Discrete and process plants fail differently
Discrete manufacturing builds countable items, and a stopped line usually means lost throughput that can be recovered by running longer. Process manufacturing transforms material continuously, and an unplanned stop can spoil work in progress, require a purge, and take considerably longer to restart than the interruption itself lasted.
That difference should shape the security programme rather than sitting in the background. In a continuous process plant, the cost of a precautionary shutdown triggered by a security finding can exceed the cost of the incident it was guarding against, which raises the bar for any automated action and makes the quality of the evidence behind an alert matter more.
The protocols on a plant floor
Manufacturing networks concentrate on a recognisable set. Profinet dominates in Siemens-based plants and EtherNet/IP with CIP in Rockwell-based ones, both carrying real-time control traffic alongside engineering access. Modbus TCP persists everywhere, usually on older cells and third-party equipment. Siemens S7comm carries engineering operations against S7 controllers. OPC UA appears at the boundary where cells feed data upwards.
CIP Safety deserves separate attention. It carries safety function traffic over the same physical network as standard control traffic, which means safety-related communication and ordinary process communication share a wire and must be distinguished in analysis rather than by segment.
Spharaka Signal decodes all of these at the application layer, which is what allows a write to be evaluated as a process action rather than counted as a session.
- Profinet, in Siemens-based cells
- EtherNet/IP and CIP, in Rockwell-based cells
- CIP Safety, carrying safety functions over the same network as standard traffic
- Modbus TCP, on older cells and third-party equipment
- Siemens S7comm, for engineering operations
- OPC UA, at the boundary where cells report upwards
Cell-to-cell segmentation is the control that matters
The single most effective structural control in a plant is that a compromise in one cell should not become a compromise of the line. Cells map naturally onto IEC 62443 zones, and the links between them onto conduits, which makes manufacturing one of the more straightforward environments in which to apply that model.
The difficulty is drift. Cells acquire connections during commissioning, during a quality project, during a line change, and those connections outlive their purpose. Because the designed diagram is rarely updated, the only reliable statement about segmentation is one derived from observed traffic.
Signal builds the conversation map from what actually crosses the sensors and compares it against the declared zones and conduits, so an unauthorised cell-to-cell path is a finding rather than a discovery made during an incident.
Recipe and logic integrity
In manufacturing, the logic and the parameters are the product. A change to a recipe, a setpoint or a controller program changes what comes off the line, and in regulated manufacturing that has consequences well beyond security.
Signal monitors program logic by hash against a captured baseline, tracks configuration drift, follows firmware versions, and watches controller mode transitions. A move from RUN to PROGRAM outside a maintenance window on a line controller is an alert in its own right; a program hash that changes after it is a critical one.
Correlating those events against declared maintenance windows is what separates an authorised line change from an unauthorised one, which is the distinction quality and security both need and neither can make from the network traffic alone.
The vendor and integrator problem
Manufacturing depends heavily on external parties. Machine builders retain access for warranty support, integrators need it during commissioning, and specialist vendors are the only people who understand a particular cell.
That access is legitimate and cannot simply be removed, which makes visibility the practical control. Signal reconstructs remote access sessions from observed traffic, so vendor connections appear whether or not they were documented, and first-seen geography or off-hours engineering activity on a vendor account is scored against that account's own history.
Where this connects to the wider estate
Manufacturing intrusions rarely begin on the plant floor. They begin with corporate credentials, an engineering laptop that moves between the office network and the cell, or a supplier connection. Findings from Signal pass into Spharaka Sphere and correlate with enterprise telemetry, so the corporate half and the industrial half of an incident are visible as one storyline.
For the broader business view of manufacturing security, including the operational outcomes and deployment model, see the Spharaka manufacturing industry page.
Frequently asked questions
What makes manufacturing OT security different from other sectors?
The cell structure. A plant is a set of production cells with their own controllers, drives, robots and safety functions, which maps unusually cleanly onto zones and conduits. The dominant protocols, Profinet and EtherNet/IP with CIP, are also more concentrated than in utilities, where the protocol estate is broader.
How do you secure a production line without stopping it?
Collect passively. Signal observes mirrored traffic from a SPAN port or tap and never sends anything to a controller, so monitoring can be introduced against live production without a change window. Installing a physical tap does require one, which is why most deployments start on a mirror port.
What is CIP Safety and why does it need separate handling?
CIP Safety carries safety function traffic over the same physical network as standard control traffic. Because safety and ordinary communication share a wire rather than a segment, they have to be distinguished in analysis. Signal decodes it and escalates severity when a safety-relevant register is written from an unexpected source.
How do you tell an authorised line change from an attack?
By correlating the change against declared maintenance windows. A controller moving from RUN to PROGRAM during an approved window with an expected engineering workstation as the source is routine. The same transition at three in the morning from a different zone is not, and the program hash comparison then establishes whether the logic actually changed.
How should vendor and integrator access be handled?
Visibility rather than removal, since the access is genuinely needed. Signal reconstructs remote sessions from observed traffic so undocumented vendor connections appear alongside approved ones, and scores unusual geography or off-hours engineering activity against the account's own history.
Does this replace the manufacturing industry page?
No. This page covers the OT-specific detail: protocols, cell segmentation and logic integrity. The manufacturing industry page covers the business view, including operational outcomes and how Sphere and Signal are deployed together across an industrial group.
Part of the cluster
OT Cybersecurity
The pillar page for operational technology security.