Industry and manufacturing
Production plant is built for availability, not for maintainability. The most common finding is a flat network: whoever gains a foothold in the office area reaches the shop floor.
Ransomware hits the IT and stops production
In 2019 a wave of ransomware hit a Norwegian aluminium group. What was affected first was the office IT, but the plants had to switch to manual operation, because without the higher-level systems no orders, recipes or batch data reached production. The damage ran into the high tens of millions, caused by standstill rather than by damaged controllers.
In 2021 a pipeline operator in the United States stopped delivery as a precaution, even though the attack had hit the billing systems and not the process technology. Anyone who cannot say with certainty how far an attacker got shuts down. That uncertainty is the actual damage.
Neither case needed ICS malware. They needed only a network in which office and production are not effectively separated, and an organisation that could not determine the reach on the day.
Separation, evidence, ability to act
The first question is always the same: who gets how far, and would anyone notice.
Actually test the segmentation
Not the zone concept on paper but the transitions between office IT, manufacturing execution level and plant network. Alongside them the remote maintenance access of the machine suppliers: who gets how far, and does anyone notice.
Build the evidence
A zone and conduit concept to IEC 62443 that matches reality. For machine builders the Cyber Resilience Act comes on top, starting with the ability to report actively exploited vulnerabilities.
Enable the people
Maintenance, plant operators and IT work together on the day without ever having practised it. Training and a facilitated incident exercise close that gap.
How testing happens without touching production
Passive methods first. Analysis of the actual communication, evaluation of the firewall rules at the transitions, and review of configurations all run during operation and deliver most of the answer.
Active tests on controllers belong in an agreed maintenance window or on a lab rig. Abort criteria are fixed beforehand, and the report distinguishes what has to be fixed immediately from what can wait until the next shutdown.
At the control and operator level the findings are rarely spectacular: default accounts, open services, missing authentication on operator panels. Their effect only follows from the question of where they are reachable from.
A real plant on which attacks are allowed
Our lab holds a real Siemens installation: controllers of the S7-1500 and S7-300 series, a driven motor and a KTP400 operator panel, wired as they would be in a production cell.
The difference from a simulation is the motor. When a manipulated message arrives it turns differently, and you can see it. On that rig we develop detection rules, test our procedures before they go to a client, and run training in which participants are allowed to attack it themselves.
Training for maintenance, engineering and IT
A production manager who does not understand why segmentation matters will work around it. An analyst who has never seen industrial traffic will click the alert away. Both are gaps in knowledge, not questions of character.
We train both sides: understanding for managers, craft for technical staff, and a joint incident exercise in which the judgement between standstill and continued operation gets made once under time pressure.
NIS2 addresses the organisation, the CRA the product
The question of role decides the duties. NIS2 addresses the entity, that is, the operation. The Cyber Resilience Act addresses the manufacturer of a product with digital elements. Whoever builds machines and also produces is both, with two different sets of duties and two different deadlines.
For the operating side, IEC 62443 is the practical frame: zones, conduits and security levels give segmentation a form that can be checked. For the manufacturing side, the CRA does not begin with product certification but with the ability to report actively exploited vulnerabilities.
What operators and machine builders ask
As a rule, no. Passive analysis, configuration review and evaluation of the segmentation run during operation. Active tests on controllers belong in a maintenance window or on a lab rig.
Especially then. With systems that cannot be patched, security shifts to segmentation, access control and detection. All of that can be done regardless of the age of the controller.
With the reporting capability. The duty to report actively exploited vulnerabilities applies before the other requirements. After that come the update path, the handling of key material, and the documentation of product security.
Through the real communication paths. We work out what was actually reachable from the affected zone, and delimit which areas of production can be ruled out.