Who should own cybersecurity for MES and shopfloor systems?

In most regulated, brownfield manufacturing environments, no single group can realistically “own” cybersecurity for MES and shopfloor systems end to end. Effective ownership is split across enterprise cybersecurity, IT infrastructure, and manufacturing/OT engineering, with clearly defined responsibilities and governance.

Typical ownership model

A practical and auditable model is:

  • Enterprise / Corporate Cybersecurity (or CISO organization) typically owns:
    • Cybersecurity policies, control framework, and alignment to standards such as IEC 62443 or NIST CSF
    • Risk assessment methods and risk acceptance thresholds for MES and OT assets
    • Security monitoring strategy (SIEM, SOC, incident response playbooks)
    • Vulnerability management process and requirements for patching, hardening, and access control
    • Third-party and remote access requirements for vendors and integrators
  • Manufacturing / OT Engineering (controls, MES, automation engineering) typically owns:
    • Implementation of cybersecurity controls in PLCs, HMIs, SCADA, MES, data collectors, and plant networks within the OT zone
    • Assessment of production and validation impact of patches, configuration changes, and new security tools
    • Lifecycle management of OT assets: obsolescence, compensating controls for unsupported systems, segmentation
    • Change control for MES and shopfloor systems, including testing and documented impact assessments
    • Ensuring cybersecurity changes do not undermine process integrity, traceability, or qualification status
  • IT Infrastructure / ICS Network Team (where it exists) typically owns:
    • Shared infrastructure used by MES: servers, virtual platforms, storage, backup, identity systems, and core network
    • Secure network design for IT/OT boundary, DMZs, remote access, and directory services
    • Implementation of enterprise controls (AV/EDR, logging, certificates) in a way compatible with OT constraints
    • Operational monitoring and incident handling in coordination with the SOC and OT engineering
  • Site Leadership (Plant Manager / Site Director) and Functional Owners should own:
    • Accountability for cyber risk to safety, quality, and production at the site
    • Resourcing for cybersecurity activities (engineering time, maintenance windows, training)
    • Escalation and decision-making when security controls conflict with throughput or schedule

Why single-function ownership usually fails

Placing full ownership with a single function is attractive on paper but usually breaks in practice:

  • Corporate IT / cybersecurity alone typically lacks detailed knowledge of control systems, validation constraints, and the consequences of unplanned downtime. They may push controls that are reasonable for office IT but unsafe or impractical for OT.
  • OT or MES engineering alone often lacks the tooling, threat intel, and enterprise visibility to manage modern cyber threats, and may underestimate business-wide risk or regulatory expectations.
  • Vendor or system integrator ownership introduces dependency and gaps in accountability, especially around cross-vendor integration, legacy systems, and incident response across the plant.

Cybersecurity for MES and OT is inherently cross-functional because security controls directly influence safety, product quality, and regulatory evidence. No single group has all the authority, skills, and visibility needed.

Key elements of a workable ownership model

The central question is not “who owns cybersecurity” in the abstract, but who is accountable for which decisions and activities. A pragmatic approach is to formalize this via RACI or similar.

1. Define a clear RACI for MES and OT cybersecurity

At minimum, define RACI across:

  • Cybersecurity policy and control standards for MES/OT
  • System and network architecture for OT zones and IT/OT boundary
  • Identity and access management for operators, engineers, and vendors
  • Patching and vulnerability management (who decides, who tests, who executes)
  • Secure configuration baselines and hardening (e.g., services, ports, protocols)
  • Monitoring, logging, and incident response, including out-of-hours events
  • Backup, restore, and disaster recovery for MES and critical control systems
  • Change control and validation for security-related changes

The accountable parties will differ by company, but MES and OT leaders should be accountable alongside cybersecurity for decisions that directly affect operations, qualification status, and traceability.

2. Keep brownfield and lifecycle realities front and center

In regulated, long-lifecycle plants:

  • There will be legacy systems that cannot be patched or upgraded without requalification or major downtime.
  • Controls like aggressive patch cycles, intrusive endpoint agents, or frequent reboots may be incompatible with validated MES instances or 24/7 lines.
  • Vendor support, integrator customizations, and historical workarounds often limit what can be changed quickly.

Ownership therefore needs to include explicit responsibility for designing and documenting compensating controls: segmentation, unidirectional gateways where feasible, tight remote-access control, enhanced monitoring, and procedural controls around media handling and configuration.

3. Align ownership with change control and validation

Cybersecurity-related changes to MES and shopfloor systems frequently trigger:

  • Formal change control and impact assessment
  • Regression testing and re-execution of validation or qualification scripts
  • Updates to SOPs, work instructions, and training materials

As a result:

  • Manufacturing / OT engineering usually owns the technical implementation within the validated system boundary and is responsible for ensuring that changes are tested and documented.
  • Quality / validation functions own decisions about what level of testing and documentation is required for compliance and product quality.
  • Cybersecurity owns the requirement that certain controls must exist and must generate evidence (logs, reports) but should not bypass validation or plant change control to enforce them.

4. Separate standard setting from execution

A useful pattern is to separate:

  • Standard setting: enterprise cybersecurity defines baseline controls, network zones, access requirements, and logging standards that apply to MES and OT, with input from OT engineering and quality.
  • Execution and adaptation: OT engineering and site IT teams translate those standards into feasible configurations for specific plants, lines, and MES instances, documenting any deviations and compensating controls.

This ensures cybersecurity retains strategic ownership of risk posture while the shopfloor functions own operational feasibility.

5. Make a site-level risk owner explicit

Even with a distributed model, there should be a clear site-level risk owner for MES and OT cyber incidents, typically the Plant Manager or Site Director with support from Operations, Quality, and EHS leadership. This role is accountable for:

  • Accepting or rejecting cyber risk that affects production, safety, or quality at the site
  • Prioritizing remediation work relative to other plant initiatives
  • Coordinating with corporate cybersecurity in incident response and recovery

Tradeoffs to acknowledge

Any ownership model for MES and shopfloor cybersecurity must navigate several tradeoffs:

  • Security vs uptime: Stronger controls (e.g., strict patch SLAs) may conflict with availability requirements and limited shutdown windows.
  • Security vs validation burden: Frequent technical changes can increase revalidation overhead and documentation load on quality and engineering teams.
  • Centralization vs local autonomy: Central ownership can standardize controls but may not account for plant-specific constraints; local ownership can adapt but risks fragmentation and inconsistent risk treatment.
  • Maturity and staffing: Smaller or less mature sites may not have dedicated OT security specialists, which increases the need for clear guidance and support from corporate cybersecurity and IT.

Because of these tradeoffs, trying to “solve” ownership purely through reorganization or by assigning everything to a single function rarely works. A pragmatic, cross-functional RACI with enforced change control, documented deviations, and shared accountability is more robust in real plants.

Content classification

Visible verification fields for authorship, dates, taxonomy, and ST assignments.

Published:

Updated:

Tags:

FAQ category:

FAQ tag:

Glossary category:

Glossary tag:

Colour:

Content type:

Location:

Audience:

Intent:

Dev-only relationship debug

Content relationships

Rendered from saved content and bridge metadata. Nothing in this panel writes back to WordPress.

Inline glossary links

No inline glossary links found in saved content.

Attached glossary terms

No glossary bridge terms attached.

Attached FAQs

No FAQ bridge items attached.

Diagnostics

Inline glossary links
0
Attached glossary terms
0
Attached FAQs
0
  • No glossary or FAQ relationships found for this item.