
As manufacturers work to rapidly modernize operations, many still treat cybersecurity as an afterthought, addressing it only once new systems are deployed. This reactive approach is proving insufficient for today’s highly connected industrial environments, where cybersecurity threats are evolving just as rapidly as the smart technologies driving modernization.
Retrofitting cybersecurity measures after commissioning can also introduce significant challenges, including excessive downtime, duplicated testing efforts, and unexpected disruptions to previously validated system functionality. To prevent these issues, manufacturers must make cybersecurity a core component of their system design from the start.
Closing the Gap
Even when manufacturers recognize the importance of cybersecurity, it often fails to make its way into actual project specifications. Several factors contribute to modernization plans overlooking the need for cybersecurity requirements, including:
- Failure to include all stakeholders, including IT teams, in developing OT specs.
- Poorly defining responsibility within the organization for ensuring OT system security.
- Lack of preferred and understood OT standards.
- A rush to deploy updates, and a lack of awareness on how cybersecurity measures are vital to system productivity and longevity.
To address these issues, be sure to check that you’ve defined and discussed your preferences and plans for the following cybersecurity considerations.
1. Adequate Protection for OT-Specific Assets
Increasing connectivity to previously isolated OT assets, as defined as Level 0-2 in the Purdue Model, makes them more vulnerable to cyberattacks. This is problematic because attacks on OT assets can endanger human workers, bring production to a halt, and threaten regulatory compliance for critical infrastructure.
Oftentimes, requirements are not added to modernization specs that ensure OT-specific assets such as PLCs, VFDs, and HMIs are protected to the same level as Windows and computer-based assets. To do this, manufacturers should define the following in their project specs:
- Backup and recovery requirements.
- Critical security controls such as network segmentation.
- A process for disabling unused services and ports on switches, HMIs, and PLCs.
- How to restrict remote programming access for controllers whenever possible.
These measures are essential not only for improving cybersecurity, but also for maintaining system availability and operational reliability. Without clearly defined protections in place, organizations risk increased downtime, system instability, and greater exposure to cyber threats.
2. Inclusion of Security Testing as Part of the Acceptance Phase
Manufacturers should always include security connectivity testing in the acceptance phase of a modernization plan, as opposed to attempting to complete it during or after onsite installation. When you wait to test security features, you run the risk of your desired functionality being incompatible with your new equipment or processes, hampering overall system functionality.
Additionally, uptime requirements after a system is commissioned often make it cost- or time-prohibitive to conduct iterative development. Building in your cybersecurity testing before deployment helps avoid these scenarios.
3. Access Control and Password Requirements
Specifications should be established from the start for access control, password requirements, and password management. Leaving passwords on vendor or integrator defaults, or leaving requirements vague, can make it challenging to maintain a clear grasp of all the accounts that exist within a system.
Your requirements should also include service accounts that are not tied directly to people and other machine-based accounts your processes depend on.
4. Specifications for Back-Up Restoration Documentation
Backup restoration documentation outlines the formal procedures and policies for backing up and recovering systems to ensure objective and integrity validation. Manufacturers should take time to develop these requirements early, because without them, you lack clarity when completing a business impact analysis or responding to incidents that occur after a system is commissioned.
Additionally, you need to be sure you have the required engineering software and installers specified to reduce recovery time and increase configuration backup integrity.
Ensuring you’re incorporating cybersecurity specifications from the onset of your modernization plan directly impacts your system’s productivity, vulnerability, and long-term health. In addition to including the key considerations above, manufacturers should employ the following best practices when forming their plans.
Identify Who is Responsible
First, as you set out to develop your modernization specs, ask, who owns the cybersecurity requirements for the system? This person needs to lead the conversation defining system security elements, and they need a seat at the table to communicate those requirements to whomever is developing the overall spec.
Similarly, if you’re contracting with an EPC firm to develop your bid packages, this person should be included from the start of these conversations as well.
Understand Key Cybersecurity Standards
Industry standards are helpful references when defining requirements, but keep in mind, you may need to go above and beyond what is recommended. For example, the IEC 62243 standard is very flexible and includes suggested activities for grading and selecting desired levels of performance.
While helpful, this standard is not simply a compliance checkmark that defines end results. Instead, it walks you through the process of setting benchmarks and metrics.
Establish Standard Security Controls for Your Environment Early
Rather than leaving cybersecurity decisions to individual vendors or project teams, you should decide what standard solutions you’d like to see implemented in your environment. Clearly outline how your organization will approach key security functions, including:
- Remote access, including multifactor authentication requirements.
- Segmentation.
- Access control.
- Patching.
- Backup and recovery.
- Secure file transfer.
Doing this will ensure consistency across systems, reduce integration challenges, and prevent gaps in protection, especially in environments that include a mix of legacy equipment and modern, connected technologies.
Conducting your next modernization project with key cybersecurity considerations built in from the start is vital for saving your team time, reducing costs, and avoiding unnecessary complexity. A proactive approach helps minimize downtime, eliminate costly rework, and streamline system validation while ultimately ensuring the necessary safety features today’s modern systems need are fully incorporated and protecting your system for years to come.
Timothy Mullen is the Cybersecurity Manager at Applied Control Engineering, Inc. (ACE), leading projects that identify and remediate cyber vulnerabilities and designing systems that incorporate security as a fundamental principle.






















