Request Demo

The New EU Machinery Regulation – or Why Many Manufacturers Are Asking the Wrong Question

The new EU Machinery Regulation puts cybersecurity higher on the agenda for manufacturers. This article explains why securing the machine itself is no longer enough and why security-relevant data must be protected throughout its entire lifecycle.

Last month, I had my first in-depth encounter with the new EU Machinery Regulation at the TeleTrusT conference. My initial thought was probably the same as that of many others: *Cybersecurity is finally becoming a regulatory requirement in the manufacturing industry!* However, the more I looked into the regulation, the more I realized that it should by no means be treated as just another compliance project. Its requirements also need to be considered throughout the machine’s entire operational lifecycle.

Let’s do a quick thought experiment: Take any machine and try to list all the places where information about it is stored—not just within the machine itself, but throughout its entire lifecycle. There are CAD drawings, PLC projects, configuration files, recipes, calibration parameters, firmware, service documentation, and backups. Today, this information is stored in PLM systems, file servers, SharePoint, Microsoft 365, or cloud platforms used to collaborate with customers and service partners. And it does not stay exclusively in one place: It is versioned, archived, backed up, replicated, and shared with suppliers, system integrators, maintenance providers, machine manufacturers, and other company locations. As development, production, and service processes become increasingly digital, this ecosystem continues to grow. So the question is no longer *whether* security-relevant machine data leaves the machine, but *when*, *where it goes*, and *who ultimately has access to it*.

From my perspective, this means we need to expand the scope of protection. In most cases, the machine itself is already secured very carefully. The data that describes its configuration, behavior, or even its safety functions, however, regularly leaves the machine’s immediate security perimeter to enable modern production processes. A successful attack therefore does not necessarily have to target the machine itself. It may be enough to manipulate engineering data before it is loaded back into the machine, replace safety parameters, or access confidential documentation that could reveal information about its security mechanisms. With every additional data interface, the attack surface grows—not because the machine itself has become less secure, but because more and more of its security-relevant information is being processed outside the machine.

The authors of the Machinery Regulation are aware of this as well. This is likely why the regulation does not mandate encryption or prescribe specific technologies. Instead, it requires manufacturers to consider cyberattacks against safety-relevant hardware and software as part of their risk assessment and to derive appropriate technical measures from that assessment. This means that, as part of their risk assessment, manufacturers and operators need to consider which data is security-relevant and therefore requires protection, where it is stored, where it is transferred, and who can access it remotely. I suspect that simply answering these questions systematically would already lead to some surprising insights for many organizations. And this is where encryption naturally becomes relevant again—not because it is explicitly required by the regulation, but because it is an obvious way to protect data even when it leaves the machine’s immediate security perimeter and moves into collaboration platforms, cloud services, or the hands of external partners.

From my perspective, the Machinery Regulation should therefore be seen as an opportunity to map your data flows and take a closer look at which information is actually security-critical, how it moves throughout the organization and beyond, and which protective measures are appropriate at each stage. Machines are increasingly becoming part of digital ecosystems, which means their data is also becoming a security-relevant component of the production chain.

At eperi, we have been addressing this question for more than two decades: How can sensitive data be protected regardless of where it is stored, processed, or who it is shared with? If you would like to discuss this topic with us, please feel free to contact us.

Did you like this article?


Then like it now or share it with colleagues, business partners, and friends.

Email
Facebook
LinkedIn
X

Knowledge that protects – your next step toward greater data security

On our download page, you will find free white papers and fact sheets on data protection, data encryption, and compliance – specifically for IT managers and decision-makers.

Get concise knowledge, strategic recommendations, and practical tips to effectively protect your data and securely comply with regulatory requirements such as GDPR, NIS2, and DORA.