Manufacturing reality. OT-IT convergence. NIS2-essential.
What is installed in manufacturing is older than the regulation now applied to it. We separate zones under IEC 62443, terminate the crossings between office IT and the plant, and put an end to standing remote access — in the operating mode the plant can carry.
What we find
In its list of the ten most important threats to industrial control systems, the BSI names "intrusion via remote maintenance access" and "control components connected to the internet", and vulnerabilities in the supply chain. That is the view from outside. From inside it looks like this:
Designs that have stood for twenty years. In manufacturing businesses, often family-owned and grown over generations, we find constructions that were taught in vendor training two decades ago — still in operation, unchanged. Most recently in remote access: a model that was state of the art then and survives no scrutiny today.
MAB as access control. MAC Authentication Bypass is sold and understood as access control, at times even described as dot1x. The vendor's own documentation states that MAB is not a strong authentication method and that it can be defeated by spoofing a valid MAC address. Anyone who can reach a camera or a printer on the shop floor has a valid port.
One vendor for every layer. VPN, firewall, proxy, access control, data-centre network — the same brand, regardless of whether that product is the strongest one for that layer. Alongside it a statically routed legacy network, while modern fabric architectures are being built at the same time because the vendor and the integrator recommended them.
And then the new world, without a network. Kubernetes, Terraform, two hyperscalers and a CDN at once, introduced by teams neither trained nor staffed for it. The result is environments nobody fully oversees in operation — and that are connected to the plant network anyway.
You are advised by the company selling the hardware
That is the core of the problem, and it is not a question of competence on the customer side. Whoever recommends an architecture usually also sells the components it is made of. That is a legitimate business motivation, but it systematically produces the same outcomes: more boxes, more licences, one vendor across every layer, and a recommendation that never reads "you don't need to buy anything for this". That MPLS offers are still being put on tables as modernisation in 2026 follows the same logic.
In many companies, responsibility has also sat with the same people for decades, grown out of operations. That is not a weakness — these people know their plant better than any outsider. The problem is the training that never happened alongside it, and the advice that came from the vendor of all places. Anyone who has looked after the same architecture for twenty years never had cause to question the principles behind it. That is exactly what an outside party is brought in for — not to replace the people.
Our position on this is uncomfortable and simple: a concept is finalised so that it can be questioned afterwards. We do that with our own every six months. What has stood unchanged in a plant for twenty years has never been through that review.
How to get out of it
Zones first, products second. IEC 62443 provides the frame: zones and conduits, a security level per zone according to damage potential. That is architecture work and costs no licence. Only afterwards does the question arise of which product enforces a zone — and the answer differs per layer.
Terminate the crossings. Between office IT, the MES level and the field level sits a system that terminates the protocol, inspects it and passes on only what is permitted. Modbus, Profinet, S7 and OPC UA have a describable normal state; a crossing that understands this is worth more than a rule that forwards a network.
Access gets an end. Vendor remote maintenance runs through a PAM path: approval per assignment, a fixed time window, session recording, no permanently stored credentials. This addresses the threat the BSI lists in its top ten without making maintenance impossible.
One source of truth. Identities, rules and states live in one place and under version control. From there the network, servers, endpoints and applications are supplied. Without it, every zone architecture stays a drawing.
No agents at device level. Nothing of ours runs on PLCs or at station level. Control sits at the crossing: terminate, inspect, forward or reject — and on the process traffic a learned normal picture that reports deviations to a human.
Where it pays to start
A survey of the crossings and the remote access paths, before anything is procured. In this order: who comes in from outside today and by which route; which zone talks to which and about what; where access control hangs on a MAC address; and which of the running projects solve a problem you actually have.
Source: BSI-CS 005, "Industrial Control System Security — Top 10 Bedrohungen und Gegenmaßnahmen", version 1.50 of 03.05.2022. On the classification of MAB: Cisco, MAC Authentication Bypass Deployment Guide.
What you can hand off
-
Segmentation survey
Review the zone architecture and name the weaknesses in the crossings.
-
ICS detection for your protocols
Modbus, Profinet, S7 and OPC UA. Understand the protocol state instead of logging it raw.
-
SOC integration with the OT level
Classify alerts correctly and route them to the escalation path that fits.
-
IEC 62443 maturity assessment
Determine the security level per zone and plan the hardening along your maintenance windows.
-
Evidence pack for NIS2
Logs, detection traces and incident reports in the form the report requires.
-
Engineering data protection
CAD, Step 7 and project databases encrypted and versioned, restored in minutes.
The four that actually bite
Four documents decide what actually has to be done in manufacturing, and in which order. Also relevant, depending on the business: KRITIS duties under the BSI Act, ISO 27001, TISAX for automotive suppliers, GDPR.
-
NIS2 · Risk managementNIS2 implementation · Risk management measures
Requires detection, continuity, supply-chain security and regular testing — and makes management personally accountable. Operationally the most expensive part is not the technology but the evidence: who decided what, and when, has to be provable. We build the evidence trail into operations instead of reconstructing it before the audit.
-
NIS2 · ReportingNIS2 implementation · Reporting obligations
Significant incidents must be reported initially within 24 hours, substantiated within 72 hours and closed within one month. Nobody meets those deadlines from a standing start. We set the reporting path up as a rehearsed process: trigger from detection, prepared report, named approver — tested before it is needed.
-
IEC 62443-3-3IEC 62443-3-3 · System security requirements and security levels
Defines security levels 1 to 4 per zone according to damage potential. This is the frame that lets architecture be defended against procurement: first it is settled which zone needs which level, then it is decided which product enforces it. We assess the current state per zone and plan the hardening along your maintenance windows.
-
IEC 62443-2-1IEC 62443-2-1 · Cybersecurity management system for OT
Requires a documented management system specifically for OT — separate from the office IT's ISO 27001 ISMS, because the risk profile is a different one. We run both scopes side by side rather than merged, so that no conditions apply in plant operations that nobody there can meet.
Sector facts
| Typical engagements | Manufacturing across several sites · family-owned to group · IT and OT in one hand |
|---|---|
| Most common triggers | NIS2 applicability, an incident in the plant, a cyber insurer's requirement, an OEM audit |
| Typical operating model | On-premise or hybrid · process network without internet access, IT side EU-hosted |
| Core regulation | NIS2 · IEC 62443 · TISAX where automotive |
| What we touch first | Remote access, crossings between office IT and manufacturing, access control at the port |
| On field devices | No agents · control sits at the crossing |
| Maintenance windows | Rare and expensive · every change tested and reversible |
| Operating levels | Manual, automated or by playbook — selectable per area |
Asked before the briefing
-
Can you detect directly at PLC level?
Not on the PLC itself — memory and compute are too constrained. We detect at network layer (fieldbus traffic) and at engineering workstations (Step7, TIA). PLC-native anomaly detection is not yet mature enough to be standard in 2026. Instead: fieldbus state-machine understanding + upstream alerts. -
How do you patch OT without production halt?
With you, in your maintenance windows. We bring patch plan and structured test procedures (staging, rollback plan, checkpoint management). You decide timing and sequence. -
Do we need air-gapped networks?
Rarely. Hybrid with strict firewall rules or diode concepts (one-way data flow for logging) is standard. True air-gap is expensive and impractical — we show alternatives. -
What if we do not have an OT inventory yet?
We start there — passive discovery from network telemetry, then active scans in coordinated maintenance windows. 30–60 days to a reliable list. We can start building first detection in parallel.
How does OT security look concretely for your plant?
The industry briefing analyses your zone architecture, shows NIS2 compliance gaps and delivers a hardening plan for the next 12 months — at times that do not interrupt production.