Skip
Ready for the SPS 2026? Get your ticket now!

Experience SPS 2026 live and secure your ticket at the early bird rate until 12 October.

We also offer special deals for travel and accommodation. Find all travel specials on our website.

Compliance does not guarantee cyber resilience

28 Sep 2026

Cyber security has become one of the most audited and regulated areas of enterprise technology. According to Howden’s cyber exposure report, the UK was the most-attacked country in Europe in 2026 and the two most targeted industries were construction and engineering. Notable cyber-attacks in the last year or so include those on engineering contractor Morrisroe, the Construction Industry Council and Bouygues UK.

Image source: Phoenix Contact // Safe and Secure
Image source: Phoenix Contact // Safe and Secure

Our colleagues at the UK publication Smart Machines and Factories have published an article explaining that simply passing an audit or achieving certification is not the same as proving that systems, people and processes can withstand a genuine outage or cyber incident. 

The Machinery Regulations, along with the CRA (Cyber Resilience Act) will come into effect next year. The question is, are you ready? The CRA introduces mandatory cyber security requirements across the entire product lifecycle, from design and development through to maintenance and vulnerability handling. 

The SPS exhibition will provide a multitude of exhibiting companies with experties in how engineering businesses can look beyond compliance to build genuine operational resilience. Phoenix Contact is one such company, fresh from running a series of workshops in the UK entitled Safe & Secure, which draws on the company's years of valuable experience. Seek advice on

  • CRA (Cyber Resilience Act) 
  • CAF (Cyber Assessment Framework) 
  • Machinery Regulation 
  • IEC 62443 
  • Other areas, such as Surge Protection and Power Reliability, that complement these subjects.

Risk assessment initiative

Image source: Rockwell // Indinvest LT – Cybersecurity audit at Italian aluminium processor
Image source: Rockwell // Indinvest LT – Cybersecurity audit at Italian aluminium processor

On the same theme, Rockwell Automation is collaborating with HS Automation to provide a structured roadmap which will identify and prioritise operational technology cybersecurity risks, supporting business continuity, modernisation and long-term operational resilience.

A case study from Italy shows how Indinvest LT, one of Italy’s leading manufacturers of aluminum billets and extrusions, is working with the two partners to strengthen the cybersecurity of its operational technology (OT) environment through a comprehensive cybersecurity risk assessment.

A cybersecurity risk assessment provides manufacturers with a structured evaluation of their operational technology environment to identify vulnerabilities, analyse potential threats, assess existing security controls and prioritise remediation activities. The process helps organisations establish a baseline understanding of cyber risk, create a roadmap for improvement, align cybersecurity investments with business objectives and support operational resilience.

"As our manufacturing environment continues to evolve, it is important that we maintain a clear understanding of potential cybersecurity risks across our operations," said Silvia Pellizzon, Indinvest LT's plant manager

This content was created in paid collaboration with the Newsletter Editors Andy Pye and Bob Dobson.

You might also be interested in