Growing connectivity, new regulations, and long-term operational requirements are pushing cybersecurity decisions into the earliest stages of industrial project design.
The earliest decisions in a new industrial project often have the longest impact. Choices involving automation, supplier access, and long-term support can be difficult and expensive to change once the process has been commissioned, yet they will continue to affect reliability, maintenance, and operational risk for years. OT cybersecurity is now one of those foundational decisions.
In many industrial projects OT cybersecurity is still treated as something that can be handled later, after the main technology selections have been made and the system design is already moving toward detailed engineering or commissioning.
That approach simply does not work anymore. As industrial systems become more connected and cybersecurity requirements continue to expand, decisions made late in the project can create compliance issues, increase costs, complicate commissioning, and leave plant owners with security gaps that are much harder to address after startup.
“In the EU, cybersecurity is enforced by law. That is why everyone is on their toes. In the United States, cybersecurity requirements are increasingly included in RFQs and are generally expected in major industrial projects,” says Teemu Kiviniemi, Solution Manager for OT Cybersecurity Services at Valmet. Valmet is a leading worldwide provider of process technologies, automation systems, and services for the pulp, paper, and energy sectors. The company’s automation and flow control offerings further extend their reach into a wide range of other process industries. With headquarters in Espoo, Finland, Valmet has over 220 years in the industrial sector.
This is where timing becomes critical. Once the system architecture is already established, new cybersecurity requirements can be difficult to accommodate without creating additional complexity. Compliance may require new components, changes to existing interfaces and workflows, or exceptions that leave the overall system more difficult to operate and maintain.
The cybersecurity requirements also continue after the project is complete.
When cybersecurity is considered only after the core system architecture has already been selected, the project team is effectively trying to add security after the product has been designed.
“It is like first making a product and then putting the quality in afterwards. It doesn’t work that way,” says Kiviniemi. “You need to take cybersecurity into consideration from the start.”
The cost of late cybersecurity decisions
With modern automation platforms like Valmet DNAe, cybersecurity is built into the underlying architecture. The platform was developed to support IT/OT convergence, with industrial-standard interfaces and edge technology providing connectivity from field-level sensors through to cloud applications. This allows data to move across the system and supports the use of digital intelligence and AI-based tools at different levels of the operation.
Because these capabilities are part of the original design, the system does not depend on cybersecurity being added later to an architecture that was not built to support it. The security requirements are addressed while the system is being designed, before the major architectural decisions are already fixed.
For more information about Valmet’s process automation systems, please visit www.valmet.com.
