SUBSCRIBE NOW
IN THIS ISSUE
PIPELINE RESOURCES
ISHG Releases Joint Industry Perspective

Why Secure Industrial Communication Depends on Deployment as well as Protocols

Joint Industry Perspective from the Industrial Security Harmonization Group

The Industrial Security Harmonization Group announced the release of a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

The ISHG—comprising leading industry organizations including the FieldComm Group, ODVA, OPC Foundation, and PROFIBUS & PROFINET International—collaborates regularly to align security concepts across Ethernet and non-Ethernet communication protocol technologies. Their shared mission is to reduce complexity for end users and promote consistent, effective cybersecurity practices in industrial automation systems.

Industrial communication protocols serve as the backbone of modern automation, enabling seamless connectivity between devices, systems, and applications across both process and factory environments. However, many widely used protocols were originally developed without cybersecurity as a primary design consideration.

The ISHG’s joint work challenges the simplistic binary classification of protocols as “secure” or “insecure.” Instead, it emphasizes a more practical and realistic approach:
  • Security is context-dependent — It relies on how protocols are configured, where they are deployed, and the surrounding operational environment.
  • Built-in security features are not sufficient alone — Even advanced protocols require correct implementation and maintenance.
  • Compensating controls are essential — Network architecture, segmentation (zones and conduits), monitoring, and physical safeguards play a critical role, especially for legacy and non-Ethernet systems.
  • This deployment-focused perspective aligns closely with emerging regulatory expectations, including those outlined in the EU Cyber Resilience Act (CRA) for hardware and software products and NIS2 for entities and organizations for operations.
Source: Industrial Security Harmonization Group media announcement
FEATURED SPONSOR:

Latest Updates





Subscribe to our YouTube Channel