Skip to content
profix::sec
HU

OT security · Manufacturing · NIS2

OT security in live production, without downtime.

Manufacturing is not IT: a badly timed scan can knock over a PLC, there is no window for the critical patch, and the network grew flat over years. This needs an engineer who has worked next to running production. On the NIS2 programme of a multinational manufacturing site, that is exactly what I did.

Or email: hello@profixsec.com

On the first engagement: if your auditor rejects the remediation plan I write, I don't invoice it.

Last updated: 22 August 2026

Why the IT playbook fails here

Four reasons manufacturing is a different game.

The network grew flat

Over fifteen years the PLCs, the HMIs, the scales and the office laptops ended up in one segment. Ransomware in accounting reaches the production line unobstructed, and from there the conversation is not about data loss, it is about downtime.

Some things cannot be patched

The controller runs on a Windows certified ten years ago; the vendor ships no updates, or updating voids support. These systems don't need replacing, they need protecting: isolation and compensating controls.

IT tools cause damage in OT

An active vulnerability scan that is routine on the office network can knock over an old PLC. On the OT side you need passive methods, and an engineer who knows which of the two applies when.

NIS2 reaches manufacturing too

Manufacturing sits on the other-critical sector list: medical devices, electronics, machinery, automotive. And those not directly in scope get reached through the supply chain by their customers' requirements.

What I build

Controls that survive three-shift operation.

Segmentation and zone boundaries

IT/OT boundary, zones and controlled conduits along the Purdue levels, with the logic of IEC 62443. The firewall ruleset documented so operations understands it too, not just me.

OT-aware monitoring

Passive traffic analysis that understands OT protocols, and alerting that doesn't stop at IT: when a new device appears in the OT segment, you need to see it.

Vulnerability management without downtime

Assessment done passively, remediation scheduled into maintenance windows, and where no patch exists, a documented compensating control. Production keeps running throughout.

Supplier remote access

Vendor remote maintenance runs over a controlled channel: scoped access, time limits, logging. Not a VPN left open forever.

Incident readiness for the plant

Decided in advance: what can be isolated, what must not stop, who decides mid-shift, and what recovery looks like. Rehearsed as a tabletop with operations.

NIS2 mapping with evidence

The controls built are mapped to the requirements with audit-ready evidence. Compliance becomes a by-product of the work, not a separate project.

How I work next to production

Four rules I never break.

  • Assessment runs on document review, passive monitoring and a physical walk-down. I never run active tooling on the OT network without prior agreement.
  • Every change happens in a maintenance window, with a rollback plan written in advance.
  • I work with operations, not against operations. The shift always knows what is happening and why.
  • Everything I build is handed over documented: the next engineer, or your own team, can carry on without me.

The reference behind it: a multinational automotive manufacturing site, plant-level NIS2 programme, segmentation and governance across five departments. Details on the home page, with the name.

Frequently asked questions

Do we have to stop production for the assessment?

No. The assessment is built on document review, passive traffic monitoring and a walk-down; none of these touch production. Work that does intervene happens exclusively in an agreed maintenance window, with a rollback plan.

We have old systems that cannot be updated. What can be done with those?

That is manufacturing's default state, not an exception. The answer is isolation and compensating controls: put the unpatchable system in a zone only reachable by what genuinely needs it, and log every transition. Protect, don't replace.

OT belongs to maintenance, IT is ours. Who is responsible?

This is the most common real obstacle, and it is not technical. I did exactly this at a multinational manufacturing site: joint governance across five departments, so a finding has one owner rather than two or none. Clarifying that responsibility map is part of the assessment.

Does NIS2 apply to us?

If your activity is on the manufacturing lists of the annexes and you have reached medium-enterprise size, probably yes. Our scope checker tells you in two minutes, without entering company data.

What manufacturing environment have you worked in?

I ran the plant-level cybersecurity strategy at a multinational automotive manufacturing site: converged OT/IT systems, network segmentation, Zero Trust, vulnerability management on ICS/SCADA-adjacent systems. The detailed case study is on the home page, with the name.

How much does it cost?

The gap assessment is from €1,200, fixed price, in 2-3 days. A focused build of one control area is from €2,500 fixed, within two weeks. Full implementation is a milestone-based proposal from roughly €6,000, continuous controls monitoring from €700 per month. The first engagement carries a guarantee: if your auditor rejects the remediation plan I write, I don't invoice it.

Let's start

One walk-down says more than any proposal.

30 minutes, free. Tell me what the network looks like and what your biggest fear is. By the end of the call you will know your three riskiest points, and what I would do with them first.

The technical side of the NIS2 obligations has its own page, and whether you are in scope takes two minutes to find out.