Industrial cybersecurity as an obligation: duties, notifications and evidence
What this answers
Which cybersecurity duties actually attach to our business and our products, and what evidence would satisfy the body asking?
Securing a plant's control systems is engineering work. Being able to show that you did, to a regulator or a major customer, is a separate discipline with its own artefacts. Duties arrive from three directions: sectoral rules for organisations judged important to essential services, security expectations attaching to connected products a manufacturer sells, and contractual demands from customers who will not onboard a supplier without evidence. Which of these apply depends on sector, size and geography, and is determined by the competent authority rather than by a checklist.
Written for: plant IT and OT managers, compliance leads, product security engineers.
Three sources of duty that get conflated
Sectoral regimes reach organisations whose disruption would affect essential services or supply, and they typically concern governance, risk management and reporting rather than specific technical controls. Product-side expectations attach to what you sell: connected machinery, controllers and software increasingly carry security requirements as a condition of market access. Customer requirements arrive through contracts and questionnaires with their own deadlines. The three ask overlapping questions in incompatible formats, which is why a single internal evidence set mapped to each request beats answering every enquiry from scratch. Mapping each incoming question to that internal set also reveals where the genuine gaps sit.
Incident notification runs on a clock you cannot negotiate
Where a reporting duty applies, the demanding part is not the report but recognising in time that something reportable happened, deciding under pressure whether it meets the threshold, and reaching the right authority while the incident is still live. Manufacturers with thin out-of-hours cover discover the gap at the worst moment. Establish in advance who can make the call, who contacts which body, what information is expected in a first notification, and how the decision is recorded. Practising it once is worth more than a written procedure nobody has read.
The evidence set that answers most requests
Whoever asks, the underlying questions converge: what assets exist and who owns them, how the control network is separated from business systems and from vendor access, how remote connections are authenticated and logged, how changes are managed, what backups exist and when they were last restored, and who does what during an incident. Holding this as a maintained set of artefacts rather than as tribal knowledge is the difference between a two-day response and a three-week scramble. The asset inventory is the foundation and is usually the weakest item. Few plants can name every device on the control network without sending somebody to look.
Selling connected equipment brings duties with a long tail
A manufacturer whose products contain software or connectivity may face expectations to handle vulnerabilities, provide updates and communicate with customers about weaknesses over the product's supported life. That is unfamiliar to firms whose machines were previously shipped and forgotten, and it implies a route for someone outside the company to report a problem and get a response. It also raises awkward questions about equipment already in the field with components no longer supported by their own suppliers, which is a portfolio decision rather than a technical one. Decide what supported life you are prepared to state before a customer decides it for you.
Reading the duty from the authority, not from a vendor
National cybersecurity authorities publish scope guidance and reporting mechanics; standards bodies publish the technical frameworks, including the IEC 62443 series widely used for industrial systems; and government cyber agencies issue advisories. The engineering practice of segmenting and hardening a plant is covered in our automation material. What this page cannot do is tell you whether a regime applies to your entity, because that turns on sector definitions and size tests decided nationally. Take the scope question to the competent authority or to counsel. Vendor marketing describing a product as compliant is not evidence about your own position.
Frequently asked questions
- We are a mid-sized parts maker. Do sectoral cyber duties reach us?
- Scope tests usually combine sector and size, so many independent component manufacturers sit outside direct regimes while suppliers to energy, water, transport, healthcare or defence chains may not. Even where no statutory duty applies, large customers frequently impose comparable requirements contractually, and their questionnaires can be more prescriptive than the law. Establish the statutory position with the competent authority in your country, then treat customer demands as a separate commercial workstream.
- What does a customer security questionnaire usually want to see?
- Beyond policies, the substantive answers concern network separation between office and production systems, control of vendor remote access, patching approach for equipment that cannot be taken offline, backup and restoration evidence, incident response arrangements and personnel security. Answers that describe intentions rather than implemented controls tend to trigger follow-up or an audit. Where a control genuinely does not exist because of legacy equipment, saying so with a compensating measure reads better than an optimistic tick.
- Who should own this in a factory with a small IT team?
- Ownership needs to bridge two groups who often barely speak: the IT function that understands networks and identity, and the engineers who own the control systems and will veto anything that risks production. A single named owner with authority over both, supported externally where specialist depth is missing, works better than assigning it to whichever team answered the last questionnaire. Senior sponsorship matters because most meaningful changes require planned downtime.
Data limitations
- Worker safety, machinery safety, chemical handling and hazardous-materials duties are set by the law of the jurisdiction and by the risk assessment for the specific workplace. Material here explains the mechanism only and is not a safety determination, a risk assessment, or legal advice.
- Standards are referenced, never reproduced. Pages describe what a standard governs and point to the issuing body; they do not restate its requirements, and conformity is determined by the standard itself and by an accredited assessment, not by anything here.
- Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.
Explore the graph
Related manufacturing topics
- Industrial effluent: sewer or watercourse, and the conditions attached to each
- Machinery obligations: the maker's duties, the user's duties, and where they swap
- Market surveillance: how enforcement actually reaches a manufacturer
- Medical device regulation: how classification decides the cost of everything else
- Notified and approved bodies: what an independent assessor can and cannot do for you
- Notifying an authority: when a product problem stops being an internal matter
Across the manufacturing graph
- Gauging and measurement: choosing equipment that can actually resolve the tolerance
- Material review: deciding what happens to parts that did not meet the drawing
- Factory HVAC: conditioning for the product or for the people
- Greenfield factory: building the plant your process wants, and carrying everything that comes with starting from nothing
- Commodity chemicals manufacturing: continuous plants, feedstock spreads and turnaround discipline
- Cosmetics manufacturing: the bulk is quick, the packaging components are not
Sources
- Cybersecurity and Infrastructure Security Agency — CISA (accessed )Covers: Guidance and advisories on industrial control system and operational technology security.Does not cover: Vendor product assessments, or the security posture of any specific installation.Why it matters: Cited on industrial cybersecurity pages as the public authority for control-system security practice.Review cadence: annual
- National Institute of Standards and Technology — NIST (accessed )Covers: Measurement science, manufacturing technology research, cybersecurity frameworks, and industrial standards support.Does not cover: Certification of products, endorsement of vendors, or costs for any specific implementation.Why it matters: A United States federal research institute whose public material covers measurement, manufacturing technology and control-system security.Review cadence: annual
- International Electrotechnical Commission — IEC (accessed )Covers: International standards for electrical, electronic and related technologies, including industrial automation and machinery safety.Does not cover: Standard text, conformity decisions, or product approval.Why it matters: Cited for the origin of electrotechnical and automation standards referenced on automation and machinery pages.Review cadence: annual
Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.
Last updated: