OT security in manufacturing protects systems that monitor or control physical processes without compromising availability, time sensitivity or the safety of people. It requires an accurate inventory, network segmentation based on actual flows, identity management, controlled remote access, monitoring and changes planned within a safe operational window.
Unlike office IT environments, industrial systems often operate under strict process continuity requirements. A communications interruption, unexpected restart or configuration change can affect production, product quality, equipment and the plant's safe state. This is why manufacturing cybersecurity does not begin with deploying a single tool. It begins with understanding the process that needs protection.
The NIST guide to OT security describes the need for an approach tailored to operational technology. In practice, this means assessing every security control for its effect on plant operations rather than automatically transferring an office IT model.
A list of IP addresses, serial numbers or network switches is not enough to manage OT risk. The inventory should help the team answer operational questions: what a device does, who is responsible for it, which part of the process it supports and what happens if it becomes unavailable or behaves incorrectly.
For every important PLC, HMI, industrial computer, server, engineering workstation, network device and connection to an external system, it is useful to record:
This inventory is not only a security register. It speeds up fault resolution, downtime planning and change assessment. If the team does not know which HMI station controls a particular section of a line or which server sends data to the ERP system, it cannot safely isolate a problem.
Asset discovery also needs to fit the plant. Passive communications monitoring is often more suitable than aggressive active scanning. Before any active check, assess how an older or sensitive device may respond, who will monitor the process during the check and how the activity will be stopped if instability appears.
Network segmentation is not merely splitting addresses across several subnets. Its purpose is to limit communication so that an incident, configuration error or compromised user account does not gain an unnecessary path to the plant's control functions.
A practical approach is to group industrial systems into zones according to function, risk level and communications need. Examples of zones may include the office network, business servers, a controlled exchange point to production, supervisory systems, engineering workstations and individual production cells. The exact design depends on the process, topology and equipment.
For every connection between zones, record:
This record turns the general rule of blocking what is unnecessary into a verifiable operational requirement. If communication is unknown, it is not clear whether it can be interrupted. If it is known, it can be permitted in a controlled way through rules between zones instead of providing broad access to the entire plant network.
The ERP connection to production needs particular care. A business planning system may need to exchange work orders, production status, material data or quality data. That does not mean an office user or ERP server should have direct access to control devices. A controlled exchange point, a clearly defined data set and restricted communication paths reduce exposure without interrupting necessary exchange. Process and data context can be connected to solutions such as ORKA manufacturing , while the security architecture must separately define how those systems are permitted to communicate.
Shared administrator passwords create a problem when it is necessary to establish who made a change or quickly remove access from a person who no longer has an operational role. Wherever the system supports it, access should be tied to an individual identity and role.
Permissions should not be identical for an operator, maintenance technician, process engineer, IT administrator, integrator and external supplier. Their scope, time and purpose differ. A person checking machine status does not necessarily need the right to modify a controller program. An external supplier may need access only to a specific workstation, during an agreed window and under the supervision of a responsible person.
Older equipment may not support individual accounts, modern sign-in methods or detailed activity logging. In these cases, do not pretend the device has capabilities it does not have. Instead, introduce compensating controls, for example:
Remote access requires the same principle. It should not remain permanently open merely because it is convenient for support. A safer operational pattern includes an access request, approval by the responsible person, a defined time window, access through a controlled point and activity logging. It should also define in advance what happens if the connection drops during an intervention or if the intervention requires a process state change.
Patching OT systems is not a reason to postpone security measures indefinitely. A vulnerability can create risk, but a change can also cause downtime, incompatibility or unexpected behavior. Both risks need to be assessed together.
Before a patch, network rule change, HMI application upgrade or PLC program modification, the team should know:
A rollback plan must be real, not merely documented. If a configuration can only be restored from media that nobody can access, or if nobody knows the restoration sequence, the organization does not have reliable rollback. The same principle applies to backups of controller programs, recipes, network configurations and communications documentation.
CISA recommended practices for industrial control systems can help structure baseline controls, responsibilities and procedures for industrial systems.
Unexpected communication, failed sign-in, configuration change, new network connection or modification to a controller program can be a security signal. However, the same symptom may result from device failure, an integration error, equipment replacement or planned maintenance work.
Monitoring therefore cannot end with sending an alert. IT, OT and production should agree on which events they monitor, who assesses them first, who is informed and what the escalation procedure is. An operator or maintenance team can often confirm whether a particular change was expected. The security team can assess whether the activity departs from permitted communications paths or access patterns.
A useful start is to select a small set of meaningful signals: changes to accounts and permissions, failed sign-ins, new communication between zones, configuration changes, unusual use of administrative tools and interruptions to important connections. For every signal, define the data source, the review owner and the action that follows.
Rather than attempting to redesign the entire plant at once, an initial project can cover one production zone or one critical integration. The objective is not perfect documentation. It is verifiable progress that does not endanger operations.
For the selected zone, use the following sequence:
Isolation is not always the same as immediately disconnecting a network. For some processes, a sudden interruption may be less favorable than a controlled transition to a safe state. The procedure should therefore be designed together with people who understand the process, machine safety and technical architecture.
Segmentation, identities and monitoring reduce exposure, but they do not remove the need for maintenance, documentation and procedure exercises. Older industrial systems, supplier agreements, limited downtime and incomplete documentation can slow implementation. These are reasons for a phased plan and compensating controls, not reasons to abandon baseline protection.
The EU NIS2 framework lists several manufacturing areas among covered sectors, but each company should confirm its specific legal scope with a qualified professional. The official text is available on EUR-Lex .
As a next step, select one zone where the process, owners and communications paths are sufficiently understood for review. Compare documented and actual traffic, confirm access rights and verify whether the zone can be recovered and isolated in a way that preserves safe plant operations. That finding provides a concrete basis for extending OT security to other industrial systems.