Cybersecurity in industry

Michael

Kölling

CEO

Cybersecurity-Michael-Kölling-iDOOGmbH

Cybersecurity is now a key success factor for digitization and the use of AI in industry. This article outlines regulatory requirements, modern security concepts, and their implementation in connected production environments. Compliance with NIS2 and the Cyber Resilience Act makes cybersecurity a mandatory part of corporate management and requires secure-by-design approaches. Solutions like iDOO enable secure, flexible, and controlled digitization.


Cybersecurity is feasible in industry and the key to successful digitization


Digitization, connectivity, and AI in industry are not only possible, they are a tremendous competitive advantage. However, this is often where progress stalls: “What about cyber security? Won’t we become vulnerable?” The good news: With the right foundations, cybersecurity in industry is very manageable. Modern solutions enable secure networking, data analysis, and AI – not with fear, but with clear rules and technologies.


1. Why cybersecurity is important


Industrial facilities today are highly connected: machines, sensors, edge devices, cloud applications, remote service. This brings great advantages, but also risks:

  • Unauthorized access (e.g., intrusion into machine controls or exposure of sensitive production data)

  • Manipulation of parameters (loss of quality, scrap, possible damage to equipment)

  • Downtime due to ransomware or sabotage

  • Data theft (production recipes, process know-how, customer data)

Especially in critical infrastructures and the manufacturing industry, the consequences are enormous – from production outages to claims for damages.

In Europe, there are also two directives that must be observed:

  • NIS2 Directive: The NIS2 Directive (Network and Information Security 2) is the European legal framework that increases cyber security in key sectors such as energy, transportation, healthcare, and parts of industry. This elevates cyber security from a “nice-to-have” to a non-negotiable element of corporate management.

  • Cyber Resilience Act (CRA): The Cyber Resilience Act (CRA) is a planned EU regulation that sets minimum security requirements for products with digital components, such as IoT devices, software, and industrial control technology. The goal: Products should be “secure by default” and “secure by design.”


2. How cybersecurity can be practically implemented in industry


Cyber security is not an abstract concept, but can be implemented concretely, especially with a clear architectural approach and suitable components.


2.1 Secured remote access and data exchange (e.g., via CRA-Compliant Edge Devices)


A modern approach is to connect production via secure edge devices that act as a central security gateway:

  • Segmentation of the production environment: The OT world (machines, controllers) is clearly separated from the IT and cloud world.

  • Central entry point: All external access and data flows go through an edge device with defined security rules.

  • Encrypted connections: Remote access is via secure protocols, VPNs, or tunneling with strong authentication.

  • Policy-based access: Only defined roles and services are allowed to access certain machines or data.

This enables remote service and data exchange without “uncontrolled opening” of the control level.


2.2 Data sovereignty for the customer: who decides where data goes?


A key success factor for the acceptance of digitization is data sovereignty:

  • The customer decides, which data remains local (e.g., detailed machine data, production recipes), or which data is aggregated and sent externally (e.g., KPIs, OEE, alarms, quality data).

  • Sensitive or personal data can be filtered, anonymized, or transmitted only in aggregated form.

  • Role and rights management determine who can see what and perform which actions.

With a well-thought-out data concept, digitization does not mean loss of control, but becomes a tool that works exactly within the defined framework.


2.3 Cloud or On-Prem? Both can be secure


Many companies ask: “Is the cloud secure enough?”

The reality today: Cloud operation is securely possible if modern security mechanisms are used, such as:

  • encryption (in transit & at rest)

  • identity & access management

  • zero-trust approaches

  • monitoring and auditing

At the same time, on-premise operation (e.g., in your own data center or edge data room) often makes sense, for example with:

  • very strict compliance requirements

  • special latency requirements

  • highly sensitive data

Ideally, a modern platform supports both operating modes or hybrid models, so companies can flexibly determine the degree of outsourcing.


2.4 Security by Design: considering security from the start


Instead of “patching” later, security should be built in from the start: security by design. Typical features include:

  • Secure software architecture (e.g., microservices, clear separation of components)

  • Hardening of systems (only necessary services active, minimizing the attack surface)

  • Standardized protocols (e.g., OPC UA with security profiles for industrial communication)

  • Role concepts and multi-factor authentication

  • Secure update management (signed updates, controlled rollouts)

  • Monitoring and logging of security-relevant events

For industry, this means: The IoT, edge, and remote solutions used already come with a security concept. Operators do not have to start from scratch, but integrate a security architecture that grows with them.


3. Connecting old hardware via connectors – without replacing everything


A common practical problem: Modern machines work alongside older controllers, proprietary protocols, or “black box” systems in production lines. The good news: These systems can also be securely integrated without modernizing the entire line.

Connectors as a Bridge: Specialized software or hardware connectors deployed on edge devices can:

  • speak old protocols (e.g., serial interfaces, proprietary fieldbuses, older controllers),

  • read data locally, preprocess, normalize, and convert it into standardized formats (e.g., OPC UA, MQTT),

  • secure access centrally, even though the connected legacy hardware itself does not have modern security features.

This makes the edge device a secure bridge between the old OT world and the modern IT/cloud world. Production remains as it is but becomes digitally visible and controllable, without being directly exposed.


4. Why the effort is worth it: added value through secure remote access, data & AI


Cyber security requires effort, but the benefits of secure digitization are enormous.


4.1 Secured remote access


  • Faster error analysis and resolution: Service technicians and experts can perform diagnostics via secure access without being on site.

  • Less downtime: Disruptions can be identified and resolved much more quickly.

  • More efficient commissioning and optimization: Parameter adjustments or software updates can be carried out remotely in a controlled and secure manner.


4.2 Better use of data


Secure data streams are the basis for:

  • Transparent production (dashboards, KPIs, OEE, throughput, scrap)

  • Process optimization (e.g., parameter settings, material usage, energy consumption)

  • Automated documentation (e.g., for quality certificates or quality passes)

  • Trend and anomaly detection (e.g., in the production process)

This approach repositions data from a passive operational byproduct to a key driver of business value.


4.3 AI-supported optimization


AI and advanced analytics need data and a secure infrastructure to process this data:

  • Predictive maintenance: detecting anomalies before failures occur

  • Quality forecasts: AI models that identify factors influencing product quality

  • Automatic recommendations for operators or automatic controls

With a clean, secure data foundation, AI applications are used in a targeted and controlled manner – not as experiments, but as industrial tools.


5. What iDOO offers in cybersecurity and how iDOO implements “Secure-by-Design”


iDOO is a B2B SaaS startup of the CiTEX Group and develops data-driven industrial IoT solutions specifically for plastics industry. The goal is to make production processes more efficient, stable, and cost-effective through real-time data analysis.


Secure Industrial IoT and edge solutions: iDOO solutions connect machines via intelligent gateways and edge services that are secure by design from the beginning:

  • Secure connection of machines via standardized industrial protocols (e.g., OPC UA) and intelligent gateways for older protocols

  • Edge services as central security and data nodes – with a focus on protected data connections and continuous monitoring

  • Integration of remote services and real-time data access without exposing the OT world unsecured

Therefore, iDOO does not simply provide data solutions, but also offers a secure infrastructure to collect, analyze, and use production data for service and optimization in a controlled manner.


Data sovereignty and flexible architecture: iDOO’s solutions are designed so that companies:

  • can decide for themselves which data is used and shared,

  • benefit from data-driven optimization without losing control over their production data.


Secure by Design as a Principle: At iDOO, security is not an add-on, but an integral part of the solution design.


Conclusion: cybersecurity is the prerequisite for digitization and AI, not the obstacle


Cybersecurity in industry is not a barrier; it is the essential foundation that enables digitization, connected production, and AI to operate securely and sustainably.

Companies that now rely on secure architectures and “secure-by-design” solutions are creating the basis not only to implement digitization, but to actively use it for their competitive advantage. Cyber security must be considered, but it is feasible – and it opens the way to a connected, intelligent industry.


About

Michael

Kölling

Michael Kölling is the Chief Executive Officer (CEO) at iDOO GmbH, bringing more than 25 years of experience in digital transformation and industrial innovation.