Questions around critical production assets, recovery priorities and the practicalities of restarting plant all require engineering input. When cyber risk reaches the factory floor The latest cybersecurity figures from Make UK make uncomfortable reading for manufacturers. Some 30% experienced a cyber incident, either directly or through their supply chain, during the past 12 months. Perhaps more significant for those concerned with the performance of plant is what happened next. Where incidents caused disruption, production downtime was among the most commonly reported consequences. That places cybersecurity in a rather different context. Much of the discussion surrounding cyber risk understandably concentrates on data, networks and business systems, but on a manufacturing site the consequences can extend much further. When production is interrupted, cybersecurity stops being an abstract corporate risk and becomes a very practical operational problem. Manufacturers hardly need reminding of the cost of downtime. Considerable effort and investment goes into preventing it, whether through planned maintenance, Editor’s Comment ‘ ’ condition monitoring, critical spares or improvements to equipment reliability. Cyber disruption presents another route to much the same unwanted destination, albeit one that has not traditionally featured prominently in maintenance planning. A high-profile case last year showed just how disruptive a cyber incident can be for manufacturing, with the effects reaching far beyond the IT department and onto the factory floor. Incidents on that scale may be unusual, but the potential consequences of lost production are something every manufacturer will recognise. Most manufacturers will never experience disruption on anything approaching that scale. Nevertheless, greater connectivity between production equipment, control systems and wider business networks means an IT problem can have consequences for the plant. Once an incident affects production, engineering knowledge will almost certainly be required as part of the response. There is no suggestion that maintenance teams should become cybersecurity specialists. That expertise belongs with those trained to provide it, just as other specialist disciplines do. Engineering does, however, have an important role in understanding the operational consequences of an incident and deciding how production can be recovered safely. It is therefore notable that Make UK found only around half of manufacturers have an incident response plan. For a manufacturing business, such a plan surely needs to consider the factory as well as the office. Questions around critical production assets, recovery priorities and the practicalities of restarting plant all require engineering input. None of this is particularly far removed from the principles already applied to plant reliability. Maintenance teams routinely consider likely failure modes, consequences, recovery times and the availability of critical spares. The source of the disruption may be different, but much of the thinking required to prepare for it is familiar. The challenge is ensuring that cybersecurity does not sit in an organisational silo until an incident occurs. IT and cybersecurity teams understand the threat and how to contain it; engineering understands the plant and the practical consequences of losing it. Bringing those areas of expertise together before production is affected makes sense. Cybersecurity may not be a maintenance responsibility in the traditional sense. Cyberrelated downtime most certainly is a plant issue. August/September 2026 www.pwemag.co.uk Plant & Works Engineering | 03
RkJQdWJsaXNoZXIy MjQ0NzM=