Home / Industries / Manufacturing

Critical Manufacturing · Chemicals · Discrete and process plants

OT security for plants that make things, from robot lines to batch reactors.

A plant makes money when the line runs, and stays safe when the safety systems work. Red Tiger Security assesses the live control network without stopping production. The walk starts where the plant touches business IT, the cloud, and machine builders, and works down to the PLCs, the DCS, and the safety instrumented systems. Then the team fixes the immediate need. If you want Red Tiger to stay, the close is 24x7 MSP + Metrics and Reports.

Robotic assembly line in a bright, clean manufacturing plant
5 weeksJaguar Land Rover's factories were shut after a cyberattack in September 2025. [11,12]
27%Drop in UK car production that September, the lowest September since 1952. SMMT said the attack was largely responsible. [12]
July 28, 2023The date Congress let CFATS authority expire. CISA cannot enforce the program. [3]

Discrete and process manufacturing

CISA's Critical Manufacturing Sector covers primary metals, machinery, electrical equipment, and transportation equipment. Chemicals is its own sector. [1,2] The control systems are similar. What fails, and how, is different.

Discrete

Parts, assemblies, and robot cells

Automotive, aerospace, machinery, electronics. PLCs, robot controllers, drives, and vision systems on a line that is tightly scheduled. A stopped line costs money by the minute. A stopped plant can stop the suppliers that feed it.

Process

Reactors, columns, and batches

Chemicals, metals, pulp and paper, pharma, and food. A DCS runs the process, and a safety instrumented system stands behind it. A bad change here is a safety problem as well as a production problem.

Pharma and food plants run the same PLCs, batch systems, and historians, with their own quality rules on top. Recipes and batch records are part of the risk.

Chemicals

Chemical plants are process plants with hazardous materials. The DCS runs reactors and columns, and the SIS takes the process to a safe state when something goes wrong. The team assesses both, plant-safe, with operations and the process safety team in the room.

The SIS is the reason to be careful. In late 2017, malware known as TRITON, TRISIS, or HatMan was found targeting Triconex safety controllers. CISA's analysis says it could modify the controllers' in-memory firmware. [10] An SIS is the last layer before an incident, so it gets its own zone and its own rules.

CFATS, as of October 2026. The statutory authority for the Chemical Facility Anti-Terrorism Standards expired July 28, 2023. CISA's CFATS page still says it cannot enforce compliance, and encourages facilities to keep security measures in place and use its voluntary ChemLock resources. [3]

Chemical plants on the water. A plant with a marine terminal that has a Facility Security Plan under 33 CFR 105 is also under the Coast Guard cyber rule, 33 CFR 101 Subpart F. The Cybersecurity Assessment and Plan are due July 16, 2027. [14] See USCG Regulated Sector.

Stainless steel batch vessels, valves, and piping in a chemical plant

The systems on the plant floor, and why they matter

6 groups and 15 systems. Open a group to see where assessment, remediation, and monitoring apply.

ARM  Core serviceARM  Dashed: where it fits the system and the riskA Assess · R Remediate · M Monitor
Control: PLCs and DCS4 systems
PLCs. Run the machines and the line. A changed program or a stopped controller stops production or damages equipment.
ARM
DCS. Runs the process in a continuous or batch plant: reactors, columns, furnaces, utilities.
ARM
HMI and SCADA. How operators see and run the plant. Usually Windows, often old.
ARM
Engineering workstations. Where control programs are written and downloaded. The most powerful computer on the plant floor.
ARM
Safety: SIS2 systems
Safety instrumented systems (SIS). Independent controllers that take the process to a safe state when something goes wrong. They are the last layer before an incident.
ARM
Burner management and machine safety. Furnace and boiler trips, light curtains, safety PLCs on robot cells.
ARM
Production systems3 systems
Robotics and motion control. Robot controllers, drives, and vision systems on the line, often supported remotely by the maker.
ARM
Batch and recipe management. Recipes and batch records in chemical, pharma, and food plants. A wrong recipe is a quality or safety problem.
ARM
MES. Manufacturing execution: work orders, genealogy, and quality between the business system and the floor.
ARM
Data2 systems
Historians. Process data collected for operations, engineering, and the business. Often the bridge between the plant and corporate IT.
ARM
ERP and MES interfaces. Where orders and schedules cross from business IT into the plant.
ARM
Utilities2 systems
Power, compressed air, steam, and cooling. The plant cannot run without them, and their controls are networked too.
ARM
Building management. HVAC and clean-room environmental control.
ARM
Access2 systems
Vendor and OEM remote access. Machine builders and integrators often keep their own remote support paths. Each one is a path into the plant.
ARM
Contractor laptops and USB. Brought onto the floor during outages and projects.
ARM

What applies, and what each one asks for

Series

ISA/IEC 62443

Industrial automation and control systems

Zones and conduits, security levels, and requirements for asset owners, integrators, and suppliers. The standard to write into machine builder and integrator contracts. [4]

September 2023

NIST SP 800-82 Rev. 3

Guide to OT security

NIST's guide to securing OT, including manufacturing and process control. It covers architecture, risk management, and how OT differs from IT. [5]

2024

NIST CSF 2.0

Voluntary framework, any sector

Six functions, including Govern. A good structure for the program and for board reporting. [6]

Draft, Sept. 29, 2025

NIST IR 8183 Rev. 2

CSF 2.0 Manufacturing Profile

Applies CSF 2.0 to manufacturing. Still an initial public draft; the comment period closed Nov. 17, 2025. [7]

IEC 61511-1:2016

ISA/IEC 61511

Safety instrumented systems, process industry

The functional safety standard for SIS, adopted in the U.S. through the ISA84 committee. Security work on an SIS has to respect the safety lifecycle. [8,9]

Expired July 28, 2023

CFATS

High-risk chemical facilities

Congress let the statutory authority for CFATS expire. CISA says it cannot enforce CFATS, and it encourages facilities to keep their security measures and use its voluntary ChemLock resources. [3]

CISA's Cross-Sector Cybersecurity Performance Goals are a reasonable baseline for a plant that has no regulator asking. [13]

Assess, fix the immediate need, then stay

Start with one plant. Plants built to the same standard usually share the same findings.

Step 1
1

Assess

  • Plant-safe OT assessment of the control network, Level 3.5 and down
  • Architecture review, from the business network and vendor connections down to the field devices
  • OT / ICS penetration testing only on staging systems or during a planned outage
  • Gap review against IEC 62443, NIST SP 800-82, and NIST CSF
The plant-safe assessment →
Step 2
2

Remediate

  • Fix the immediate need first
  • Segmentation between business IT and the plant
  • Secure remote access for machine builders and integrators
  • OT cybersecurity roadmap tied to outages and capital projects
  • Policy and procedures
  • Plant staff training through CambiOS Academy
Fix the immediate need →
Step 3
3

Monitor and maintain

  • 24x7 MSP + Metrics and Reports on the assets the team assessed
  • ICS / OT incident response planning and support
  • Tabletop exercises with operations, maintenance, and IT
  • Reassessment after major projects
24x7 MSP + Metrics and Reports →

Where each service fits

AssessRemediateMonitor
System groupOT assessmentArchitecture reviewPen testing (staging)Standards gapSegmentation, hardeningSecure remote accessRoadmap, policy24x7 monitoringIR, tabletops
PLCs and DCSControllers, HMI, SCADA
Engineering workstationsProgramming and downloads
Safety instrumented systemsSIS, BMS, safety PLCs
Robotics and motionRobot cells, drives, vision
Batch, MES, historiansRecipes, records, data
UtilitiesPower, air, steam, cooling
Vendors and contractorsRemote access, laptops, USB
  Core service for this group  Where it fits the system and the riskBlank: rarely appropriate

Why pen testing is limited

Active testing on a running line or a live SIS can trip it. Test on staging systems or during a planned outage.

Why the SIS is handled separately

The process safety team owns the SIS and its safety lifecycle. They are in the room before anyone touches it.

Why vendors get a row

Machine builders and integrators often hold remote access to the line. Their access is part of the plant's risk.

References

Numbers match the bracketed citations on this page. Sources checked Oct. 4, 2026.

  1. CISA, Critical Manufacturing Sector. https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector
  2. CISA, Chemical Sector. https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector
  3. CISA, Chemical Facility Anti-Terrorism Standards (CFATS), program page and lapse announcement. https://www.cisa.gov/resources-tools/programs/chemical-facility-anti-terrorism-standards-cfats
  4. ISA, ISA/IEC 62443 series of standards. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
  5. NIST, SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, September 2023. https://csrc.nist.gov/pubs/sp/800/82/r3/final
  6. NIST, Cybersecurity Framework. https://www.nist.gov/cyberframework
  7. NIST, IR 8183 Rev. 2 (Initial Public Draft), Cybersecurity Framework 2.0 Manufacturing Profile, Sept. 29, 2025. https://csrc.nist.gov/pubs/ir/8183/r2/ipd
  8. IEC, IEC 61511-1:2016, Functional safety: Safety instrumented systems for the process industry sector. https://webstore.iec.ch/en/publication/24241
  9. ISA, ISA84 standards committee, Instrumented Systems to Achieve Functional Safety. https://www.isa.org/isa84
  10. CISA, MAR-17-352-01, HatMan: Safety System Targeted Malware (Update B), Feb. 27, 2019 (PDF). https://www.cisa.gov/sites/default/files/documents/MAR-17-352-01%20HatMan%20-%20Safety%20System%20Targeted%20Malware%20%28Update%20B%29.pdf
  11. BBC News, "Jaguar Land Rover production severely hit by cyber-attack," Sept. 2, 2025. https://www.bbc.com/news/articles/c9wywvllq7wo
  12. BBC News, "JLR cyber-attack caused UK car production to hit 70-year low for September," Oct. 23, 2025. https://www.bbc.com/news/articles/cvgmp1prnv0o
  13. CISA, Cross-Sector Cybersecurity Performance Goals. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
  14. eCFR, 33 CFR Part 101 Subpart F, Cybersecurity. https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-F

Request an assessment

Start with one plant, plant-safe, with operations and process safety in the room. +1.877.387.7733 · info@redtigersecurity.com

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.