Resilience moves to the factory floor
Industrial control system (ICS) cybersecurity has spent years moving closer to broader business cybersecurity. It’s now an indistinguishable part of how industrial operations are run.
Older ICS and production equipment were never designed to be attached to the internet. But, as IIoT devices, remote access, and enterprise platforms became the norm, so did cyber incidents, which have direct operational consequences.
A compromised system can halt production, undermine product quality, disrupt traceability, delay deliveries, or even pose safety risks and threaten loss of life. Manufacturers understand this, and are doing their best to improve their security controls. Recent research by Kaspersky and VDC Strategy found only 9% of manufacturers say they are currently completely digital, however 60% expect to be so in two years. 60% also said any cyberattack could result in losses of over $1 million and would last, on average, 15 hours.
This puts a much greater emphasis on recovery. For businesses relying on OT, competitive advantage comes from understanding which processes must remain available, production’s appetite for disruption, and what must be checked before operations can resume safely. Restoring a system is not the same as restoring production. Certain things (process parameters, quality records, and operational data) need to be verified before a plant can return to normal.
Recovery becomes the test
It’s clear that the way OT environments measure success is changing. Vulnerability management and alerts are still important in these environments. Though now, MTTR, reliable backups, how well legacy systems are covered, and the ability to keep critical operations up and running safely during a disruption matter, too.
Accountability lies throughout the company. IT might define security policies, but OT knows which systems can be patched or taken offline without risk. The engineering team understands the dependencies between different equipment and systems, while production can identify where a loss of productivity will have the greatest impact.
Regulation pushes resilience forward
Regulations in Europe are piling on the pressure, and rightly so. The NIS2 directive, the Cyber Resilience Act (CRA), and the Machinery Regulation all increase accountability for cybersecurity risk management in supply chains, connected devices, and OT environments.
For industrial entities, this is becoming part of a much larger discussion about keeping production running. Cybersecurity teams will still be expected to prevent and detect attacks, but they will be judged more and more on how well they handle any resulting disruption.
Top trends
- More regard to recovery: Manufacturers are focusing more on how quickly operations can be restored, whether they can rely on backup, and which processes can carry on running safely while systems recover.
- More teams have a role in cyber resilience. Security decisions in industrial environments increasingly involve OT, engineering, production, quality, safety, and business continuity teams because each has a different view of what disruption means on the plant floor.
- More regulation reaches further into the product lifecycle. The CRA introduces vulnerability-handling and incident-reporting obligations that continue after connected products have entered the market.
Regulatory watch
11 September 2026 marks an important milestone for the CRA. Following that day, manufacturers will be required to report on active exploits and serious problems related to their products containing digital components. These obligations will come into force 24 hours after the discovery of these problems, followed by a fuller notification within 72 hours. In addition, the European Commission issued guidelines to manufacturers in July. In July 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the EU Court of Justice over their failure to fully transpose NIS2, requesting financial sanctions until the process is completed.
CISO voice
“Industrial cybersecurity resilience means being prepared for an attack to get through. In OT environments, where legacy and specialized systems cannot always be patched or replaced, organizations need to know what is critical, limit pathways between IT and OT, test incident response plans, and be ready to contain incidents while maintaining safe operations.” – Phil Wylie, Senior Consultant & Evangelist, Suzu Labs.
Innovation/startup spotlight
The Cognisec Security’s IEC 62443 Engine automates much of the work involved in IEC 62443 compliance. It maps plant networks, calculates security levels, and produces audit-ready documentation without relying on manual spreadsheets. It can also group legacy systems into secure Zones and Conduits, identify gaps across the seven Foundational Requirements, and help manufacturers apply the right security controls without disrupting production.
Barcelona Cybersecurity Congress update
This year’s Barcelona Cybersecurity Congress will examine the ways in which industrial cyber resilience is changing due to increased connectivity and reliance on software in environments. Issues such as software resilience, securing software supply chains, AI-powered development and its dangers, and the necessary evolution of security practices will be in focus at the conference.
Barcelona Cybersecurity Congress 2026
Dates: 3–5 November
Location: Barcelona
Co-located with: Smart City Expo World Congress
CONNECTING EUROPE’S CYBERSECURITY ECOSYSTEM