The earliest decisions in a new pulp and paper project often have the longest impact. Choices involving automation, supplier access, and long-term support can be difficult and expensive to change once the process has been commissioned, yet they will continue to affect reliability, maintenance, and operational risk for years. Operational Technology or OT cybersecurity is now one of those foundational decisions.
In many pulp and paper projects, however, OT cybersecurity is still treated as something that can be handled later, after the main technology selections have been made and the system design is already moving toward detailed engineering or commissioning.
That approach simply does not work anymore. Decisions made late in the project can create compliance issues, increase costs, complicate commissioning, and leave plant owners with security gaps that are much harder to address after startup.
Pulp and paper mills rely heavily on OT because the Distributed Control System (DCS) can extend through the entire production process. On a paper or board machine, the DCS and associated automation systems can monitor and control processes from stock preparation through forming, pressing, drying, coating, reeling, and winding.
However, the same level of integration also creates cybersecurity concerns, particularly as mills connect more systems for remote support, process optimization, analytics, and other digital applications.
In the European Union, OT cybersecurity is moving beyond a matter of technical preference. The Cyber Resilience Act and NIS2 are placing defined responsibilities on both sides of the industrial environment. Suppliers must provide products that meet security requirements, while critical infrastructure operators must manage cybersecurity risk throughout their operations.
“In the EU, cybersecurity is enforced by law. That is why everyone is on their toes,” says Teemu Kiviniemi, Solution Manager for OT Cybersecurity Services at Valmet. Valmet is a leading worldwide provider of process technologies, automation systems, and services for the pulp, paper, and energy sectors.
When cybersecurity is considered only after the core system architecture has already been selected, the project team is effectively trying to add security after the product has been designed.
With modern automation platforms like Valmet DNAe, cybersecurity is built into the underlying architecture. The platform was developed to support IT/OT convergence, with industrial-standard interfaces and edge technology providing connectivity from field-level sensors through to cloud applications. This allows data to move across the system and supports the use of digital intelligence and AI-based tools at different levels of the operation.
Valmet’s services are also designed to support the entire cybersecurity lifecycle. Valmet can continue to manage that risk through patch assessment, vulnerability management, monitoring, endpoint protection, and lifecycle support for its automation systems.
For more information about Valmet’s process automation systems, please visit www.valmet.com.
