Why OT Cybersecurity starts before design
Growing connectivity, new regulations, and long-term operational requirements are pushing cybersecurity decisions into the earliest stages of industrial project design.
The earliest decisions in a new industrial project often have the longest impact. Choices involving automation, supplier access, and long-term support can be difficult and expensive to change once the process has been commissioned, yet they will continue to affect reliability, maintenance, and operational risk for years. OT cybersecurity is now one of those foundational decisions.
Operational Technology, or OT, includes the control systems, industrial networks, software, and connected devices used to monitor and operate physical processes. Unlike traditional IT systems, which primarily manage business information, OT controls the plant itself, including pumps, valves, turbines, motors, production equipment, and other critical process assets. As industrial facilities become more connected, protecting these systems is becoming just as important as protecting the physical infrastructure they control.
In many industrial projects, however, OT cybersecurity is still treated as something that can be handled later, after the main technology selections have been made and the system design is already moving toward detailed engineering or commissioning.
That approach simply does not work anymore. As industrial systems become more connected and cybersecurity requirements continue to expand, decisions made late in the project can create compliance issues, increase costs, complicate commissioning, and leave plant owners with security gaps that are much harder to address after startup.
In the European Union, OT cybersecurity is moving beyond a matter of technical preference. The Cyber Resilience Act and NIS2 are placing defined responsibilities on both sides of the industrial environment. Suppliers must provide products that meet security requirements, while critical infrastructure operators must manage cybersecurity risk throughout their operations.
In the EU, cybersecurity is enforced by law. That is why everyone is on their toes.
Valmet is a leading worldwide provider of process technologies, automation systems, and services for the pulp, paper, and energy sectors. The company’s automation and flow control offerings further extend their reach into a wide range of other process industries. With headquarters in Espoo, Finland, Valmet has over 220 years in the industrial sector.
In the United States, cybersecurity requirements are increasingly included in RFQs and are generally expected in major industrial projects. However, the regulatory structure is more fragmented. Requirements may come from the plant owner, the contract, federal procurement rules, or regulations that apply to a specific industry. Unlike NIS2, which can make company management responsible for approving and overseeing cybersecurity measures, most U.S. requirements do not create the same direct management liability across industrial sectors.
According to Kiviniemi, the shift in Europe – and to a lesser degree in the United States and the rest of the world – is creating a particular challenge in Engineering, Procurement and Construction projects, where EPCs are often responsible for bringing together the many suppliers required to deliver a complete power plant, refinery, chemical plant, water treatment facility, or other industrial asset.
In these projects, the EPC may be responsible for defining the cybersecurity requirements during the project and making sure suppliers meet them. However, once the plant is handed over, the owner is responsible for operating the system securely and maintaining that security over time.
“The analogy is similar to an automobile: the manufacturer can build a vehicle that meets applicable regulations, but the driver must still understand and follow the rules of the road,” says Kiviniemi.
That puts EPCs in the position of delivering plants that support compliance, even though the ongoing cybersecurity responsibilities extend beyond the construction project and into the operating life of the facility.
This is where timing becomes critical. When cybersecurity is considered only after the core system architecture has already been selected, the project team is effectively trying to add security after the product has been designed.
It is like first making a product and then putting the quality in afterwards. It doesn’t work that way. You need to take cybersecurity into consideration from the start.
The cost of late cybersecurity decisions
Once the system architecture is already established, new cybersecurity requirements can be difficult to accommodate without creating additional complexity. Compliance may require new components, changes to existing interfaces and workflows, or exceptions that leave the overall system more difficult to operate and maintain.
The cybersecurity requirements also continue after the project is complete. Although the EPC may still deliver the project on time, any compromises made during design can remain with the owner for the next 20 to 30 years. This is particularly important in OT, where industrial systems cannot be patched, modified, or rebooted with the same freedom as conventional IT systems.
“Email server patching may inconvenience employees for an hour. A poorly timed or poorly tested OT patch can affect production, safety, or, in the case of a power plant one million people don’t get electricity and it makes headlines,” says Kiviniemi.
In an OT system, a known vulnerability may remain open for some time before the patch can be installed. Software updates in an industrial control system are rarely immediate. Before anything is installed, the automation supplier must determine whether the update applies, test it against the control system, and confirm that it will not interfere with operations.
Even after that work is completed, the plant may not be able to install the update until the next scheduled outage or maintenance window. Until then, the vulnerability remains, which means some other form of protection is required.
Kiviniemi says this is where support after commissioning becomes critical. Valmet can continue to manage that risk through patch assessment, vulnerability management, monitoring, endpoint protection, and lifecycle support for its automation systems.
“Our system can detect if there is unauthorized access, or for some reason a specific server is starting to communicate with an unknown IP-address and it shouldn’t do that,” says Kiviniemi.
OT/IT integration raises the stakes
Traditionally, automation systems have functioned as isolated, highly secured environments with strict controls preventing any external data exchange. This isolated architecture provided strong protection against cyber threats, but it also meant that data could not move freely into or out of the OT network.
That became a problem as industrial operators began looking for ways to connect production systems with analytics platforms, cloud services, ERP systems, and other business technologies. These connections can provide a much clearer view of plant performance and help operators identify problems earlier. However, they also remove some of the separation that once protected the OT environment.
As a result, the challenge is no longer simply keeping the OT network isolated. It is controlling how operational data moves between OT and IT systems without creating unnecessary risk. This becomes even more important as AI-driven tools enter process automation and place greater demands on the distributed control systems that keep continuous industrial processes running safely and reliably.
With modern automation platforms like Valmet DNAe, cybersecurity is built into the underlying architecture. The platform was developed to support IT/OT convergence, with industrial-standard interfaces and edge technology providing connectivity from field-level sensors through to cloud applications. This allows data to move across the system and supports the use of digital intelligence and AI-based tools at different levels of the operation.
Communication and data management are organized through the Trusted Information Framework, or TIF, which forms the foundation of the Valmet DNAe Distributed Control System. Security measures including authentication, role-based access control, encryption, endpoint protection, and audit trails are incorporated into that framework.
Because these capabilities are part of the original design, the system does not depend on cybersecurity being added later to an architecture that was not built to support it. The security requirements are addressed while the system is being designed, before the major architectural decisions are already fixed.
Valmet’s services are designed to support the entire cybersecurity lifecycle. This includes determining which patches are required for specific automation systems, testing those patches before they are recommended to customers, and supporting deployment when the operating schedule allows. It also includes vulnerability monitoring, antivirus protection, network detection, secure access management, backup and recovery planning, compliance reporting, and periodic testing as long as the system remains in operation.
In addition, Valmet has introduced cybersecurity exercise services that help customers test how well their personnel, procedures, and support model would perform during an incident. In a typical exercise, Valmet works with the customer to create a realistic cyber incident scenario and then walks the customer’s automation, operations, and cybersecurity teams through the response over several hours.
Today, cybersecurity belongs in the earliest project conversations because the decisions made during design will remain with the plant long after commissioning. When those questions are left until the end, the plant may still operate as intended, but securing and maintaining it will usually become more difficult and more expensive.
That problem will only increase as industrial systems become more connected and cybersecurity requirements continue to expand. Cybersecurity is no longer a separate task that can be assigned near the end of engineering. It must be considered as part of the automation system from the beginning and carried through the life of the plant.
For more information about Valmet’s process automation systems, please visit www.valmet.com.