Zero trust must follow everything onto the factory floor
Manufacturing security was easier to define when production networks were relatively isolated and the number of people or systems crossing their boundaries was limited. That model has been eroded by remote maintenance, connected machinery, cloud services and deeper integration between operational technology and enterprise systems. The next complication is already arriving as AI agents begin interacting with industrial data and, eventually, with the systems controlling production.
Daniele Mancini, Field CISO, EMEA at Fortinet, believes this is changing how manufacturers need to think about zero trust. Rather than treating it as another security product, he describes it as an operating principle built around continually establishing whether a user, device or system should be trusted at that moment.
“Industries are finally understanding that zero trust is a philosophy rather than a technology,” he says. “Technology is now capable of verifying the posture of what is connected, rather than simply segmenting it. A person or device may have authenticated correctly, but it could still be compromised by a dormant agent. Authentication alone does not tell you whether that entity remains safe to interact with the production environment.”
That distinction becomes important in OT because manufacturers cannot simply impose enterprise IT practices on equipment that may have been operating reliably for decades. Legacy controllers can be difficult to patch, older machines may use proprietary protocols and production availability places strict limits on when changes can be made. Zero trust therefore must strengthen control without introducing another source of disruption.
Mancini recommends beginning at the network layer, where modern security capabilities can provide additional protection without requiring manufacturers to redesign every production asset. “The shop floor was traditionally a closed or air-gapped environment, and now it is opening to cloud and enterprise technologies,” he says. “I would start the zero-trust concept from the network because there you can apply the latest technology without touching the productivity or availability of the shop floor at the application level. You can then understand the protocols being used and gradually innovate around equipment that may have been installed 20 or 30 years ago.”
Visibility must come before control
Industrial networks often contain far more equipment than formal asset registers suggest. Machinery installed by different suppliers, engineering workstations and devices introduced during maintenance can remain connected for years without a complete record of what they are or why they need network access. Applying zero trust to such an environment is difficult because policy depends on first knowing what is there.
Mancini returns to a longstanding security principle: an organization cannot control an asset it cannot see. Network infrastructure can help build that picture by identifying connected devices and separating equipment that cannot be matched confidently to the manufacturer’s asset inventory.
“If something is part of my asset management system or CMDB, it can remain in the appropriate network,” he explains. “If something appears that is not mapped, you can route it towards an unknown or quarantine network. On a shop floor you do not necessarily want to interrupt production immediately, but you can gain visibility into what is running while keeping unknown equipment isolated until you understand what it is.”
A recent Fortinet deployment at specialty chemicals manufacturer Best Value Chem illustrates the operational problem. The company operates three plants and had accumulated a fragmented mix of IT and OT systems that limited visibility and made consistent policy difficult to enforce. Its security modernization introduced automated device discovery and classification alongside segmentation and centralized policy management across the environment.
Once access has been granted, the security question does not disappear. Controllers, sensors and engineering workstations can all change posture after connection, whether through compromise, configuration drift or dormant malware. In an OT environment, where lateral movement can be difficult to detect and legacy assets may offer limited protection, that makes continuous verification more important than treating authentication as a one-time gate.
Remote access exposes the same weakness in a more obvious form. Traditional VPNs have often authenticated a user and then opened access to a broad network segment, which may be far more than an external maintenance engineer needs. “With modern zero-trust technology you can go beyond the traditional VPN,” Mancini says. “Instead of authenticating somebody and giving access to an entire network segment, you can allow access to a specific protocol or port. You reduce the amount of network that is exposed and continuously verify the posture of the person or agent using that connection. That is particularly valuable where third parties need to reach industrial systems.”
AI introduces identities that may exist only briefly
The arrival of agentic AI makes the identity problem less static again. Manufacturers are beginning to experiment with agents that search operational information, support engineering workflows or interact with other software agents. Some may be persistent services, while others could be created for one task and disappear when the work is complete.
However, Mancini is concerned that adoption is moving faster than the controls required to govern these interactions. “Everybody is rushing to implement AI agents and language models internally, but I do not see the same attention being given to cybersecurity measures,” he says. “We are moving towards delegation, where one agent receives a task and then multiple agents collaborate to complete it. In automotive manufacturing we are already seeing concepts like this appearing around robotics and digital twins, but I do not yet see adequate cyber-defense measures developing at the same speed.”
AI also increases the importance of protecting the information those systems consume. More autonomous production environments will depend on continuous flows of engineering and operational data, making data stores and retrieval systems part of the attack surface. An attacker who corrupts the information an agent relies upon may not need to compromise the robot or control system directly.
Zero trust therefore must evolve with the entity being evaluated. A human engineer, a legacy PLC and a short-lived software agent require different forms of evidence, but the underlying question remains similar: what is this entity, what should it be allowed to do and does its current behavior remain consistent with that decision?
“The manufacturing ecosystem often has long-term relationships with third parties, so there is a long history of trust,” Mancini continues. “Cybersecurity requires you to keep verifying whether their posture remains aligned with the level of risk you are prepared to accept. The same applies to hardware procurement. Cost pressure can push companies towards alternative components, but you need to understand the protocols, firmware and credentials that come with that equipment rather than assessing it only on functionality and price.”
Procurement therefore becomes part of the zero-trust conversation before a device ever reaches the production network. Security teams need enough visibility into the technology being purchased to understand what will eventually be connected, how it communicates and whether its risk can be managed within the plant’s existing controls.
Zero trust cannot be imposed as a big-bang project
Production teams are understandably wary of security controls that could introduce latency, restrict established working practices or stop equipment unexpectedly. Mancini argues that much of this risk comes from how security changes are introduced rather than from zero trust itself. He favors small-scale incubation environments where manufacturers can understand existing workflows and test policies with the people who operate the process before scaling them more widely. That allows security teams to determine which restrictions are genuinely necessary and where controls would interfere with availability.
“A big-bang approach is exactly what manufacturers need to avoid,” he says. “You need to understand the processes and involve the people who operate them, then develop the business case and technology together. If you test that in a controlled environment first, you can scale with a much clearer understanding of the operational risk instead of pushing a new security concept onto a shop floor and discovering the disruption afterwards.”
For an existing plant, the practical starting point is consequently less dramatic than rebuilding the architecture. Mancini recommends establishing the asset inventory, understanding the age and lifecycle of hardware and software, then examining which protocols are moving across the production network. The business processes dependent on those assets provides the context for deciding where tighter access controls can be introduced safely.
Best Value Chem followed a similar progression as it converged its IT and OT security environment. Segmentation was introduced around communication between enterprise and industrial systems, while network access controls were used to manage device onboarding and enforce policy at the edge. The company reports improved visibility and fewer downtime events because of the wider modernization program.
The factory-floor zero-trust challenge will become more complicated as automation becomes more autonomous, but the underlying objective remains practical. Manufacturers need to replace inherited assumptions about trusted networks, familiar suppliers and authenticated users with a clearer understanding of what is connected and what each entity should be permitted to do.
As AI agents join people and machines inside production environments, that verification will have to become continuous. Zero trust is moving onto the factory floor because the idea of granting trust once and relying on it indefinitely is becoming increasingly difficult to defend.

