Why Cybersecurity Must be Part of Your Safety Plan

Safety Rockwell

May 5, 2020

By Steve Ludwig

The dangers that cyber threats pose to intellectual property, customer records and productivity are well known, but less discussed are the safety implications of these threats. A cyberattack on your industrial control system (ICS) can damage physical assets, alter recipes, injure workers or cause severe environmental damage.

If you’re on a digital transformation journey — whether it’s a managed process or slow evolution — managing the inherent safety and security risks should be an integral part of the process.

A properly designed security approach will improve information collection, analysis and delivery. It will minimize security-related interruptions and frustrations. And it will help protect your enterprise.

Know your risks

Today, both security and safety standards already recognize the link between safety and security risks.

Cybersecurity standard ISA/IEC 62443-1-1 mentions that security breaches can have consequences beyond compromised information. The standard states: “The potential loss of life or production, environmental damage, regulatory violation and compromise to operational safety are far more serious consequences. These may have ramifications beyond the targeted organization; they may grievously damage the infrastructure of the host region or nation.”

Functional safety standard IEC 61508-1 specifies that hazards associated with equipment and control systems must be determined under all reasonably foreseeable circumstances. The standard says: “This shall include all relevant human factor issues and shall give particular attention to abnormal or infrequent modes of operation of the EUC. If the hazard analysis identifies that malevolent or unauthorized action, constituting a security threat, as being reasonably foreseeable, then a security threats analysis should be carried out.”

Security, like safety, approaches issues based on managing risk, leveraging continuous assessment and baselining to ensure you are managing to a risk threshold. Your level of acceptable risk will vary by industry and potential outcomes.

Considering that most cybersecurity attacks are based on the attacker simply finding a vulnerable target — rather than being specifically targeted due to industry or prominence — a cybersecurity attack is a foreseeable circumstance in virtually every industry. Assessing your cybersecurity risks, determining your level of acceptable risk and mitigating identified risks to an acceptable level are now the basic “reasonable” steps to help protect people from foreseeable misuse and malevolent or unauthorized actions.

As with safety, ignoring cybersecurity and associated risks is the mistaken belief that “if I don’t know about the risk, I can’t be held accountable.” That’s not an acceptable posture, ethically or for compliance purposes, especially when lives are on the line.

Address risks together

Some have used the risks that connected technologies can introduce as an argument against modernization. But, it’s important to recognize that doing nothing is not a solution. Maintaining legacy systems too long not only deprives you of valuable insights and other IIoT benefits, but these systems also often lack the security measures of contemporary systems making them more vulnerable rather than less.

The better approach is to make the most of digital transformation, while helping protect safety and security as part of the process. As you do this, keep some key things in mind.

For example, many security practices have long been used in the IT world, but they’re new to the OT world. And, while many of the mitigation steps are similar in comparison, they’re applied very differently in the front office than on the plant floor.

In a manufacturing environment, cybersecurity and safety risks should both be part of risk management and part of the management of change (MOC) process. And EHS professionals should be involved in managing processes and compliance with standards and laws.

It’s a new age in industry. The advantages of Industry 4.0 certainly outweigh the increased risks. And by understanding the risks and mitigating them as part of your digital initiatives, you can expand what’s possible in your operations while helping protect what matters most to you.

Learn more about industrial security.

Steve Ludwig is Commercial Programs Manager, Safety, Rockwell Automation. Rockwell Automation is a founding member of the ISA Global Cybersecurity Alliance and has received multiple ISA/IEC 62443 certifications.

Related Articles


Latest Articles

  • ANNQUAN Brand Power Strips Recalled Due to Fire Hazard

    ANNQUAN Brand Power Strips Recalled Due to Fire Hazard

    January 23, 2026 Summary Affected products This recall involves ANNQUAN-branded power strips models EX-D112-05 and EX-D106-25. Power strip model EX-D112-05 has a black metal enclosure with 12 receptacles made of yellow plastic. There is one on/off switch located at the end of the housing closest to the power cord. Power strip model EX-D106-25 has a yellow Read More…

  • Lighting Case Study: The Historic Congregation Emanu-El

    Lighting Case Study: The Historic Congregation Emanu-El

    January 23, 2026 By Mac’s II Agencies Nestled in the heart of Victoria, the historic Congregation Emanu-El presented a unique opportunity for Mac’s II Agencies to craft a lighting experience that enhances worship while respecting the architectural heritage of the space. True to our “Design, Supply, Support” approach, we led the project from design concept Read More…

  • Electrical Permit Requirements for Alarm System and Voice, Data, Video Installations

    Electrical Permit Requirements for Alarm System and Voice, Data, Video Installations

    January 19, 2026 Other than the exceptions listed below, electrical permits and inspections are required for all electrical work involved in the installation of intrusion and similar alarm systems in all structures. Electrical permits and inspections ensure that low -voltage systems are installed safely and in compliance with Code requirements. A permit and inspections must Read More…

  • The Role of Lighting in the AI-Powered Home

    The Role of Lighting in the AI-Powered Home

    January 14, 2026 Elizabeth Parks, President and CMO of Parks Associates, joins Derek Richardson, Founder and CEO of Deako, for a wide-ranging conversation on how lighting is becoming a core layer of the intelligent home. The discussion explores how Deako’s plug-and-play lighting approach is removing long-standing barriers to adoption by simplifying installation, reducing costs, and Read More…


Changing Scene

  • New Skills Program to Help Veterans Build Construction Careers in Nova Scotia

    New Skills Program to Help Veterans Build Construction Careers in Nova Scotia

    January 23, 2026 The Province is helping Canadian Armed Forces veterans, reservists and their family members transition to construction careers. The assistance is through the new Skills Bridge initiative that will support up to 100 people over the next three years. The program, funded by the Province and delivered by the non-profit organization Helmets to Read More…

  • Renewed Funding to Support Skills Training and Employment for Indigenous Peoples in PEI

    Renewed Funding to Support Skills Training and Employment for Indigenous Peoples in PEI

    January 23, 2026 The provincial government has renewed a four-year funding agreement with the Mi’kmaq Confederacy of PEI for programs that help the Mi’kmaq and Indigenous community in PEI to gain valuable employment and mentorship experiences.  A total of $1.67M in funding through SkillsPEI will support 144 Indigenous participants in two separate programs. The project-based Read More…

  • NSI Industries Announces Transition of Remke® CordGrips and Connectors into Bridgeport® Brand Portfolio

    NSI Industries Announces Transition of Remke® CordGrips and Connectors into Bridgeport® Brand Portfolio

    January 23, 2026 NSI Industries today announced that effective January 1, 2026, the Remke® product line of cord grips and connectors has officially transitioned into the Bridgeport® brand. This strategic move unites two trusted names in electrical fittings under one brand identity, giving distributors and contractors a stronger, more complete product offering. “This transition is Read More…

  • Skilled Trades Ontario to Deliver Certifying Exams In-House

    Skilled Trades Ontario to Deliver Certifying Exams In-House

    January 23, 2026 Skilled Trades Ontario (STO) is taking a major step to strengthen how certifying exams are delivered across the province. “We’ve heard the feedback loud and clear. Apprentices and employer sponsors told us they want increased capacity and a reliable, streamlined exam experience. And that’s exactly why we’re making this change,” said Candice Read More…