Inside the new industrial cyber security playbook
The Engineering Network Ltd
Posted to News on 10th Aug 2026, 11:00

Inside the new industrial cyber security playbook

As industrial operations become increasingly connected, the rules of cyber security are changing. Success is no longer defined by preventing every attack but by building the resilience to withstand and recover from them. Lee Carter, Industrial Cyber Security Product Manager, SolutionsPT, explores the three steps necessary for industrial cyber resilience and why yesterday's security playbook no longer works.

Inside the new industrial cyber security playbook

The last year has shown that industrial cyber security can no longer be treated as an optional add-on. Not only is it a core business enabler, but cyber security is critical to reliability, safety and competitiveness. Last year, the themes of operational complexity, industrial AI and supply chain resilience were top priorities. This year, the discussion has matured, with cyber security for operational technology (OT) positioned as a board-level strategic issue by the National Cyber Security Centre (NCSC).

The challenge now is turning compliance activity into operational resilience that engineers can apply in the real world.

Manufacturing remains the number one most targeted sector for cyber attack, with a fifth consecutive year at the top of IBM's X-Force threat rankings. Homing in on a specific attack, ransomware groups posted 1,060 manufacturing organisations as victims in the last year alone. These figures show how the real risks to organisations and prove awareness is no longer the issue.

The challenge for manufacturers is that they must understand how to apply cyber security without disrupting production, demonstrate resilience rather than assume it and translate compliance requirements into risk reduction. With that in mind, these are the most important steps OT cyber security teams should be taking as we look toward 2027 and beyond.

Step one - practical compliance over paperwork

Since last year, enterprises are now facing a growing number of regulations, standards and frameworks. Now, it's about cutting through regulatory noise and moving beyond checkbox compliance, turning standards, policies and controls into practical actions. Unfortunately, many compliance activities can create more paperwork than protection. Documentation alone does not stop ransomware, recover production or prevent equipment failure. The gap between compliance and operational resilience is where organisations must put their focus.

So, what does this mean for operators? Compliance must focus on applying security protocols that support day-to-day operations, with regulations asking about architecture rather than paperwork.

Compliance starts with knowing exactly which assets are connected and who should have access to them. Access permission must be managed, regularly reviewed and updated, especially in applications where measures must protect operations without affecting availability or safety. Instead of adopting IT security policies, OT needs practical procedures that reflect how industrial systems are maintained. Remote access should be formally requested, recorded and time limited. Sessions should be treated much like contractors visiting a site with only the required access granted. Activity must be monitored and access privileges removed once work is complete. Restricted access needs to become the default, with no permanent access for convenience.

The objective of OT cyber security is not to pass an audit but to keep processes running while reducing the chance and impact of incidents. To achieve this, regulatory compliance must be translated into realistic protocols that engineers can adopt without adding unnecessary complexity. This positions compliance not as the end goal, but as the start point of OT cyber security. Businesses can build the strongest resilience by using regulations to create repeatable practices rather than demonstrating compliance at a single point in time. These practices can evolve alongside regulations as they change in 2026 and 2027.

Step two - adapt security protocols to fit operational reality

One question now is how to implement cyber security without disrupting operations. Too often, security standards look good on paper but create friction for engineers and operators. Engineers will naturally find workarounds to keep processes running, with the unintended outcome of leaving a gap in security. This behaviour is not malicious, it simply reflects the reality that operators are under pressure and may bypass any security processes that slow maintenance activities, complicate troubleshooting or impact availability. Good cyber security should support operations rather than complicate them.

Once visibility is established across all connected assets, including legacy systems, remote facilities and equipment, operators can look to reduce the likelihood of incidents happening in the first place. Front line operators must have a say in the practices that affect routine processes and day-to-day decision making. IT security expertise is still essential, but operators understand the nuance of how systems interact and what constitutes business-as-usual. Most importantly, their insight is essential in identifying where security standards could unintentionally introduce risk. Setting OT security principles should be a collaboration, building around real workflows, making security a core function of daily operations.

Most manufacturers do not start with a blank sheet of paper when applying security on brownfield facilities. Each facility has a unique mix of legacy equipment and control systems that cannot simply be replaced. Attempting a complete transformation for a brownfield site can seem daunting and risky. Manufacturers should identify critical communication pathways, improve visibility and strengthen security in manageable stages. Resilience is rarely rebuilt overnight, it is achieved through consistent evolution.

Step three - demonstrate cyber resilience not cyber prevention

Compliance is like a car's MOT as it demonstrates that security protocols are in place on one specific day. Cyber resilience is different. It goes beyond deploying technology and focuses on how quickly enterprises can recover. Organisations are increasingly required by regulators, customers and internal leadership to demonstrate rather than assume resilience, changing how cyber security success is measured. This shift in thinking puts more emphasis on recovery, continuity and proving systems can perform in real-world conditions.

Resilience can be engineered through backup strategies, recovery procedures, inbuilt designs that predict and plan for failure, and network architecture. Furthermore, OT cyber security should be viewed as an operational capability that supports continuity rather than a perimeter to defend. Often systems are described as 'secure by design' whereas there should be an emphasis on 'survival by design'. This is a proactive, resilience focused approach where systems are engineered to withstand, absorb, and recover from cyber attacks, rather than merely attempting to prevent them.

Shifting from prevention to resilience means adapting to evolving threats. Sophisticated AI-driven tools are lowering the barrier to entry so that less-experienced hackers could impact industrial systems. This means OT security must assess risk continuously, rather than in reaction to isolated incidents.

Vulnerabilities can be exploited at greater speed and scale than traditional security was designed to handle with practices that focused only on IT. Resilience must be embedded into the way systems evolve rather than treated as a reactive layer. One advantage that security experts have is that industrial environments are inherently predictable. Production lines, control systems and processes all perform the same tasks repeatedly so unexpected changes are easier to identify than in IT environments. As the number of vulnerabilities increases, this visibility helps manufacturers to know what has changed and compare it with what is expected.

Achieving resilience for continuous operations

These steps, if followed in unison make up a new playbook for dealing with modern cyber threats. The recent Cyber Secure OT conferences hosted by SolutionsPT highlighted that OT cyber security is not defined by one tool, technology, framework or isolated improvement, but by how well enterprises connect regulation, operations and resilience into a joined-up approach.

Resilience is becoming the defining measure of a successful cyber security strategy and while regulation can lag behind the rapidly evolving threat landscape, compliance provides a strong starting point.


SolutionsPT Ltd

Unit 1, Oakfield Road
Cheadle Royal Business Park
SK8 3GX
UNITED KINGDOM

+44 (0)161 495 4600

The Engineering Network Ltd Pilz Automation Technology AutomateUK
The Engineering Network Ltd