Industrial cybersecurity has become a strategic priority for machinery manufacturers. In this context, B&R Industrial Automation, technology partner of Barcelona Packaging Hub, shares its perspective on the new regulatory landscape and the key elements companies must consider to adapt their designs and processes to new requirements.
The regulatory shift that cannot be ignored
The rules of the game in machinery manufacturing are undergoing a structural change. With the entry into force of NIS2 and the Cyber Resilience Act (CRA), industrial cybersecurity is no longer a discretionary technical decision but a binding legal requirement. Machines that do not comply with these standards will not be allowed to enter the European Union market, and manufacturers who fail to adapt will face significant civil, criminal, and commercial liabilities.
While regulation is not new to the industry, its scope in cybersecurity certainly is. For the first time, the machine builder is responsible for ensuring that the product placed on the market is secure throughout its entire lifecycle, not only at the time of delivery.
Technical debt: the hidden cost of inaction
In software engineering, the concept of technical debt is well known. It arises when short-term design decisions are taken to save time or cost, but generate increasing future expenses in the form of corrections, redesigns, and vulnerabilities. In industrial cybersecurity, this phenomenon is equally real, and its consequences can be even more critical. Technical debt in cybersecurity cannot be repaid with a patch; it requires a redesign. And that redesign, when performed retrospectively, is always more expensive, slower, and more disruptive than doing it correctly from the start.
Want to stay updated on the latest in the packaging sector? Subscribe to our newsletter!
When standard technology is not enough
One of the major challenges in the sector is recognising that some of the most widely used and established industrial automation technologies were not designed with cybersecurity in mind. Communication protocols and fieldbuses do not include fundamental mechanisms such as device authentication, role-based access control, or encrypted communication. These are robust technologies, widely deployed and well understood by engineers, but they were designed in an era when industrial networks were closed and isolated environments.
Relying on the assumption that an industrial network is secure because “it has always worked this way” is precisely the type of reasoning that creates technical debt and that new regulations aim to eliminate.
The impact is tangible: when a rigorous risk analysis is carried out on a typical machine architecture based on IEC 62443, it is common to identify clear attack vectors in components that have been in production for years without scrutiny. The visibility provided by this analysis can be uncomfortable, but it is essential.
The future of industrial protocols
The evolution of industrial protocols is not a hypothesis; it is an ongoing trend. Standardisation bodies such as the International Electrotechnical Commission, the OPC Foundation, and the industry itself are pushing towards protocols that embed native encryption, mutual authentication, and certificate management as core features rather than optional add-ons. OPC UA, with its security profiles, is one of the clearest examples, but not the only one. The zone and conduit model defined in IEC 62443, which structures how networks are segmented and how communication flows between zones of different trust levels are controlled, is now the most solid methodological framework for managing this transition in an orderly and auditable way.
B&R approach: secure by design as a starting point
B&R is integrating the principle of “secure by design” into the core of its product and solution architecture. This does not mean adding security layers on top of existing systems, but rather starting from an architecture where security is an inherent design attribute: user and device authentication, encrypted communications, certificate management, and secure firmware and software updates are built-in features, not optional extras.
This approach is aligned with CRA requirements and with the security levels defined in IEC 62443, enabling machine builders using B&R technology to rely on a solid technical foundation for compliance. However, technology alone is not enough. Manufacturers also need the methodological knowledge to document, justify, and demonstrate compliance to customers and regulatory bodies. It is not sufficient to use the right product; its correct application must also be properly justified.
Two webinars to address the challenge with methodology
To support machine builders, engineering companies, and system integrators in this transition, B&R is hosting two dedicated webinars on 20 and 27 May.
The first session, on 20 May, focuses on regulation. It will provide a detailed analysis of the CRA: its requirements, scope, timelines, and how manufacturers can rely on secure design principles to address compliance step by step.
The second session, on 27 May, takes a practical approach. It focuses on risk analysis methodology based on IEC 62443, covering threat identification, vulnerability assessment, and the design of effective countermeasures. It also introduces the documentation of zones and conduits as the foundational step for building a secure and auditable architecture. Participants will gain a replicable method that can be directly applied to their own projects.
Beyond compliance
The question machine manufacturers must ask today is not whether they will need to address industrial cybersecurity, but how to start and structure the process in a way that ensures long-term stability and confidence.
B&R provides the sector with technology, knowledge, and methodology to ensure this process is structured, documented, and aligned with current regulations. The webinars on 20 and 27 May are the first step. For more information, visit: Update Talks Spain | B&R Industrial Automation
Ciberseguridad industrial como eje estratégico del ecosistema
At Barcelona Packaging Hub, industrial cybersecurity is understood as a structural pillar for both the present and future of the packaging sector. It is not only about regulatory compliance, but about designing machines and architectures ready for a connected, demanding, and regulated environment.
Embedding industrial cybersecurity from the design phase enhances competitiveness, strengthens market trust, and ensures the long-term technological sustainability of industrial projects.
If you would like to explore how to address this challenge within your organisation, please contact the Barcelona Packaging Hub team.