Production lines, climate systems, door locks and cameras were built to run for twenty years, not to be attacked. In plain language: how they get reached, why they cannot simply be patched, and what keeps the plant running. Productielijnen, klimaatsystemen, deursloten en camera's zijn gebouwd om twintig jaar te draaien, niet om aangevallen te worden. In gewone taal: hoe ze bereikt worden, waarom je ze niet zomaar kunt patchen, en wat de fabriek draaiend houdt.
Most plants, warehouses and buildings grew their networks over decades. The controllers on the line, the climate system, the badge readers and the cameras were plugged into whatever cable was nearest. Today that cable usually leads to the same network as the office laptops. An infection that starts with a spreadsheet in finance can, an hour later, be talking to the machine that fills the bottles. Nobody designed it that way. Nobody designed it at all.
Business impact: an office incident becomes a production incident. Instead of “some laptops need rebuilding” the conversation is “the line is down, the shift is sent home, and we do not know when it restarts”. Downtime is measured in lost output per hour, and in penalties to customers who were promised delivery.
De meeste fabrieken, magazijnen en gebouwen hebben hun netwerk in tientallen jaren laten groeien. De besturingen op de lijn, het klimaatsysteem, de paslezers en de camera's werden aangesloten op de kabel die het dichtst bij lag. Vandaag leidt die kabel meestal naar hetzelfde netwerk als de kantoorlaptops. Een besmetting die begint met een spreadsheet bij finance kan een uur later praten met de machine die de flessen vult. Niemand heeft het zo ontworpen. Niemand heeft het überhaupt ontworpen.
Bedrijfsimpact: een kantoorincident wordt een productie-incident. In plaats van “een paar laptops moeten opnieuw geïnstalleerd worden” gaat het gesprek over “de lijn staat stil, de ploeg is naar huis gestuurd en we weten niet wanneer hij weer start”. Stilstand wordt gemeten in gemiste productie per uur, en in boetes aan klanten aan wie levering was beloofd.
A laptop gets a security update every month. A controller on the line gets one never: the vendor no longer exists, or the update requires stopping production, or the machine is certified as a whole and touching its software voids that certification. Cameras, door controllers and meeting-room screens ship with a factory password that nobody changes because nobody owns them. These devices will run for another decade exactly as they are, holes included.
Business impact: “patch it” is not an option, so the usual answer to a published vulnerability does not exist. The choice is between isolating the device so nothing can reach it, replacing it early at capital cost, or accepting that it is open. That is a business decision with a price tag, not an IT ticket.
Een laptop krijgt elke maand een beveiligingsupdate. Een besturing op de lijn krijgt er nooit een: de leverancier bestaat niet meer, of de update vereist dat de productie stopt, of de machine is als geheel gecertificeerd en aan de software komen maakt die certificering ongeldig. Camera's, deurbesturingen en vergaderschermen worden geleverd met een fabriekswachtwoord dat niemand verandert, omdat niemand er eigenaar van is. Deze apparaten draaien nog tien jaar precies zoals ze zijn, inclusief de gaten.
Bedrijfsimpact: “patch het” is geen optie, dus het gebruikelijke antwoord op een gepubliceerde kwetsbaarheid bestaat niet. De keuze is: het apparaat isoleren zodat niets het kan bereiken, het vervroegd vervangen tegen investeringskosten, of accepteren dat het open staat. Dat is een bedrijfsbeslissing met een prijskaartje, geen IT-ticket.
When the line was installed, the vendor's engineer set up a remote connection so they could fix faults from their office. It was convenient, so it stayed. Years later it is still there: one password shared by the vendor's whole service team, past and present, valid around the clock, terminating directly on the controllers. If that vendor is breached, or an ex-engineer keeps the password, the attacker walks straight past every wall we did build.
Business impact: this is the entry route in a large share of real plant incidents, because it is the one path that was deliberately built to bypass the network boundary. The maintenance contract usually says nothing about it. Whoever signs that contract is, in practice, granting standing access to the production floor.
Toen de lijn werd geïnstalleerd, richtte de monteur van de leverancier een verbinding op afstand in om storingen vanuit kantoor op te lossen. Het was handig, dus het bleef. Jaren later is het er nog: één wachtwoord, gedeeld door het hele serviceteam van de leverancier, huidig en voormalig, dag en nacht geldig, rechtstreeks op de besturingen. Wordt die leverancier gehackt, of houdt een ex-monteur het wachtwoord, dan loopt de aanvaller dwars door elke muur die we wél hebben gebouwd.
Bedrijfsimpact: dit is de ingang bij een groot deel van de echte fabrieksincidenten, omdat het de ene route is die bewust is aangelegd om de netwerkgrens te omzeilen. Het onderhoudscontract zegt er meestal niets over. Wie dat contract tekent, geeft in de praktijk permanente toegang tot de productievloer.
In the office, the worst case is data: stolen, leaked, encrypted. On the plant floor the worst case is physical. A changed setpoint overheats a vessel. A disabled interlock lets two things happen at once that must never happen at once. A frozen cooling system in a data centre or a cold store ruins what is inside. And the operator screen can be made to show normal values while the process is anything but. The damage is to equipment, product, people and the environment, and it is not restored from a backup.
Business impact: a safety incident brings the labour inspectorate, the environmental regulator and the insurer, on top of the production loss. The board is accountable for safety in a way it is not for a data breach. This is why OT security belongs with the operations director and the safety officer, not only with IT.
Op kantoor is het ergste geval data: gestolen, gelekt, versleuteld. Op de productievloer is het ergste geval fysiek. Een gewijzigde instelwaarde laat een vat oververhitten. Een uitgeschakelde vergrendeling laat twee dingen tegelijk gebeuren die nooit tegelijk mogen gebeuren. Een stilgevallen koeling in een datacenter of een koelhuis verpest wat erin ligt. En het bedienscherm kan normale waarden tonen terwijl het proces alles behalve normaal is. De schade is aan apparatuur, product, mensen en milieu, en die komt niet terug uit een back-up.
Bedrijfsimpact: een veiligheidsincident brengt de arbeidsinspectie, de milieutoezichthouder en de verzekeraar aan tafel, bovenop het productieverlies. De directie is aansprakelijk voor veiligheid op een manier die bij een datalek niet geldt. Daarom hoort OT-beveiliging bij de operationeel directeur en de veiligheidskundige, niet alleen bij IT.
| Control | Stops | In one line |
|---|---|---|
| Device inventory | Unpatchable (02) | Every connected controller, camera, sensor and screen on a list, with a named owner and a support end date. You cannot protect what you have not counted. |
| IT/OT segmentation | Reachable (01) | A wall between the office network and the plant, with one crossing point that is monitored. An office infection stays an office infection. |
| Vendor access on request | Vendor door (03) | Remote maintenance only when we open it, for a named person, for a set time, through a jump host that records the session. Closed by default. |
| Isolate the unpatchable | Unpatchable (02) | Default passwords changed. Devices that cannot be patched put in their own corner where only what needs them can reach them. |
| OT monitoring | Safety (04) | Listening to plant traffic for things that never happen normally: a new device, a controller being reprogrammed, a setpoint changed from an unusual place. |
| Configuration backups | Safety (04) | The programs and settings of every controller saved offline, so a tampered or bricked machine can be restored in hours rather than re-engineered in weeks. |
| Incident plan with operations | All four | The plant manager and the safety officer in the plan, with the authority to stop the line. Rehearsed with a scenario that involves a machine, not a laptop. |
| Procurement rules | Unpatchable (02) | Before buying anything that connects: how long will it get security updates, can the password be changed, does it need the internet. No answer, no purchase. |
| Maatregel | Stopt | In één zin |
|---|---|---|
| Apparaatinventaris | Niet te patchen (02) | Elke aangesloten besturing, camera, sensor en scherm op een lijst, met een eigenaar bij naam en een einddatum van ondersteuning. Wat je niet geteld hebt, kun je niet beschermen. |
| IT/OT-segmentatie | Bereikbaar (01) | Een muur tussen het kantoornetwerk en de fabriek, met één bewaakte overgang. Een kantoorbesmetting blijft een kantoorbesmetting. |
| Leverancierstoegang op aanvraag | Leveranciersdeur (03) | Onderhoud op afstand alleen als wij het openzetten, voor een persoon bij naam, voor een vaste tijd, via een jump host die de sessie opneemt. Standaard dicht. |
| Isoleer wat niet te patchen is | Niet te patchen (02) | Standaardwachtwoorden gewijzigd. Apparaten die niet gepatcht kunnen worden in een eigen hoek, waar alleen bij kan wat ze nodig heeft. |
| OT-monitoring | Veiligheid (04) | Meeluisteren op het fabrieksverkeer naar dingen die normaal nooit gebeuren: een nieuw apparaat, een besturing die wordt geherprogrammeerd, een instelwaarde die vanaf een ongebruikelijke plek verandert. |
| Configuratieback-ups | Veiligheid (04) | De programma's en instellingen van elke besturing offline bewaard, zodat een gesaboteerde of onbruikbare machine in uren wordt teruggezet in plaats van in weken opnieuw ontworpen. |
| Incidentplan met operations | Alle vier | De fabrieksmanager en de veiligheidskundige in het plan, met de bevoegdheid om de lijn te stoppen. Geoefend met een scenario rond een machine, niet rond een laptop. |
| Inkoopregels | Niet te patchen (02) | Voordat iets wordt gekocht dat verbinding maakt: hoe lang krijgt het beveiligingsupdates, kan het wachtwoord worden gewijzigd, heeft het internet nodig. Geen antwoord, geen aankoop. |
Anyone with a plant, a building system or cameras has devices that were never meant to be on a network. Almost everyone does.Iedereen met een fabriek, een gebouwbeheersysteem of camera's heeft apparaten die nooit voor een netwerk bedoeld waren. Dat is bijna iedereen.
Production stopped for days, physical damage to equipment or product, a possible safety or environmental incident, and lost output per hour.Productie dagen stil, fysieke schade aan apparatuur of product, een mogelijk veiligheids- of milieu-incident, en gemiste productie per uur.
The old devices stay. Segmentation, controlled vendor access and monitoring mean an incident is contained to one cell and restored from configuration backups.De oude apparaten blijven. Segmentatie, gecontroleerde leverancierstoegang en monitoring zorgen dat een incident beperkt blijft tot één cel en wordt hersteld uit configuratieback-ups.
With the CIO for the network boundary and the safety officer for consequences. Not an IT-only risk.Samen met de CIO voor de netwerkgrens en de veiligheidskundige voor de gevolgen. Geen risico van IT alleen.
connected devices without a named owner · network paths allowed from office to plant · vendor remote-access connections open right now · devices past vendor support still on the network.aangesloten apparaten zonder eigenaar bij naam · toegestane netwerkpaden van kantoor naar fabriek · leveranciersverbindingen op afstand die nu open staan · apparaten zonder leveranciersondersteuning die nog op het netwerk zitten.
“Compromise or manipulation of production and building systems through the office network or vendor remote access causes production loss, physical damage and a safety risk.”“Compromittering of manipulatie van productie- en gebouwsystemen via het kantoornetwerk of leverancierstoegang op afstand veroorzaakt productieverlies, fysieke schade en een veiligheidsrisico.”
| Framework | What it requires of you | When a supplier hands you their report | When this incident happens |
|---|---|---|---|
| NIS2 | Many OT operators are essential or important entities: energy, water, manufacturing, food, transport, health. The required measures apply to the plant as much as to the office, including access control, supply chain security and continuity. Management is accountable. | Machine builders and maintenance firms are suppliers under NIS2. Their remote access and update process is your risk: put security lifetime, access rules and incident notification in the contract. Confirm scope with legal. | A production disruption or safety event is a significant incident: early warning within roughly 24 hours, full notification within about 72, final report within a month. Safety and environmental regulators may need to hear separately. |
| DORA | For financial entities the OT is mostly buildings and data centres: cooling, power, physical access. These belong in the ICT risk framework as part of the critical functions they support. | Data-centre and facility providers are ICT third parties: they go in the register, and their report should show controls over physical access, environmental systems and remote maintenance. A report is input, not a substitute. | An outage of a critical function caused by a facility system is a major ICT incident: initial notification within hours of classification, intermediate report within about 72 hours, final report within a month. |
| SOC 2 | Physical and environmental controls and network segmentation are tested. Plant-floor devices are rarely in scope unless the service delivered depends on them. | For a manufacturing or hosting partner: check whether the plant and building systems appear in the system description. Often only the corporate IT does, and the line is out of scope. | An OT incident that hits a customer service becomes an availability deviation in the report. Expect auditors to ask for segmentation evidence and the incident timeline. |
| ISAE 3402 | Relevant where production or logistics is outsourced: continuity of processing and physical safeguards are common control objectives, but the service organisation chooses them. | Read whether the continuity objectives cover the machines and warehouse systems, not just the ERP. A report about the office systems says nothing about the line. | Production loss at a service organisation must be disclosed to the user auditors. If you are the operator, expect it in your opinion and in your customers’ audits. |
| Kader | Wat het van u vraagt | Als een leverancier u zijn rapport geeft | Als dit incident u treft |
|---|---|---|---|
| NIS2 | Veel OT-exploitanten zijn essentiële of belangrijke entiteiten: energie, water, industrie, voeding, transport, zorg. De verplichte maatregelen gelden voor de fabriek net zo goed als voor het kantoor, inclusief toegangsbeheer, ketenbeveiliging en continuïteit. Het bestuur is aansprakelijk. | Machinebouwers en onderhoudsbedrijven zijn leveranciers onder NIS2. Hun toegang op afstand en updateproces zijn uw risico: leg beveiligingslevensduur, toegangsregels en incidentmelding vast in het contract. Bevestig de reikwijdte met legal. | Een productieverstoring of veiligheidsincident is een significant incident: vroegtijdige waarschuwing binnen ongeveer 24 uur, volledige melding binnen ongeveer 72 uur, eindrapport binnen een maand. Veiligheids- en milieutoezichthouders moeten mogelijk apart worden geïnformeerd. |
| DORA | Voor financiële instellingen bestaat de OT vooral uit gebouwen en datacenters: koeling, stroom, fysieke toegang. Die horen in het ICT-risicokader als onderdeel van de kritieke functies die ze ondersteunen. | Datacenter- en facilitaire leveranciers zijn ICT-derden: ze staan in het register, en hun rapport moet maatregelen tonen voor fysieke toegang, klimaatsystemen en onderhoud op afstand. Een rapport is input, geen vervanging. | Een uitval van een kritieke functie door een gebouwsysteem is een ernstig ICT-incident: eerste melding binnen enkele uren na classificatie, tussenrapport binnen ongeveer 72 uur, eindrapport binnen een maand. |
| SOC 2 | Fysieke en omgevingsmaatregelen en netwerksegmentatie worden getest. Apparaten op de productievloer vallen zelden binnen scope, tenzij de geleverde dienst ervan afhangt. | Bij een productie- of hostingpartner: controleer of de fabriek en de gebouwsystemen in de systeembeschrijving staan. Vaak staat alleen de kantoor-IT erin en valt de lijn erbuiten. | Een OT-incident dat een klantdienst raakt, wordt een afwijking op beschikbaarheid in het rapport. Verwacht dat auditors bewijs van segmentatie en de incidenttijdlijn opvragen. |
| ISAE 3402 | Relevant waar productie of logistiek is uitbesteed: continuïteit van verwerking en fysieke beveiliging zijn gangbare beheersdoelstellingen, maar de serviceorganisatie kiest ze zelf. | Lees of de continuïteitsdoelstellingen de machines en magazijnsystemen dekken, en niet alleen het ERP. Een rapport over de kantoorsystemen zegt niets over de lijn. | Productieverlies bij een serviceorganisatie moet aan de auditors van haar klanten worden gemeld. Bent u zelf de exploitant, verwacht het dan in uw oordeel en in de audits van uw klanten. |