// BRIEFING

The factory, the building and the cameras. Four ways they stop. De fabriek, het gebouw en de camera's. Vier manieren waarop ze stilvallen.

Production lines, climate systems, door locks and cameras were built to run for twenty years, not to be attacked. In plain language: how they get reached, why they cannot simply be patched, and what keeps the plant running. Productielijnen, klimaatsystemen, deursloten en camera's zijn gebouwd om twintig jaar te draaien, niet om aangevallen te worden. In gewone taal: hoe ze bereikt worden, waarom je ze niet zomaar kunt patchen, en wat de fabriek draaiend houdt.

// RISK 01RISICO 01

The office can reach the line. Het kantoor kan bij de lijn.

flat network / no boundary between IT and OT plat netwerk / geen grens tussen IT en OT
ONE NETWORKÉÉN NETWERK
💻
Office laptopKantoorlaptop
🏭
Production lineProductielijn
NO WALL · SAME NETWORKGEEN MUUR · ZELFDE NETWERK

Most plants, warehouses and buildings grew their networks over decades. The controllers on the line, the climate system, the badge readers and the cameras were plugged into whatever cable was nearest. Today that cable usually leads to the same network as the office laptops. An infection that starts with a spreadsheet in finance can, an hour later, be talking to the machine that fills the bottles. Nobody designed it that way. Nobody designed it at all.

Business impact: an office incident becomes a production incident. Instead of “some laptops need rebuilding” the conversation is “the line is down, the shift is sent home, and we do not know when it restarts”. Downtime is measured in lost output per hour, and in penalties to customers who were promised delivery.

De meeste fabrieken, magazijnen en gebouwen hebben hun netwerk in tientallen jaren laten groeien. De besturingen op de lijn, het klimaatsysteem, de paslezers en de camera's werden aangesloten op de kabel die het dichtst bij lag. Vandaag leidt die kabel meestal naar hetzelfde netwerk als de kantoorlaptops. Een besmetting die begint met een spreadsheet bij finance kan een uur later praten met de machine die de flessen vult. Niemand heeft het zo ontworpen. Niemand heeft het überhaupt ontworpen.

Bedrijfsimpact: een kantoorincident wordt een productie-incident. In plaats van “een paar laptops moeten opnieuw geïnstalleerd worden” gaat het gesprek over “de lijn staat stil, de ploeg is naar huis gestuurd en we weten niet wanneer hij weer start”. Stilstand wordt gemeten in gemiste productie per uur, en in boetes aan klanten aan wie levering was beloofd.

ONE INFECTION · WHOLE PLANT · HOURS OF OUTPUTÉÉN BESMETTING · HELE FABRIEK · UREN PRODUCTIE FIX: IT/OT SEGMENTATION + ONE MONITORED CROSSINGOPLOSSING: IT/OT-SEGMENTATIE + ÉÉN BEWAAKTE OVERGANG
// RISK 02RISICO 02

It cannot be patched. Het kan niet gepatcht worden.

legacy controllers / default passwords / devices nobody owns verouderde besturingen / standaardwachtwoorden / apparaten zonder eigenaar
INVENTORYINVENTARIS
NO PATCHESGEEN PATCHES
⚙️
Line controllerLijnbesturing
installed 2008 · runs the linegeplaatst 2008 · draait de lijn
vendor gone · reboot = stopleverancier weg · herstart = stop
admin / admin
📷
Camera, loading dockCamera, laadperron
default password · internet-facingstandaardwachtwoord · aan internet
owner: nobodyeigenaar: niemand
NEVER UPDATEDNOOIT BIJGEWERKT
📺
Boardroom screenScherm bestuurskamer
microphone · Wi-Fi · app storemicrofoon · wifi · app store
listens to every board meetingluistert elke vergadering mee

A laptop gets a security update every month. A controller on the line gets one never: the vendor no longer exists, or the update requires stopping production, or the machine is certified as a whole and touching its software voids that certification. Cameras, door controllers and meeting-room screens ship with a factory password that nobody changes because nobody owns them. These devices will run for another decade exactly as they are, holes included.

Business impact: “patch it” is not an option, so the usual answer to a published vulnerability does not exist. The choice is between isolating the device so nothing can reach it, replacing it early at capital cost, or accepting that it is open. That is a business decision with a price tag, not an IT ticket.

Een laptop krijgt elke maand een beveiligingsupdate. Een besturing op de lijn krijgt er nooit een: de leverancier bestaat niet meer, of de update vereist dat de productie stopt, of de machine is als geheel gecertificeerd en aan de software komen maakt die certificering ongeldig. Camera's, deurbesturingen en vergaderschermen worden geleverd met een fabriekswachtwoord dat niemand verandert, omdat niemand er eigenaar van is. Deze apparaten draaien nog tien jaar precies zoals ze zijn, inclusief de gaten.

Bedrijfsimpact: “patch het” is geen optie, dus het gebruikelijke antwoord op een gepubliceerde kwetsbaarheid bestaat niet. De keuze is: het apparaat isoleren zodat niets het kan bereiken, het vervroegd vervangen tegen investeringskosten, of accepteren dat het open staat. Dat is een bedrijfsbeslissing met een prijskaartje, geen IT-ticket.

TEN MORE YEARS · HOLES INCLUDED · NO OWNERNOG TIEN JAAR · INCLUSIEF GATEN · GEEN EIGENAAR FIX: INVENTORY + OWNER + ISOLATE WHAT CANNOT BE PATCHEDOPLOSSING: INVENTARIS + EIGENAAR + ISOLEER WAT NIET TE PATCHEN IS
// RISK 03RISICO 03

The vendor's door is always open. De deur van de leverancier staat altijd open.

permanent remote maintenance access / shared login / nobody watching permanente onderhoudstoegang op afstand / gedeelde inlog / niemand kijkt
MAINTENANCE LINKONDERHOUDSVERBINDING
🛠️
Machine vendorMachineleverancier
⚙️
Our controllersOnze besturingen
🚪
SINCE 2016 · ONE SHARED PASSWORDSINDS 2016 · ÉÉN GEDEELD WACHTWOORD
🔧
🔧
🕵️SAME PASSWORD, DIFFERENT PERSONZELFDE WACHTWOORD, ANDER PERSOON

When the line was installed, the vendor's engineer set up a remote connection so they could fix faults from their office. It was convenient, so it stayed. Years later it is still there: one password shared by the vendor's whole service team, past and present, valid around the clock, terminating directly on the controllers. If that vendor is breached, or an ex-engineer keeps the password, the attacker walks straight past every wall we did build.

Business impact: this is the entry route in a large share of real plant incidents, because it is the one path that was deliberately built to bypass the network boundary. The maintenance contract usually says nothing about it. Whoever signs that contract is, in practice, granting standing access to the production floor.

Toen de lijn werd geïnstalleerd, richtte de monteur van de leverancier een verbinding op afstand in om storingen vanuit kantoor op te lossen. Het was handig, dus het bleef. Jaren later is het er nog: één wachtwoord, gedeeld door het hele serviceteam van de leverancier, huidig en voormalig, dag en nacht geldig, rechtstreeks op de besturingen. Wordt die leverancier gehackt, of houdt een ex-monteur het wachtwoord, dan loopt de aanvaller dwars door elke muur die we wél hebben gebouwd.

Bedrijfsimpact: dit is de ingang bij een groot deel van de echte fabrieksincidenten, omdat het de ene route is die bewust is aangelegd om de netwerkgrens te omzeilen. Het onderhoudscontract zegt er meestal niets over. Wie dat contract tekent, geeft in de praktijk permanente toegang tot de productievloer.

BYPASSES EVERY WALL · NOBODY SEES ITOMZEILT ELKE MUUR · NIEMAND ZIET HET FIX: ACCESS ON REQUEST + JUMP HOST + SESSION RECORDINGOPLOSSING: TOEGANG OP AANVRAAG + JUMP HOST + SESSIEOPNAME
// RISK 04RISICO 04

It is not data. It is safety. Het gaat niet om data. Het gaat om veiligheid.

process manipulation / physical damage / injury / environment procesmanipulatie / fysieke schade / letsel / milieu
SETPOINTINSTELWAARDE
🖥️
Operator screenBedienscherm
🧪
ReactorReactor
TEMP 80 °C · NORMALNORMAAL
TEMP 140 °C · SCREEN SAYS 80SCHERM ZEGT 80

In the office, the worst case is data: stolen, leaked, encrypted. On the plant floor the worst case is physical. A changed setpoint overheats a vessel. A disabled interlock lets two things happen at once that must never happen at once. A frozen cooling system in a data centre or a cold store ruins what is inside. And the operator screen can be made to show normal values while the process is anything but. The damage is to equipment, product, people and the environment, and it is not restored from a backup.

Business impact: a safety incident brings the labour inspectorate, the environmental regulator and the insurer, on top of the production loss. The board is accountable for safety in a way it is not for a data breach. This is why OT security belongs with the operations director and the safety officer, not only with IT.

Op kantoor is het ergste geval data: gestolen, gelekt, versleuteld. Op de productievloer is het ergste geval fysiek. Een gewijzigde instelwaarde laat een vat oververhitten. Een uitgeschakelde vergrendeling laat twee dingen tegelijk gebeuren die nooit tegelijk mogen gebeuren. Een stilgevallen koeling in een datacenter of een koelhuis verpest wat erin ligt. En het bedienscherm kan normale waarden tonen terwijl het proces alles behalve normaal is. De schade is aan apparatuur, product, mensen en milieu, en die komt niet terug uit een back-up.

Bedrijfsimpact: een veiligheidsincident brengt de arbeidsinspectie, de milieutoezichthouder en de verzekeraar aan tafel, bovenop het productieverlies. De directie is aansprakelijk voor veiligheid op een manier die bij een datalek niet geldt. Daarom hoort OT-beveiliging bij de operationeel directeur en de veiligheidskundige, niet alleen bij IT.

NOT RESTORED FROM BACKUP · REGULATORS · LIABILITYKOMT NIET TERUG UIT BACK-UP · TOEZICHTHOUDERS · AANSPRAKELIJKHEID FIX: OT MONITORING + CONFIG BACKUPS + SAFETY IN THE INCIDENT PLANOPLOSSING: OT-MONITORING + CONFIGURATIEBACK-UPS + VEILIGHEID IN HET INCIDENTPLAN
// CONTROLSMAATREGELEN

What keeps the plant running. Wat de fabriek draaiend houdt.

mostly knowing what you have and drawing one line — not replacing the machines vooral weten wat je hebt en één lijn trekken — niet de machines vervangen
DEFENCE STACKVERDEDIGINGSLAGEN
INVENTORYINVENTARIS SEGMENTATIONSEGMENTATIE JUMP HOST OT MONITORINGOT-MONITORING CONFIG BACKUPSCONFIGURATIEBACK-UPS
ControlStopsIn one line
Device inventoryUnpatchable (02)Every connected controller, camera, sensor and screen on a list, with a named owner and a support end date. You cannot protect what you have not counted.
IT/OT segmentationReachable (01)A wall between the office network and the plant, with one crossing point that is monitored. An office infection stays an office infection.
Vendor access on requestVendor door (03)Remote maintenance only when we open it, for a named person, for a set time, through a jump host that records the session. Closed by default.
Isolate the unpatchableUnpatchable (02)Default passwords changed. Devices that cannot be patched put in their own corner where only what needs them can reach them.
OT monitoringSafety (04)Listening to plant traffic for things that never happen normally: a new device, a controller being reprogrammed, a setpoint changed from an unusual place.
Configuration backupsSafety (04)The programs and settings of every controller saved offline, so a tampered or bricked machine can be restored in hours rather than re-engineered in weeks.
Incident plan with operationsAll fourThe plant manager and the safety officer in the plan, with the authority to stop the line. Rehearsed with a scenario that involves a machine, not a laptop.
Procurement rulesUnpatchable (02)Before buying anything that connects: how long will it get security updates, can the password be changed, does it need the internet. No answer, no purchase.
MaatregelStoptIn één zin
ApparaatinventarisNiet te patchen (02)Elke aangesloten besturing, camera, sensor en scherm op een lijst, met een eigenaar bij naam en een einddatum van ondersteuning. Wat je niet geteld hebt, kun je niet beschermen.
IT/OT-segmentatieBereikbaar (01)Een muur tussen het kantoornetwerk en de fabriek, met één bewaakte overgang. Een kantoorbesmetting blijft een kantoorbesmetting.
Leverancierstoegang op aanvraagLeveranciersdeur (03)Onderhoud op afstand alleen als wij het openzetten, voor een persoon bij naam, voor een vaste tijd, via een jump host die de sessie opneemt. Standaard dicht.
Isoleer wat niet te patchen isNiet te patchen (02)Standaardwachtwoorden gewijzigd. Apparaten die niet gepatcht kunnen worden in een eigen hoek, waar alleen bij kan wat ze nodig heeft.
OT-monitoringVeiligheid (04)Meeluisteren op het fabrieksverkeer naar dingen die normaal nooit gebeuren: een nieuw apparaat, een besturing die wordt geherprogrammeerd, een instelwaarde die vanaf een ongebruikelijke plek verandert.
Configuratieback-upsVeiligheid (04)De programma's en instellingen van elke besturing offline bewaard, zodat een gesaboteerde of onbruikbare machine in uren wordt teruggezet in plaats van in weken opnieuw ontworpen.
Incidentplan met operationsAlle vierDe fabrieksmanager en de veiligheidskundige in het plan, met de bevoegdheid om de lijn te stoppen. Geoefend met een scenario rond een machine, niet rond een laptop.
InkoopregelsNiet te patchen (02)Voordat iets wordt gekocht dat verbinding maakt: hoe lang krijgt het beveiligingsupdates, kan het wachtwoord worden gewijzigd, heeft het internet nodig. Geen antwoord, geen aankoop.
The board-level point: in the plant, security is safety and uptime, and both are already board responsibilities. Two questions settle where we stand: can a laptop in the office reach the production line today, and who would notice if it did? If the answers are “probably” and “nobody”, the first control on this list is not a product. It is a line drawn on a network diagram. De kern voor de directie: in de fabriek is beveiliging veiligheid en beschikbaarheid, en beide zijn al verantwoordelijkheden van de directie. Twee vragen bepalen waar we staan: kan een laptop op kantoor vandaag bij de productielijn, en wie zou het merken als dat gebeurt? Zijn de antwoorden “waarschijnlijk” en “niemand”, dan is de eerste maatregel op deze lijst geen product. Het is een lijn op een netwerktekening.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Anyone with a plant, a building system or cameras has devices that were never meant to be on a network. Almost everyone does.Iedereen met een fabriek, een gebouwbeheersysteem of camera's heeft apparaten die nooit voor een netwerk bedoeld waren. Dat is bijna iedereen.

ImpactImpactCriticalKritiek

Production stopped for days, physical damage to equipment or product, a possible safety or environmental incident, and lost output per hour.Productie dagen stil, fysieke schade aan apparatuur of product, een mogelijk veiligheids- of milieu-incident, en gemiste productie per uur.

Residual after controlsRestrisico na maatregelenMediumMiddel

The old devices stay. Segmentation, controlled vendor access and monitoring mean an incident is contained to one cell and restored from configuration backups.De oude apparaten blijven. Segmentatie, gecontroleerde leverancierstoegang en monitoring zorgen dat een incident beperkt blijft tot één cel en wordt hersteld uit configuratieback-ups.

Risk ownerRisico-eigenaarCOO / plant directorCOO / fabrieksdirecteur

With the CIO for the network boundary and the safety officer for consequences. Not an IT-only risk.Samen met de CIO voor de netwerkgrens en de veiligheidskundige voor de gevolgen. Geen risico van IT alleen.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

connected devices without a named owner · network paths allowed from office to plant · vendor remote-access connections open right now · devices past vendor support still on the network.aangesloten apparaten zonder eigenaar bij naam · toegestane netwerkpaden van kantoor naar fabriek · leveranciersverbindingen op afstand die nu open staan · apparaten zonder leveranciersondersteuning die nog op het netwerk zitten.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Compromise or manipulation of production and building systems through the office network or vendor remote access causes production loss, physical damage and a safety risk.”“Compromittering of manipulatie van productie- en gebouwsystemen via het kantoornetwerk of leverancierstoegang op afstand veroorzaakt productieverlies, fysieke schade en een veiligheidsrisico.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Many OT operators are essential or important entities: energy, water, manufacturing, food, transport, health. The required measures apply to the plant as much as to the office, including access control, supply chain security and continuity. Management is accountable.Machine builders and maintenance firms are suppliers under NIS2. Their remote access and update process is your risk: put security lifetime, access rules and incident notification in the contract. Confirm scope with legal.A production disruption or safety event is a significant incident: early warning within roughly 24 hours, full notification within about 72, final report within a month. Safety and environmental regulators may need to hear separately.
DORAFor financial entities the OT is mostly buildings and data centres: cooling, power, physical access. These belong in the ICT risk framework as part of the critical functions they support.Data-centre and facility providers are ICT third parties: they go in the register, and their report should show controls over physical access, environmental systems and remote maintenance. A report is input, not a substitute.An outage of a critical function caused by a facility system is a major ICT incident: initial notification within hours of classification, intermediate report within about 72 hours, final report within a month.
SOC 2Physical and environmental controls and network segmentation are tested. Plant-floor devices are rarely in scope unless the service delivered depends on them.For a manufacturing or hosting partner: check whether the plant and building systems appear in the system description. Often only the corporate IT does, and the line is out of scope.An OT incident that hits a customer service becomes an availability deviation in the report. Expect auditors to ask for segmentation evidence and the incident timeline.
ISAE 3402Relevant where production or logistics is outsourced: continuity of processing and physical safeguards are common control objectives, but the service organisation chooses them.Read whether the continuity objectives cover the machines and warehouse systems, not just the ERP. A report about the office systems says nothing about the line.Production loss at a service organisation must be disclosed to the user auditors. If you are the operator, expect it in your opinion and in your customers’ audits.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Veel OT-exploitanten zijn essentiële of belangrijke entiteiten: energie, water, industrie, voeding, transport, zorg. De verplichte maatregelen gelden voor de fabriek net zo goed als voor het kantoor, inclusief toegangsbeheer, ketenbeveiliging en continuïteit. Het bestuur is aansprakelijk.Machinebouwers en onderhoudsbedrijven zijn leveranciers onder NIS2. Hun toegang op afstand en updateproces zijn uw risico: leg beveiligingslevensduur, toegangsregels en incidentmelding vast in het contract. Bevestig de reikwijdte met legal.Een productieverstoring of veiligheidsincident is een significant incident: vroegtijdige waarschuwing binnen ongeveer 24 uur, volledige melding binnen ongeveer 72 uur, eindrapport binnen een maand. Veiligheids- en milieutoezichthouders moeten mogelijk apart worden geïnformeerd.
DORAVoor financiële instellingen bestaat de OT vooral uit gebouwen en datacenters: koeling, stroom, fysieke toegang. Die horen in het ICT-risicokader als onderdeel van de kritieke functies die ze ondersteunen.Datacenter- en facilitaire leveranciers zijn ICT-derden: ze staan in het register, en hun rapport moet maatregelen tonen voor fysieke toegang, klimaatsystemen en onderhoud op afstand. Een rapport is input, geen vervanging.Een uitval van een kritieke functie door een gebouwsysteem is een ernstig ICT-incident: eerste melding binnen enkele uren na classificatie, tussenrapport binnen ongeveer 72 uur, eindrapport binnen een maand.
SOC 2Fysieke en omgevingsmaatregelen en netwerksegmentatie worden getest. Apparaten op de productievloer vallen zelden binnen scope, tenzij de geleverde dienst ervan afhangt.Bij een productie- of hostingpartner: controleer of de fabriek en de gebouwsystemen in de systeembeschrijving staan. Vaak staat alleen de kantoor-IT erin en valt de lijn erbuiten.Een OT-incident dat een klantdienst raakt, wordt een afwijking op beschikbaarheid in het rapport. Verwacht dat auditors bewijs van segmentatie en de incidenttijdlijn opvragen.
ISAE 3402Relevant waar productie of logistiek is uitbesteed: continuïteit van verwerking en fysieke beveiliging zijn gangbare beheersdoelstellingen, maar de serviceorganisatie kiest ze zelf.Lees of de continuïteitsdoelstellingen de machines en magazijnsystemen dekken, en niet alleen het ERP. Een rapport over de kantoorsystemen zegt niets over de lijn.Productieverlies bij een serviceorganisatie moet aan de auditors van haar klanten worden gemeld. Bent u zelf de exploitant, verwacht het dan in uw oordeel en in de audits van uw klanten.