Skip to content

NIS2 Implementation in Manufacturing: IT-OT Convergence Regulated

The essential point: NIS2 compels manufacturing companies to document uncontrolled IT-OT convergence and manage cybersecurity risks on a system-wide basis.

The NIS2 Directive requires manufacturing companies to control the increasing merger of IT and OT (Operational Technology). Uncontrolled IT-OT convergence endangers the availability of production processes — an economically critical risk that regulation now addresses.

Manufacturing plants were long isolated and air-gapped. As digitalisation advances and networked systems are deployed, however, IT and OT infrastructures are converging. This convergence delivers efficiency gains, but simultaneously creates new attack vectors and vulnerabilities in classic production environments that were not designed for IT-like threat scenarios.

For CISOs, this presents a dual challenge: they must enforce IT security standards while accounting for the operational requirements and long-lived systems of manufacturing. NIS2 now formalises this responsibility through binding requirements on critical infrastructure and the management of cybersecurity risks across all connected systems.

The first step lies in honest stocktaking: which systems are connected to one another, and how? Where do new dependencies between IT and production networks emerge? Such transparency is necessary to identify vulnerabilities at all and to establish control over the entire system landscape.


Source: www.security-insider.de · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: