Industrial cyber security begins with smarter choices

Posted on 1 Oct 2025 by The Manufacturer
Company: ABB

Manufacturers will be all too aware of the recent cyber attack on a major UK-based automaker, which forced the shutdown of several plants, halted production of around 1,000 cars every day and left suppliers scrambling. But behind the headlines of lost revenue and disrupted operations, the attack serves as a stark reminder: even the largest and most sophisticated operations are not immune to rising tide of industrial cyber crime. Here, Prabhu Nagavi, Global Product Manager for Machinery Drives, ABB looks at the best place to start to improve industrial cyber security.

This recent attack isn’t an isolated case. In fact, the first quarter of 2025 alone saw ransomware incidents in manufacturing surge 46%. For many in the sector, these threats are not unexpected; they’re the inevitable result of a major shift, as  more and more factories move towards becoming interconnected, data-driven ecosystems. In today’s industries, the very technologies that enable efficiency and innovation are also creating new vulnerabilities.

Key takeaways

  • Industrial drives are critical cyber security points: Modern factories’ connected drives can be exploited if not secured, making them a primary target in cyber attacks.
  • Built-in security is essential: Secure-by-design drives with features like secure boot, digitally signed firmware, and role-based authentication protect operations from the inside out.
  • Connectivity increases vulnerability: While Ethernet and IoT-enabled devices improve efficiency, they also create new entry points for attackers if not properly managed.
  • Regulatory compliance drives security adoption: Upcoming regulations, such as the EU Machinery Regulation, require security to be embedded in equipment, making proactive measures essential.
  • Operational resilience depends on secure drives: Properly secured drives reduce downtime, simplify integration, support auditing, and protect the entire plant network from cascading failures.

FAQs

  • Why are industrial drives a cyber security risk?
  • What is secure-by-design in industrial drives?
  • How does connectivity affect industrial cyber security?
  • What regulations affect industrial drive cyber security?
  • How can manufacturers protect their operations from cyber attacks?

At the heart of this lies the operational technology (OT) layer, where equipment like electric motors do the heavy lifting (and turning) while connected to variable speed drives, that keep production running smoothly. Yet, despite their importance, industrial drives are often overlooked in cyber security measures. And when neglected, they represent not just a single point of failure, but a door left wide open to the entire plant network.

For small and mid-sized OEMs, however, implementing secure-by-design drives brings cost and resource challenges. Limited budgets and a lack of deep cyber security expertise often mean security gets overlooked in early design stages. But in today’s landscape, securing only at the IT network level isn’t enough. True resilience means embedding protection directly into OT components – starting with drives.

Connectivity’s hidden cyber cost

For many OEMs and plant operators, productivity targets like uptime and throughput come first, with cyber security often addressed only after the fact. This add‑on mentality is increasingly risky, especially as European regulators roll out stricter requirements that demand security to be baked in from the start.

Part of the challenge comes from just how connected factories have become. What were once largely isolated control systems are now data‑rich, highly networked environments. Ethernet has become standard for linking drives, PLCs and sensors, giving operators visibility and control.

But connectivity is a double‑edged sword. Misconfigured devices, unpatched firmware, weak authentication or even something as small as a neglected open port can give cyber criminals a foothold, and snowball into system‑wide vulnerabilities. Skilled and malicious actors could cause power outages, production line shutdowns or even fires by manipulating the digital underpinnings of a plant’s machinery.

Beyond the perimeter

Industrial cyber security has traditionally focused narrowly on defending the perimeter – the places where the trusted internal network meets the untrusted external world, in this case, the internet. In today’s interconnected factories, that approach leaves gaps. That’s why newer generations of industrial drives are secure from the inside out, securing every interface and control function by default.

For smaller OEMs, the benefit of these next generation devices is a ready‑made foundation of cyber security without the extra complexity or cost of retrofitting protection later. For larger OEMs, it provides a scalable layer of security that can be applied across fleets of machines and complex, multi-site operations.

Device‑level safeguards also extend through the supply chain. Tamper‑resistant features prevent counterfeit or altered components from worming their way in, closing off pathways that attackers might otherwise exploit. In practice, this means one weak link is far less likely to bring the entire system down.

Beyond immediate operational safety, this built‑in approach gives manufacturers breathing room to adapt to future regulations, including the EU’s updated Machinery Regulation. In an environment where even the smallest vulnerability can cascade across entire factories and fleets, taking security down to the drive level is essential.

Commissioning without the complication

For OEMs, commissioning and firmware management can be some of the most time‑consuming and frustrating parts of deploying new drives. However, modern drives are designed to strip away some of that complexity and make life easier for commissioning engineers.

Traditionally, engineers needed to constantly swap cables when configuring multiple drives, slowing the entire process down. With newer drive models, commissioning can be done directly over Ethernet, allowing PCs on the same network as drives and PLCs to configure IP addresses and get to work. Without manual juggling of cables, the process is significantly faster.

For quick access to drive parameters, the USB‑C port provides another option. Because it doesn’t disturb existing communication cabling, engineers can plug in while keeping operations intact. And since USB‑C is now a universal standard, any compatible 2.0 cable can be used, provided proper grounding is in place on the PC side to safeguard the drive.

Firmware management is another area where problems emerge. Instead of requiring users to search for the latest firmware version themselves, modern drives can connect to DOFS (Drive Online Firmware Management System), an always‑up‑to‑date repository of official releases. For end users and OEMs, that means firmware updates are streamlined and secure, removing the risk of running outdated or mismatched versions.

The right key for every door

Modern drives can apply the same disciplined approach to communication as they do to motor control. Only trusted devices are allowed to connect, dormant ports are automatically switched off and any attempted breach is recorded for immediate review. In an industrial environment, this kind of visibility is as important as preventing the intrusion itself, because knowing when and how an attack was attempted is partly what stops it from happening again.

Another key consideration for both OEMs and end users when shaping their cyber security strategies is how user management and authorisation are handled. Without clear rules and boundaries on user access, even the strongest defences can be compromised.

However, devices available today ensure that both centralised and local account management are supported and built around strict role‑based access rules. Secure boot processes verify that only authorised software can run, with automatic rollback to a clean state if tampering is detected.

What buyers should be asking themselves

Not long ago, choosing an industrial drive was largely about function: how precisely it could control motor speed, how efficiently it used energy, and how smoothly it kept production on track. Of course, those capabilities still matter. But in today’s environment, a drive that can’t stand up to cyber threats is a drive that’s already out of date. Cyber security needs to become a core buying criterion. For procurement professionals, this means asking a new set of questions before signing off.

Firstly, buyers should start by asking whether the equipment is compliant with both current and future cyber security regulations. Rules such as the EU Machinery Regulation, arriving in 2027, are already setting higher standards for product security. Compliance is far more than a formality, as it determines whether equipment can legally remain on the market and in operation. Choosing solutions that meet these requirements ahead of time means fewer patch‑jobs later and a much smoother audit process.

It is equally important to confirm that the drive includes safeguards such as secure boot, digitally signed firmware, and role‑based authentication. These features act as the lock on the front door of an operation, stopping unauthorised code or users before they can take hold. Without them, even well‑defended plants may expose hidden back doors vulnerable to exploitation.

Compatibility with broader plant‑level security systems is another key factor. A drive that functions in isolation may appear secure in theory, but if it cannot integrate with existing firewalls or identity management tools, it leaves behind blind spots. True resilience depends on smooth integration, making sure that security decisions aren’t scattered across devices.

Buyers should also look at the drive’s ability to provide logging and monitoring capabilities. In the wake of an incident, forensic information is worth its weight in gold. Drives that can record logs and flag suspicious behaviour create the data trail needed to understand exactly what happened, and to defend against future attacks. Without such visibility, organisations are essentially flying blind when responding to threats.

Finally, it is essential to ensure that unused ports and access points can be disabled before deployment. Every open interface is a potential entry point for attackers, and drives designed to deactivate these vulnerabilities from day one remove the need to rely on manual intervention later.

Neglecting questions like these doesn’t just heighten exposure to downtime or data breaches. It can also leave entire facilities out of step with regulatory requirements and unprepared for the next wave of audits. These are challenges that are more costly to fix after the fact than they are to avoid through careful planning and procurement in the first place.

The case for built-in security

Cyber security is no longer separate from performance; it is what makes high performance attainable and sustainable. Without robust protection, every productivity gain rests on shaky ground.

Modern drives prove that advanced motor control, connectivity, event logging and built-in security can coexist seamlessly. For equipment procurers and plant operators, adopting such solutions reduces integration complexity, strengthens resilience, and helps meet the challenges posed by fast-evolving cyber risks.

With ransomware showing no signs of slowing down, ignoring the cyber security of industrial drives is simply no longer an option. No matter the scale of the operation, whether a global manufacturer running multiple plants or a start‑up scaling its first production line, the risks and consequences are the same. Protecting drives is central to safeguarding the industrial operations of the future.

For more articles like this, visit our Digital Transformation channel