Why cyber risk has become an operational challenge
Conventional cybersecurity advice is straightforward: identify vulnerable systems, apply security updates and reduce risk as quickly as possible. Manufacturing is rarely that simple. Many industrial assets remain in service for decades, controlling processes that cannot easily be interrupted without affecting production, product quality or even worker safety. In some facilities, taking critical control systems offline to install a security patch can create greater operational consequences than leaving the vulnerability in place.
According to Nick Haan, Field CTO at Claroty, that reality has fundamentally changed the way manufacturers must think about cybersecurity. It is no longer simply an IT responsibility. It has become an operational discipline that must balance cyber resilience with the practical demands of keeping production running.
Few examples illustrate that challenge more clearly than heavy industrial processes. Haan points to aluminum smelters, where shutting down control systems unexpectedly can allow molten metal to solidify inside the equipment, potentially damaging the smelters themselves and leaving production halted for months. In environments like these, the decision to apply a security update cannot be separated from the operational consequences that follow.
“Cybersecurity is needed to keep production up,” Haan explains. “The problem is cybersecurity can also bring production down. Updating controllers often means downtime, and for some manufacturers that simply isn’t possible. They may only have a planned shutdown every two, three or even four years, so they have to find other ways of managing that cyber risk.”
As manufacturers embrace greater automation, remote maintenance and increasingly connected operations, those decisions are becoming more complex. Protecting operational technology is no longer about applying conventional IT security practices to the factory floor. It requires manufacturers to understand their operational environment, accept that some risks cannot be eliminated immediately and build cybersecurity into everyday production decisions rather than treating it as a separate technology program.
Connectivity has expanded both opportunity and risk
Manufacturers have not simply become more digital. They have become far more connected. Modern factories are no longer isolated production environments. Data now flows continuously between operational technology, enterprise systems and cloud platforms to support AI, predictive analytics, production optimization and remote maintenance. While these connections create significant operational benefits, they also introduce new pathways into environments that were never originally designed with cybersecurity in mind.
“In the past, there was very little reason for data to leave the OT environment,” Haan adds. “Now AI, analytics and business systems all need access to production data. At the same time, manufacturers want equipment suppliers to carry out maintenance remotely rather than sending engineers to site. All of those connections increase complexity, and if they haven’t been designed with cybersecurity in mind, attackers can use exactly the same routes to gain access.”
The challenge is compounded by the age of many industrial assets. Unlike enterprise IT, where computers and servers are replaced every few years, manufacturing equipment often remains in operation for decades. Control systems running operating systems such as Windows XP, Windows 7 and even DOS continue to perform critical production functions because they remain reliable and economically viable. Replacing them simply to improve cybersecurity is rarely a practical business decision.
“These machines are still generating revenue,” Haan says. “The company that built them may no longer exist, so software updates aren’t available, but that doesn’t mean the equipment stops being useful. Manufacturers have to find other ways of protecting those assets rather than assuming they can just replace or patch everything.”
That combination of increasing connectivity and ageing infrastructure means manufacturers cannot rely on conventional IT security practices alone. Instead of assuming every vulnerability can be removed, they must first understand where their operational risks exist before deciding how those risks can be reduced without compromising production.
Managing exposure instead of chasing every vulnerability
If vulnerable equipment cannot always be patched, manufacturers need a different way of thinking about cyber resilience. For Haan, that starts with understanding exactly what is connected to the operational network. Without a complete inventory of industrial assets, manufacturers have little chance of assessing which systems are genuinely critical, how they communicate with one another or where the greatest operational risks lie.
“You need to know what you have before you can protect it,” he says. “In IT there are standard protocols that make discovering assets relatively straightforward. Industrial environments are completely different. There are proprietary protocols, multiple network technologies and devices with very limited resources. Traditional IT discovery tools can generate so much traffic that they actually disrupt the equipment you’re trying to protect.”
Once that visibility has been established, Haan argues that manufacturers should move beyond treating every vulnerability as equally urgent. Conventional vulnerability scoring systems provide a useful starting point, but they rarely reflect the operational realities of manufacturing. A high-severity vulnerability affecting an isolated asset may present less immediate risk than a lower-scoring weakness on a production line connected to multiple external systems.
Instead, manufacturers need to understand how likely a vulnerability is to be exploited, whether exploit code already exists, how exposed the affected asset is and what operational consequences would result if it were compromised. Just as importantly, they need to assess risk at the level of the production process rather than focusing solely on individual devices.
“We don’t just look at a single PLC,” Haan explains. “We look at the purpose of the entire production line, understand its exposure and then decide where the biggest operational risks really are. You can never eliminate every risk, but you can reduce your exposure and concentrate your efforts where they will have the greatest impact.”
That risk-based approach also underpins technologies such as network segmentation and virtual patching. Where production systems cannot be updated immediately, isolating critical assets and tightly controlling the traffic entering and leaving those environments allows manufacturers to reduce their exposure while continuing to operate safely until planned maintenance windows become available.
Making cybersecurity part of everyday operations
Technology alone will not make manufacturing environments more cyber resilient. Haan believes the biggest change many organizations still need to make is treating cybersecurity as part of everyday operational management rather than as a standalone IT program. Decisions about production availability, maintenance, remote access and operational risk are increasingly intertwined with cybersecurity, requiring closer collaboration between plant operations, engineering and enterprise security teams.
One area where that integration is particularly important is remote access. Equipment suppliers, maintenance contractors and systems integrators all require secure access to production assets, yet many manufacturers have accumulated multiple remote access solutions over time, creating unnecessary complexity and making oversight increasingly difficult.
“We assessed one manufacturer that had more than 80 different remote access tools in use,” Haan says. “When every supplier brings their own solution, you lose visibility, you lose control and it becomes almost impossible to monitor who has access to what. Industrial environments need remote access that is designed specifically for operational technology rather than adapted from enterprise IT.”
Effective cyber resilience also depends on understanding how industrial environments behave under normal operating conditions. Continuous monitoring allows manufacturers to detect unusual network activity, identify unauthorized changes and recognize behavior that falls outside established operational patterns before those issues develop into production incidents. Unlike predictive maintenance systems that monitor the health of physical assets, Haan’s focus is on monitoring the operational technology network itself, providing early warning of cyber threats without disrupting production.
Ultimately, Haan believes responsibility for OT cybersecurity should begin in the boardroom but extend throughout the organization. Executive leadership must provide ownership, investment and accountability, while individual sites need people responsible for embedding cybersecurity into daily operations. His advice is deliberately practical: stop treating cybersecurity as a planning exercise and start building the foundations. Asset visibility, risk assessment, network segmentation, continuous monitoring and secure remote access are not independent projects but the building blocks of a manufacturing operation where cybersecurity supports production instead of competing with it.
From cyber strategy to operational discipline
For manufacturers, cybersecurity has never been a simple choice between protecting systems and maintaining production. Increasingly, it demands both. Cybersecurity now belongs in that same conversation. As factories become more connected, more automated and increasingly dependent on data, cyber resilience can no longer be treated as a specialist IT function operating alongside production. It has become part of the operational decisions that determine whether manufacturing continues safely, reliably and profitably.
For Haan, improving cyber resilience does not begin with eliminating every vulnerability. It starts with understanding the operational environment, knowing which assets are critical, reducing unnecessary exposure and building security into the way factories are managed every day.
“Start a program and start actually doing it,” Haan concludes. “Start with building your asset inventory. That is the first step that everybody should take. From there you can understand your risks and continuously improve your environment.”
Ultimately, the manufacturers that build the greatest resilience will not be those that attempt to apply every cybersecurity control as quickly as possible. They will be those that understand how to balance cyber risk with operational reality, protecting production while steadily strengthening the security of the industrial environments on which their business depends.

