Insights

OT/ICS security: Protecting the factory floor under NIS2

NIS2 is not simply an IT compliance initiative. For manufacturers, it is a catalyst for building resilient, secure, and connected operations that can withstand cyber disruption while supporting continued industrial modernization.

For OT security, NIS2 changes the stakes for covered manufacturers. A cyber incident can do more than compromise data: it can halt production, disrupt supply chains, damage equipment, and endanger safety. NIS2 manufacturing compliance therefore requires operational technology security to become a shared resilience and governance priority. Swedish manufacturers need asset visibility, risk-based segmentation, controlled remote access, OT-aware monitoring, and tested response and recovery plans. Effective OT risk management aligns IT, OT, security, engineering, and leadership around shared risks, accountability, and measurable operational resilience.

Nordic manufacturers increasingly depend on connected production systems, industrial automation, cloud services, remote access, and third-party support to improve efficiency, flexibility, and innovation. This industrial digital transformation also creates new paths into the factory. An incident that begins in corporate IT, a supplier environment, or a remote maintenance connection can move into operational technology (OT), disrupt production, and put safety, quality, and delivery commitments at risk.

The threat is already affecting the sector. ENISA’s Threat Landscape 2025 found that cybercrime accounted for 59.3% of the threat activity affecting manufacturing and was also the leading threat by reported impact. Against this backdrop, OT security under NIS2 is no longer a plant-level technical concern.

Sweden’s Cybersecurity Act, which implements NIS2, took effect on January 15, 2026. Covered manufacturers must now manage risks to the network and information systems supporting their operations, including relevant IT and OT environments. For Swedish manufacturing cybersecurity leaders, NIS2 manufacturing compliance therefore requires stronger governance, clearer accountability, and cyber resilience across the connected factory.

DIVIDER

Why connected OT environments create distinct security risks

OT comprises the hardware and software that monitor or control physical equipment and production processes. Industrial control systems (ICS) coordinate these operations through programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems.

Operational technology security differs from conventional IT security in its priorities and potential consequences. Protecting data remains important, but safety, availability, product quality, and production continuity may take precedence. Many industrial systems remain in service for decades and were designed for reliability, not modern connectivity. Standard IT practices such as active scanning, rapid patching, or device isolation can interrupt production or create safety concerns if they are not adapted to the environment.

Meanwhile, IT/OT convergence, industrial IoT devices, cloud connectivity, and remote maintenance are connecting once-isolated cyber-physical systems to an expanded attack surface. A compromise can disrupt production, damage equipment, create unsafe conditions, reduce output, or affect product quality, not only expose or destroy data. Effective industrial control system security must therefore protect physical operations as well as information while accounting for the safety and availability requirements of the production environment.

DIVIDER

What NIS2 means for industrial organizations

NIS2 does not provide a separate checklist labeled “OT security requirements.” Its cybersecurity risk-management obligations apply to the network and information systems used to provide covered services, including relevant OT environments and dependencies. Not every manufacturer is covered; applicability depends on factors such as sector, subsector, company size, and national legislation. For those within scope, NIS2 compliance for industrial organizations involves five practical obligations.

Cybersecurity risk management

Organizations must address risks across the systems, people, processes, facilities, and dependencies supporting industrial operations.

Incident reporting

A significant incident may require an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Meeting these deadlines requires escalation paths connecting plant operations with security, leadership, legal, and compliance teams.

Supply chain security

Supply chain risk management must include supplier access, equipment vendors, maintenance providers, managed services, software dependencies, and connected products.

Governance and accountability

Management bodies must approve and oversee cybersecurity risk-management measures and receive appropriate training. Leaders need visibility into material OT risks, control gaps, remediation priorities, and readiness.

Business continuity and recovery

Incident handling, backups, disaster recovery, crisis management, and business continuity plans must support the safe and reliable restoration of industrial operations.

Common OT security gaps that undermine NIS2 readiness

Cybersecurity controls are often implemented inconsistently across plants, production lines, suppliers, and legacy systems, creating gaps in OT risk management and operational resilience.

Incomplete OT asset visibility

Unmanaged equipment, outdated inventories, and undocumented connections leave organizations unable to assess what they cannot see. Without OT asset discovery, risk assessments, monitoring, and incident response begin with incomplete information.

Flat or poorly segmented networks

Limited separation between enterprise IT, plant networks, production zones, and critical equipment can allow an attacker to move laterally.

Legacy and difficult-to-patch systems

Unsupported operating systems, proprietary applications, availability requirements, and vendor restrictions can delay remediation.

Insecure remote and third-party access

Shared accounts, permanent connections, weak authentication, and inadequate session controls increase supply chain exposure.

Fragmented IT and OT responsibility

Different tools, terminology, priorities, and reporting structures can create blind spots between IT and OT teams. Shared authority and escalation paths support coordinated incident handling and NIS2 accountability.

DIVIDER

Common OT security gaps that undermine NIS2 readiness

Cybersecurity controls are often implemented inconsistently across plants, production lines, suppliers, and legacy systems, creating gaps in OT risk management and operational resilience.

Incomplete OT asset visibility

Unmanaged equipment, outdated inventories, and undocumented connections leave organizations unable to assess what they cannot see. Without OT asset discovery, risk assessments, monitoring, and incident response begin with incomplete information.

Flat or poorly segmented networks

Limited separation between enterprise IT, plant networks, production zones, and critical equipment can allow an attacker to move laterally.

Legacy and difficult-to-patch systems

Unsupported operating systems, proprietary applications, availability requirements, and vendor restrictions can delay remediation.

Insecure remote and third-party access

Shared accounts, permanent connections, weak authentication, and inadequate session controls increase supply chain exposure.

Fragmented IT and OT responsibility

Different tools, terminology, priorities, and reporting structures can create blind spots between IT and OT teams. Shared authority and escalation paths support coordinated incident handling and NIS2 accountability.

DIVIDER

A practical OT security roadmap for NIS2

A practical roadmap translates NIS2 obligations into controls that reflect operational priorities. Manufacturers can use the following eight steps to strengthen protection while preserving safety and production continuity. The goal is not to deploy controls, but to measurably reduce risk across the industrial environment.

Step 1: Discover and classify OT assets

Create and maintain a continuously updated asset inventory covering hardware, software, firmware, industrial protocols, network connections, ownership, support status, and operational criticality. Use passive OT asset discovery where active scanning could affect sensitive equipment. Then identify the assets, systems, and dependencies supporting essential production processes.

Step 2: Assess operational risk and critical dependencies

Evaluate cyber risk based on potential consequences for safety, production, product quality, the environment, contractual commitments, and recovery, while mapping dependencies across IT, OT, cloud platforms, suppliers, communications, and power. Effective OT risk management prioritizes remediation according to operational consequence rather than vulnerability scores alone.

Step 3: Segment critical environments

Separate enterprise IT from OT and divide industrial networks into appropriate zones and conduits. Permit only required communications and monitor traffic crossing trust boundaries. Segmentation should reflect process dependencies to limit lateral movement without interrupting safe operations.

Step 4: Secure remote and third-party access

Remove unnecessary connections and replace persistent supplier access with controlled, time-limited authorization. Strong remote access security requires individual accounts, multifactor authentication, least privilege, approved devices, and auditable session logs. Define how emergency access is granted, reviewed, and revoked.

Step 5: Strengthen OT monitoring and threat detection

Establish baselines for normal communications, device behavior, and production activity. Use OT-aware industrial threat detection that recognizes industrial protocols. Provide the security operations center with relevant OT context and ensure plant teams understand escalation processes and operational implications.

Step 6: Prepare an OT-specific incident response plan

Define how security, IT, plant operations, engineering, safety, legal, communications, and leadership will coordinate during an incident. Develop and exercise playbooks for ransomware, unauthorized remote access, compromised engineering workstations, production disruption, and affected safety systems. Specify who can isolate equipment or halt production, and the conditions that require those actions.

Step 7: Test recovery and operational continuity

Maintain tested backups of configurations, engineering files, system images, and other resources needed to restore operations. Confirm that equipment and processes can return to a known, safe state, with alternative or manual procedures available during prolonged disruption.

Step 8: Establish governance and compliance evidence

Assign ownership across IT, OT, security, risk, compliance, and plant leadership. Document risk decisions, policies, access reviews, supplier assessments, exercises, control testing, exceptions, and remediation plans. These records create an auditable trail while giving leaders business-level visibility into whether NIS2 manufacturing compliance efforts reduce risk and strengthen operational resilience.

DIVIDER

OT security metrics that measure resilience

NIS2 readiness cannot be assessed by counting deployed tools or completed tasks. Effective OT security metrics should show whether exposure is declining, controls cover critical operations, and the organization can respond and recover safely.

A focused scorecard can measure:

Track these measures over time. For NIS2 manufacturing compliance, progress means demonstrating that operational risk is decreasing and recovery capability is improving, not that more security technology has been deployed.

DIVIDER

How Nordic manufacturers are advancing industrial resilience

Across the Nordic market, emerging cybersecurity priorities reflect a shift toward treating cyber resilience as part of manufacturing modernization. These include shared IT/OT governance, unified IT/OT visibility across plants, risk-based segmentation, least-privilege access, stronger control of vendor connections, and OT-aware security operations. Cyber resilience by design also incorporates security into new plants, production lines, connected products, and automation initiatives. These priorities reflect the region’s emphasis on advanced manufacturing, digitalization, reliability, and business continuity. For Swedish manufacturing cybersecurity leaders, the objective is to protect current operations while creating a secure foundation for continued industrial innovation.

Final thoughts: Resilience beyond compliance

NIS2 compliance cannot be achieved through documentation or security-tool deployment alone. Controls matter only if they reduce the likelihood of production disruption, limit operational consequences, support safe recovery, and give management reliable evidence that risks are being controlled.

Manufacturers that integrate cybersecurity into manufacturing modernization can strengthen continuity without slowing innovation. Embedding security in connected plants, automation initiatives, supplier relationships, and new production capabilities advances industrial resilience and creates a dependable foundation for digital growth. NIS2 is therefore a compliance obligation and an opportunity to strengthen cyber resilience and adopt connected technologies with greater confidence.

DIVIDER

Build a more resilient industrial security strategy

Turning that ambition into action starts with understanding where operational risk exists across the manufacturing environment. UST helps Nordic organizations strengthen OT security, improve operational resilience, and modernize cybersecurity programs for connected industrial operations.

Learn how UST Sweden helps manufacturers secure critical operations and navigate evolving cybersecurity requirements.

Explore UST Sweden

Read UST’s NIS2 is here whitepaper → NIS2 is here

Resources:

FAQs

What is OT security?

Operational technology security protects the systems, networks, and processes that monitor or control physical operations. It prioritizes the safety, availability, integrity, and reliability of industrial machinery and systems, including ICS, SCADA platforms, PLCs, and HMIs.

How does NIS2 impact manufacturers?

NIS2 requires covered manufacturers to strengthen risk management, incident reporting, supply chain security, governance, and operational resilience. Applicability depends on sector, subsector, entity size, and the legislation implementing NIS2 in each country.

Does NIS2 apply to operational technology environments?

Yes. When OT systems support covered services or essential operations, their risks and dependencies fall within the organization’s cybersecurity risk-management responsibilities, including incident response, business continuity, and governance.

What is the difference between IT and OT security?

IT security primarily protects business systems and data, while OT security protects industrial equipment and physical processes. OT environments place greater emphasis on safety, availability, production continuity, and product quality.

What are the biggest OT security risks for manufacturers?

Major OT security risks include ransomware, supply chain attacks, insecure remote access, legacy systems, weak segmentation, insider threats, and incomplete asset visibility.

How can manufacturers improve OT cybersecurity?

Manufacturers should prioritize asset visibility, risk assessment, segmentation, secure remote access, monitoring, incident response, recovery testing, access controls, and governance. An OT cybersecurity strategy should align these measures with operational risk.