31 www.drivesncontrols.com July/August 2026 INDUSTRIAL SECURITY n on the defence-in-depth principle. Safety is not achieved through a single barrier, but through multiple layers of protection arranged one after the other. If one layer is overcome, the next one stands firm. Zones form these tiered spaces, while conduits are the monitored passageways between them. This way, a single vulnerability cannot compromise the entire system – particularly when it's a matter of safety and therefore protecting people. At Pilz, we are pursuing this approach as security-for-safety, safety being the primary protection goal of security. The focus is on protecting safety which, in turn, protects people. That is why we separate safety from general machine control, thus reducing the exposure of safety-related functions. The more clearly these “assets” are separated functionally, the fewer additional safety measures are needed to provide reliable protection. The benefits of this approach are evident throughout the entire lifecycle of a machine. If safety functions and standard functions are separate, there is no need to recertify or adapt the safety functions in parallel if the standard functions are updated. This reduces maintenance and servicing work significantly. Classic safety controllers also require considerably fewer safety-critical updates than standard controllers, so this separation eliminates the need for many unnecessary interventions. Separation also offers technological advantages. A standalone safety system, such as Pilz’s PNOZmulti 2 small safe controller, can be combined freely with control systems from different manufacturers, unlike integrated systems which are often tied to specific technologies. At the same time, separate safety systems raise the bar for attackers, because they must be compromised individually, making manipulation much more difficult. What's more, a standard system can be online when needed, while the actual safety functions remain isolated, thus drastically reducing the attack surface. This separation of safety and security automation – each with perfectly coordinated security levels – also increases efficiency by making it easier to plan safety, maintenance and expansion measures. So changes to the standard program do not require any intervention in the safetyrelated section, significantly reducing the amount of programming and adaptation work required. Simultaneously, this separation has a positive impact on software and support costs, as separate systems often incur lower licence and service fees. Protection through separation The clear separation of safety and standard automation not only ensures technical robustness, but also reduces operator errors and lowers training requirements. As safetyrelated functions run on dedicated hardware and are clearly separated in organisational terms, they remain protected even if changes are made to the standard program. As a result, errors in day-to-day operations do not compromise safety, and responsibilities can be assigned more clearly. At Pilz, we are offering a training and service programme to help companies implement this architecture. These include the training courses “Fundamentals of Industrial Security” and “CESA – Certified Expert for Security in Automation”, as well as industrial security services. These explain how to develop robust security for safety concepts from the individual blocks, but also go much further. They demonstrate: how to manage security risks systematically and develop holistic safety concepts; how to incorporate the requirements of IEC 62443; how to structure the architecture of a safe machine network; and how to assess and continuously improve the effectiveness of the measures that are taken. One key advantage of this approach: operators at the end-user do not need to be deeply immersed in issues of security because the protection of the safety functions is already guaranteed by the architectural design. For this reason, the training courses are aimed primarily at those who make security decisions or design systems, while operators can continue to work safely without needing additional training in industrial security. The result is a practical division of roles, simplifying plant operation while at the same time sustainably increasing the level of protection. Tangible added value An effective security-for-safety strategy is not achieved through individual measures, but through a well-thought-out architecture, clear lines of responsibility and targeted skills development. With a strict focus on defence-in-depth and a clear separation between safety and standard automation, we are laying the foundations for resilient machinery, supplemented by practical training and consultancy to ensure that companies can follow this path with confidence. The result is a level of safety that not only meets the requirements of the standards, but also delivers tangible added value in day-to-day operations – simpler, more robust and effective, long-term. n The Machinery Regulation adds security to the safety focus of the Machinery Directive Key parts of IEC 62443: Industrial communication networks - Network and system security For component manufacturers For systems integrators For operators IEC 62443-4-1: Development process IEC 62443-2-4: Directives and procedures IEC 62443-2-4: Directives and procedures IEC 62443-4-2: Security functions for components IEC 62443-3-2: Security functions for automation and control systems IEC 62443-2-1: Operation and service IEC 62443-3-3: Security functions for the entire automation and control system
RkJQdWJsaXNoZXIy MjQ0NzM=