segmented production network and brings production lines to a standstill. A clean separation of the two worlds is therefore the single most important measure.
Typical environments
- Programmable logic controllers (PLCs) and industrial controllers
- Control systems (SCADA) for monitoring production
- Manufacturing execution systems (MES) at the interface to IT
- Connected machines, robots and industrial sensors
- Remote-maintenance access by machine and plant suppliers
The product side — CRA and secure development
For manufacturers it goes beyond their own production: your products must become CRA-conform. We accompany the classification, the building of an SBOM and vulnerability process, the reporting capability (mandatory since September 2026) and the technical documentation — technically underpinned by IEC 62443-4-1 and 4-2. That secures not only your production but your ability to sell.
What we deliver
On the operator side: an OT security assessment, separation of production and office networks, securing of remote maintenance, and NIS2 scoping. On the product side: IEC 62443 and CRA guidance through to conformity. Both from one source, with one contact who commands both the technology and the boardroom language.
Why the mid-market is especially exposed
Large corporations run their own security departments; very small businesses are a less rewarding target. In between sits the industrial mid-market — large enough to hold valuable data, costly plant and recognised names, but often without a specialist security team. Attackers exploit exactly this gap. On top of that, many mid-sized firms sit as suppliers in longer supply chains, and so become the way in for attacks on larger customers.
Customers demand evidence
In manufacturing, cybersecurity has long been a selling point. More and more buyers require evidence against IEC 62443 or of CRA conformity in tenders before they will source a machine or component. A supplier who cannot provide it loses orders, regardless of the technical quality of the product. Security thus becomes a precondition for market access, not only an obligation towards the authorities.
A typical attack scenario
The most common damage arises not from a highly sophisticated attack but from malware that enters administration through a harmless-looking message and spreads from there into an inadequately separated production network. Once production stands still, every hour counts. The best precaution is therefore unspectacular: a clean separation of office and production networks, secured remote maintenance, and a rehearsed incident plan.
First steps
We recommend starting with an assessment of the two most pressing questions: how well are production and administration separated, and which of your products fall into which CRA class? The answers yield a prioritised path that brings operator and manufacturer obligations together rather than working them separately.
Connected products change liability
As long as a machine was a closed system, the manufacturer's responsibility largely ended at delivery. Connected products change that: a vulnerability in a shipped controller can be exploited years later — and the manufacturer is obliged to fix it and, where applicable, report it. The CRA casts this responsibility into law. It demands a shift in thinking: away from the product as a one-off delivery, towards the product that must be maintained across its entire lifecycle.
Automation and integrators
It is not only machine manufacturers who are affected, but system integrators and automation companies that combine components from various makers into one solution. IEC 62443 applies here with particular force: the standard explicitly describes the responsibility of integrators and the requirements for how components work together. We support you in fulfilling that role cleanly — towards your customers as towards the regulator. An unclear chain of responsibility thus becomes a traceable, auditable level of security.
Your partner with industry and product understanding
Pure IT providers do not understand production; large consultancies rarely deliver as far as the machine or into the product. We bring both — an understanding of operational technology and the regulatory framing for management and the authorities — and remain one fixed, accountable point of contact.
Both obligations, one project
Approaching operator and manufacturer obligations separately costs twice over. We bring NIS2, IEC 62443 and the CRA into one coordinated approach — producing a level of security that does justice to both roles without wasting resources.
Further reading: Product Security & CRA · IEC 62443 – Assessment & Security Architecture · OT Security Assessment
Book a call for manufacturers
A free intro call, no commitment, a reply within 24 hours.