Solutions

Cyber Security for Manufacturing and Engineering Firms

Downtime is the loss that matters. We separate the factory floor from the office network, contain the machines that cannot be patched, and make sure a ransomware event does not stop production.

PRIORITY
Availability & Production Uptime
APPROACH
IT / OT Network Separation
LEGACY KIT
Isolate Rather Than Patch
DRIVER
Customer Supply Chain Assurance
In short

How do you secure old machinery that cannot be patched?

You isolate it rather than patch it. Legacy machines running unsupported operating systems are placed on their own segmented network with strictly controlled access, no internet route, and monitoring at the boundary — so the machine keeps running while the risk it carries is contained.

The machine that cannot be touched

Nearly every manufacturer we assess has at least one critical machine driven by a controller running an operating system that stopped receiving updates a decade ago. The vendor will not support an upgrade, replacement costs six figures, and the machine works. Telling the business to patch it is not advice, it is an evasion.

The answer is containment. The machine goes onto its own network segment with no internet route, access restricted to the specific engineering workstations that need it, removable media controlled, and monitoring at the boundary so unusual traffic is visible. The risk is not eliminated, but it is bounded and documented — which is also what an auditor or insurer wants to see.

  • Dedicated network segment for OT with a controlled boundary
  • No direct internet access from the production network
  • Access limited to named engineering workstations and accounts
  • USB and removable media control on machine controllers
  • Documented accepted risk with compensating controls recorded

Vendor remote access

Machinery suppliers frequently require remote access for diagnostics and support, and that access is often permanent, shared between engineers, and unmonitored. It is a standing route into the production network held by a third party whose own security you have never assessed.

We replace always-on vendor access with access that is requested, time-limited, individually attributable, multi-factor authenticated and logged. Vendors reasonably need access; they do not need it at three in the morning on a Sunday without anyone knowing.

  • Time-limited, request-based vendor access rather than standing connections
  • Individual named accounts, never shared vendor logins
  • MFA and session logging on all third-party access
  • Access scoped to specific machines, not the whole network

Supply chain questionnaires

For many manufacturers the immediate driver is commercial rather than technical: a large customer has sent a security questionnaire, and continued business depends on answering it credibly. These questionnaires are increasingly detailed and increasingly verified.

We help answer accurately, identify which gaps genuinely need closing before the answer is truthful, and — where the customer will accept it — substitute a Cyber Essentials certificate, which satisfies many questionnaires outright and saves repeating the exercise for every customer.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Manufacturing Security — your questions answered

How do we secure machines running Windows XP or Windows 7?
Isolate rather than patch. Place them on a dedicated network segment with no internet route, restrict access to specific engineering workstations, control removable media, and monitor the boundary. Document it as an accepted risk with those compensating controls.
What is IT/OT segmentation?
Separating the office IT network from the operational technology that runs production, with a controlled boundary between them. It means a ransomware event in the office cannot spread to the factory floor and stop the line.
A customer sent us a security questionnaire we cannot answer. Can you help?
Yes. We work through it with you, identify which answers are currently untrue, prioritise the gaps that matter, and help you respond credibly. Cyber Essentials often satisfies a large portion of these questionnaires in one step.
Will security changes risk stopping production?
Changes to OT are planned around your production schedule, staged, and reversible, with rollback agreed before anything is touched. Assessment and documentation work is non-intrusive and runs while you produce.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about manufacturing security?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.