Trade News

  1. Home
  2. Products
  3. Trade News
  4. ISA and OTCC Join Forces to Address Growing Industrial Automation Cybersecurity Risks
ISA and OTCC Join Forces to Address Growing Industrial Automation Cybersecurity Risks

ISA and OTCC Join Forces to Address Growing Industrial Automation Cybersecurity Risks


Cybersecurity has become one of the most important challenges facing the global industrial automation industry.

As PLCs, DCS systems, SCADA platforms, industrial networks, remote monitoring technologies, and cloud services become increasingly connected, industrial organizations must protect operational technology environments against increasingly sophisticated cyber threats.

A new partnership announced in August 2026 highlights the growing importance of collaboration in this area.

The International Society of Automation and the Operational Technology Cybersecurity Coalition announced a Memorandum of Understanding intended to strengthen OT cybersecurity across critical infrastructure. The partnership focuses on increasing awareness of OT cybersecurity risks and solutions, supporting technical engagement, and encouraging stronger implementation of ISA/IEC 62443 cybersecurity standards.

For PLC, DCS, and industrial automation professionals, the development is particularly important because cybersecurity is increasingly becoming part of the complete automation lifecycle.

Why OT Cybersecurity Is Different from Traditional IT Security

Industrial control systems are different from ordinary corporate IT systems.

A company laptop can often be disconnected, updated, or replaced relatively quickly.

A PLC controlling a production line may need to operate continuously for years.

A DCS controlling a chemical process cannot simply be restarted whenever a software update becomes available.

Industrial systems prioritize:

  • Safety
  • Availability
  • Reliability
  • Deterministic control
  • Long operational lifecycles

These requirements create unique cybersecurity challenges.

A security strategy designed only for office IT environments may not be suitable for industrial control systems.

PLC Cybersecurity Is Becoming a Critical Engineering Issue

PLC systems are at the heart of many industrial automation applications.

They control:

  • Motors
  • Pumps
  • Valves
  • Conveyors
  • Production machinery
  • Packaging equipment
  • Process equipment

If a PLC is compromised, the consequences can potentially extend beyond data loss.

An attacker could potentially interfere with physical processes.


This is why PLC cybersecurity must be considered during system design, commissioning, operation, and maintenance.

Engineers increasingly need to understand:

  • Network segmentation
  • Access control
  • Authentication
  • Secure remote access
  • Firmware management
  • Backup strategies
  • Security monitoring

Cybersecurity is becoming an engineering responsibility rather than an issue handled only by IT departments.

DCS Systems Face Similar Challenges

DCS platforms are widely used in industries where process continuity and safety are critical.

Examples include:

  • Oil and gas
  • Chemical manufacturing
  • Power generation
  • Pharmaceuticals
  • Water treatment
  • Pulp and paper

These facilities often operate continuously.

A cyber incident affecting a DCS can potentially impact production, safety, equipment, and business operations.

Therefore, DCS cybersecurity requires a comprehensive approach.

It is not enough to install a firewall and assume the system is protected.

Organizations must understand the entire architecture.

ISA/IEC 62443 Provides a Structured Approach

One of the key elements of the new ISA and OTCC partnership is promoting the implementation and recognition of ISA/IEC 62443.

The standard series provides a framework specifically designed for industrial automation and control system cybersecurity.

It addresses cybersecurity across multiple areas, including:

  • Industrial automation system design
  • Component security
  • System requirements
  • Security lifecycle management
  • Industrial asset owners
  • Product suppliers

The objective is to establish a structured approach rather than relying on isolated cybersecurity tools.

For industrial automation engineers, this can help integrate security considerations into the architecture of PLC, DCS, SCADA, and network systems.

Vendor-Neutral Collaboration Is Increasingly Important

Industrial automation environments frequently contain equipment from multiple manufacturers.

A single factory may use:

  • Siemens PLCs
  • Rockwell Automation controllers
  • Schneider Electric systems
  • ABB DCS equipment
  • Mitsubishi Electric automation products
  • Third-party sensors and drives

This creates a complex cybersecurity environment.

A security strategy cannot focus on only one supplier.

Vendor-neutral standards and cooperation can therefore help organizations create consistent security policies across different automation technologies.

The ISA and OTCC partnership emphasizes open, vendor-neutral collaboration as part of its approach to OT cybersecurity.

The Industrial Automation Supply Chain Must Also Adapt

Cybersecurity is increasingly affecting automation equipment suppliers.

Customers are becoming more interested in:

  • Secure PLCs
  • Secure communication modules
  • Industrial firewalls
  • Security-certified components
  • Firmware management
  • Secure remote access

This means automation suppliers need to understand cybersecurity requirements in addition to traditional product specifications.

For example, when supplying a PLC module, customers may increasingly ask:

  • What firmware version is supported?
  • How is access controlled?
  • How are security updates handled?
  • Does the component support secure communication?
  • What security standards apply?

The answers can become important purchasing criteria.

Legacy Automation Systems Are a Major Challenge

One of the biggest difficulties in OT cybersecurity is the large installed base of legacy systems.

Many industrial plants continue to use automation equipment that was designed long before today's cybersecurity environment existed.

Legacy PLCs and DCS systems may have:

  • Limited authentication
  • Older communication protocols
  • Outdated operating systems
  • Limited security monitoring
  • Difficult firmware upgrade procedures

Replacing an entire system can be expensive.

Therefore, industrial organizations need practical modernization strategies.

These can include:

  1. Network segmentation
  2. Controlled remote access
  3. Asset inventory
  4. Security monitoring
  5. Regular backups
  6. Risk-based modernization
  7. Replacement of unsupported components

Cybersecurity and DCS Modernization Are Becoming Connected

The recent ABB Pelican Point DCS modernization project provides a useful example of how cybersecurity is increasingly included in automation modernization.

In that project, modernizing the DCS controller infrastructure was intended not only to improve performance and monitoring but also to strengthen cybersecurity.

This illustrates an important industry trend.

Automation modernization is no longer only about replacing old hardware.

It is increasingly about improving the overall operational technology architecture.

The Skills Required for Automation Engineers Are Changing

Industrial automation engineers traditionally focused on:

  • PLC programming
  • DCS configuration
  • Instrumentation
  • Electrical control
  • Industrial networks

Cybersecurity is now becoming another important area of expertise.

Modern automation engineers increasingly need to understand basic cybersecurity concepts.

They do not necessarily need to become full-time cybersecurity specialists, but they should understand how their control systems interact with industrial networks and security infrastructure.

This is especially important during commissioning and maintenance.

Why the ISA and OTCC Partnership Matters

The new partnership provides an example of how the industrial automation industry is responding to cybersecurity challenges through collaboration.

The organizations intend to work together on awareness, technical engagement, and stronger implementation of foundational OT cybersecurity practices.

This is relevant to manufacturers, system integrators, automation suppliers, and critical infrastructure operators.

Cybersecurity cannot be solved by one company or one product.

It requires cooperation between:

  • Automation vendors
  • System integrators
  • Industrial operators
  • Cybersecurity specialists
  • Standards organizations
  • Government agencies


Tags:

Look forward to your comments!Comment
Latest comments

0.0
Points

Need Assistance? Chat with Us on WhatsApp!
Need Assistance? Click to Inquire
Back to top