When compliance looks good on paper but fails on the factory floor. By Christina Hoefer
Manufacturers are under growing pressure to demonstrate cybersecurity maturity. Regulations such as NIS2, industry frameworks like IEC 62443, and increasing supply chain scrutiny mean that security programs must now prove both operational resilience and regulatory compliance.
Yet despite significant investment, many manufacturers still struggle to translate cybersecurity activity into measurable improvements in risk reduction – even when all compliance boxes are checked. In practice, resilience depends less on preventing every incident and more on being able to detect, act, and contain the blast radius to limit downtime as much as possible.

The issue is rarely a lack of tools or frameworks, but a structural challenge. Most organizations already have a broad security stack in place, often consisting of fragmented visibility tools spanning IT and, increasingly, operational technology (OT), alongside separate perimeter and endpoint security solutions. As a result, many security programs remain structurally focused on vulnerability management and periodic compliance exercises rather than continuous risk management.
For manufacturers looking to improve both cybersecurity maturity and compliance outcomes, the biggest gains often come from being open to new technologies, approaches, and collaboration. While we can try to converge IT and OT security techniques and adopt firewalls, endpoint tools, and VPNs to secure OT environments, we quickly run into new challenges. These technologies do not account for industrial processes or safety requirements and can interfere with process operations. One emerging theme across these efforts is the adoption of Universal Zero Trust Network Access (UZTNA) principles, a unified approach that applies Zero Trust principles consistently across users, devices, and applications spanning IT and operational environments. It takes into account the different requirements of legacy and modern devices and applies risk- and context-based controls to protect un-patchable and outdated systems. UZTNA allows controlled vendor access and is critical for containing new threats.
This becomes even more important in a post-Mythos world, where AI-driven testing and autonomous discovery are accelerating how quickly vulnerabilities are uncovered, particularly in legacy OT devices that have historically received far less scrutiny than traditional IT systems.
The hidden complexity of manufacturing security
Manufacturing environments are among the most complex environments to secure. Industrial control systems, legacy equipment, IoT devices, cloud platforms, and corporate IT networks all coexist, often with decades of accumulated technology.
Many organizations have responded to rising cyber risk by adding layers of security tooling and are now operating dozens of security tools across different domains. This creates a fragmented operational picture rather than a cohesive defense strategy.
In practice, this lack of integration creates several challenges including:
- Asset inventories that differ depending on which system you consult
- Alerts and telemetry that are difficult to correlate across tools
- Policies that exist on paper but are difficult to enforce consistently
- Limited visibility into unmanaged or legacy devices
The result is a cybersecurity program that ticks all the compliance checkboxes and appears mature on paper but struggles to deliver consistent operational control.
As AI-powered research accelerates vulnerability discovery, organizations are increasingly faced with a growing volume of findings without the context needed to determine which exposures actually matter.
When security gaps become operational incidents
When performing post-mortem analysis of cyberattacks in manufacturing, it quickly becomes apparent how small security gaps can quickly escalate into operational disruption.
For example, a ransomware attack against a European steel manufacturer forced production facilities offline for several days after attackers exploited known vulnerabilities and moved laterally between IT and OT networks, using east-west pathways that were poorly monitored or insufficiently restricted. The absence of effective segmentation meant that shutting down critical systems was the only way to contain the threat.
In another case, a pharmaceutical company suffered a ransomware attack that halted production and disrupted medicine distribution after attackers gained access through a phishing email and exploited unpatched vulnerabilities within the network.

These incidents highlight a recurring pattern. The problem is rarely a single missing control. Instead, it is the accumulation of small weaknesses like incomplete visibility into assets and vulnerabilities, weak access control, insufficient segmentation between IT and operational systems or slow remediation processes. In many cases, organizations are forced into full shutdowns because they lack the ability to contain an incident once it is underway, or they lack the confidence that their security stack will do its job. This is why containment is the critical control, rather than detection alone.
Addressing these structural issues can significantly improve both cyber resilience and satisfy regulatory compliance.
Three changes that deliver the greatest impact
While every manufacturing environment is different, organizations looking to strengthen their cybersecurity strategy often see the biggest improvements by focusing on three areas.
1. Start with asset visibility
Every cybersecurity framework begins with the same fundamental question: what needs to be protected?
Yet many manufacturing organizations still struggle to maintain an accurate inventory of connected devices across their environment. Industrial controllers, sensors, remote access tools, engineering workstations, and third-party connections can easily fall outside traditional asset management processes and the interconnectivity and dependencies are rarely tracked.
This lack of visibility creates risk because either vulnerabilities cannot be identified or prioritized, access policies cannot be consistently enforced, or compliance reporting may not reflect the real environment – or some combination of all three.
For frameworks like NIS2 and IEC 62443, asset and risk management form the foundation of effective cybersecurity programs. Without reliable visibility across IT, OT and IoT environments, organizations cannot meaningfully assess risk or demonstrate control effectiveness.
Improving visibility into assets and their dependencies is therefore one of the most impactful steps organizations can take to strengthen both security posture and compliance readiness.
2. Move from periodic compliance to continuous assurance
Many compliance programs still rely heavily on point-in-time assessments. Audits, vulnerability scans and spreadsheet-based reporting may demonstrate compliance during an assessment window, but they rarely reflect the constantly changing reality of operational environments.
Manufacturing networks are more dynamic than we think. Employees and vendors connect and disconnect, software versions change, vulnerabilities emerge, and operational priorities shift. Therefore, a compliance strategy based solely on periodic validation creates inevitable inaccuracies between what an audit report shows and what is actually happening across the environment.
Continuous monitoring of asset posture and control effectiveness helps close this gap by providing real-time visibility into whether policies are being enforced and whether controls remain effective as environments evolve.
This shift from snapshot compliance to continuous assurance is becoming increasingly important as regulators and boards expect organizations to demonstrate not just compliance, but operational resilience.
3. Strengthen segmentation and access control
Industrial environments have historically prioritized reliability and uptime over security architecture and operated under the assumption of being air-gapped. As industrial processes digitalize, hybrid work, remote maintenance, and vendor access are now essential. Yet segmentation between IT and OT networks is often limited with remote access becoming one of the least governed paths into OT/CPS systems, and access privileges may be broader than necessary.
Modern cybersecurity strategies are becoming more reliant on least-privilege access and dynamic segmentation to reduce attack paths and limit lateral movement. Within a UZTNA framework, segmentation evolves from a static, IP-centric exercise into a dynamic control that adapts to device type, user identity, function, and risk, helping organizations reduce exposure without disrupting operations. For example, if attackers gain initial access through phishing, compromised credentials or unpatched systems, segmentation can prevent them from moving freely across networks and reaching critical industrial systems. Frameworks such as IEC 62443 explicitly recommend segmenting industrial networks into security zones and controlling communications between them. Implementing this architecture significantly reduces the potential blast radius of a cyber incident.
Combined with strong identity controls and monitoring, segmentation creates a layered defense that protects both operational systems and safety-critical processes.
From compliance to resilience
Boards and executive teams are recognizing that understanding how cyber risk affects production, safety, and supply chains is critical to business longevity. Effective cybersecurity programs must therefore translate security activity into clear operational outcomes.
Rather than asking whether an organization is ‘secure’, leadership should be asking:
- What systems could disrupt production if compromised?
- How quickly would we detect an attack targeting those systems?
- What controls limit the impact of a breach?
Cyber risk becomes far easier to manage when it is framed in terms of operational consequences rather than technical complexity.
The path to higher cybersecurity maturity
Manufacturers do not need to rebuild their cybersecurity programs from scratch to achieve meaningful improvements. In many cases, the foundations already exist. The challenge is ensuring those capabilities work together to provide clear visibility, consistent control enforcement and meaningful insight into risk.
Organizations that focus on improving asset visibility, implementing continuous assurance and strengthening segmentation with UZTNA often find that these changes deliver an improvement in both cybersecurity maturity and compliance readiness.
Christina Hoefer
www.forescout.com
Christina Hoefer is VP of OT & IoT Strategy at Forescout. As AI-driven vulnerability discovery and exploitation accelerate attack velocity to machine speed, Forescout is a foundational cyber defense layer that allows organizations to segment and isolate compromised systems, block lateral movement, and automate response across IT, OT, IoT, and IoMT environments. The Forescout Vistaro™ platform, powered by agentic AI and enhanced with Vedere Labs threat intelligence, delivers a Universal Zero Trust Network Access (UZTNA) architecture that integrates seamlessly with 180+ security and IT products.
