Back to Industries
INDUSTRIES · MANUFACTURING & IIOT

Manufacturing reality. OT-IT convergence. NIS2-essential.

What is installed in manufacturing is older than the regulation now applied to it. We separate zones under IEC 62443, terminate the crossings between office IT and the plant, and put an end to standing remote access — in the operating mode the plant can carry.
NIS2-essential IEC 62443 OT-IT convergence

What we find

In its list of the ten most important threats to industrial control systems, the BSI names "intrusion via remote maintenance access" and "control components connected to the internet", and vulnerabilities in the supply chain. That is the view from outside. From inside it looks like this:

Designs that have stood for twenty years. In manufacturing businesses, often family-owned and grown over generations, we find constructions that were taught in vendor training two decades ago — still in operation, unchanged. Most recently in remote access: a model that was state of the art then and survives no scrutiny today.

MAB as access control. MAC Authentication Bypass is sold and understood as access control, at times even described as dot1x. The vendor's own documentation states that MAB is not a strong authentication method and that it can be defeated by spoofing a valid MAC address. Anyone who can reach a camera or a printer on the shop floor has a valid port.

One vendor for every layer. VPN, firewall, proxy, access control, data-centre network — the same brand, regardless of whether that product is the strongest one for that layer. Alongside it a statically routed legacy network, while modern fabric architectures are being built at the same time because the vendor and the integrator recommended them.

And then the new world, without a network. Kubernetes, Terraform, two hyperscalers and a CDN at once, introduced by teams neither trained nor staffed for it. The result is environments nobody fully oversees in operation — and that are connected to the plant network anyway.

You are advised by the company selling the hardware

That is the core of the problem, and it is not a question of competence on the customer side. Whoever recommends an architecture usually also sells the components it is made of. That is a legitimate business motivation, but it systematically produces the same outcomes: more boxes, more licences, one vendor across every layer, and a recommendation that never reads "you don't need to buy anything for this". That MPLS offers are still being put on tables as modernisation in 2026 follows the same logic.

In many companies, responsibility has also sat with the same people for decades, grown out of operations. That is not a weakness — these people know their plant better than any outsider. The problem is the training that never happened alongside it, and the advice that came from the vendor of all places. Anyone who has looked after the same architecture for twenty years never had cause to question the principles behind it. That is exactly what an outside party is brought in for — not to replace the people.

Our position on this is uncomfortable and simple: a concept is finalised so that it can be questioned afterwards. We do that with our own every six months. What has stood unchanged in a plant for twenty years has never been through that review.

How to get out of it

Zones first, products second. IEC 62443 provides the frame: zones and conduits, a security level per zone according to damage potential. That is architecture work and costs no licence. Only afterwards does the question arise of which product enforces a zone — and the answer differs per layer.

Terminate the crossings. Between office IT, the MES level and the field level sits a system that terminates the protocol, inspects it and passes on only what is permitted. Modbus, Profinet, S7 and OPC UA have a describable normal state; a crossing that understands this is worth more than a rule that forwards a network.

Access gets an end. Vendor remote maintenance runs through a PAM path: approval per assignment, a fixed time window, session recording, no permanently stored credentials. This addresses the threat the BSI lists in its top ten without making maintenance impossible.

One source of truth. Identities, rules and states live in one place and under version control. From there the network, servers, endpoints and applications are supplied. Without it, every zone architecture stays a drawing.

No agents at device level. Nothing of ours runs on PLCs or at station level. Control sits at the crossing: terminate, inspect, forward or reject — and on the process traffic a learned normal picture that reports deviations to a human.

Where it pays to start

A survey of the crossings and the remote access paths, before anything is procured. In this order: who comes in from outside today and by which route; which zone talks to which and about what; where access control hangs on a MAC address; and which of the running projects solve a problem you actually have.

Source: BSI-CS 005, "Industrial Control System Security — Top 10 Bedrohungen und Gegenmaßnahmen", version 1.50 of 03.05.2022. On the classification of MAB: Cisco, MAC Authentication Bypass Deployment Guide.

Concrete offerings

What you can hand off

  • Segmentation survey

    Review the zone architecture and name the weaknesses in the crossings.

  • ICS detection for your protocols

    Modbus, Profinet, S7 and OPC UA. Understand the protocol state instead of logging it raw.

  • SOC integration with the OT level

    Classify alerts correctly and route them to the escalation path that fits.

  • IEC 62443 maturity assessment

    Determine the security level per zone and plan the hardening along your maintenance windows.

  • Evidence pack for NIS2

    Logs, detection traces and incident reports in the form the report requires.

  • Engineering data protection

    CAD, Step 7 and project databases encrypted and versioned, restored in minutes.

Regulatory framework

The four that actually bite

Four documents decide what actually has to be done in manufacturing, and in which order. Also relevant, depending on the business: KRITIS duties under the BSI Act, ISO 27001, TISAX for automotive suppliers, GDPR.

  • NIS2 · Risk management
    NIS2 implementation · Risk management measures

    Requires detection, continuity, supply-chain security and regular testing — and makes management personally accountable. Operationally the most expensive part is not the technology but the evidence: who decided what, and when, has to be provable. We build the evidence trail into operations instead of reconstructing it before the audit.

  • NIS2 · Reporting
    NIS2 implementation · Reporting obligations

    Significant incidents must be reported initially within 24 hours, substantiated within 72 hours and closed within one month. Nobody meets those deadlines from a standing start. We set the reporting path up as a rehearsed process: trigger from detection, prepared report, named approver — tested before it is needed.

  • IEC 62443-3-3
    IEC 62443-3-3 · System security requirements and security levels

    Defines security levels 1 to 4 per zone according to damage potential. This is the frame that lets architecture be defended against procurement: first it is settled which zone needs which level, then it is decided which product enforces it. We assess the current state per zone and plan the hardening along your maintenance windows.

  • IEC 62443-2-1
    IEC 62443-2-1 · Cybersecurity management system for OT

    Requires a documented management system specifically for OT — separate from the office IT's ISO 27001 ISMS, because the risk profile is a different one. We run both scopes side by side rather than merged, so that no conditions apply in plant operations that nobody there can meet.

Sector facts

As of 2026-09 · Source: dynexo Operations
Typical engagementsManufacturing across several sites · family-owned to group · IT and OT in one hand
Most common triggersNIS2 applicability, an incident in the plant, a cyber insurer's requirement, an OEM audit
Typical operating modelOn-premise or hybrid · process network without internet access, IT side EU-hosted
Core regulationNIS2 · IEC 62443 · TISAX where automotive
What we touch firstRemote access, crossings between office IT and manufacturing, access control at the port
On field devicesNo agents · control sits at the crossing
Maintenance windowsRare and expensive · every change tested and reversible
Operating levelsManual, automated or by playbook — selectable per area
Asked often

Asked before the briefing

  • Can you detect directly at PLC level?
    Not on the PLC itself — memory and compute are too constrained. We detect at network layer (fieldbus traffic) and at engineering workstations (Step7, TIA). PLC-native anomaly detection is not yet mature enough to be standard in 2026. Instead: fieldbus state-machine understanding + upstream alerts.
  • How do you patch OT without production halt?
    With you, in your maintenance windows. We bring patch plan and structured test procedures (staging, rollback plan, checkpoint management). You decide timing and sequence.
  • Do we need air-gapped networks?
    Rarely. Hybrid with strict firewall rules or diode concepts (one-way data flow for logging) is standard. True air-gap is expensive and impractical — we show alternatives.
  • What if we do not have an OT inventory yet?
    We start there — passive discovery from network telemetry, then active scans in coordinated maintenance windows. 30–60 days to a reliable list. We can start building first detection in parallel.
Next step

How does OT security look concretely for your plant?

The industry briefing analyses your zone architecture, shows NIS2 compliance gaps and delivers a hardening plan for the next 12 months — at times that do not interrupt production.