Why Cybersecurity Must be Part of Your Safety Plan

Safety Rockwell

May 5, 2020

By Steve Ludwig

The dangers that cyber threats pose to intellectual property, customer records and productivity are well known, but less discussed are the safety implications of these threats. A cyberattack on your industrial control system (ICS) can damage physical assets, alter recipes, injure workers or cause severe environmental damage.

If you’re on a digital transformation journey — whether it’s a managed process or slow evolution — managing the inherent safety and security risks should be an integral part of the process.

A properly designed security approach will improve information collection, analysis and delivery. It will minimize security-related interruptions and frustrations. And it will help protect your enterprise.

Know your risks

Today, both security and safety standards already recognize the link between safety and security risks.

Cybersecurity standard ISA/IEC 62443-1-1 mentions that security breaches can have consequences beyond compromised information. The standard states: “The potential loss of life or production, environmental damage, regulatory violation and compromise to operational safety are far more serious consequences. These may have ramifications beyond the targeted organization; they may grievously damage the infrastructure of the host region or nation.”

Functional safety standard IEC 61508-1 specifies that hazards associated with equipment and control systems must be determined under all reasonably foreseeable circumstances. The standard says: “This shall include all relevant human factor issues and shall give particular attention to abnormal or infrequent modes of operation of the EUC. If the hazard analysis identifies that malevolent or unauthorized action, constituting a security threat, as being reasonably foreseeable, then a security threats analysis should be carried out.”

Security, like safety, approaches issues based on managing risk, leveraging continuous assessment and baselining to ensure you are managing to a risk threshold. Your level of acceptable risk will vary by industry and potential outcomes.

Considering that most cybersecurity attacks are based on the attacker simply finding a vulnerable target — rather than being specifically targeted due to industry or prominence — a cybersecurity attack is a foreseeable circumstance in virtually every industry. Assessing your cybersecurity risks, determining your level of acceptable risk and mitigating identified risks to an acceptable level are now the basic “reasonable” steps to help protect people from foreseeable misuse and malevolent or unauthorized actions.

As with safety, ignoring cybersecurity and associated risks is the mistaken belief that “if I don’t know about the risk, I can’t be held accountable.” That’s not an acceptable posture, ethically or for compliance purposes, especially when lives are on the line.

Address risks together

Some have used the risks that connected technologies can introduce as an argument against modernization. But, it’s important to recognize that doing nothing is not a solution. Maintaining legacy systems too long not only deprives you of valuable insights and other IIoT benefits, but these systems also often lack the security measures of contemporary systems making them more vulnerable rather than less.

The better approach is to make the most of digital transformation, while helping protect safety and security as part of the process. As you do this, keep some key things in mind.

For example, many security practices have long been used in the IT world, but they’re new to the OT world. And, while many of the mitigation steps are similar in comparison, they’re applied very differently in the front office than on the plant floor.

In a manufacturing environment, cybersecurity and safety risks should both be part of risk management and part of the management of change (MOC) process. And EHS professionals should be involved in managing processes and compliance with standards and laws.

It’s a new age in industry. The advantages of Industry 4.0 certainly outweigh the increased risks. And by understanding the risks and mitigating them as part of your digital initiatives, you can expand what’s possible in your operations while helping protect what matters most to you.

Learn more about industrial security.

Steve Ludwig is Commercial Programs Manager, Safety, Rockwell Automation. Rockwell Automation is a founding member of the ISA Global Cybersecurity Alliance and has received multiple ISA/IEC 62443 certifications.

Related Articles


Latest Articles

  • ABB Wins New Product Award at MCEE Show

    ABB Wins New Product Award at MCEE Show

    April 28, 2025 ReliaHome™ Smart Panel won Best New Product Award in the Software, Controls and Related Components category. Iberville® Gangable boxes with low-voltage cables support bracket was recognized as a finalist in the Commercial, Institutional and Industrial Electrical Products category. ABB was honored with a Best New Product Award in the Software, Controls and… Read More…

  • Weidmuller Celebrating a Legacy: 175 Years Globally, 50 Years in Canada

    Weidmuller Celebrating a Legacy: 175 Years Globally, 50 Years in Canada

    April 28, 2025 The year 2025 is truly special for Weidmüller. The company proudly celebrates not just 50 remarkable years in Canada but also its 175th anniversary globally—an extraordinary achievement few companies can claim. This legacy is a testament to the company’s relentless pursuit of innovation and commitment to refining its offerings. But the journey… Read More…

  • Canada Stands Tall at Hannover Messe 2025

    Canada Stands Tall at Hannover Messe 2025

    April 28, 2025 By Owen Hurst At Hannover Messe earlier this month Canada had a strong presence as the host country with a wide variety of companies and programs focusing on the development of advance technology. The presence was accentuated by numerous halls hosting Canada pavilions. Partner Country Canada presented itself impressively at HANNOVER MESSE…. Read More…

  • BC Prompt Payment Legislation Progressing

    BC Prompt Payment Legislation Progressing

    April 28, 2025 Consistent with its mandate of growing the economy, the government wants to ensure that businesses are paid promptly for work performed on (or material provided to) construction projects. British Columbia’s Ministry of Attorney General staff have been tracking the issue of payment delay in the construction industry, including legislative responses in other… Read More…


Changing Scene

  • Schneider Electric Advances in Product Environmental Data Transparency

    Schneider Electric Advances in Product Environmental Data Transparency

    April 28, 2025 Schneider Electric has launched its Environmental Data Program. This initiative, which builds on the legacy Green Premium label, provides customers with unique access to information on the environmental impact of its products, enabling them to make better informed, data-based decisions and meet evolving regulatory requirements with confidence. Schneider Electric has frequently been recognized… Read More…

  • nVent Sustainability Report Highlights Progress and Focus on Electrification

    nVent Sustainability Report Highlights Progress and Focus on Electrification

    April 15, 2025 nVent Electric plc announced the release of its 2024 Sustainability Report. The new report highlights nVent’s achievements in each of its sustainability focus areas: People, Products, Planet and Governance. The report also highlights how nVent solutions support electrification, digitalization and sustainability efforts around the world. “nVent is becoming a more focused electrical… Read More…

  • Ontario Introduces Legistlation to Unlock Trade and Labour Mobility Within Canada

    Ontario Introduces Legistlation to Unlock Trade and Labour Mobility Within Canada

    April 18, 2025 As a next step in its plan to protect Ontario by unleashing the province’s economy, the Ontario government is introducing the Protect Ontario through Free Trade within Canada Act to unlock free trade and labour mobility within Canada. This legislation will, if passed, create new opportunities for job creation and investment attraction, supporting economic… Read More…

  • Ontario, P.E.I. Join Nova Scotia With Legislation to Remove Internal Trade Barriers

    Ontario, P.E.I. Join Nova Scotia With Legislation to Remove Internal Trade Barriers

    April 18, 2025 Prince Edward Island and Ontario have joined the Nova Scotia by introducing reciprocal legislation that will help foster an environment of mutual recognition of goods, services and labour mobility between these provinces. “Leaders across the country are expressing interest in removing trade barriers, and I’m very pleased that P.E.I. and Ontario have… Read More…