Cyber security for manufacturing in the UAE
Production cannot stop for a patch, and the control network was never built to be watched. We bring the plant floor into visibility without touching what is running, and hold the IT and OT sides to the tolerances each of them actually has.

On a plant floor, the safe action and the secure action are not always the same
In an office estate, isolating a suspect machine is uncontroversial. On a production line the same action can stop a batch, spoil material or create a safety condition. The control system was designed for determinism and uptime, not for the kind of interruption security tooling takes for granted.
The equipment reflects that. Controllers and interfaces are specified for a working life of fifteen or twenty years, run software that stopped being supported long ago, and frequently cannot be changed at all without requalifying the process. Patching is not deferred out of negligence. It is deferred because the change carries more risk than the vulnerability.
Meanwhile the two worlds have been quietly joining for a decade. Production data feeds corporate reporting, vendors hold remote access for maintenance, and engineering laptops move between both networks. The boundary that exists on the architecture diagram is usually more porous in the routing table, and that gap is how ransomware reaches a line.
The work that pays is therefore structural: know exactly what is on the control network, decide what may cross the boundary, and watch it passively. Containment first, hardening only where it is genuinely safe.
What actually reaches a production environment
Very little of it targets the plant directly. Most of it arrives from the corporate side and crosses a boundary that was weaker than assumed.
What a manufacturing security programme has to work around
Four conditions that decide whether a control can be used on a live line.
The services behind a manufacturing security programme
Designed so the plant is watched without anything being installed on equipment that cannot take it.
What a UAE manufacturer works to
Manufacturing is governed less by a single regulator and more by standards, customer requirements and, for critical sectors, national obligations.
IEC 62443
The international standard for industrial automation and control system security. Its zones and conduits model is the practical basis for segmenting a plant, and its security levels give a defensible target per zone.
UAE Information Assurance Standards
Applies to the corporate estate and, for operators considered critical infrastructure, to the wider environment. Logging, access control and incident response are examined first.
Customer and supply chain requirements
Large customers increasingly impose security conditions through contracts and audits, particularly in automotive, aerospace, pharmaceutical and food production. These often arrive before any regulator does.
ISO 27001
Commonly used as the management system wrapper around all of the above, and frequently the certification a customer actually asks to see.
How an engagement with a manufacturer runs
Before anything is connected we establish which systems are safety related, which cannot tolerate any probing, who authorises an action that could affect production, and what the change window calendar looks like.
- Safety related systems named and fenced off
- Passive only collection agreed for the control network
- Operational authority named for anything that could stop a line
Passive discovery establishes what is actually on the plant network, which is invariably more than the drawings show, and reveals where corporate and production genuinely touch.
- Devices discovered without being probed
- Real IT to OT crossings found in traffic, not on the diagram
- Vendor remote access paths identified
The plant is divided by function and criticality and the crossings are controlled. Most of this can be staged without a production stop, and what cannot is sequenced into a planned shutdown.
- Zones and conduits defined against IEC 62443
- Work sequenced around existing change windows
- Dual homed machines removed or properly controlled
Monitoring covers IT and OT with separate rules, separate severities and separate permitted actions, and reporting shows both to the people accountable for each.
- Separate response rules for corporate and production
- Detections tuned against your own plant traffic
- Evidence assembled for customer audits and certification
Manufacturing security questions
The priorities invert. IT protects confidentiality first and can usually accept a short outage to do it. OT protects availability and safety first, and an unplanned stop has a direct cost and sometimes a physical consequence. A control that is routine in IT, such as pushing an agent or forcing a reboot, can be unacceptable on a production line. The two need separate designs, separate tolerances and a boundary between them.
Yes, and that is the normal approach. Collection on the control network is passive: we watch traffic rather than install anything on a PLC or an HMI. That gives an accurate picture of what is communicating with what, and it changes nothing on the equipment, so no vendor agreement is affected and no process is put at risk.
It is the international standard for industrial automation and control system security, and its most useful idea is zones and conduits: dividing the plant into zones by function and criticality, and controlling precisely what may pass between them. Most practical improvement on a manufacturing estate comes from applying that idea rather than from buying detection.
They are contained rather than patched. A machine controller running an operating system that stopped receiving updates a decade ago is normal and often cannot be changed without requalifying the process. It is placed in a zone that limits what it can reach and what can reach it, and its traffic is watched for change. The aim is to make a compromise survivable rather than impossible.
Almost always through the corporate side and then across a boundary that turned out to be weaker than the diagram suggested. Common routes are a flat link left from a reporting integration, an engineering laptop that moves between both networks, and remote access installed by an equipment vendor for maintenance. Segmentation and control of vendor access address more risk here than any product.
We have to. Vendors frequently hold permanent remote access for maintenance and support, which is one of the most direct routes into a plant network. We bring that access into monitoring, scope it to what the vendor genuinely needs, and make it time bound rather than standing where the contract allows.