Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Mouser, “Industrial Cybersecurity Rapidly Emerges as a Social Responsibility Area in the NIS2 Era”

Google 우선 소스Published2026.04.30 11:46

(Source: Oleksii/stock.adobe.com)

OT security is expanding from a simple IT issue into a social challenge that protects people, facilities, and the economy.
Systematic security strategies such as asset identification, zero trust, and patch management are essential for resilience

Industrial systems are entering a new era where the boundary between the digital and physical worlds is no longer a clear line, but is transforming into a shared vulnerable zone.

As factory, utility, and infrastructure operators adopt more intelligent automation and tighter connectivity, they also face challenges that grow alongside technological advancements.

It is precisely the urgent need to protect the facilities that power modern society.

Environments that previously operated behind closed networks and air-gap systems are now closely connected to cloud platforms, remote sensors, and global data flows, providing opportunities for improved efficiency while simultaneously creating new vulnerabilities that did not exist 10 years ago.

In this environment, cybersecurity is no longer just an issue for the Information Technology (IT) department.

This has established itself as a frontline essential for engineers, operators, and policymakers alike who strive to keep critical infrastructure secure.

The evolution to Industry 5.0 not only emphasizes the values of human-centered design and sustainability but also highlights the need for resilience.

This means that the physical infrastructure of society must now be able to withstand the digital threats surrounding it.

The European Union's NIS2 Directive (Network and Information Security 2) reflects these changes and requires organizations to reconsider their methods of protecting operational technology (OT).

At the same time, it emphasizes that protecting industrial systems is just as essential as maintaining the machinery itself.

Operational Technology (OT) is a technology that deals with actual physical equipment and processes, such as moving water in water treatment facilities, monitoring factory temperatures, and controlling power plant turbines, and is becoming increasingly interconnected.

While such connectivity opens up opportunities to provide efficiency and insights, it simultaneously exposes systems to an increasingly expanding and dangerous digital threat environment.

This article explains why OT cybersecurity has suddenly emerged as a frontline issue, how related regulations are changing, and what engineers and organizations need to do to maintain resilience.

■ The New Reality of Connected Industries

Even 10 years ago, most industrial systems were isolated from the outside world.

The top priority at the time was reliability, not connectivity.

However, Industry 4.0 introduced real-time data sharing between millions of sensors, controllers, and machines.

These changes have enabled companies to reduce waste, optimize productivity, and predict maintenance issues in advance.

However, this rapid expansion came with a hidden price.

Billions of devices designed without security considerations suddenly began to be exposed to the internet..

And the attackers realized this.

According to a recent survey, 62% of water and power operators in the U.S. and the U.K. experienced cyber attacks in 2024, and many incidents went undetected due to a lack of tools or expertise to identify them.

This threat is no longer theoretical, but is already at our doorstep.

Some cases look like a scene from a cyber thriller.

A casino's network was compromised through smart thermometers installed in water tanks.

In another case, a hacker infiltrated the SCADA (Supervisory Control and Data Acquisition) system of a water purification facility and attempted to contaminate the drinking water of a city in Florida.

Such attacks also occurred at the national level.

For example, a cyber attack targeting a steel facility in Iran in 2022 caused a massive fire.

These events demonstrate one clear fact.

The point is that OT cybersecurity is no longer just a matter of protecting data, but is expanding to a matter of protecting people, infrastructure, and even the entire economy.

■ NIS2: Europe’s Response for Stronger Cyber Defense

Recognizing the growing threat, the European Union (EU) expanded the existing NIS1 guidelines into the more comprehensive NIS2 and implemented them in January 2023.

NIS2 covers a much broader scope than previous guidelines.

Various industries, including public communications, wastewater management, manufacturing, transportation, postal services, and space operations, have been subject to stricter cybersecurity requirements.

In addition, medium-sized and large enterprises must strictly comply with the relevant regulations, and if they violate them Significant sanctions may be imposed.

One of the key changes in NIS2 is 'accountability'.

Executives will now bear direct responsibility for the state of cybersecurity preparedness. Companies must be able to demonstrate the following:

o Proactive risk management strategy
o Rapid accident reporting system within 24 hours
o Clear recovery and business continuity plan


In addition, supervision, enforcement, and even peer review mechanisms have been introduced, strongly requiring organizations to actually fulfill these responsibilities.

■ Building Resilience in the Hyper-connected Era

Although NIS2 presents requirements, implementing effective OT cybersecurity requires several key foundational practices that are similar to traditional IT security but not exactly the same.

○ Identifying those subject to protection
Modern industrial sites contain thousands of network-connected devices, many of which are regularly replaced or updated. Maintaining an up-to-date inventory of assets is essential for identifying vulnerabilities and setting protection priorities.

○ Introduction of Zero Trust Principles
Zero Trust is based on the premise that no user or device is trusted by default. Methods such as Multi-Factor Authentication (MFA), secure remote access for maintenance vendors, and detailed logging help prevent unauthorized access.

○ Uninterrupted patch application
Most OT systems operate continuously 24 hours a day. Therefore, it is not always possible to shut down the system for updates. Effective cybersecurity requires a systematic approach that includes pre-planned maintenance times, offline testing, and response procedures in the event of failures.

○ Separation and Isolation
Separating core OT assets from the main network can prevent attackers from lateral movement within the system, a technique commonly used in sophisticated cyber attacks.

○ Continuous monitoring and evaluation
Because threats evolve rapidly, cybersecurity cannot be a one-time activity. Continuous readiness must be maintained through techniques such as risk modeling, simulated attacks, and compliance checks.

○ Strengthening team capabilities
Human error remains one of the biggest vulnerabilities. Regular training, threat awareness programs, and collaboration between IT and OT teams play a crucial role in strengthening an organization's defensive capabilities.

■ The Nature of Risk

Industry 5.0 promises a smarter and more flexible industrial ecosystem, but that promise is bound to collapse without strong cybersecurity to back it up.

As the convergence of OT and IT continues, the risks also expand. Even a single breach can halt production lines, cause environmental damage, and even threaten public health.

The cost of leaving cybersecurity as a retrospective consideration is now too high.

The necessary frameworks and technologies already exist. The success depends on the commitment to continuous improvement, collaboration between organizations, and investment in resilience.

■ Conclusion

Industrial cybersecurity is no longer a simple technical issue but is expanding into the realm of social responsibility.

As we enter the Industry 5.0 era, resilience is establishing itself as a key element of sustainable development.

By understanding the changing threat landscape and adopting guidelines such as NIS2, organizations can protect not only their own operations but also the entire society that depends on them.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자