Control System Cyber Security

Control system cyber security
A distributed control system is not an IT system. It cannot be patched on Tuesday, it cannot be rebooted for an update, and the vendor's supported release may be years behind what the IT department considers current. The consequence is that plant control systems drift out of support and stay there.
We treat this as part of the maintenance scope, not as a project.
What we do
Keep assets at a supported release level. Vendor lifecycle tracking for the installed DCS, ESD and historian software, with an upgrade path planned against the plant's outage schedule rather than against a calendar.
Patch and release management. What can be applied online, what requires a shutdown, what the vendor has validated, and what has to wait. Recorded, so that the answer to "what version is running" does not depend on who is on shift.
Backup and recovery. A backup regime for every control system asset that allows a system to be restored quickly enough to keep the plant running after a failure. Tested by restoring, not by checking that the job completed.
Separation. Segregation between the control network and the business network, and control of the paths that necessarily cross it — engineering workstations, historian data flows, remote access for support.
Remote access. Where we provide remote support, the access path is part of what we secure, not an exception to it.
Products with digital elements
Regulation (EU) 2024/2847, the Cyber Resilience Act, obliges manufacturers of products with digital elements to report an actively exploited vulnerability within 24 hours of becoming aware of it, and to file a full notification within 72. The reporting obligations apply from 11 September 2026.
We built and operate that procedure for our own product line: reporting roles, the awareness timestamp that starts the clock, an incident register, CycloneDX SBOM generation in the build pipeline, monthly reconciliation against published vulnerability sources, and a coordinated disclosure policy. This is described in more detail under Compliance and Testing.