September/October 2026
156
Industrial Ethernet
ISSN 1470-5745
Automation Networking, IIoT and Industrial AI
Industri
Special Report
IT-OT Convergence in Focus Page 25
Industrial Cybersecurity 6 Technology Update
Making Networks More Resilient 26
Industrial Ethernet Corporate Profiles 37
Delivering Effective AI Manufacturing Data 46
Cost of Temperature 52 Monitoring
Visit us on the web n www.industrialethernet.net
GET CONNECTED…
Visit our new website at: www.iebmedia.com
Contents
Industrial Cybersecurity Industrial cybersecurity is undergoing a decisive shift from perimeter‑based protection toward device‑level security, identity‑driven communication, and resilient architectures designed for increasingly connected OT environments. Here are highlights from our coverage in this issue: Modern edge controllers now ship with hardened operating systems, built‑in firewalls, encrypted communications, and certificate‑based authentication—marking a departure from the historical model of relying on external firewalls to protect inherently insecure devices. Publish‑subscribe messaging, especially MQTT with Sparkplug, further reduces the attack surface by eliminating inbound polling and enabling secure, outbound‑only data flows.
2026 Corporate Profiles: 37
New Products: 56
Contents Industry News
4
Industrial Cybersecurity Technology Update
6
How to Make Industrial Networks More Resilient
20
Practical Takeaways from 2026 ISA OT Cybersecurity Summit
23
IT-OT Convergence and AI Shaping Network Operations
25
Regulatory pressure—including the EU Cyber Resilience Act and IEC 62443—is accelerating adoption of secure‑by‑design products, lifecycle vulnerability management, and harmonized security standards across multi‑vendor ecosystems. Industry groups such as FieldComm Group, ODVA, OPC Foundation, and PI are aligning identity, authorization, and access concepts to simplify deployment and improve interoperability.
Manufacturers Adopting Agentic AI Without a Governance Plan
35
Industrial Ethernet Solutions: 2026 Corporate Profiles
37
How Protocol Gateways Deliver Effective AI Manufacturing Data
46
Zero Trust is becoming operationally feasible in brownfield environments through overlay technologies that enable certificate‑backed, encrypted communication without major network redesign. Integrated cybersecurity platforms now combine segmentation, visibility, remote access, and monitoring into deployable OT‑friendly solutions.
Using IP Routers to Simplify Industrial Machine Integration
49
The Real Cost of Temperature Monitoring
52
New Products
56
Artificial intelligence is reshaping the threat landscape on both sides. Defenders benefit from AI‑driven anomaly detection, behavioral analytics, and accelerated incident investigation, while attackers leverage generative AI to scale reconnaissance, craft convincing phishing, and automate vulnerability discovery. This dual impact raises the urgency of foundational practices such as segmentation, patching, least‑privilege access, and secure data pathways.
All perspectives are emphasizing a shift from protecting individual devices to ensuring the resilience of entire industrial operations. Continuous asset visibility, granular segmentation, secure remote access, and process‑aware anomaly detection are becoming essential as manufacturers pursue digital transformation. Modern cybersecurity is no longer a barrier—it is the foundation that enables safe connectivity, AI adoption, cloud integration, and smart‑manufacturing innovation.
Al Presher 09.2026
Industrial Ethernet magazine The next issue of Industrial Ethernet magazine will be published in Nov/Dec 2026. Deadline for editorial: November 13, 2026 Advertising deadline: November 13, 2026 Editor: Al Presher, editor@iebmedia.com Advertising: info@iebmedia.com Tel.: +1 585-598-6627 Free Subscription: iebmedia.com/subscribe Published by IEB Media Corp., 1247 Anthony Beach Rd., Penn Yan, NY, 14527 USA ISSN 1470-5745
i n d u s tr i a l e th e r n e t m a g a z i n e
3
| MX04
Industry news
ISASecure Certification Scheme for Commercial Components SOURCE: ISTOCKPHOTO
The ISASecure mission is to provide the highest level of assurance possible for the cybersecurity of industrial automation control systems.
The ISASecure mission to provide effective cybersecurity for industrial automation control systems includes conducting certifications for off-the-shelf control system products and supplier development practices. The International Society of Automation (ISA) has announced that ISASecure®, a wholly owned subsidiary of ISA, is partnering with the United States National Security Agency (NSA) to develop a new certification scheme for commercial operational technology (OT) components sold by manufacturers and procured by the US government for use within National Security Systems (NSS). With a common goal of securing high criticality OT systems, the new certification scheme is intended to increase confidence in the security of commercial components. ISA developed a set of security levels (SL) with specific cybersecurity requirements for OT components in the international OT cybersecurity standard ISA 62443-4-2. In addition, six new technical security requirements were developed and published by NSA’s Operational Technology Assurance Partnership (OTAP) Program in the NSA/ CSS Cybersecurity Technical Report titled “Operational Technology Assurance Partnership: Smart Controller Security within National Security Systems” (April 2025). In response to the need, ISASecure is developing a separate High Criticality Component Security Assurance (HCSA) certification scheme derived from the wellestablished Component Security Assurance
4
certification scheme (CSA). Upon completion and the OTAP program office’s acceptance of the ISASecure HCSA scheme, the NSA will use the scheme as an approved certification mechanism in the evaluation process of adding OT OEM components to the NSS OT Product Compliant List (PCL). “This is a major achievement in the history of ISASecure,” said Dr. Mark P. DeAngelo, program manager of ISASecure. “The NSA recognizes the importance of the ISA 62443 standard and the ISASecure program, which independently evaluates a product’s conformity to the ISA 62443 standard. ISASecure’s reputation and commitment to robust OT security precedes the NSA’s decision to partner with us. Our CSA product certification set the foundation for HCSA.” An ISASecure HCSA certificate provides a product manufacturer with essential evidence in consideration of that product’s inclusion on the NSA’s NSS OT PCL. In other words, ISASecure certification is an important step before a smart controller can be purchased and installed within an NSS. Manufacturers interested in developing smart controllers are encouraged to join ISASecure to be part of the HCSA development. Stakeholders include manufacturers of components, accreditation bodies and certification bodies.
About ISASecure®
Founded in 2007 by the International Society of Automation (ISA), the ISASecure mission is to provide the highest level of assurance possible for the cybersecurity of industrial automation control systems. ISASecure, a wholly owned subsidiary of ISA, is a globally recognized ISA/IEC 62443 conformance scheme, conducting certifications for off-theshelf control system products and supplier development practices since 2010. Founders and key supporters of ISASecure include BP, Chevron, ExxonMobil, Saudi Aramco, Shell, GSK, Honeywell, Johnson Controls, Schneider Electric, Yokogawa, Carrier, Siemens, YPF, Amazon Web Services, exida, TUV Rheinland, CSSC, FM Approvals, Synopsys, Trust CB, SecurityGate, BYHON, TUV SUD, Trane and Bureau Veritas. The program’s ISASecure designation signifies to the marketplace that industrial automation and control products conform to industry-consensus cybersecurity standards. The ISASecure trademark provides confidence to users of ISASecure certified products and systems and creates product differentiation for suppliers who conform to the ISASecure specifications. Learn more at isasecure.org. International Society of Automation (ISA)
in d u s t r ial et h er ne t mag azin e
09.2026
Plan quickly, configure reliably: smart and cabinet-free With the free MX-System Designer
mx-system-designer.beckhoff-cloud.com Design your machine architecture quickly, reliably, and intuitively with the MX-System Designer. Online tool: offering anytime, anywhere access – no need for software installation Easy configuration: select suitable components via graphical planning functions such as drag and drop Integrated cable management: pre-assembled cables are included in the design Automated documentation: export BOMs, etc., with the click of a button Fewer planning errors: with integrated validation functions Compare faster: easily compare with existing control cabinet solutions
Cybersecurity
Industrial Cybersecurity 2026 Technology Update
SOURCE: IEB MEDIA
Industrial cybersecurity is shifting to device‑level protection, identity‑based communication, AI‑assisted detection, and secure‑by‑design standards. As IT/OT environments converge, plants must harden legacy systems, segment networks, and adopt resilient architectures that safeguard operations without compromising uptime.
“AI cuts both ways. On defense, machine learning is good at spotting the thing a human misses: a controller that suddenly talks to an address it has never contacted, a process value drifting outside its normal envelope, a login at 3 a.m. from a new device,” Dan White, Director of Technical Marketing, Opto 22. CYBERSECURITY IN INDUSTRIAL ENVIRONMENTS is undergoing a major transformation as protection moves from perimeter defenses to hardened, secure‑by‑design devices. At the same time, AI is reshaping both attack and defense—accelerating reconnaissance for adversaries while enabling faster anomaly detection and behavioral analytics for defenders. Regulatory pressure, including the EU Cyber Resilience Act and IEC 62443, is pushing manufacturers toward consistent, lifecycle‑focused security practices across multi‑vendor systems. Zero Trust networking, secure remote access, segmentation, and unified monitoring are becoming essential as IT/OT convergence grows. The goal is clear: protect production, maintain reliability, and build cyber‑resilient operations capable of
6
safely supporting modern connectivity and smart‑manufacturing innovation. In this special report, Industrial Ethernet magazine reached out to industry experts to get their perspectives on the current state Industrial Cvbersecurity.
Security at Device Level
New edge controllers ship with a hardened operating system, a built-in firewall, user accounts and encrypted communications. Dan White, Director of Technical Marketing at Opto 22 said that “the biggest shift is that security is moving into the device. For years, OT security meant wrapping an insecure controller inside firewalls and hoping no one
got past them. That model is breaking down. New edge controllers ship with a hardened operating system, a built-in firewall, user accounts, and encrypted communications out of the box. Security is a property of the device, not a perimeter bolted on later.” White said that a second trend is publishsubscribe messaging, specifically MQTT with Sparkplug. Instead of SCADA polling controllers through open inbound ports, the controller makes a single outbound TLS connection to a broker and reports by exception. You close the inbound holes attackers look for, and you get a secure data pipe as a side effect. Third is identity. Devices now authenticate with certificates, not shared passwords, so you know what is actually on your network.
in d u s t r ial et h er ne t mag azin e
09.2026
“AI cuts both ways. On defense, machine learning is good at spotting the thing a human misses: a controller that suddenly talks to an address it has never contacted, a process value drifting outside its normal envelope, a login at 3 a.m. from a new device,” White said. “Anomaly detection is only as good as the data feeding it, though. Garbage in, garbage out. This is where a clean, contextualized pipeline from the edge matters.” Models trained on robust, high-quality data see the process clearly instead of guessing. On offense, attackers use the same tools. AI writes better phishing emails, finds vulnerabilities faster, and lowers the skill needed to launch an attack. The barrier to entry is dropping. The practical takeaway for OT teams: AI raises the stakes on the basics. It does not replace segmentation, patching, and least-privilege access. It makes them more urgent. And wherever you run AI, at the edge or in the cloud, watch how the data gets there. Every new pipe is a new thing to secure.
Technology Solutions
White added that the concrete benefit is a smaller attack surface. When a controller reports out to a broker over one encrypted connection, you can close the inbound ports
that legacy polling required. Fewer open doors, fewer ways in. You also get data integrity you can trust. Encrypted, authenticated messages mean the number in your dashboard is the number the sensor actually sent, and nobody changed along the way. For analytics and AI, that matters as much as security does. Device-level identity changes the game too. When every controller carries its own certificate, you know exactly what is on the network and can revoke access to one device without touching the rest. The larger impact on smart manufacturing is that you can finally connect the plant floor to the enterprise safely. The old answer to “can we get this data to the cloud” was “not without opening a hole.” Now you move production data up to MES, databases, and cloud analytics through a secure, decoupled pipe, and get the visibility a smart factory needs without betting the plant on a firewall rule.
Innovative Technologies
“Take a modern edge controller as the example,” White said. “Underneath the control engine runs a hardened Linux OS that the vendor patches and signs. The device has two or more network interfaces, so you physically separate the trusted control network from the plant or business network and route
only what you choose between them. Each interface has its own firewall. Communications are encrypted with TLS and authenticated with device certificates.” He said that, for data movement, the controller acts as an MQTT edge node: it publishes tag changes to a broker using Sparkplug, which defines a standard payload plus birth and death messages so consumers always know a device’s state and structure. A controller runs the machine, publishes its data outbound to a broker in the DMZ, and a VPN handles remote access for maintenance, with no permanent inbound path to the floor. Logic apps run on the same box, so edge processing happens next to the I/O instead of on a PC someone has to patch separately. One hardened device does the control, the security, and the connectivity.
Cybersecurity
The Impact of AI
Automation Engineering Concerns
White said that the first concern for automation engineers implementing security solutions is legacy equipment. Most plants run controllers installed before security was a design goal, and you cannot patch or replace them without downtime. Engineers have to protect gear that will be on the floor for another decade. The second is uptime. In OT, availability wins. A patch that reboots a line is a
Skorpion Switches Designed for Automation • Plug-and-play simplicity • 10/100 Mbps performance • Auto-MDIX on all copper ports • Auto-negotiated data rate, duplex and flow control on twisted-pair ports • Rugged metal enclosure
Skorpion Switches Providing Solutions to Your Automation Needs
Learn more at www.ccontrols.com/skorpion
+1 630-963-7070 • info@ccontrols.com
SOURCE: FIELDCOMM
Cybersecurity The ISHG—comprising leading industry organizations including the FieldComm Group, ODVA, OPC Foundation, and PROFIBUS & PROFINET International (PI)—are working to align security concepts across industrial technologies and multi-vendor environments. production loss, so engineers are cautious about the update cycles IT takes for granted. Security has to fit around the process, not the other way around. Third is ownership. IT and OT often report to different bosses with different priorities: IT wants to patch and lock down, OT wants the line running. Somebody has to own OT security, and in many companies no one clearly does. "Then there is the skills gap. The person keeping the plant running may not be a network security expert, and the security team may not understand a PLC. The honest answer is that good tools help but do not solve this alone. The wins come from segmentation, least-privilege access, and starting with the highest-risk assets, not from trying to secure everything at once," White concluded.
EU Cyber Resilience Act (CRA)
Accelerating the focus on secure-by-design products, vulnerability management, software updates and lifecycle support. “For plant and automation engineers, cybersecurity is becoming part of the everyday engineering process. It now must be considered when selecting devices, designing
8
networks, managing user access, and planning how systems will be maintained over their full lifecycle,” said Stephen Mitschke, Director - Standards Development & Conformance at FieldComm Group. Mitschke said that the EU Cyber Resilience Act (CRA) is helping accelerate that shift by putting more focus on secure-by-design products, vulnerability management, software updates, and lifecycle support. At the same time, IEC 62443 gives engineering teams a practical, risk-based way to decide what protections are appropriate for a specific system or application. “Another big trend is industry harmonization,” Mitschke said. “Through the Industrial Security Harmonization Group (ISHG), FieldComm Group, ODVA, OPC Foundation, and PI are working to align security concepts across industrial technologies and multi-vendor environments. NAMUR NE 201 is helping inform that work with practical OT use cases for identity and access management, particularly around authentication and authorization.” For engineers, the goal is straightforward: security that is consistent, interoperable, and practical to deploy without making the plant harder to operate, maintain, or support.
New Solutions Benefits
“For end users, one of the biggest benefits of new industrial cybersecurity solutions is the move toward common, standards-based security approaches that can be applied across multi-vendor, multi-protocol automation environments,” Mitschke said. “This helps reduce the complexity of managing separate credentials, access methods and security policies for individual devices.” Approaches reflected in NAMUR NE 201 use cases support centralized identity management, role-based authorization, and time-limited access tokens. Engineers and technicians can authenticate through a central system and receive access only to the devices and functions they are authorized to use, helping support least-privilege access while improving traceability. “The broader benefit is scalability,” he said. “When common security concepts can be used across technologies such as HART-IP, EtherNet/ IP, OPC UA and PROFINET—and across wired, wireless and Bluetooth interfaces—plants can apply more consistent security policies as networks become more connected.” For smart manufacturing, Mitschke said that this creates a stronger foundation for secure remote access, asset management, diagnostics, analytics and IT/OT integration, while preserving the interoperability and operational flexibility that end users need.
IT/OT Convergence Driver
OT security often moving from plant-level teams to centralized IT and cybersecurity organizations. According to Michael Metzler, Vice President, Horizontal Management Cybersecurity for Digital Industries at Siemens, several technology trends are shaping the newest Industrial Cybersecurity Solutions. First, IT/OT convergence continues to be a major driver. As industrial environments become increasingly connected, responsibility for OT security is often moving from plantlevel teams to centralized IT and cybersecurity organizations. “Many OT incidents can be traced back to compromised IT environments, remote access paths, or interconnected systems, driving the adoption of enterprisegrade security practices while still respecting OT requirements for availability, reliability, and safety. Second, Zero Trust is evolving from a security concept into a practical deployment model for industrial networks. In the past, implementing Zero Trust in brownfield environments often required significant network redesign. Today, overlay-network technologies such as Siemens' SINEC Secure Connect enable identity-based, certificate-backed, end-to-end encrypted communications between machines, cloud
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: ISTOCKPHOTO
Cybersecurity
"IT/OT convergence continues to be a major driver. As industrial environments become increasingly connected, responsibility for OT security is often moving from plant-level teams to centralized IT and cybersecurity organizations," Michael Metzler, Vice President, Horizontal Management Cybersecurity for Digital Industries, Siemens. services, and users on top of existing network infrastructure, reducing deployment effort while improving security. Third, AI adoption and AI-specific cybersecurity are becoming increasingly important. Industrial organizations are deploying AI for applications such as quality inspection, predictive maintenance, and operational optimization, creating new security requirements. Finally, there is a broader trend toward integrated, pre-validated cybersecurity platforms that combine networking, visibility, segmentation, remote access, and security monitoring into operationally deployable solutions.
AI Effect on Industrial Cybersecurity Landscape
“AI is significantly reshaping the Industrial Cybersecurity landscape. On the attacker side, generative AI is lowering the barrier to entry. Activities such as reconnaissance, phishing content creation, malware modification, and vulnerability research can potentially be performed faster and at greater scale than before, allowing attackers to operate more efficiently,” Metzler said. He said that, on the defender side, industrial organizations are increasingly using AI to improve threat detection, anomaly identification, incident investigation, and response automation. Because industrial networks often contain heterogeneous assets and legacy systems, AI-driven behavioral analytics can help identify suspicious activities that traditional signature-based approaches may miss. At the same time, the growing adoption of 09.2026
AI within industrial environments introduces new cybersecurity requirements. AI models, training data, inference engines, and edge AI infrastructure become additional assets that must be protected against manipulation, unauthorized access, data poisoning, and intellectual property theft. As a result, cybersecurity is expanding beyond protecting OT systems and networks to also securing the AI applications that increasingly support industrial operations.
Impact on Smart Manufacturing
“Industrial networks are the backbone of modern manufacturing and are becoming increasingly complex as organizations connect to machines, production systems, edge computing platforms, cloud services, and AI applications,” Metzler said. “As a result, hardware alone no longer determines network performance and resilience. Softwaredefined network management, continuous visibility, and integrated cybersecurity have become essential components of industrial operations.” “Modern industrial cybersecurity solutions improve visibility into OT assets and communications, enable earlier detection of abnormal behavior, and help organizations respond more quickly to potential incidents,” he added. Technologies such as Zero Trust networking, secure remote access, network segmentation, and identity-based communication reduce the attack surface while protecting both modern and legacy industrial assets. These solutions also help increase operational resilience by reducing the likelihood and impact of cyber
i n d u s tr i a l e th e r n e t m a g a z i n e
incidents that could disrupt production. In addition, centralized management and security policies can simplify administration, reduce operational complexity, and support compliance with standards such as IEC 62443 and emerging regulatory requirements. For smart manufacturing networks, the impact is significant.
Protecting Production Environments
Metzler said that industrial cybersecurity must protect production environments against increasingly sophisticated cyber threats while maintaining the availability, reliability, and safety of industrial processes. Modern cybersecurity solutions therefore combine the principles of Defense in Depth and IEC 62443 with advanced technologies specifically designed for operational technology (OT) environments. What makes today's cuttingedge cybersecurity technologies unique is their ability to provide strong security without disrupting industrial operations. Unlike traditional IT security solutions, modern OT cybersecurity technologies can integrate into existing brownfield environments, including legacy devices that were not originally designed with cybersecurity in mind. Examples include AI-driven anomaly detection, which continuously analyses network traffic and device behavior to identify suspicious activities that may not match known attack signatures. It also includes industrial firewalls with deep packet inspection, which understand industrial protocols such as PROFINET, Modbus TCP, or OPC UA and can detect unauthorized commands; and Zero Trust solutions that establish identity-based,
9
SOURCE: ISTOCKPHOTO
Cybersecurity “The most significant benefit of modern industrial cybersecurity is not simply preventing cyberattacks, it is instead empowering manufacturers to pursue digital transformation without introducing unacceptable operational risk,,” Charles Lim, Head of Digital Security Solution for Yokogawa Engineering Asia. encrypted communication between authorized devices, users, and applications. In factory environments, these technologies are applied to segment production networks, secure remote maintenance access, monitor industrial assets, detect abnormal behavior in real time, and protect data flows between machines, edge systems, cloud platforms, and enterprise IT systems. Increasingly, security functions are also being integrated directly into the infrastructure layer, enabling continuous inspection, visibility, and threat detection without impacting production performance. He noted that the primary concern when implementing cybersecurity strategies is to ensure that security measures do not negatively impact availability, reliability, and safety. Production environments are designed to operate continuously, and any change that could introduce downtime, latency, or operational risk is carefully evaluated before deployment. A second major challenge is the age and heterogeneity of industrial infrastructure. Many production assets remain in service for 15 to 20 years or longer and were not originally designed with modern cybersecurity features such as authentication, segmentation, encryption, or centralized asset management. Securing these legacy environments without requiring complete modernization or network redesign remains a significant technical
10
challenge. Companies also frequently struggle with asset visibility and risk assessment. Before implementing effective cybersecurity controls, organizations must first understand which assets are deployed, how they communicate, their software and firmware versions, and which vulnerabilities may affect them. In many brownfield environments, this information is incomplete or unavailable. Another important challenge is the ongoing OT cybersecurity skills gap. Industrial organizations often lack personnel who possess both deep operational technology expertise and modern cybersecurity knowledge. Finally, organizations face increasing pressure from regulatory requirements.
Goal is Resilience of Entire Industrial Operation
Interconnected, traditional perimeter-based security is no longer sufficient. “Industrial cybersecurity is undergoing a fundamental shift from protecting individual devices toward protecting the resilience of the entire industrial operation. As information technology (IT), operational technology (OT), Industrial internet of things (IoT), cloud platforms, and edge computing become increasingly interconnected, traditional perimeter-based security is no longer sufficient,” said Charles Lim, Head of Digital
Security Solution for Yokogawa Engineering Asia. Lim said that several technology trends are accelerating this change. First is continuous OT asset visibility to understand not only what devices exist, but their communication relationships, vulnerabilities, configurations, and operational criticality. Second is increasingly granular network segmentation and identity-based access, reducing unnecessary pathways between IT, OT and third-party environments. Third is the convergence of network, endpoint, identity, and process information into unified security monitoring. Another important development is the growing emphasis on cyber recovery. Industrial organizations must assume that prevention will not always succeed, and therefore design environments capable of detecting abnormal activity, containing an incident, and safely restoring production. “At Yokogawa, we see cybersecurity increasingly becoming an engineering discipline integrated throughout the industrial system lifecycle. The objective is therefore moving beyond “secure the network” toward maintaining safe, reliable, and resilient operations despite cyber disruption,” Lim said.
AI and Industrial Cybersecurity
“AI is changing industrial cybersecurity on both sides of the equation. Attackers can use
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: .YOKOGAWA
Cybersecurity
Yokogawa perspective on the trends shaping secure and resilient smart manufacturing. AI to accelerate reconnaissance, vulnerability discovery, social engineering, and malware development, while defenders can use AI to process volumes of operational and security data that humans cannot realistically analyse manually,” Lim added. For industrial environments, however, he said that AI must go beyond conventional IT threat detection. The real opportunity is to correlate network behaviour system behaviour, user activity, and process behaviour. A network connection may appear legitimate from a traditional cybersecurity perspective, for example, while the resulting command or process change may be highly abnormal. This creates an important role for an AI-assisted security operations center (SOC) to perform behavioural analytics and industrial anomaly detection. The goal should not be autonomous decision-making without context, but instead helping engineers understand what is abnormal, why it matters operationally and what action is safe to take. Industrial AI must therefore be explainable, trustworthy, and grounded in process knowledge. Yokogawa believes the strongest future cybersecurity models will combine AI intelligence with OT engineering expertise and human judgement, rather than attempting to replace operators with algorithms.
Empowering Manufacturers
“The most significant benefit of modern industrial cybersecurity is not simply preventing cyberattacks, it is instead empowering manufacturers to pursue digital transformation without introducing unacceptable operational risk,” Lim said. Smart manufacturing depends on connectivity among production systems, edge platforms, analytics, cloud applications, 09.2026
remote specialists, suppliers, and enterprise systems. Each connection creates business value but also creates another potential pathway into the operational environment. Modern cybersecurity provides the visibility, segmentation, authentication, monitoring, and governance necessary to make that type of connectivity sustainable. For operators, better asset visibility reduces blind spots. Network detection identifies abnormal communications without disrupting sensitive OT equipment. Secure remote access allows vendors and engineers to support plants while controlling identity, privilege, and session activity. Integrated monitoring gives security teams greater context when incidents occur. “Perhaps most importantly, modern solutions help organizations transition from reactive security toward cyber resilience. Manufacturers can identify critical operations, prepare response procedures, isolate affected environments, and restore essential functions in a controlled manner,” Lim said. “Cybersecurity should therefore not be viewed as a barrier to smart manufacturing. Properly implemented, it instead becomes a foundation that allows greater connectivity, automation and innovation to occur safely.” Lim said that the distinguishing characteristic of cutting-edge industrial cybersecurity is context. Traditional security technologies may detect IP addresses, vulnerabilities, or suspicious traffic; but industrial cybersecurity must also understand assets, communication protocols, production dependencies, and the potential consequence to the physical process. A modern factory architecture therefore combines multiple defensive layers. Passive OT network monitoring can identify industrial
i n d u s tr i a l e th e r n e t m a g a z i n e
assets and establish normal communication patterns without actively interrogating sensitive controllers. Network segmentation separates production zones according to their function and criticality, while industrial DMZs mediate connections between enterprise and plant environments. Identity-based secure remote access controls which engineers or vendors can access which asset, for what purpose, and for how long. These telemetry sources can then feed an IT/OT security operations capability where information from firewalls, endpoints, identity systems, OT network sensors, and industrial systems is correlated. The next step is process-aware detection. Instead of analyzing cyber indicators independently, security platforms increasingly combine network anomalies with system and operational behavior. This defense-in-depth architecture empowers staff to detect threats earlier, while respecting a fundamental OT requirement: cybersecurity controls must never compromise safety, availability, or deterministic plant operation.
Addressing Engineering Challenges
“One of the biggest challenges is that industrial cybersecurity cannot simply apply enterprise IT security practices directly to the plant floor. OT environments have different priorities: safety, availability, and production continuity often come before confidentiality and data protection, and many systems were designed to operate for decades rather than follow short IT technology refresh cycles,” Lim said. He noted that automation engineers therefore face several concerns. Legacy controllers and operating systems may not
11
SOURCE: ISTOCKPHOTO
Cybersecurity “We are seeing expansion of cybersecurity regulations across all industries, which are being enforced not only locally, but also with regulations like NIS 2 and CRA as a requirement in Europe as a whole, potentially with international implications,” Tadeu Batista, global cybersecurity business development manager, Emerson. support modern security controls, patching may require production shutdowns, and active vulnerability scanning can introduce operational risk. Plants may also contain undocumented assets, flat networks, and third-party systems that no one currently owns from a cybersecurity perspective. Another challenge is organizational. Cybersecurity increasingly sits between IT, OT, engineering, operations, safety and external vendors. Without clear governance, responsibility can become fragmented. Companies should therefore avoid beginning with technology procurement. The starting point should instead be understanding the assets, critical processes, threats, and operational consequences, followed by a risk-based roadmap aligned with frameworks such as IEC 62443 and NIST CSF. Ultimately, successful industrial cybersecurity requires three elements working together: technology, processes, and people. Technology alone cannot create cyber resilience.
AI Beginning to Make Impact
Primary user goals include increased visibility into infrastructure and detection of abnormal behavior. “It can be hard to identify individual trends in cybersecurity because it’s never a one-sizefits-all response. Some industries are more
12
open to using new technologies, while others may take years, or, in some cases, even decades to implement cybersecurity measures,” Tadeu Batista, global cybersecurity business development manager at Emerson told Industrial Ethernet magazine. “When talking to end users, what we hear the most is the request to increase visibility into their infrastructure, and to detect abnormal behavior and respond to it on a timely basis. This all starts with a consistent asset inventory defining the criticality of each asset to drive tactics, techniques and procedures. The way end users approach this goal differs, with some industries are very open to cloud-based solutions, while others are more conservative, wanting everything on-prem and as isolated as possible,” Batista said. He said that, fortunately for the more conservative teams, the Emerson DeltaV Automation Platform provides everything they need—application protection, endpoint protection and more—on prem. Emerson also partners with expert OT cybersecurity solutions providers to support many cloud technology strategies. “We are also seeing increased discussion around ‘IT/OT convergence’. Conceptually, this idea is important, though we prefer “IT/OT confluence” because although IT/OT synergies are happening more frequently, we must recognize the objectives and behaviors in IT and OT remain different, typically requiring distinct measures. Working closely with an
expert automation partner can help teams navigate those disparities,” Batista said. Shifting Industrial Cybersecurity Landscape Batista said that the industrial cybersecurity landscape is anything but homogeneous, as different organizations in different industries will undoubtedly be on different maturity levels when it comes to cybersecurity. Nonetheless, artificial intelligence (AI) has made an impact as more reports detail the increased threat and increasing capabilities of deterrent solutions delivered by the rise of AI. Even the least cybersecurity-mature organizations are taking notice by making moves towards improving their cybersecurity posture, all thanks to the new possibilities AI is bringing on both sides of the fence. It’s too early to say if novel vulnerabilities have been discovered, but the exploitation landscape has changed regardless. More numerous and sophisticated attacks can be carried out faster at a much lower cost, and the ability to explore non-obvious affordances is creating a new paradigm. Therefore, he noted that Emerson sees increased need for tools that can identify threats faster and leverage AI-compatible behavior to respond accordingly. This does not mean that traditional methods should be discarded altogether, however. IEC 62443 provides a comprehensive framework in a very structured way for organizations to improve their security program using traditional methods. As we continue to
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: .EMERSON
Managing Cloud Connectivity
“We’re seeing a significant shift in how organizations manage cloud connectivity. There is increasing demand for cybersecurity tools that can secure data movement to and from cloud platforms, and for secure remote access, while also detecting abnormal behavior on prem before any impact is caused to operations,” Batista said. “At Emerson, we partner with expert cybersecurity solutions providers like Belden, Trellix, Dragos, Nozomi Networks, OPSWAT and others to help customers design customized solutions to meet their need for increased data accessibility in the emerging AI era. With secure data connectivity, teams have the tools they need to improve continuous operations with less downtime.” He said that many organizations have been gathering process data for several years or even decades. This data is hosted on cloudbased data lakes, and with frontier models these organizations are creating high fidelity process models and using them to improve their production systems. Another example is using statistical models on advanced process control (APC) applications to deliver tighter control and optimize processes. And today AI is taking these strategies to a whole new level—but delivering those strategies means having the tools in place to securely deliver that data to AI engines so teams can detect issues before process upsets occur, and without creating new attack surfaces.
AI as Defensive Asset
Even as AI creates new threats, Batista said that it is also playing a key role in defense. At Emerson, they are using AI as part of the secure IEC 62443-4-1 certified development processes. Secure development augments code testing and provides vulnerability discovery/ assessment to support developers so they can address vulnerabilities before they ever make it into the product. He said that the result has been incredibly secure solutions. Patching is another foundational requirement that’s being transformed by AI technology. Adversaries have been augmenting their exploit capabilities, which makes it even more important for teams to keep their systems up to date. This means replacing end-oflife systems that are no longer maintained or receiving patches, while developing a regular patching strategy for modern systems to ensure new vulnerabilities don’t create additional attack vectors. A consistent, up to date asset inventory is the basis for this plan. Endpoint protection is another important 09.2026
Cybersecurity
develop and deploy zero-trust cybersecurity principles, Emerson always recommends a layered approach that includes traditional cybersecurity strategies and technologies.
Today's most advanced automation solution providers are delivering secure-by-design software built around a zero-trust cybersecurity methodology to further enhance the traditional layered cybersecurity approach. foundational requirement. Endpoint detection and response (EDR) and extended detection and response (XDR) are becoming very relevant, and vendors have been using AI to significantly improve their behavioral models. “While protecting the endpoint is important, we cannot forget that data flows across the network, which is where intrusion detection solutions that are specifically tailored for OT environments deliver tremendous advantages,’ Batista said. “Fit-for-purpose solutions can understand industrial and vendor specific protocols, along with OT specific behaviors, to better identify abnormal behaviors. These include but aren’t limited to detecting new devices on protected network segments, firmware updates from unauthorized devices/ users, logic downloads from unusual devices/ users, and mode changes to control loops outside of normal conditions.”
local and/or industry specific regulations. Cybersecurity-specific regulations are nothing new, for example NERC-CIP is a cybersecurity regulation focused on critical infrastructure in the U.S. and it came into effect in 2010, with discussions starting as early as 2006. “We are seeing expansion of cybersecurity regulations across all industries, which are being enforced not only locally, but also with regulations like NIS 2 and CRA as a requirement in Europe as a whole, potentially with international implications,” Batista added.
Engineering Concerns
According to Tim Wheeler, cybersecurity manager for industrial products at AutomationDirect, regulation is one of the strongest technology trends driving the development of new industrial cybersecurity solutions. Requirements such as the EU Cyber Resilience Act (CRA), along with other emerging cybersecurity regulations, are moving industrial cybersecurity from a recommended practice toward a defined business and product requirement. Manufacturers are increasingly expected to address cybersecurity throughout the product lifecycle, including secure-by-design development, vulnerability management, secure updates, incident reporting, and software supply-chain transparency. As
“We are seeing regulation expanding rapidly beyond just critical infrastructure to impact other companies as well. Many industrial asset owners will be impacted by regulations such as the Network and Information Security Directive (NIS2) and Cyber Resilience Act (CRA). Going back to the IT/OT Confluence paradigm, security engineers are now tasked with finding solutions that provide compliance while improving plant operational performance. Simply applying IT tools and techniques as-is will not work because OT requirements are fundamentally different,” Batista said. He said that this is creating an environment where meeting organizational objectives will include, among other things, adherence to
i n d u s tr i a l e th e r n e t m a g a z i n e
Cybersecurity’s Changing Landscape
Industrial cybersecurity moving from a recommended practice toward a defined business and product requirement.
13
SOURCE: ISTOCKPHOTO
Cybersecurity “Frameworks such as IEC 62443 help manufacturers, system integrators, and asset owners establish common expectations for areas such as authentication, access control, network segmentation, secure communications, system integrity, vulnerability management, and secure development practice,” Tim Wheeler, cybersecurity manager for industrial products, AutomationDirect. these requirements mature, they are driving demand for industrial products with stronger built-in security capabilities and encouraging organizations to take a more proactive approach to managing cybersecurity risk. “Cybersecurity frameworks and standards are providing the structure needed to turn these regulatory and security objectives into practical solutions,” said Wheeler. “Frameworks such as IEC 62443 help manufacturers, system integrators, and asset owners establish common expectations for areas such as authentication, access control, network segmentation, secure communications, system integrity, vulnerability management, and secure development practices. As these frameworks become more widely adopted, they are helping the industry move away from isolated security solutions toward a more consistent, risk-based approach. This provides a common language between IT, OT, engineering, manufacturers, and cybersecurity teams and helps organizations determine which security controls are appropriate for their specific systems and risks.” Wheeler said that Artificial intelligence (AI) represents one of the newest and potentially most significant technology trends affecting industrial cybersecurity. AI provides the ability to analyze large volumes of network, asset, vulnerability, and operational data much faster than traditional manual processes, creating new opportunities for anomaly detection, threat identification, vulnerability
14
research, predictive maintenance, and incident response. “AI is also increasingly being used by both cybersecurity defenders and attackers, making it important for industrial organizations to understand both its opportunities and its risks. When combined with stronger regulatory requirements and established cybersecurity frameworks, AI has the potential to improve visibility and response capabilities while allowing limited cybersecurity resources to focus their attention on the risks that matter most to industrial operations,” he added.
The move to AI
Artificial intelligence is rapidly changing the industrial cybersecurity landscape by giving defenders new capabilities for monitoring, analysis, and system verification. Industrial environments generate enormous amounts of network, device, and operational data that can be difficult for security teams to analyze manually. AI can help identify unusual network behavior, detect changes in system configurations, prioritize vulnerabilities, verify expected device behavior, and recognize potential threats before they develop into larger incidents. This is especially valuable in OT environments where cybersecurity resources are often limited and where understanding what is “normal” for a system is critical to identifying potential problems. AI does not replace experienced cybersecurity and engineering personnel, but
it can significantly increase their visibility and ability to respond quickly. “At the same time, AI is increasing the capabilities available to attackers. Techniques that once required significant expertise, time, and resources can increasingly be assisted or automated through AI, including vulnerability research, reconnaissance, malware development, social engineering, and analysis of unfamiliar systems and protocols,” Wheeler said. “This has the potential to give less sophisticated attackers access to capabilities that begin to approach those historically associated with highly skilled or state-sponsored threat actors. For industrial organizations, this means the threat landscape is likely to become faster and more sophisticated. The challenge moving forward will be to use AI as a defensive force multiplier while continuing to strengthen industrial systems against attackers who are benefiting from many of the same technological advances.”
Industrial Cybersecurity Solutions
Wheeler said that new industrial cybersecurity solutions provide greater visibility, control, and resilience across increasingly connected smart manufacturing networks. Technologies such as AI-assisted monitoring, secure communications, network segmentation, stronger authentication, automated asset discovery, and continuous vulnerability management allow organizations to identify
in d u s t r ial et h er ne t mag azin e
09.2026
09.2026
SOURCE: .AUTOMATIONDIRECT
Cybersecurity
abnormal behavior and security risks faster while maintaining the availability and reliability required by industrial operations. As smart manufacturing continues to connect PLCs, robots, sensors, production systems, cloud platforms, and enterprise applications, these capabilities make it possible to take advantage of greater connectivity and data sharing without unnecessarily increasing operational risk. Ultimately, stronger cybersecurity enables manufacturers to adopt new technologies with greater confidence, making security an enabler of smart manufacturing rather than a barrier to innovation. “Cutting-edge industrial cybersecurity technologies are designed to protect factory systems without getting in the way of production. Newer tools can monitor industrial networks, learn what normal activity looks like, and alert teams when something unusual happens,” Wheeler said. “AI can help sort through large amounts of network and device information to identify possible threats faster. At the same time, newer PLCs, HMIs, gateways, and other industrial products are being built with stronger security features such as secure boot, signed firmware, encryption, user access controls, and security logging. Instead of relying on one security tool, these technologies create multiple layers of protection throughout the factory.” In practice, he noted that these technologies help manufacturers connect machines, production systems, business networks, and cloud services more securely. For example, passive monitoring can identify unusual PLC communications without actively scanning or disrupting production equipment, while industrial firewalls and secure gateways can control which devices are allowed to communicate. AI can then help security teams make sense of this information and focus on the issues that present the greatest risk. When these technologies are implemented using a framework such as IEC 62443, manufacturers can take advantage of greater connectivity and automation while still protecting the safety, reliability, and availability of their production systems. “One of the biggest concerns for automation engineers is finding the right balance between cybersecurity and keeping the plant running. Unlike traditional IT systems, industrial systems often cannot simply be rebooted, patched, scanned, or taken offline whenever a security issue is discovered,” Wheeler said. Changes can affect production, equipment reliability, and even personnel safety. Many facilities also have older PLCs, HMIs, and other equipment that were designed long before today's cybersecurity expectations. Engineers therefore need to understand the actual risk and apply security controls that make sense for
AutomationDirect supports cybersecurity needs by following global standards, reducing unnecessary complexity, considering the entire product lifecycle, and providing practical resources and guidance to help end users strengthen their overall approach without making cybersecurity feel disconnected from day-to-day operations. their environment rather than simply applying traditional IT security practices to the factory floor. “Another major challenge is resource limitations and the growing complexity of cybersecurity requirements. Automation teams are being asked to understand new regulations, standards such as IEC 62443, vulnerability management, network segmentation, secure remote access, and increasingly AI and cloudconnected technologies—all while continuing to support production,” he said. “Companies may not have enough people with experience in both cybersecurity and industrial automation, making cooperation between IT, OT, engineering, and management increasingly important. The most successful approach is a practical, risk-based strategy that focuses resources on the systems and threats that matter most while gradually improving the organization's cybersecurity maturity over time,” Wheeler added.
Protecting Networks versus Managing Operational Risk
Simply building a stronger perimeter is no longer sufficient. According to Steve Mustard, president of National Automation, Inc. and former president of the International Society of Automation, industrial cybersecurity is moving from protecting networks to managing
i n d u s tr i a l e th e r n e t m a g a z i n e
operational risk. Industrial environments are increasingly connected to enterprise systems, cloud services, remote support, IIoT devices, analytics platforms, and AI. Simply building a stronger perimeter is no longer sufficient. “One trend is improved asset visibility and contextualization,” Mustard told Industrial Ethernet. “Modern solutions increasingly identify not only what devices exist, but what they do, how they communicate, and how important they are to the industrial process. This enables cybersecurity decisions to be based on operational consequence rather than simply vulnerability severity.” Mustard said that network segmentation and zero-trust concepts are becoming more practical in OT. Technologies such as industrial firewalls, secure remote access, identitybased access controls and software-defined segmentation allow organizations to restrict communications without redesigning entire control networks. Secure-by-design products are another significant development, driven by standards, in particular ISA/IEC 62443. Asset owners increasingly expect security capabilities to be built into industrial products and systems rather than added afterward. “The overall trend is therefore toward integrated, risk-based cybersecurity: visibility, context, identity, segmentation, monitoring and resilience working together rather than as independent security products,” he said.
15
SOURCE: ISTOCKPHOTO
Cybersecurity “The overall trend is therefore toward integrated, risk-based cybersecurity: visibility, context, identity, segmentation, monitoring and resilience working together rather than as independent security products,” Steve Mustard, president of National Automation, Inc. and former president of the International Society of Automation.
AI Effect on Industrial Cybersecurity
“AI is affecting industrial cybersecurity in two very different ways: it is becoming both a cybersecurity tool and a new source of cybersecurity risk,” Mustard said. On the defensive side, he noted that AI can help analyze the enormous volumes of information generated by modern industrial environments. Machine-learning techniques can identify unusual communications, changes in device behavior and patterns that would be difficult for a human analyst to recognize. Generative AI can also help security teams investigate alerts, correlate information and explain complex findings, potentially making sophisticated cybersecurity capabilities accessible to organizations with limited specialist resources. However, AI does not eliminate the need for engineering judgment. An unusual network connection might indicate an attack, or it might represent a legitimate operational condition. In an industrial environment, understanding the process and its consequences remains essential. The operational consequences of interrupting a process in response to a suspected cybersecurity event may be more severe than the event itself. AI creates new attack surfaces. Organizations
16
must consider the integrity and provenance of data used by AI systems, manipulation of models or inputs, inappropriate autonomous actions, and the security of connections between AI platforms and operational systems. The important principle is that AI should augment industrial cybersecurity decisionmaking, not replace accountable human and engineering judgment.
Impact on Smart Manufacturing Networks
“The biggest benefit of newer industrial cybersecurity solutions is their ability to provide security while recognizing that OT networks have fundamentally different priorities from conventional IT environments,” Mustard said. “Availability, safety, product quality, and production continuity can be just as important as confidentiality.” Passive asset discovery and network monitoring, for example, can provide visibility without actively interrogating sensitive controllers. Industrial intrusion-detection technologies can understand protocols such as EtherNet/IP, PROFINET, Modbus TCP and OPC UA, allowing them to identify behavior that would appear perfectly legitimate to a conventional IT security product but may be
abnormal for the industrial process. Improved segmentation can also reduce the consequences of compromise. Instead of treating an OT network as one trusted environment, organizations can establish zones and conduits based on function and consequence, consistent with concepts defined in ISA/IEC 62443. For OT, these capabilities are particularly important because increased connectivity creates both opportunity and dependency. More data can improve optimization, predictive maintenance and production decisions, but every connection potentially creates another pathway for failure or attack. Effective industrial cybersecurity therefore enables digitalization. The objective is not to prevent connectivity, but to make connectivity appropriately controlled, observable and resilient.
Cutting edge cybersecurity
“Cutting-edge industrial cybersecurity increasingly combines several layers of technology rather than relying on a single defensive control,” Mustard said. “At the network layer, deep packet inspection can interpret industrial protocols and identify commands, configuration changes, and
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: ISTOCKPHOTO
Cybersecurity
“The question should not simply be, Are we secure? It should be: Do we understand our risks, their potential operational consequences, and whether those risks have been reduced to an acceptable level?, Steve Mustard, president of National Automation, Inc. abnormal communications. Passive monitoring allows this analysis to occur without introducing traffic into sensitive control networks.” At the architectural layer, segmentation technologies enforce permitted communication between industrial zones. Industrial firewalls, access-control lists, secure gateways and, increasingly, identity-aware technologies can restrict communication to explicitly required pathways. Secure remote-access solutions add multifactor authentication, session control, and auditing to vendor and engineering access. At the endpoint and device level, secure boot, signed firmware, hardware roots of trust, and stronger authentication help establish whether devices and software can be trusted. Asset-management and vulnerability platforms then combine device identity, firmware information, vulnerabilities, and operational context to support risk-based decisions. This all forms part of an integrated, consequence-based approach. A vulnerability 09.2026
with a high technical severity does not automatically represent the organization’s highest operational risk. Increasingly, cybersecurity information must be considered alongside asset criticality, network architecture, operational context, and the potential consequences of compromise. This allows organizations to move from asking, “What is vulnerable?” toward the more useful question: “What could actually affect our operation, what would the consequences be, and what should we do about it?” This is consistent with the risk-based approach embodied in the ISA/IEC 62443 series.
Concerns for Automation Engineers
“For automation engineers, one of the biggest concerns is that a cybersecurity control intended to reduce risk can itself create operational risk,” Mustard said. “A control that is routine in IT, such as automated patching, aggressive vulnerability scanning, or automatically isolating a suspicious device, can have very different consequences when the device controls a production process.”
i n d u s tr i a l e th e r n e t m a g a z i n e
Legacy equipment remains another major challenge. Industrial facilities frequently contain equipment with operating lives measured in decades. Some devices cannot support modern authentication, encryption, or endpoint-security software, and others cannot be patched without interrupting production. Replacement may be technically possible but economically or operationally impractical. Organizations also face a skills problem. Effective industrial cybersecurity requires knowledge of cybersecurity, networking, automation, process operations, safety and risk. Few individuals possess all those skills, making collaboration between IT, OT, engineering and operations essential. Finally, organizations must avoid treating compliance as the objective. Standards such as ISA/IEC 62443 provide an important framework, but implementing cybersecurity is ultimately an exercise in risk management. “The question should not simply be, ‘Are we secure?’ It should be: ‘Do we understand our risks, their potential operational
17
SOURCE: ISTOCKPHOTO
Cybersecurity “AI is reshaping industrial cybersecurity for both defenders and attackers. On defense, machine learning can now perform tasks that once required engineers to analyze packet captures manually, such as identifying normal behavior on aging SCADA networks, filling gaps in asset inventories from limited device data, and prioritizing the unpatched vulnerabilities that pose the greatest process risk,” Anand Edke, Cybersecurity Executive, Siemens US Digital Industries. consequences, and whether those risks have been reduced to an acceptable level?’” Mustard concluded.
AI Reshaping Industrial Cybersecurity
AI-assisted monitoring as a part of the broader security operation, not a separate plant function. Anand Edke, Cybersecurity Executive, Siemens US Digital Industries said that three technology trends are reshaping industrial cybersecurity. First, asset visibility is becoming more intelligent. Passive monitoring tools now use machine learning to identify device types and establish communication baselines for controllers that cannot report their own status, helping close a long-standing OT security gap. Second, identity is replacing network location as the basis of trust. More facilities assign each PLC, HMI, and workstation a unique cryptographic identity through plant-specific public key infrastructure, requiring devices to verify themselves before
18
communicating. Third, as plants send more process data to cloud historians and analytics platforms, security is moving closer to the edge. Lightweight cryptographic modules embedded in PLCs and RTUs can keep data encrypted from the machine to the cloud, while secure gateways extend similar protection to legacy devices. Together, these advances signal a shift from perimeter-based defenses to continuous verification and data-centric encryption. “AI is reshaping industrial cybersecurity for both defenders and attackers. On defense, machine learning can now perform tasks that once required engineers to analyze packet captures manually, such as identifying normal behavior on aging SCADA networks, filling gaps in asset inventories from limited device data, and prioritizing the unpatched vulnerabilities that pose the greatest process risk,” Edke said. Edke noted that a recent OT survey found that more than half of organizations placed OT security under the CISO in 2025, compared with 16 percent three years earlier. This shift reflects a growing view
that AI-assisted monitoring should be part of the broader security operation, not a separate plant function. At the same time, adversaries are using generative AI to create more convincing phishing messages aimed at operators. At least one tracked threat group has also used fake recruiter profiles on professional networking sites to gain initial access before targeting the network. AI has not reduced the need for OT expertise; it has expanded the range of skills that expertise must include.
Industrial Cybersecurity Solutions
When asked about the benefits of new industrial cybersecurity solutions, Edke said that the most practical benefit is better triage. A widely cited annual OT threat report found that only about three percent of tracked vulnerabilities in industrial environments require immediate patching, while roughly 71 percent can be managed through compensating controls such as segmentation or monitoring. Solutions that make this distinction automatically—rather than forcing engineers to sort through a CVE spreadsheet without context on how a
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: SIEMENS USA
Cybersecurity
Industrial cybersecurity has become the clearest point of joint concern and collaboration for both IT and OT professionals. controller is deployed—help stretched teams focus on the risks that matter most. “For smart manufacturing networks— where PLCs, robotics cells, and MES platforms stream data to cloud analytics systems and historians—encrypted and identity-verified pipelines make that connectivity safer. They allow teams to capture benefits such as predictive maintenance and cross-site benchmarking without turning a cloud connection into a shortcut into the plant,” Edke said. Another key benefit is faster detection of process-level tampering. Because many OT investigations still begin with an unexplained operational anomaly instead of a security alert, closing that gap helps teams catch manipulation before it becomes a quality defect, downtime event, or safety issue.
State-of-the-art Cybersecurity
Edke said that today’s OT security technologies stand out because they understand how plants operate instead of simply adapting IT tools for the factory floor. Deep packet inspection built for protocols such as Modbus, DNP3, PROFINET, and EtherNet/IP examines 09.2026
function codes and register values within each command. This context helps distinguish an authorized setpoint change during a shift from the same command sent at 2 a.m. by an unfamiliar workstation. Increasingly, this protocol-aware monitoring is paired with switch-level microsegmentation. This prevents, for example, a compromised packaging-line HMI from reaching PLCs that control a batch reactor several cells away, without requiring complete redesign of the physical network. In practice, a sensor can learn a control loop’s normal behavior over several weeks, then immediately flag a command that falls outside that pattern—whether caused by malware, an incorrect change, or a failing sensor. Because this monitoring does not alter the PLC’s logic or firmware, it is especially valuable for legacy equipment that cannot be easily patched or taken offline for testing.
Engineering Challenges
Edke said that the most common concern in plant discussions is not a single threat, but the challenge of securing legacy equipment. “Control systems installed 15 or 20 years
i n d u s tr i a l e th e r n e t m a g a z i n e
ago were not designed to be patched, segmented, or fully inventoried, yet replacing them may be impractical when production cannot stop. Recent manufacturing surveys rank cybersecurity as the second-highest external risk to production, and about one-third of manufacturers consider stronger IT/OT security architecture essential over the next five years. Even so, retrofits remain costly and maintenance windows limited,” Edke said. “Cloud-connected analytics and historians introduce another concern: unclear responsibility for encrypting process data and controlling access between plant operators and cloud providers. Many legacy devices also cannot support the encryption required for cloud connectivity without a secure gateway. The industrywide skills shortage is further compounding both these issues. Nearly half of manufacturers now consider cybersecurity expertise extremely important when hiring for automation roles, yet many candidates are trained in process control and safety, but not in network and cloud security,” he added. Al Presher, Editor, Industrial Ethernet
19
Cybersecurity
How to Make Industrial Networks More Resilient SOURCE: PHOENIX CONTACT
Mandatory implementation of verifiable security measures is now a requirement. The IEC 62443 series of standards, supplemented by European legislation such as the NIS 2 Directive and the Cyber Resilience Act (CRA), require operators and manufacturers to implement verifiable security measures.
Among the key regulatory frameworks is the international IEC 62443 series of standards, which defines the requirements for components, systems, and processes in industrial automation. WHILE THE INCREASING DIGITALIZATION OF industrial processes boosts efficiency and flexibility, it also makes modern production facilities more vulnerable to attacks. Cyberthreats no longer only target IT systems; they now increasingly affect operational technology (OT) as well. To ensure adequate protection, a growing number of standards and legal requirements have been established. Among the key regulatory frameworks is the international IEC 62443 series of standards, which defines the requirements for components, systems, and processes in industrial automation. It is supplemented by European legislation such as the NIS 2 Directive and the Cyber Resilience Act (CRA), which require operators and manufacturers to implement verifiable security measures.
20
NIS 2 extends responsibility beyond critical infrastructure systems to large parts of the industrial value chain. The CRA, on the other hand, addresses the cybersecurity of products with digital elements throughout their entire lifecycle. Together, these requirements aim to make industrial networks more resilient and ensure their continuous availability.
Securely developed devices with comprehensive security functions
Industrial networks consist of various components, each performing their own security-related role. Manufacturers such as Phoenix Contact offer solutions for these device categories that are developed using secure processes and are equipped with comprehensive security functions. Managed switches form the
backbone of communication. They ensure the segmentation, prioritization, and stability of data traffic. Security routers with firewall functionality protect the boundaries between zones or network segments and control who is allowed to access what. Wireless infrastructures, from industrial WLAN access points to cellular routers, enable flexible applications and remote access. At the same time, however, they open up additional attack vectors via wireless technologies in the public sphere. Many of these devices operate over long lifecycles within heterogeneous system structures. Misconfigurations, inadequately secured interfaces, or firmware updates that have not been installed can, over time, expose critical vulnerabilities and thus become a major security risk.
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: PHOENIX CONTACT
Cybersecurity
A comparison of the European NIS 2 and CRA legislation'
Diverse requirements for network components
How can certified network components actually increase the cybersecurity of industrial networks? From the point of view of IEC 62443, components must contribute to achieving the security levels defined by the standard within a system. For network technology components, this means secure management access, role-based user and rights administration, cryptographically protected communication channels, firmware integrity checks, and traceable logging of security-related events. In addition, there are hardening measures such as disabling unnecessary services or ports, protection against brute-force attacks, and secure update mechanisms. Only when these capabilities are present at the device level can operators efficiently map the zone and line models described in the standard in practice. The benefits of such functions are particularly evident in machine building and systems manufacturing. Today, production cells are typically designed as separate security zones with strictly defined communication relationships. Managed switches in these zones do more than just perform switching. They also logically separate the various machine components via VLANs, prioritize time-critical protocols (such as Profinet or EtherNet/IP), and support ring redundancy mechanisms to ensure high availability. Security routers installed at the boundary between the security zones enforce the strictly defined communication relationships mentioned above using integrated firewalls with stateful inspection. Remote service access can be enabled via IPsec or OpenVPN tunnels for a limited period of time and with unique authentication. This includes logging which connection was active when and which controllers were addressed. 09.2026
Comprehensive protection of critical infrastructure and older systems
Public infrastructure and critical supply networks face even stricter requirements. Here, the control room, remote control, and field levels must be protected against both external attacks and misconfigurations. For example, managed switches ensure that only
authorized devices are permitted access to specific ports (e.g., via port security, 802.1X, or MAC filters), thereby making manipulation attempts at Layer 2 level more difficult. Timestamped logs and integration with central Syslog or SIEM systems make it possible to track security-related events in the control center.
Use of managed switches and security routers in the control cabinet.
i n d u s tr i a l e th e r n e t m a g a z i n e
21
SOURCE: PHOENIX CONTACT
Cybersecurity Network components from Phoenix Contact are certified in accordance with IEC 62443.
A third common scenario involves retrofitting older systems. Many control systems were originally developed without a focus on security. As a result, they do not use encrypted protocols or modern authentication mechanisms. Here, operators use certified security routers as an upstream layer of protection to operate these components in isolated segments. Typical measures in this context include the strict allowlist configuration of permitted connections, the establishment of defined engineering access, and the restriction of remote access to clearly defined maintenance windows. In combination with switch functions such as the port security described above, this approach significantly reduces the attack surface without requiring a fundamental overhaul of the existing automation infrastructure.
Collaboration based on clear processes
Certified individual devices alone are not enough, however. They only unleash their full potential within a coordinated system architecture, as specified by IEC 62443: defense in depth, zoning, defined communication paths, and consistent hardening measures. It is crucial that all stakeholders, such as operators, integrators, and manufacturers, speak the same language and act according to clear processes. Companies like Phoenix Contact therefore complement certified products with secure development processes, solution architectures, and incident response structures. For operators, this means they can rely on end-to-end security concepts that extend beyond the individual device. Furthermore, IEC 62443 supports operators not only in
Certified cybersecurity from Phoenix Contact
Phoenix Contact offers a comprehensive portfolio of IEC 62443-4-2-certified products for industrial networks. These include the managed switches from the FL Switch 2000 series, security routers from the mGuard product family, and industrial cellular solutions such as the Cellulink routers for 4G/5G networks. Other series – such as the FL WLAN infrastructure devices with Wi-Fi 6/6E technology and the FL Switch 5900 series managed switches for 19-inch rack mounting – already meet key requirements of IEC 62443-4-2. All products are developed using secure development processes, certified in accordance with IEC 62443-4-1. They comply with the security functions described for use in demanding OT environments. In addition to secure products and processes, Phoenix Contact’s 360-degree security strategy also encompasses secure solutions and active vulnerability management by a Product Security Incident Response Team (PSIRT). The company thus supports operators in holistically securing industrial networks – from planning and operation to incident handling.
22
Phoenix Contact offers a holistic 360-degree security concept. developing holistic security concepts, but also in complying with new legal requirements, such as the Cyber Resilience Act (CRA). This is because many of the new legal requirements are already addressed by IEC 62443 (Figure 5). Industrial cybersecurity is not a static state, but an ongoing process. Certified components provide a robust foundation for this. They enable networks to be built in accordance with recognized standards, minimize threats, and ensure compliance with regulatory requirements. In an era of increasing digitalization and standardization, certified security components are thus an indispensable building block for stable industrial value creation. Jan Aulenberg, Product Marketing Network Technology, Phoenix Contact GmbH Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
Cybersecurity
Practical Takeaways from 2026 ISA OT Cybersecurity Summit
SOURCE: ISTOCKPHOTO
Sensor-rich devices and the operational demands of always-on infrastructure, along with the emergence of AI, are making organizations across critical sectors rethink how they manage cyber risk. This report shows how ISA brought together regulators, engineers, vendors and policymakers to tackle some of the toughest challenges.
The takeaways from Prague point to a common threat. Standards, workforce development, procurement practices and regulatory readiness all need to move in step as IT and OT systems continue to converge. Organizations that anchor their programs in proven standards like ISA/IEC 62443, build cybersecurity into engineering practice, test AI against their own OT environments and negotiate security expectations into contracts will be better positioned as NIS2 and CRA obligations take full effect. WITH THE RISE OF ARTIFICIAL INTELLIGENCE, sensor-rich devices and operational demands of always-on infrastructure, organizations across critical sectors are rethinking how they manage cyber risk. The International Society of Automation (ISA) brought together regulators, engineers, vendors and policymakers to tackle some of the toughest challenges in operational technology (OT) cybersecurity at the 2026 ISA OT Cybersecurity Summit (OTCS) in Prague. Through keynotes, forums, training sessions and in hallways and conference rooms, I saw so many great discussions bear fruit. Managing cybersecurity across connected industrial environments can often mean conflicting priorities, and I was glad to see so many people sharing their thoughts on how best to keep the world’s critical infrastructure safe and secure. I’d like to share a few of the overarching takeaways I gathered from attending and speaking at OTCS this year.
Fund and Operationalize Existing Frameworks
At the Cyber Empowerment Forum, moderated by Megan Samford, VP, Product & Supply Chain Security at Schneider Electric, Tatyana Bolton 09.2026
of the Operational Technology Cybersecurity Coalition identified funding and adoption, not a shortage of frameworks, as the limiting factor in OT security progress. The ISA/IEC 62443 series of standards, for example, is already widely adopted all over the world. Bolton’s recommendation was to embed baseline cybersecurity expectations directly into contracts, supply-chain relationships and industry guidance, giving asset owners, suppliers and system integrators a consistent minimum standard of care from which to work.
Build Cybersecurity into Engineering Practice
Cheri Caddy of Savannah River National Laboratory, also speaking at the Cyber Empowerment Forum, focused on the engineering workforce. Electrical, mechanical, civil, nuclear and software engineers all make design decisions that shape security posture. Caddy suggested building cyber-informed engineering education and disciplined processes into workforce development, treating cybersecurity as an engineering problem set rather than a function handled solely by IT.
i n d u s tr i a l e th e r n e t m a g a z i n e
Use International Cooperation as a Resilience Tool
Berta Jarošová, speaking then in her role as cyber attachée to the United States and Canada at the US Embassy of the Czech Republic, highlighted the Czech Republic's cooperation with US agencies on ransomware notification, using rapid target identification and indicator-sharing to help defenders act before incidents escalate. Her keynote on transatlantic cyber cooperation added another point: organizations should apply the joint advisories developed by US, European, Indo-Pacific and Five Eyes partners directly to their own defenses, since these advisories provide actionable, publicly available threat intelligence. She also pointed to Prague and Brno as a growing cybersecurity ecosystem linking national cyber capabilities, universities, AI labs and industry investment.
Apply Secure-by-Design Principles Early, and Test AI
Panelists at the Cyber Empowerment Forum agreed that AI and sensors are expanding the number of systems organizations must secure. Their guidance was to apply secure-by-design
23
SOURCE: ISA
Cybersecurity Cybersecurity panel at the 2026 ISA OT Cybersecurity Summit (OTCS) in Prague. principles from the earliest stages of system planning, rather than retrofitting security once systems are deployed. As Bolton recommended, organizations should actively test how AI affects their own OT systems and client environments, since AI both strengthens defensive capability and speeds up adversary activity. The panel also recommended refreshing legacy practices such as annual risk assessments and static vulnerability scoring, and building resilient OT architectures around segmentation, secure remote access and rapid detection.
Distinguish NIS2 from CRA Before Building Compliance Plans
The European Union’s Cyber Resilience Act (CRA) remains top of mind for suppliers. At the "From Compliance to Execution" forum, moderated by Steve Mustard of au2mation, with Ilja David of Iron OT, Gustav Martin Bartel of Robert Bosch GmbH, Dr. Lukasz Kister (CRA Expert Group member, representing Honeywell) and Petr Kopřiva of BDO Consulting s.r.o., the panel's first recommendation was to treat NIS2 and the CRA as separate instruments with distinct obligations. NIS2 governs day-to-day risk management for operators of essential and important services. The CRA governs manufacturers of digital products across the full product lifecycle, from design through end of life, requiring secure-by-default delivery and continuous vulnerability management.
Start Compliance Work with Risk Assessment, and Negotiate Security Terms
The compliance forum panelists recommended anchoring compliance work in a risk assessment, since both NIS2 and the CRA are risk-based frameworks. Organizations that base their compliance programs on actual
24
operational risk are best-positioned to hold up to regulatory review. Furthermore, organizations should review their procurement contracts carefully. As the panelists stated, security clauses and SLAs should be negotiated at the contract stage, and operational staff should understand those terms once contracts are signed, as well as legal teams.
Track Upcoming Legislation for Alignment
In a keynote on the operational threat environment and cyber legislation in Europe, UK Parliament CISO Mark Harbord framed cybersecurity as a matter of operational resilience, mandatory governance and supply-chain assurance. He recommended that organizations track upcoming legislation such as the UK’s forthcoming Cyber Security and Resilience Bill, which he emphasized will be more aligned with NIS2, the Digital Operational Resilience Act (DORA) and the CRA. In a world where cybersecurity is a geopolitical concern, organizations should prepare their own programs accordingly.
Build from Standards as the Foundation
As ISA’s CEO, I used my time at the podium at OTCS to point to ISA's cybersecurity work going back to the establishment of the ISA99 committee in 2001. ISA99 developed the ISA/ IEC 62443 series, which is relied upon all over the world and anchors initiatives like the ISASecure® conformity assessment and the ISA Global Cybersecurity Alliance (ISAGCA), in addition to ISA’s cybersecurity training and certification programs. I emphasized in my keynote that industrial cybersecurity depends on sustained collaboration among technology providers, asset owners, governments,
educators and cybersecurity professionals. Consensus-based globally relevant standards are the foundation from which we can build a safer and more secure world.
With OT Cybersecurity, Collaboration Is Key
As the speakers at the 2026 OT Cybersecurity Summit made clear, industrial cybersecurity is now well past the point of being just a strategic concern for some distant future. Organizations need to focus on execution, and they need to do it today. The takeaways from Prague point to a common thread: standards, workforce development, procurement practices and regulatory readiness all need to move in step as IT and OT systems continue to converge. Organizations that anchor their programs in proven standards like ISA/IEC 62443, build cybersecurity into engineering practice, test AI against their own OT environments and negotiate security expectations into contracts will be better positioned as NIS2 and CRA obligations take full effect. With vulnerability and incident reporting requirements under the CRA now in place as of September 2026, and the 2027 deadline for full essential cybersecurity requirements quickly approaching, speakers at OTCS offered a practical roadmap. The organizations that treat these recommendations as immediate operational priorities will be those bestequipped to manage risk across an increasingly connected industrial landscape. For anyone interested in joining these conversations around the future of OT cybersecurity, the next OTCS will be hosted in Athens, Greece 16-17 June 2027. Claire Fallon, Chief Executive Officer, ISA Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
IT-OT Convergence
IT-OT Convergence and AI Shaping Network Operations
SOURCE: INDUSTRIAL ETHERNET
Industrial IT/OT convergence is continuing to accelerate as edge computing, open protocols, AI and stronger cybersecurity reshape how plants connect, contextualize, and govern data—turning once‑isolated systems into unified, insight‑driven operations.
“The most effective answers to IT/OT convergence are usually architectural patterns rather than a single product. That can include segmented networks, industrial gateways or edge agents, open protocol adapters, a governed operational data layer, semantic models, ontologies or a Unified Namespace, hybrid analytics, and secure application lifecycle management," -- Chris Herrera, Head of API and Interoperability at Seeq. INDUSTRIAL ENVIRONMENTS ARE UNDERGOING a profound architectural shift as IT/OT convergence moves from aspiration to necessity. Manufacturers are replacing isolated, site‑specific systems with hybrid edge‑to‑cloud designs that keep time‑critical control close to the process while enabling enterprise‑level analytics, governance, and cross‑site learning. Open, multi‑protocol connectivity—OPC UA, MQTT, Modbus TCP, EtherNet/IP, REST APIs— is becoming the backbone that dissolves data silos and supports Unified Namespace models where contextualized events flow freely to automation, MES, analytics, and AI systems. At the same time, powerful industrial PCs, containerized edge software, and secure-bydesign OT products are enabling advanced processing, AI inference, and protocol conversion directly at the edge, reducing 09.2026
latency and improving resilience. Cybersecurity frameworks, regulated expectations, and AI‑driven analytics are pushing organizations toward more governed, collaborative architectures. The result is a new era where industrial data becomes accessible, contextual, secure, and actionable—fueling reliability, optimization, and smarter decision‑making across the enterprise.
Open, Multi-Protocol Connectivity
Focus is moving from isolated, site-specific systems toward hybrid edge-to-cloud architectures. Chris Herrera, Head of API and Interoperability at Seeq said that IT/OT convergence is moving
i n d u s tr i a l e th e r n e t m a g a z i n e
from isolated, site-specific systems toward hybrid edge-to-cloud architectures. Timecritical processing and resilience stay close to equipment on the shop floor, while cloud and enterprise platforms handle governance, fleet-wide analytics, and cross-site learning. “Open, multi-protocol connectivity is essential for effective IT/OT convergence. Manufacturers need to connect assets using OPC UA, MQTT, Modbus TCP, EtherNet/IP, REST APIs, and other standards instead of building a point-to-point integration for every application,” Herrera said. “Unified Namespace architectures are emerging as a shared, event-oriented information layer that makes contextualized operational events available to automation, analytics, MES, and enterprise applications.” Herrera said that context is just as important
25
IT-OT Convergence
as connectivity, and a tag or alarm is useful only with asset, process state, batch, product, recipe, and operating-mode context. Softwaredefined automation and industrial edge platforms bring control-adjacent workloads and analytics onto manageable infrastructure while keeping real-time and non-real-time functions isolated. AI is also a driving force, as organizations pursue faster and more productive ways of using operational data, raising the importance of cybersecurity, governance, and context. Ontologies and context providers connect AI to assets, processes, and operating states, while human-in-the-loop design keeps people accountable for decisions.
Technology Solutions
“The most effective answers to IT/OT convergence are usually architectural patterns rather than a single product. That can include segmented networks, industrial gateways or edge agents, open protocol adapters, a governed operational data layer, semantic models, ontologies or a Unified Namespace, hybrid analytics, and secure application lifecycle management,” Herrera said. Many of these technologies are mature, yet the IT/OT gap remains. Historically, convergence often meant copying OT data into IT, but consuming meaningful, contextualized outputs while preserving authoritative sources is a better approach. Systems like Seeq serve as an industrial analytics and decision layer across historians, databases, cloud sources, and other systems, empowering engineers to work with time-series data in context. It is not intended to replace PLCs, DCSs, safety systems, historians, or a customer’s broader data platform, but its role is to add context to signals, conditions, events, and calculations so they are more useful to people and workflows. A unified namespace (UNS) can expose normalized events, while ontologies help explain what those events mean. AI extends this model through governed, natural-language questions. An agent can resolve asset and time context, call the right connector or analytics service, and retrieve evidence without copying every signal. But maintaining accuracy is a challenge: evaluations must cover query selection, calculations, provenance, permissions, uncertainty, and safe abstention. Deterministic calculations and repeatable tests make that reliability measurable, while people remain responsible for final decisions.
Specific Technical Benefits
Herrera noted that these technologies provide benefits at several levels. At the plant or edge, local processing can reduce latency for anomaly detection, quality monitoring, predictive maintenance, and operator assistance. Filtering, aggregation, compression, and event-
26
based transmission reduce the need to move high-frequency raw data. And local buffering improves resilience when cloud connectivity is intermittent. And at the data level, contextualization, timestamp alignment, asset modeling, and operating-state awareness make analytics more trustworthy and reduce false alarms. Seeq helps engineers define and scale conditions, events, calculations, and analytical patterns that connect operations to quality, reliability, energy, production, or business context. Enterprise applications can consume those outputs without understanding every sourcesystem detail. At the enterprise level, a governed data foundation—potentially including a UNS— makes reuse easier. Once a source is connected and its data has consistent meaning, multiple teams and sites can use the same analytical patterns instead of creating custom integrations. Identity controls, segmentation, encrypted transport, and managed updates make the environment easier to protect. “So the end goal is not simply connecting more equipment, but creating a repeatable path from machine data to governed insight and action, while keeping deterministic control and safety functions local and within normal OT change-management practices,” he said.
How the Technology Works
Herrera said that an effective IT/OT architecture starts with the control and information systems already operating in the plant. Sensors provide measurements, PLCs execute control, and DCS/SCADA provides a graphical interface and alarming. Historians capture and retain timestamped time-series data, but they do not, by themselves, explain what each tag means or why a value changed. Determining this requires context. A temperature tag, for example, should be tied to a specific asset, location, unit, operating mode, batch, and set of engineering limits. Other important sources of context include current P&IDs linked to tags, SOPs, asset hierarchies, maintenance history, and FMEA analyses. They should be current, versioned, searchable, and linked to signals; otherwise, both AI systems and human users can end up working with technically correct data in the wrong operational context. Systems like Seeq query source data in place and contextualize signals, conditions, events, and calculations without copying data. An AI assistant can resolve the asset and time range, retrieve data and documents, apply calculations, and return evidence. If context is missing or stale, it should abstain, and human review must remain in the workflow before action. A UNS or context-provider layer can publish normalized events, while secure connectivity and auditability support the combination of
control data, historization, and engineering knowledge.
Progress Toward IT/OT Convergence
“IT/OT convergence has been a north star for many organizations for years. AI is now adding urgency, pushing companies to move faster and get more value from operational data. But organizations cannot simply roll out AI without addressing how it is implemented,” Herrera said. ‘AI needs context to be useful in an industrial environment. Operational data models, ontologies, and context providers must connect signals with the assets, processes, documents, and operating states they represent to make human-assisted AI practical and narrow the gap between OT and IT. It also gives teams something concrete to evaluate: Did it use the right sources and calculations? Did it apply the correct engineering context? Those are the types of questions that should be answered before trusting a result.” “Progress depends on more than connectivity. Organizations need governed architectures that preserve OT boundaries, maintain authoritative sources, and expose meaningful information to AI and enterprise workflows. Agentic systems should be tested against defined scenarios and expected ranges, with traceable tool calls, permission checks, regression testing, red-team cases, and human review before action is taken. Flexible orchestration can be valuable, but a convincing answer is not the same as a proven one. cloud security,” he concluded.
Connecting Data Islands the Priority
Democratizing data to ensure it can get where and when it’s needed to help users and analytics systems turn data into actionable information. According to Gene Juknevicius, solution architect at Emerson, connecting data islands has become an imperative across nearly every industry. In the OT world, teams have different control and monitoring systems, and each often have their own data, protocol stacks, and key objectives. He said that systems typically don’t communicate well, if at all, with each other. This creates data islands, with critical information siloed. Teams are looking for ways to democratize data to ensure that it can get where and when it is needed to help human users and analytics systems turn that data into actionable information. Another trend that is becoming common is that compute power at the edge is steadily increasing. “Historically, in the OT world, edge control technology was very limited in its capability. But today, powerful and robust edge compute devices—along with modern, fully featured operating system and application
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: ISTOCKPHOTO
IT-OT Convergence
Gene Juknevicius, solution architect at Emerson: "Connecting data islands has become an imperative across nearly every industry. In the OT world, teams have different control and monitoring systems, and each often have their own data, protocol stacks, and key objectives." software—are available to help OT teams unlock more sustainable, flexible, efficient, and profitable operations,” Juknevicius said. “Much of this capability comes from analytics, but teams are learning that some of their goals cannot support the latency or cybersecurity risk of constantly sending data back and forth to and from the cloud or remote data centers.”
that makes them easy to configure, deploy and maintain. Both the best modern IPCs and the most advanced edge software platforms are also designed to communicate with a multitude of PLCs and IO devices, providing the seamless integration necessary to eliminate data silos.
Impact on Industry
Juknevicius said that the most advanced modern IPCs bring high-performance and AI-accelerated computing power right to the edge without sacrificing the stability necessary for industrial operations. With no moving parts, soldered memory, and reliable SSD storage, modern IPCs can deliver AI-capable performance at the edge without the risk of high vibration, extreme temperatures, or dust and dirt contamination causing failures. In addition, the most advanced IPCs offer far longer lifecycles than off-the-shelf consumer hardware, empowering teams to implement validated solutions without fear they will have to re-validate if they need to replace an IPC within a typical industrial lifecycle. “Edge software solutions empower teams to run applications, process data, and integrate systems in a containerized environment as close to the industrial application as possible. These solutions provide a sandbox environment for development of advanced applications like analytics and vision systems, and they create a centralized solution for protocol conversion,” Juknevicius said. Instead of a wide variety of analog
“If a team is putting all its data up in the cloud before they perform analytics, they can only send so much data, and it becomes easy to miss valuable insights that can only be captured right at the device,” Juknevicius said. “This challenge only increases as operations become more remote and cloud connectivity becomes less reliable, such as in mining operations. As a result, we’re seeing far more compute power being delivered right at the edge, including full operating systems that can perform more complex and power-consumptive tasks. Today, teams are leveraging that processing power to run AI processing right at the edge. This power comes from technologies like modern industrial PCs (IPC) that provide ruggedized and increased processing power for deployment closer to the process to leverage AI at the edge to provide feedback and adjust processes in real time,” he added. In addition, OT teams are also increasingly leveraging solutions like Emerson’s PACEdge™ software to transform those industrial PCs into more intelligent edge nodes in a very freeform manner in a containerized, intuitive format 09.2026
New Levels of Enterprise/ Automation Integration
i n d u s tr i a l e th e r n e t m a g a z i n e
connections—modern IO devices now integrate serial, wireless or even Ethernet/IP interfaces— simplifying connectivity to the edge systems where different protocols can be terminated, and where data can be normalized and made available to the upper software layers in a uniform fashion. “Consider a device like a temperature sensor which traditionally transmitter data using a 4-20 mA analog signal. Today, a temperature sensor might instead have a microcontroller powerful enough to run a true IP protocol stack and support an ethernet port, wi-fi, or even low-energy Bluetooth,” he said. “It can communicate via an IT protocol like MQTT or OPC UA. That allows automatic connectivity to the IPCs without a need for hardware-specific converter devices so that the data can flow naturally from the OT world into the IT stack.“ He added that there are also many more applications designed to perform AI processing in the OT world, right on edge devices, to bring the benefits of AI to the edge. These solutions, with vision systems being the most common example today, can often work in closed-loop control systems because they meet the latency requirements necessary to operate without disrupting the process. In terms of the software stack, in the IT world, technologies like virtualization have been the standard for a long time. But in OT, compute power has typically been insufficient. Memory and processing cores were much more limited, so virtualization was much harder to implement than with IT-based systems.
27
SOURCE: EMERSON
IT-OT Convergence Emerson’s next-generation Industrial PCs, edge controllers, and PACEdge™ software create a unified data fabric that seamlessly connects OT assets with IT systems to support protocol conversion, edge analytics, and cloud integration.
Now, with the increase of the available compute power at the edge, and advances in software containerization, the concept of micro services has emerged. Instead of using virtual machines and virtualizing the full operating system, teams can instead use containers to provide isolated environments for applications, while sharing many of the same software resources in the operating system. Now, teams can easily add, remove, or replace applications without worrying about software conflicts and other technology challenges. This approach is more cybersecure, and far more intuitive to implement. Given the challenges of IT-OT Convergence from a technology perspective, Juknevicius said that the trend is connectivity. “Today, seemingly everything in the OT environment is being connected to everything else to make the best use of the data as it is the key to operational excellence. To gain the best business insights, teams need access to data— the more robust, granular, and real-time the better—so they can drive the desired business outcomes resulting from timely decisions,” he said. “Moreover, if the ultimate vision is
28
autonomous control, teams will need to be able to deploy the technologies that have traditionally been stuck in the IT realm, and they will need to do so as close to the OT devices as possible. The outcomes will be better reliability, better optimization, and more uptime—ultimately improving business outcomes,” he concluded.
Edge Controllers Communicate Multiple OT Protocols
Technology is collapsing the gap between the plant and the enterprise. According to Dan White, Director of Technical Marketing at Opto 22, convergence used to mean bolting a PC gateway between the plant and the enterprise. The trend now is collapsing that gap. Edge controllers speak OT protocols like Modbus, Ethernet/IP, ProfiNET, OPC UA and IT protocols like MQTT and REST—all from the same device. The translation layer that used to be its own box is now a feature of the controller. A second trend is publish-subscribe data movement. MQTT with Sparkplug decouples
who produces data from who consumes it. A controller publishes once, and SCADA, a database, and a cloud analytics service all subscribe. You stop building point-to-point integrations for every new consumer. And third, IT technology is showing up natively in OT gear: Linux, containers, Git, standard APIs. That lets OT teams use IT tools, and lets IT people work with equipment they recognize. The result is that the old Purdue model—rigid layers stacked between the sensor and the enterprise—is flattening. Data can move from an I/O point to a cloud database in one hop, securely, without the middle layers that used to define plant architecture.
Potential Solutions for IT-OT Convergence
“A few technologies do most of the work. Edge programmable controllers combine real-time control with an IT-friendly computer, so one device handles the machine and the data. MQTT with Sparkplug provides the messaging backbone: lightweight, secure, and built for report-by-exception, which fits industrial data far better than constant polling,” White said. “OPC UA still has its place, as a way to
in d u s t r ial et h er ne t mag azin e
09.2026
09.2026
None of them talk to the controller directly, which keeps it protected. “And if you need to do some work on the data first, onboard tools, like Node-RED or Ignition Edge can run right on the controller. You filter, reshape, and even add context to data at the edge before it ever leaves the plant,” White said. “The payoff is real-time data from across the whole plant that any authorized system can use, and you don't have to rebuild the network every time you add one.”
ways to use the people and technology they already have. Successful convergence does not necessarily mean combining IT and OT into a single organization. Instead, it means establishing clear responsibilities, communication paths, and shared security processes while recognizing that OT environments have different priorities than IT—particularly safety, availability, reliability, and operational continuity,” he added.
Challenges of IT-OT Convergence
Wheeler said that regulation is accelerating IT-OT convergence because cybersecurity is increasingly becoming a product, operational, and business requirement rather than simply an IT concern. Requirements and frameworks such as the EU Cyber Resilience Act (CRA), IEC 62443, NIS2, and sector-specific critical-infrastructure requirements are pushing organizations toward more structured cybersecurity practices across the entire lifecycle of industrial products and systems. Meeting these expectations requires cooperation across departments that historically operated independently. Engineering, IT, OT, cybersecurity, legal, product management, and supply-chain teams increasingly need to share information and coordinate activities such as vulnerability management, asset inventories, SBOMs, incident response, access control, patching, and risk assessment. Regulation is therefore helping drive convergence not simply at the network level, but at the organizational and process level.
“Convergence matters more every year, and I think the technology side is largely solved. Edge controllers, MQTT, Sparkplug, and OPC UA are proven and in production across the industry,” White said. “Sparkplug is now a managed open standard, brokers are mature, and the tooling is good. If you start a project today, you are not fighting the technology. The progress that is left is cultural. The hard part was never the protocols. It was getting IT and OT to share ownership, agree on who secures what, and trust a shared data layer. That is people and process, and it moves slower than firmware.” “My honest opinion: we have crossed the point where convergence is a question of whether. It is now a question of how well. The plants pulling ahead are the ones treating their data as a shared asset instead of two teams guarding two networks. The technology has done its job. The remaining work is organizational, and that is where companies should put their attention now,” he concluded.
Resources, Regulation and AI
Organizations can no longer afford to treat IT and OT cybersecurity as completely separate efforts. Tim Wheeler, cybersecurity manager for industrial products at AutomationDirect told Industrial Ethernet that three key technology trends shaping IT-OT convergence are resources, regulation, and artificial intelligence. “One of the biggest drivers of IT-OT convergence is resources. Organizations can no longer afford to treat IT and OT cybersecurity as completely separate efforts, especially as industrial environments become more connected. OT teams traditionally have strong knowledge of the physical process, industrial equipment, and operational risks, while IT teams often have greater experience with networking, identity management, cloud services, cybersecurity monitoring, and enterprise security tools. Bringing these resources together allows organizations to take advantage of the strengths of both groups rather than attempting to duplicate expertise,” Wheeler said. “At the same time, the shortage of experienced OT cybersecurity professionals is forcing organizations to find more efficient
i n d u s tr i a l e th e r n e t m a g a z i n e
IT-OT Convergence
consolidate various proprietary protocols into a single information model. And container platforms plus tools like Node-RED let teams add logic, protocol conversion, and integrations without ripping out the controller.” White said that why it matters is that these are open, widely supported technologies, not one vendor’s proprietary stack. That lowers the risk of lock-in and lets IT and OT meet on common ground. The impact on industry is practical. When a controller can publish clean, described data straight to a database or cloud service, you stop spending projects on plumbing and start spending them on outcomes: predictive maintenance, energy tracking, quality analytics. Convergence stops being an integration headache and becomes the plumbing that finally lets a plant use its own data. When asked about the specific technical benefits these solutions provide, White said the clearest benefit is cybersecurity. Almost every recent OT attack exploits the same weakness: a controller exposed to the internet with open inbound ports. In July 2026, coordinated attacks hit more than 30 Minnesota water systems through internet-facing PLCs—attackers changed passwords, locked out operators, and forced a switch to manual control. “A publish-subscribe architecture removes that exposure,” White said. The controller makes one outbound, encrypted connection to a broker and authenticates with a certificate. There are no inbound ports to scan and no controller sitting on the public internet. Secure connectivity becomes a property of the design, not a firewall rule you hope holds. The integration benefits follow from the same model. Decoupling lets you add a consumer, like a dashboard, a databased, or an ML model, without touching the controller. Sparkplug's self-describing data carries structure and context, so tags arrive already explained instead of mapped by hand. “Let's walk through the data, start to finish,” White added. “An edge controller scans its I/O the way it always has, reading sensors and driving outputs. When a value changes, the controller sends that change to an MQTT broker over an encrypted connection. That's called report-by-exception. The network carries data only when something actually happens, instead of asking every point "what's your value?" over and over on a timer.” Sparkplug adds the structure. When a device connects, it introduces itself with a birth message that lists every tag it has and each one's current value, so any subscriber knows the device's full state right away. If the device drops off, a death message lets everyone know. Nobody has to wonder whether their data is stale. The subscribers, like a SCADA screen, a SQL database, or a cloud service, all connect to that same broker and get only the tags they ask for.
Regulation
Artificial Intelligence
AI is another major driver of IT-OT convergence. Industrial organizations are beginning to use AI for cybersecurity monitoring, predictive maintenance, anomaly detection, engineering assistance, vulnerability research, and analysis of large amounts of operational data. To provide value, many of these technologies need access to information that historically remained within isolated OT environments. This creates both opportunities and new risks. Connecting industrial data and systems to AI platforms can improve visibility and efficiency, but it also introduces questions about data security, system access, cloud connectivity, trust, and the ability of AI-driven decisions to affect physical processes. Organizations will need IT, OT, engineering, and cybersecurity teams working together to establish appropriate boundaries for AI. The challenge will be gaining the benefits of AI without introducing connectivity or automation that negatively affects the safety, reliability, or security of industrial operations.
IT-OT Convergence Solutions
“Emerging technologies are providing new ways to address the challenges associated with IT-OT convergence, with artificial intelligence
29
SOURCE: AUTOMATION DIRECT
IT-OT Convergence For new automation systems or updates of existing installations, IT-OT convergence is essential for realizing the full value from massive amounts of field-sourced data available, especially for AI and analytical purposes. Modern PLCs, like the AutomationDirect CLICK and BRX, provide a capable way to connect OT-centric manufacturing zone data up to the IT-centric enterprise zone while addressing safety, reliability, regulatory, and other requirements. being one of the most significant. AI can help organizations process the growing amount of information generated across both IT and OT environments, improving areas such as anomaly detection, predictive maintenance, asset monitoring, vulnerability identification, and incident response,” Wheeler said. “As industrial environments become more connected, AI can help teams identify patterns and potential risks that would be difficult to recognize manually. However, the value of AI will depend on how responsibly it is integrated into OT environments, with appropriate controls to ensure that new capabilities do not negatively affect safety, availability, or reliability.” He noted that equally important is the continued growth of cybersecurity frameworks and the security capabilities built into OT products themselves. Frameworks and standards such as IEC 62443 are creating a more consistent approach to securing industrial environments, while manufacturers are increasingly incorporating technologies such as secure communications, authentication, role-based access control, secure boot, signed firmware, logging, and improved vulnerability management directly into industrial products. As OT devices gain the resources necessary to support these capabilities, organizations can begin applying stronger security controls
30
without relying entirely on external IT security solutions. Together, AI, mature cybersecurity frameworks, and more capable OT products can help industry achieve convergence in a controlled manner—taking advantage of the connectivity and visibility of IT while maintaining the safety, reliability, and availability required by OT.
Enterprise/automation Integration
These solutions provide several important technical benefits by improving visibility, communication, security, and decisionmaking across IT and OT environments. AI can help analyze large amounts of operational and cybersecurity data to identify abnormal behavior, equipment issues, and potential threats more quickly. At the same time, maturing cybersecurity frameworks provide a common structure for managing access, network segmentation, secure communications, vulnerability management, and incident response. Modern OT products are also gaining the processing power and security capabilities needed to support technologies such as encryption, secure boot, signed firmware, role-based access control, logging, and more secure industrial protocols. Together, these improvements allow organizations to increase connectivity without having to sacrifice the
safety, availability, and reliability required in industrial environments. “From an enterprise and automation integration perspective, these capabilities allow information to move more securely between the plant floor and enterprise systems. Production data can be made available to business applications, analytics platforms, cloud services, and AI tools while stronger security controls help maintain separation between critical control functions and higherlevel enterprise networks,” Wheeler said. “This can improve predictive maintenance, production planning, asset management, cybersecurity monitoring, and overall operational visibility. Ultimately, the goal of IT-OT convergence should not simply be to connect more systems—it should be to create secure, controlled pathways for sharing the right information with the right systems while protecting the industrial process itself.”
New possibilities for Addressing Challenges
Wheeler noted that modern IT-OT integration works by creating controlled and secure pathways for data to move between industrial systems and enterprise platforms without exposing critical control functions to unnecessary risk. Technologies such as
in d u s t r ial et h er ne t mag azin e
09.2026
optimization moves securely into enterprise systems. “The enabling technology trend is therefore the development of purpose-built edge controllers that embody the growing collaboration between IT and OT. Rather than favoring one discipline over the other, these technologies are designed from the outset to respect the unique strengths and requirements of both,” Cloutier said. “They enable each discipline to continue doing what it does best while providing the secure, reliable, and predictable exchange of information needed for modern industrial systems. The result should be solutions valued equally by enterprise architects and automation engineers alike, providing the all-important confidence and longevity demanded by both.”
IT-OT Convergence Solutions
Cloutier said that the technologies enabling IT-OT convergence are commonly known. More interesting are the technologies increasingly challenging its future. For more than two decades, the industry has spoken of IT-OT convergence as though it were an inevitable destination. Ethernet, standardized protocols, and secure SOURCE: INTEG
but that the interaction between them is becoming increasingly collaborative. Modern automation systems are expected to provide secure, structured access to operational data while continuing to meet the deterministic and long-life requirements of industrial control,” Cloutier said. “The growing overlap has driven adoption of standardized communications, stronger cybersecurity, and enterprise connectivity, allowing IT and OT systems to cooperate without sacrificing the unique strengths of either.” Cloutier said that the expanding overlap requires each discipline to contribute its strengths without imposing its architecture on the other. OT systems must expose useful operational information through secure, well-defined interfaces while preserving deterministic control, reliability, and long service life. IT systems must consume that information, manage identities and access, correlate data across the enterprise, and support analysis without becoming part of the real-time control path. The most successful integration therefore establishes a deliberate boundary: operational decisions remain close to the equipment, while information needed for supervision, maintenance, planning, and
IT-OT Convergence
industrial firewalls, secure gateways, network segmentation, encrypted protocols, role-based access control, and centralized logging provide the foundation for this connectivity, while newer OT products increasingly have the processing resources to support these security capabilities directly. AI can then analyze information collected from both environments to identify abnormal behavior, cybersecurity threats, equipment degradation, and operational trends that may otherwise go unnoticed. Cybersecurity frameworks such as IEC 62443 provide the structure for determining where these technologies should be applied and how systems should be separated into appropriate security zones and communication paths. Together, these technologies create new opportunities to securely connect plant-floor information with enterprise analytics, cloud platforms, predictive maintenance systems, and business applications while maintaining the safety, availability, reliability, and integrity of the industrial process. “IT-OT convergence will continue to grow in importance as industrial systems become more connected, capable, and dependent on enterprise technologies, but successful convergence requires a thoughtful and balanced approach rather than simply applying traditional IT solutions to OT environments,” Wheeler said. “Organizations should adopt a risk-based process that considers the specific needs of their systems, including safety, availability, reliability, cybersecurity, operational requirements, and business objectives. Continued improvements in OT security capabilities, cybersecurity frameworks, AI, and collaboration between IT and OT teams are making secure integration increasingly achievable.” “The goal should not be convergence for the sake of connectivity, but rather to identify where integration provides meaningful operational or business value and then implement it with security controls appropriate to the actual risks. Ultimately, there is no single solution that works for every industrial environment; organizations must develop an approach that balances risk and opportunity while protecting the systems and processes that matter most to their operations,” he concluded.
IT/OT Collaboration
Growing overlap has driven adoption of standardized communications, stronger cybersecurity, and enterprise connectivity. Bruce Cloutier, CEO/Founder of INTEG Process Group, said that key technology trends are shaping the discussion about IT-OT Convergence. “Consider the perspective in which IT and OT are not converging into a single discipline, 09.2026
The INTEG Process Group JNIOR automation controller, first envisioned over 20 years ago, was architected to deliver balanced functionality, determinism, and longevity, providing designers with a trustworthy platform incorporating the unique strengths of both IT and OT, so end users can easily handle the increasing demands of IIoT, AI, and other applications.
i n d u s tr i a l e th e r n e t m a g a z i n e
31
SOURCE: ISTOCKPHOTO
IT-OT Convergence “Today, AI comes along with its own insatiable appetite. Not just for the information that we have deemed important, but for every possible data point it can consume. If we are going to ask AI to tell us what is important. If we want AI to identify correlations that we had never before recognized, then it needs to be fed EVERYTHING," Bruce Cloutier, CEO/Founder of INTEG Process Group. communications have unquestionably brought the two worlds closer together. Yet at the very moment convergence appears within reach, one of its greatest enablers has become one of its greatest challenges. Strong encryption, authenticated identities, and trusted communications have enabled OT devices to participate safely in enterprise networks. But each new generation of cybersecurity demands potentially unavailable computational resources, more frequent updates, and increasingly complex trust infrastructures. Those expectations fit naturally within enterprise computing, yet they challenge industrial platforms designed for deterministic operation with service lives measured in decades rather than years. Ironically, the complexity required to secure these systems can itself become a source of operational risk. “AI only amplifies this trend, increasing expectations for secure, persistent connectivity to enterprise intelligence. The question is no longer simply how to converge IT and OT, but how to ensure that advances in cybersecurity remain practical across the long service lives of industrial systems,” Cloutier said. “New
32
technology makes its greatest impact not when it demands replacement of proven platforms, but when it extends their ability to participate safely and confidently in an increasingly connected world.”
Technology Benefits
Cloutier said that many of the technologies commonly presented as IT-OT convergence solutions are better described as enabling tools. Ethernet, secure communications, web technologies, standardized protocols, APIs, and enterprise messaging all provide important capabilities, but none by themselves solve the fundamental challenge of integrating two disciplines with very different design priorities. “The solution is not a collection of enabling technologies, but a purpose-built edge controller that incorporates those technologies within an architecture intentionally designed to satisfy both IT and OT requirements simultaneously. By treating these technologies as capabilities rather than the architecture itself, the platform can incorporate today's tools—and those yet to come—without compromising the deterministic behavior and
longevity that industrial automation demands,” Cloutier said. From the IT perspective, the platform provides capabilities that traditional industrial controllers were never expected to offer: secure web interfaces, authenticated communications, encrypted protocols, enterprise APIs, structured data exchange, identity management, and seamless integration with business systems and cloud services. From the OT perspective, none of those capabilities matter if they compromise deterministic operation, long service life, reliability, or the confidence that the controller will behave predictably years after installation. Enterprise software often assumes continual updates, evolving dependencies, and changing infrastructures. Industrial automation cannot. The operating system, communications architecture, security model, and application environment must be designed together to maintain predictable operation while exposing modern enterprise functionality. The result is an automation platform that avoids unnecessary software complexity, minimizes version dependency, reduces update anxiety,
in d u s t r ial et h er ne t mag azin e
09.2026
Addressing Engineering Challenges
The challenges of IT-OT integration are not static. New protocols emerge. Security requirements evolve. Enterprise software changes. Cloud services come and go. The engineer's task is therefore not to solve one integration problem, but a continuing series of integration problems. It is a career,” Cloutier said. “Since engineering resources are always finite, success depends less on eliminating future challenges and more on giving engineers the right tools to address them efficiently.” He added that many of the technologies discussed in IT-OT convergence—secure communications, standardized protocols, enterprise messaging, APIs—are valuable tools for specific tasks. Equally important is providing an integration platform that allows those tools to be employed naturally, consistently, and without repeatedly solving the same architectural problems. The key technical detail is establishing a strategy based upon a packaged engineeringcertified platform that is fully supported by a manufacturer. A reliable edge controller with demonstrated longevity. One in which you can have confidence. And that would be familiar to other engineers should service be required in the future in your absence. The greatest technical advantage of a purpose-built IT-OT platform is not that it eliminates future integration challenges. It is that it removes the need to repeatedly solve those same issues day after day. By providing a stable, integrated foundation, it frees engineers to focus their limited time and expertise on the next new challenge rather than continually rebuilding the platform beneath it. It is what makes careers successful. “In looking back over the past two decades, there has always been a growing need for IT-OT edge devices. That it is not a new requirement. Technologies have been available to service that need throughout that period,” Cloutier concluded. “Beyond local process control, remote monitoring and control has been a steadily growing theme. Edge controllers have been deployed successfully. In Digital Cinema, beginning in 2005, for example, applications manipulate I/O and coexist simultaneously with ongoing protocol conversion and web-based GUI. This has all been handled by engineeringcertified, deterministic and trusted devices all supported by manufacturers.” The fact of the matter is that the technologies that most will cite as being solutions for this have been available for quite some time. Perhaps not by the same names or in exactly 09.2026
the same packages. Lightweight Publish/ Subscribe protocols have been in use for years and predate MQTT and others. There is no doubt that engineers have, and have had, the tools, technologies, and skills to create successful integrated IT-OT solutions for some time. What has changed is the appetite for information. In years past, anything that was needed remotely had to have a specific purpose. A switch needed to be located miles away or the main office needed up to date status as to county water tank levels. With the proliferation of cloud-based analytics, the quantity of information needed remotely has increased. We are no longer talking about a single displayed value, but multiple values charted over time. And, in enough detail to help us visualize the correlations. “Today, AI comes along with its own insatiable appetite. Not just for the information that we have deemed important, but for every possible data point it can consume. If we are going to ask AI to tell us what is important. If we want AI to identify correlations that we had never before recognized, then it needs to be fed EVERYTHING,” Cloutier said. “The demand for IT-OT integration has exponentially skyrocketed. And, suddenly we have an IT-OT convergence problem in need of a solution? There are already solutions. But, getting control over the situation and in an economically sensible fashion… now that may be real the problem.”
Zero Trust Concepts Valuable
Concepts translate well between the IT and OT worlds, and tools often can be applied between the two. Chris McLaughlin, a frequent speaker on OT cybersecurity topics and former Chief Information Security Officer at Johns Manville said that technology has shifted dramatically over the course of his 30 years in the industry and perhaps we have yet to see the biggest shift that will occur with AI. The adoption of ethernet, the Internet, mobile expansion, big data and digital transformation efforts have each played a part in the slow convergence that has occurred between IT and OT over the years. “Today, many organizations find that they have converged further than they may have thought and are forced to recognize that they may not have done it securely enough. As organizations continue to find themselves victims of ransomware, sadly, many discover that their businesses are integrated tighter that they thought between IT and OT,” McLaughlin said. “Many business executives discover the hard way that when IT functions fail, their OT functions are unable to be performed. For instance, how does a company that manufactures a product continue to produce goods if they are not able to send schedule
i n d u s tr i a l e th e r n e t m a g a z i n e
changes or put products away? How confident is the CEO of an oil and gas pipeline to continue operations if all of their physical security cameras, etc. have been taken offline. Many Chief Information Security Officers (CISOs) are starting to understand that they must partner with their OT counterparts to collaboratively identify risks and mitigate them.”
IT-OT Convergence
and remains stable throughout the operational life of the equipment. Perhaps the greatest technical benefit is that integration is no longer something added to the controller. It becomes an inherent property of its design..
Zero Trust Concepts
McLaughlin said that, generally, Zero Trust concepts in which access to a given system or service only by what someone is required to have access to is being implemented heavily in IT. With IT focused solutions maturing, some of the technology will be applied to OT worlds. ISA / IEC 62443 has long defined the concepts of Zones and Conduits to separate out segments based upon level of access (Zones) and limit communications between those segments to only what is required (Conduits). The fundamental concepts translate well between the IT and OT worlds, and the tools often can be applied between the two. He said that security monitoring solutions have also developed significantly over the last 5 years along with OT targeted monitoring. Security teams have been collecting massive amounts of log data over the last few decades and each year the amount of data (and undoubtable the costs of that data) has risen. With Machine Learning, Behavioral Heuristics, and AI advances in technology; this data is becoming extremely valuable in early detection and response to cyber activity. This is the good news; the bad news is that attackers are also using AI to launch attacks against us. Perhaps this these ultimately support what is most important for IT / OT convergency, effective OT operations. Organizations that are able to secure their operations with standards such as ISA / IEC 62443 are able to focus on Data integration and the benefits of digital convergence and the use of AI to better understand their business.
Technology Benefits
“Zero Trust technologies help organizations limit the exposure from a breach while provide greater security for the things that they want to protect to a great level. Breaches still largely come about through phishing emails or other forms of social engineering,” McLaughlin said. “In most organizations, the breach of a single user and their computer can expand into a full blown ransomware attack. Zero trust solutions help to isolate the blast area from a compromise of a single user and in some cases provide warnings to security teams when that user account or computer has started to do things that are not ‘normal’. “ OT monitoring solutions then detect unusual activity on OT networks and likewise, are able to detect and stop attacks at early stages and could prevent a catastrophic event from
33
SOURCE: ISTOCKPHOTO
IT-OT Convergence "The challenges of IT-OT integration are not static. New protocols emerge. Security requirements evolve. Enterprise software changes. Cloud services come and go. The engineer's task is therefore not to solve one integration problem, but a continuing series of integration problems," Chris McLaughlin, former Chief Information Security Officer at Johns Manville. happening to the Industrial Control Systems. Ultimately these technologies are in place to allow organizations to focus on operational advances with AI and other business level digital convergence efforts. Providing real time data for modeling, using AI to scan for visual defects, detecting machine problems though indicators and preventing a major outage; these are the true benefits. Organizations that are able to achieve these benefits will have a competitive advantage against their competitors. Those that decide to implement these OT / IT integrations without security? They do so at their own peril. McLaughlin added that zero Trust technologies are complex and can vary significant from one supplier to the others. Essentially, they start with the concept of “Identity” and determine from there what services that identity can access. Fundamentally, concepts of identity management have been around a long time. As a user of a system you may have access to some things while others users may have access to others. Zero Trust is deeper than that in that it specifically blocks you from access those services. For instance, your access may
34
have been able based upon security roles in that system but were you able to get to other applications on that system that you should not have. Zero Trust takes things a step further by blocking that access entirely. OT Monitoring solutions, generally, work in one of two ways. They are either passive or active. Active systems actually scan the OT network or may have agents installed on OT systems for the purposes of monitoring or system management. Passive systems can often be configured so they cannot actually interface with the industrial network at all. Essentially, they are configured as a mirror of the traffic from the ethernet switch and simply provide data to the monitoring service and the service evaluates the network traffic. Passive monitoring is the more conservative options for many companies as it reduces the monitor as a potential attack point. Active monitoring systems may provide more information to analyze and perhaps greater visibility into threats, but that comes at potentially higher risk. Given the challenges of IT-OT Convergence from a technology perspective, his opinion is that there has been continuing progress made
on this issue. “Progress will continue to be needed and although many of the technology advances will be driving that progress, the biggest issues will involve people and process. The biggest risk that I see for OT organizations is that they will be tempted to integrate IT systems too quickly and will not appropriately implement the people, process, and technology considerations. AI will likely provide tremendous opportunities in the future for OT based businesses, however, if done without securing those properly, they could be introducing extinction level risks to a business,” McLaughlin said. He also noted that ISA/IEC 62443 standards provide guidelines for implementing things such as Zones and Conduits in OT environments which is a core foundation for Zero Trust. These standards go beyond that and help organizations understand the risks related to convergence specifically between IT and OT systems and best practices for both understanding the risk and implementing these integrations while managing that risk. Al Presher, Editor, Industrial Ethernet
in d u s t r ial et h er ne t mag azin e
09.2026
Expert Insights
Manufacturers Adopting Agentic AI Without a Governance Plan
SOURCE: ISTOCKPHOTO
IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements. Using features, such as NAT, port forwarding, and network segmentation, they preserve validated configurations while complying with customer IT requirements.
IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements using advanced features. MANUFACTURERS ARE RACING TOWARD AUTONOMOUS AI faster than most can currently govern it. Recent enterprise research found that nearly three quarters of organizations expect to deploy agentic AI within two years, yet only about one-infive currently have a governance model mature enough to manage systems that act on their own. That gap is not a footnote. It is the central operating risk of the next two years for any manufacturer installing AI vision systems on an inspection line. Most coverage of this research treats the gap as evidence that governance is behind schedule. Fewer accounts explain what closing it actually requires once the AI in question is not summarizing a report but deciding whether a part passes 09.2026
inspection, whether an aircraft is cleared for flight, or whether a robot should act on what it just detected.
What Is Actually at Stake on the Line
In manufacturing inspection, an AI vision call is rarely just a data point. It can trigger a mechanical action, halt a line, or sign off on a component headed into an assembly that eventually leaves the factory. The consequences of a wrong call are not abstract. They show up as recalled parts, grounded aircraft, or a robot arm acting on a false positive. That is why regulators are not waiting for the technology to mature before drawing lines around it. Three different
i n d u s tr i a l e th e r n e t m a g a z i n e
philosophies are playing out inside the same industry right now, and manufacturers operating across borders are effectively living under all three at once.
Three Regulatory Philosophies, One Factory Floor
In the European Union, AI systems used as safety components of products that already require third-party conformity assessment, a category that captures aviation equipment and industrial machinery, are treated as high risk and ca r r y docum e n te d r is k m anagement obligations across their lifecycle. In the United States, aviation regulators have been explicit about
35
SOURCE: ISTOCKPHOTO
Expert Insights IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements using advanced features. where the line sits. When the FAA restored some certification authority after years of tightened oversight, it kept the arrangement deliberately partial: the agency and the manufacturer now alternate weekly in conducting final safety inspections and issuing the certificate that clears an aircraft for delivery and flight. Full autonomy over that sign off has not returned. Singapore has taken a third path. Rather than freezing a comprehensive rulebook, its regulators built a model designed to evolve in roughly six-month cycles, releasing a version, learning from real deployments, and revising before the next release. The country’s National AI Council has named advanced manufacturing as one of the sectors this framework is meant to govern first. None of these approaches is wrong. But a manufacturer running the same inspection system across an EU, a US, and a Singapore facility is effectively operating under three different definitions of who is allowed to decide what.
A Three-Tier Model for Decision Rights
One practical response is to stop treating AI autonomy as a single switch and instead sort decisions into three tiers. The first tier covers decisions the AI
36
can make fully on its own, typically high volume, low consequence calls where an occasional error is small and recoverable. The second tier covers decisions that always require a human to sign off before action is taken, which is where most safety critical inspection calls belong today. The third tier covers decisions that remain off limits to AI entirely, reserved for human judgment regardless of how confident the model is.
The Infrastructure Problem Few Are Naming
A structural obstacle sits underneath all of this. Most industrial IT systems were built as one way reporting layers. Data flows up from the sensor to the dashboard, and a person reads it. Responsible automated decision making needs the opposite: a system that can send instructions back down to the line, confirm they were carried out, and log the exchange for audit. Very few factories have that two way loop built and validated today, which quietly caps how much of the second and third tier can safely move into the first.
Who Answers When the System Is Wrong
Liability is the other constraint doing more to slow full autonomy than any model limitation. When an AI inspection
system clears a defective part or misreads a sensor, the manufacturer holds the legal responsibility, not the software vendor and not the model itself. That unresolved question of accountability, more than raw technical capability, is what keeps many manufacturers from moving decisions out of the second tier and into the first.
Narrowing the Loop, Not Removing It
There is also a less comfortable admission worth making plainly. Alert fatigue is real, and human reviewer bottlenecks have not been solved. Flooding inspectors with every borderline AI flag does not produce safety, it produces exhaustion and rubber stamping. The more durable path is narrowing what requires review gradually, using validated performance data to move specific, well understood decision types from tier two toward tier one only after they have earned that trust in production, not in a lab. That is a slower story than most agentic AI coverage tells, but it is the one manufacturers actually need to build against. Dijam Panigrahi, Co-founder and COO, GridRaster Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
Industrial Ethernet Solutions
2026 Corporate Profiles Learn about the companies and technologies shaping the future of Industrial Ethernet, the IIoT and Industry 4.0.
Industrial Ethernet Automation Networking, IIoT and Industrial AI
Corporate Profile
Beckhoff Automation: New Automation Technology SOURCE: BECKHOFF
Beckhoff implements open automation systems using proven PC-based control technology. The main areas that the product range covers are industrial PCs, I/O and fieldbus components, drive technology, automation software, control cabinet-free automation, and hardware for machine vision.
PRODUCT RANGES THAT CAN BE USED AS separate components or integrated into a complete and mutually compatible control system are available for all sectors from Beckhoff Automation. New Automation Technology stands for universal and industryindependent control and automation solutions that are used worldwide in a large variety of different applications, ranging from CNC-controlled machine tools to intelligent building control.
Worldwide presence on all continents
PC-based control technology
EtherCAT – the Ethernet Fieldbus
Since Beckhoff’s foundation in 1980, the development of innovative products and solutions on the basis of PC-based control technology has been the foundation of the company's continued success. We recognized many standards in automation technology that are taken for granted today at an early stage and successfully introduced to the market as innovations. Beckhoff’s philosophy of PC-based control as well as the invention of the Lightbus system and TwinCAT automation software are milestones in automation technology and have proven themselves as powerful alternatives to traditional control technology. EtherCAT, the real-time Ethernet solution, provides a powerful and future-oriented technology for a new generation of control concepts.
38
The corporate headquarters of Beckhoff Automation GmbH & Co. KG in Verl, Germany, is the site of the central departments such as development, production, administration, sales, marketing, support and service. Beckhoff’s presence in the international market is guaranteed by its subsidiaries. Beckhoff is represented in more than 75 countries by worldwide cooperation partners. Selecting the communication technology is important: it determines whether the control performance will reach the field and which devices can be used. EtherCAT, the Industrial Ethernet technology invented by Beckhoff, makes machines and systems faster, simpler and more cost-effective. EtherCAT is regarded as the "Ethernet fieldbus" because it combines the advantages of Ethernet with the simplicity of classic fieldbus systems and avoids the complexity of IT technologies. The EtherCAT Technology Group (ETG), founded in 2003, makes it accessible to everyone. With over 8,000 member companies from 72 countries (as of February 2025), the ETG is the world's largest fieldbus user organization. EtherCAT is an international IEC standard that not only stands for openness, but also for stability: until today, the specifications
have never been changed, but only extended compatibly. This means that current devices can be used in existing systems without any problems and without having to consider different versions. The extensions include Safety over EtherCAT for machine and personnel safety in the same network, and EtherCAT P for communication and supply voltage (2 x 24 V) on the same 4-wire cable. And also EtherCAT G/G10, which introduces higher transfer rates, while the existing EtherCAT equipment variety is integrated via the so called branch concept: even here there is no technology break.
Beckhoff Automation at a glance
• 2025 global sales: €1.24 billion • Headquarters: Verl, Germany • Managing owner: Hans Beckhoff • Employees worldwide: 5,450 (FTE, February 2026) • Engineers: 2,000 • Subsidiaries/representative offices worldwide: 41 • Sales offices in Germany: 23 • Representatives worldwide: >75
Beckhoff Automation GmbH & Co. KG info@beckhoff.com Phone: +49 5246 963-0
Visit Website
in d u s t r ial et h er ne t mag azin e
09.2026
Corporate Profiles
Contemporary Controls: Your Trusted Partner SOURCE: CONTEMPORARY CONTROLS
Providing innovative and reliable solutions to the industrial automation industry for more than 50 years, Contemporary Controls has been a leader in innovative solutions for industrial automation. WITH MORE THAN 50 YEARS OF experience, Contemporary Controls has been a leader in innovative solutions for industrial automation. Contemporary Controls’ CTRLink products are designed for unattended operation in environments not conducive to office-grade equipment. The products provide convenient DIN-rail mounting in control panels, 24 VAC/DC power, UL 508, improved EMC compliance and reliability. Contemporary Controls’ repeating hub, switches, media converters and IP routers adhere to IEEE 802.3 standards and more. Special regulatory needs are addressed in selected models.
Simplified, Secure Remote Communication
Utilizing the EIGR series VPN routers, Contemporary Controls offers three VPN solutions that deliver secure, remote access—RemoteVPN subscription service, and Self-HostedVPN and BridgeVPN solutions. Hosted on the Internet and maintained by Contemporary Controls, RemoteVPN provides secure communication and the convenience of remote access without having to maintain a VPN server. Contemporary Controls’ Self-Hosted VPN and BridgeVPN solutions allow users to set up and maintain their own secure remote access without subscription fees and without the need for a cloud-based VPN server.
Rugged Ethernet Switches
Whatever the Ethernet infrastructure need, a solution is available from CTRLink products. For simple systems, plug-and-play unmanaged switches provide a cost-effective method for expanding Ethernet networks. Most models include features such as auto-MDIX and auto- negotiation. For demanding applications, managed switches provide features such as VLANs, SNMP, Quality of Service, port security, port mirroring, alarming and cable redundancy.
Innovative Diagnostic Switches
EIMK-T1L SPE Media Converter
The EIMK-T1L SPE Media Converter complies with IEEE 802.3cg to connect 10BASE-T1L and 10BASE-T networks over long distances using single-pair Ethernet cabling. Ideal for new and retrofit installations, it combines Ethernet performance with the reach and flexibility of fieldbus and serial networks while supporting the reuse of existing cabling.
Cost-Effective, Trusted IP
Routers Contemporary Controls’ Skorpion series of IP routers ease the integration of new machines into the existing network. Each machine consisting of multiple IP devices
Solutions You Can Depend On SOURCE: CONTEMPORARY CONTROLS
For troubleshooting, diagnostic switches allows a network sniffer to attach to an unused port on a switch and observe all traffic on the network.
connects to the LAN side while keeping the same IP settings for the devices and the application, lowering installation cost and eliminating trouble shooting. The IP address for the WAN port on the IP router is the only setting that requires modification allowing multiple machines to reuse the same configuration on the LAN side. Skorpion routers have been successfully used in Robotics, Automated Guided Vehicles (AGVs), Packaging and Scientific Equipment.
With automation systems, applications vary and can require a special product or need. Contemporary Controls has worked with OEMs in obtaining UL 864 compliance with some CTRLink switches and can help in other areas such as private-labeling, unique packaging or extreme environmental design. Contemporary Controls’ customers are systems integrators, contractors and OEMs seeking simple, reliable networking and control products from a dependable source. With headquarters based in the US, Contemporary Controls also has operations in the UK, Germany and China and is well suited to fulfil your application needs.
Contemporary Controls www.ccontrols.com
Visit Website
09.2026
i n d u s tr i a l e th e r n e t m a g a z i n e
39
Corporate Profiles
Softing Industrial: Connecting OT and IT SOURCE: SOFTING INDUSTRIAL/SHUTTERSTOCK
Softing enables reliable data flows from field devices and controllers to IT, edge, and cloud applications across factory and process automation.
WITH MORE THAN 40 YEARS OF EXPERIENCE, Softing Industrial Automation specializes in integrating and optimizing digital data communication in industrial environments. Its products enable reliable and secure data flow from the OT level to IT systems, edge, and cloud applications, helping customers improve operational efficiency.
Solutions for industrial data integration
Industrial data integration makes data from machines, controllers, and field devices available for more transparent, efficient, and data-driven production. Softing solutions provide centralized access to production data while supporting both existing automation systems and new Industrial IoT applications. The dataFEED OPC Suite supports secure OT-IT integration in industrial environments. It provides access to PLC and CNC data and makes this information available to IT systems and cloud platforms through OPC UA and MQTT. The SDEX Suite provides a scalable platform for industrial connectivity and data integration. It can be deployed on Windows, in Docker environments, or as a hardware gateway, allowing companies to choose the model that best fits their automation and IT architecture. For developers building industrial connectivity directly into their own
40
applications, siAccess provides a communication library for accessing data from Siemens PLCs and CNC systems. Its documented programming interface supports the efficient development of customized connectivity and data-integration solutions on Windows and Linux.
Industrial network and field device monitoring
In process plants and factory automation, stable communication between controllers, networks, and field devices is essential for reliable operation. Softing solutions provide visibility into device status, communication flows, and network conditions, enabling users to detect disturbances early, accelerate troubleshooting, and improve plant availability. smartLink HW-PN, smartLink HW-DP, and smartLink SW-HT provide controllerindependent access to field devices in PROFINET, PROFIBUS, and HART networks. This enables asset management, device configuration, diagnostics, and monitoring without affecting ongoing plant operations. Combined with the smartLink hardware gateways, plantPerfect Monitor generates live device inventories and provides diagnostic messages, status information, and detailed network performance statistics. Its secure web interface supports efficient monitoring
and faster troubleshooting of industrial communication networks.
Future-proof connectivity with Ethernet-APL
Ethernet-APL extends high-speed Ethernet communication into process automation environments, including hazardous areas. Softing’s infrastructure solution helps process plants modernize their automation architecture while maintaining reliable communication at the field level. aplSwitch Field connects Ethernet-APL field devices with higher-level PROFINET networks. This provides continuous access to field and diagnostic data for applications such as predictive maintenance, process optimization, and data-driven plant operations.
Softing key solutions at a glance
• Industrial data integration: dataFEED OPC Suite and SDEX Suite, and siAccess • Field-device access: smartLink solutions for PROFINET, PROFIBUS and HART • Network monitoring: plantPerfect Monitor • Ethernet-APL infrastructure: aplSwitch Field
Softing Industrial Automation Email: info.automation@softing.com Visit Website
in d u s t r ial et h er ne t mag azin e
09.2026
Corporate Profiles
Phoenix Contact: Leader in Industrial Communication Innovative solutions for enable end-to-end networking from the field to the cloud. Offering a complete portfolio of Industrial Ethernet, wireless technologies and cybersecurity solutions enables end-to-end networking of machines, systems and infrastructure. SOURCE: PHOENIX CONTACT
Industrial Communication
Phoenix Contact develops innovative solutions for industrial communication and enables end-to-end networking from the field level through to the cloud. With a comprehensive portfolio of Industrial Ethernet, wireless technologies, and cybersecurity solutions, the company enables the end-to-end networking of machines, systems, and infrastructure worldwide.
Industry 4.0 End-to-End Networking
Digitalizing industrial processes requires a reliable and secure communication network between sensors, control systems, IT systems, and cloud applications. Phoenix Contact provides a wide range of communication solutions that are ideal for this, including industrial Ethernet switches, industrial routers, wireless products, media converters, device servers, and gateways. These technologies enable the seamless integration of existing systems into stateof-the-art Ethernet networks and help companies make production processes more transparent, reduce downtime, and fully realize the potential of Industry 4.0 and the Industrial Internet of Things (IIoT).
Secure and High-Performance Networks Robust Ethernet switches and highperformance backbone solutions ensure reliable data transmission in demanding industrial environments. The portfolio is complemented by mGuard-based cybersecurity solutions with VPN and firewall functions that protect systems against cyberattacks and enable secure remote maintenance. The IEC 62443-certified products in this range enable users to lay the foundation for a secure, high-performance, and future-proof network infrastructure that ensures high system availability and meets the demands of digital production.
Open Standards and Future-Proof Communication
Phoenix Contact values the use of established, vendor-neutral communication standards such as Profinet, OPC UA, and IO-Link to enable the seamless networking of sensors, machines, facilities, and IT systems. The portfolio is complemented by cutting-edge technologies such as Industrial 5G, Single Pair Ethernet 09.2026
(SPE), Ethernet-APL, and Time-Sensitive Networking (TSN), which support highperformance, real-time, end-to-end Ethernet communication from the sensor all the way to the cloud. With this approach, companies can lay the foundation for flexible and scalable automation concepts, increase the transparency of their processes, and use production and process data securely and efficiently. Today, the Phoenix Contact Group employs approximately 21,000 people worldwide and, in fiscal year 2025, generated sales of €3.3
i n d u s tr i a l e th e r n e t m a g a z i n e
billion. The company was founded in 1923 and is headquartered in Blomberg, Germany. With more than 100 subsidiaries throughout the world and a strong global presence, the company is one of the leading providers of innovative automation and communication solutions for the networked industry.
Phoenix Contact
www.phoenixcontact.com Visit Website
41
Corporate Profiles
Rugged instrumentation for reliable measurement and control SOURCE: MOORE INDUSTRIES
Moore Industries is a world leader in the design and manufacture of exceptionally rugged, reliable and highquality field and DIN rail-mounted instrumentation for the process monitoring and control industries. MOORE INDUSTRIES WORLDWIDE SALES AND support offices provide first rate customer service and solutions for the chemical, petrochemical, utilities, petroleum extraction, refining, pulp and paper, food and beverage, mining and metal refining, pharmaceuticals, and biotechnology industries.
IIoT Solutions built to Deliver Field Data to your Host Systems
HART and MODBUS industrial communication protocols have dramatically increased access to device and process information that allows you to make more effective operational process decisions. Our Remote I/O systems, including the NCS Net concentrator System® and HART gateways and converters such as the HES HART to Ethernet Gateway System with HART Tunneling and the HCS HART to MODBUS Converter, help integrate valuable data into your monitoring and control system strategy.
Instrument Panels and Systems Engineering
Moore Industries can specify, procure, and assemble your multi-vendor electronic and pneumatic instrumentation/hardware into custom-built instrument panels, systems and enclosures. We will provide complete documentation, expert technical assistance, and the assurance that complete and thorough testing has been performed.
Complete Temperature Solutions
Functional Safety Solutions
Programmable Alarm Trips
Provide on/off control, warn of trouble, or provide emergency shutdown with one or more programmable alarm (relay) outputs when a monitored process signal falls outside SOURCE: MOORE INDUSTRIES
Moore Industries Universal PC-Programmable, Smart HART® Temperature Transmitters convert and send RTD or thermocouple signals ready for
of a selected high and/or low limit. Our SLA Multiloop and Multifunctional Safety Logic Solver and Alarm bridges the gap between single-loop logic solvers and costly safety PLCs. With up to 16 alarms and eight physical alarm outputs, simple and complex alarming strategies can be implemented. The SLA is SIL 3-capable, simple to program, and offers costeffective protection by reducing installation and engineering time.
direct interface with an indicator, recorder, PLC, DCS, or SCADA system. Temperature assemblies and measurement components include the WORM® flexible RTD and thermocouple sensors, connection heads and enclosures, thermowells and fittings. Our TCS Temperature Concentrator System now enables highdensity temperature monitoring over Ethernet, supporting more connections while providing precision measurements via HART, MODBUS RTU, MODBUS/TCP, and HART-IP, significantly reducing hardware, wiring, and installation costs.
Our spectrum of SIL 2 and SIL 3 capable FS Functional Safety Series instruments include signal isolators and splitters, single and multi-loop alarm trips and logic solvers, temperature transmitters and more. Every instrument is built and approved for use in Safety Instrument Systems and is third-party certified by exida to IEC 61508 standards.
More Than 55 Years Designing and Manufacturing Rugged and Reliable Instruments
Moore Industries has been proudly serving the process instrumentation needs of global manufacturers and automation companies since 1968. Designing, building and supporting more than 170 products across 14 product lines with unmatched systems, support and services expertise.
Moore Industries-International www.miinet.com Email: info@miinet.com
Visit Website
42
in d u s t r ial et h er ne t mag azin e
09.2026
Corporate Profiles
Industrial Connectivity Made Easier HMS Networks helps device manufacturers and machine builders simplify connectivity across product development and the full lifecycle through Anybus®. SOURCE: HMS NTWORKS
Industrial communication is what we do
Industrial automation depends on reliable communication between devices, machines, control systems, and software. However, supporting different networks, standards, security requirements, and customer configurations can demand considerable engineering time and specialist knowledge. HMS Networks helps device manufacturers and machine builders overcome these challenges through its Anybus portfolio of industrial communication solutions.
The right solution for each connectivity challenge
Anybus solutions connect industrial devices, machines, and systems across major networks. Anybus supports all major fieldbus, Industrial Ethernet, and Industrial Internet of Things technologies, including PROFINET, PROFIBUS, EtherNet/IP, EtherCAT, Modbus, CANopen, CC-Link, OPC UA, and MQTT. This helps device manufacturers and machine builders support different networks, product variants, and market requirements without developing a separate connectivity solution for every application.
associated with protocol implementation, interoperability, certification, cybersecurity, and lifecycle management. HMS keeps pace with evolving technologies and requirements, helping you address regulations such as the EU Cyber Resilience Act and maintain products over longer lifecycles. HMS follows a secure product development process certified according to IEC 62443-4-1. This allows engineering resources to remain focused on the products and features that create the greatest value.
Reduce development and lifecycle effort
A long-term connectivity partner
Industrial communication is not a one-time development task. Initial development, validation, and certification are followed by maintenance, updates, and compliance obligations throughout the product lifecycle. As product portfolios grow, supporting additional networks and variants can multiply this effort. By working with HMS, device manufacturers and machine builders can reduce the effort SOURCE: HMS NTWORKS
Different products and applications present different connectivity challenges. Device manufacturers and machine builders may need to integrate communication directly into a device, connect existing equipment to a new network, replace cabling with wireless communication, add functional safety, or connect a PC-based application. Under the Anybus brand, HMS provides specialized solutions for each situation: • Embedded network interfaces: Add ready-made industrial network communication directly to a device. • Gateways: Connect existing devices and machines to control systems and other industrial networks without changing the equipment. • Industrial wireless: Provide reliable communication where cabling is difficult or equipment needs to move. • Functional safety: Add standardized safety communication to devices and machines. • PC and IPC interfaces: Connect PC-based hosts and applications to industrial networks.
HMS has more than 35 years of industrial communication experience. More than 2,000 device makers use Anybus technology, with over 10 million Anybus nodes installed worldwide. HMS combines proven technology with dedicated technical expertise, global sales and support, long-term product availability, and controlled lifecycle management. Together, these capabilities help accelerate time to market, scale connectivity across product portfolios, and prepare for changing technologies and requirements. Anybus is part of HMS Networks’ broader portfolio of industrial communication solutions serving a wide range of industries and applications.
HMS Networks
www.hms-networkss.com Proven industrial communication expertise, trusted by device makers worldwide. 09.2026
i n d u s tr i a l e th e r n e t m a g a z i n e
Explore Anybus Solutions
43
Corporate Profiles
HARTING Connects the Industrial Internet Driving the digital transformation of smart factories with standardized, robust, and miniaturized connectivity solutions built for high-speed automated infrastructure and cutting-edge industrial networks.
The HARTING Technology Group is driving the future of industrial automation with innovative, standardized communication technologies. As smart factories demand increased efficiency in compact environments, conventional networking interfaces face spatial limits. To solve this, the HARTING ix Industrial® interface sets a new benchmark for Ethernet connectivity. It utilizes an engineering layout that is 70% smaller than a traditional RJ45 socket, allowing device manufacturers to shrink internal circuit footprints substantially. Despite its small stature, the interface supports Cat. 6A performance for 1/10 Gb/s Ethernet transmission alongside robust PoE++ capabilities, up to 1.5 A per pair. Built with an active dual-metal latching mechanism, solid contact design for up to 5.000 tested mating cycles, it guarantees exceptional shock and vibration resistance conforming to stringent EN 50155 railway standards.
Empowering The Edge with Single Pair Ethernet
HARTING ix Industrial® interfaces deliver Cat. 6A 10Gb/s performance while saving 70% space. classic ethernet protocols to distances, where petrol and chemical process industry can use it for large factories.
barrier-free IP communication from the cloud straight down to simple sensor networks. By using just one single twisted pair of copper wires instead of four, SPE eliminates legacy bus barriers, simplifies automated parameter setting, and cuts deployment weight. This creates lean, cost-efficient cabling ecosystems perfect for modern robotics and automated material handling lines. Maximum link lengths of 1.000 meters stretch the former limit of 100 meters of
Smart Device Configuration and Network Control
SOURCE: HARTING
As integrated industry and IIO-driven architectures evolve, field-level data continuity is crucial. HARTING’s T1 Industrial (acc. to IEC 63171-6) technology spearheads the transition toward Single Pair Ethernet (SPE), allowing
SOURCE: HARTING
Miniaturized Connectivity for Next-Gen Automation
Beyond physical hardware, HARTING streamlines complex engineering workflows with its next-generation digital product configurators. These interactive tools let design engineers build bespoke modular configurations, download real-time CAD data, and cross-verify system bills of materials instantly. Additionally, the expanding line of unmanaged Ha-VIS eCon Ethernet switches offers flexible M12 D- / X-coded, ix Industrial®, T1 Industrial SPE, RJ45, and fiber-optic ports. This empowers facilities to scale up or configure secure, high-density edge networks without administrative complexity. Through collaborative initiatives like the HARTING Industrial Ethernet Week, the company continuously shares actionable project strategies, uniting technology experts to realize a fully electrified and automated industrial future.
HARTING Technology Group www.harting.com
Discover Industrial Ethernet Solutions Single Pair Ethernet (SPE) T1 Industrial connectors bring seamless IP communication to the field level.
44
in d u s t r ial et h er ne t mag azin e
09.2026
Industrial Ethernet magazine & blog The best of both worlds ... the in-depth technical features our readers expect, but now also a daily blog with the latest product news and industry updates. The Industrial ethernet magazine has been rebranded Industrial Ethernet, but it's still the only publication worldwide dedicated to Industrial Ethernet automation and machine control networking, the IIoT and Industry 4.0. The difference is a deepened focus on a daily blog to deliver more and deeper content (more product news, industry updates and technology focus) to keep our readers fully informed ... while also delivering the Industrial Ethernet magazine they have come to expect.
Industrial Ethernet Visit industrialethernet.net
Technology
How Protocol Gateways Deliver Effective AI Manufacturing Data AI IN MANUFACTURING FAILS FOR ONE REASON: inconsistent, unformatted, unavailable data. In 35 years moving factory data for NASA engineers, amusement park operators, wastewater plant architects, tea companies and everything between, I’ve seen the same gap derail every project. Unlike traditional control architecture, LLMs need data from as many sources as possible: not just PLCs and DCS, but pneumatic controls, chilled water systems, power controllers and the subsystems that describe how the plant actually runs. Without the full picture, the analysis is wrong. To make AI work — and Industry 4.0 live up to the slides — protocol gateways must reliably move the right data, normalize it and build it into consistent data models. This article explains why protocol gateways, engineered out for years as sources of latency and cost, have become essential in 2026. It defines the categories — data bridges, protocol, edge and secure edge — and shows when an in-rack module beats a standalone device. It lays out the six requirements that matter: support above all else, IEC 62443 security out of the box, real normalization and scaling, hardware over subscription, a dependable supply chain and a vendor who answers the phone. Price matters the least as integration time, not hardware, is the true cost.
Key Points
Due to the more extensive data requirements from AI systems, protocol gateways are again an important part of the manufacturing system architecture. 1. Standalone protocol gateways win on flexibility and security, which matters when you’re pulling data from diverse field sources to feed an LLM. 2. In-rack protocol gateways make sense when the integration is simple and panel real estate is available. 3. Support matters more than anything else. Accessible and knowledgeable support saves money. 4. Demand IEC 62443 out of the box. 5. A software protocol gateway is a recurring bill, while a purpose-built protocol gateway is bought once and runs for years without anyone touching it.
46
SOURCE: ISTOCKPHOTO
In an AI-enabled plant, protocol gateways are how the right data reaches the LLM. The quality of your AI is capped by the quality, consistency and completeness of the data feeding it — and that data arrives through protocol gateways that name it, normalize it, scale it and deliver it in a consistent data model.
Data is the bottleneck to implementing effective manufacturing AI. This article discusses how Protocol Gateways can deliver the right data in 2026. 6. “The price of the protocol gateway?” is the least important question to ask. Get a protocol gateway with great support that is easy to integrate and it will be the least overall cost.
Definitions
Smart Manufacturing – A data-driven approach to optimizing production processes and creating manufacturing processes that enhance efficiency, quality and flexibility. Data Bridge – A bridge simply moves a message from one network to another network with no interpretation or modification of the data. Protocol Gateway – A protocol gateway interprets the data contained in the messages of a network protocol and maps that data to the message structure of a different protocol on another network. Industrial Protocol Gateways are devices that exist within a manufacturing system. Edge Gateway – An Edge Gateway is a protocol gateway that maps data from an Industrial Control System or machine
to protocols, networks, databases and applications that are external to the industrial control system. It adds local compute, scripting, light analytics, store-and-forward, MQTT publishing, REST/JSON and container runtimes to what a protocol gateway delivers. Secure Edge Gateway – An Edge gateway with an explicit security posture: signed firmware, certificate management, role-based access, IEC 62443 alignment, outbound-only patterns and audit logging that prevents access to the machine or industrial control system as it delivers data to external databases and applications. Data Model – A collection of related attributes of a manufacturing system described by some technique such as a User Defined Type (UDT), a database schema, a set of variables structured in code or even a paper diagram. Metadata – Descriptive data associated with a data item in a data model.
FAQs
Why Are Protocol Gateways Important in 2026? In 2026, manufacturers are architecting
in d u s t r ial et h er ne t mag azin e
09.2026
Standalone Gateway
Form Factor
DIN-rail or card-slot mount; lives inside the control panel or PLC rack
Separate enclosure; wall-mount, panelmount or field-mount near the source device
Wiring & Cabling
Short cable runs within the panel; reduced EMI exposure
Longer field runs to the control room; more cabling cost and labor
Power Supply
Draws from existing panel power (24 VDC bus); no separate feed
Needs its own local power drop or PoE infrastructure
Protocol Reach
Limited to protocols accessible from the rack; struggles with remote or field-bus devices far from the panel
Can be placed at the source device regardless of distance; reaches field-level sensors and remote PLCs easily
Scalability
Rack space is finite; adding more gateways may require new panels
Deploy additional units anywhere without modifying existing panels
Maintenance Access
Panel must be opened (often requires lockout/tagout) for firmware updates or replacement
Field-accessible without interrupting control panel operations
Cybersecurity Posture
Shares physical access boundary with safety-critical PLC hardware
Physical separation limits blast radius of a compromised unit
Installation Complexity
Simpler initial install if rack space exists
More site work per unit, especially in hazardous or hard-to-reach locations
Best Fit
Centralized architectures with few protocol types; space-constrained panels; low-complexity integrations
Distributed architectures; multi-site or remote I/O; AI data aggregation from diverse field sources
Space & Footprint
Data is the bottleneck to implementing effective manufacturing AI. Saves Here floor is space; shares existing how Protocol Gateways can Requires dedicated mounting space and enclosure deliverenclosure the right data in 2026.
SOURCE: REAL TIME AUTOMATION
In-Rack Gateway
Technology
Factor
Table 1 – In-Rack Module vs Standalone Protocol Gateway AI-enabled systems that benefit immensely from data delivered by industrial protocol gateways. External process variables like air pressure, power, ambient temperature and humidity, and water temperature typically originate outside the control architecture — and it typically takes a gateway to deliver that data to the Large Language Models (LLMs). Prior to the development of AI and LLMs, control system architects frowned at including protocol gateways. Protocol gateways were viewed as sources of latency, complexity and expense. Control system architects tried to select devices that worked directly within the control architecture. Today, with more extensive data requirements (driven by AI), protocol gateways are once again an important part of the manufacturing system architecture. When To Use In-Rack or Standalone Protocol Gateways. For AI-enabled manufacturing, standalone protocol gateways win on 09.2026
flexibility and security, which matters when you’re pulling data from diverse field sources to feed an LLM. In-rack gateways make sense when the integration is simple and panel real estate is available.
Six Protocol Gateway Requirements That Actually Matter In 2026?
#1. Support Is the Most Important Requirement Support matters more than anything else. Buy the most expensive protocol gateway you can find and the integration will still cost double what the hardware costs. Accessible and knowledgeable support saves money. You are, by definition, integrating equipment you didn’t design — often from vendors whose docs are thin or out of date. Forum-only support, no direct engineering access and ticket SLAs measured in days are red flags that will cost you money. #2. Demand IEC 62443 Out of the Box Cybersecurity is now table-stakes, not a
i n d u s tr i a l e th e r n e t m a g a z i n e
“nice to have”. All manufacturers must create a cybersecurity plan that defines the base level of cybersecurity in every product they buy. IEC 62443 is the standard that defines the requirements for firmware signing, secure boot and certificate-based authorization. Your plant’s unsecured protocol gateways, especially the older ones, make attackers salivate. #3. Normalization & Scaling If your protocol gateways just moves bytes but you don’t name, normalize, model and scale the data, you’re simply relocating the confusion to someone downstream. How you name. How you model. How you scale. These kinds of decisions matter greatly when using LLMs to process manufacturing data. #4. Buy Hardware, Not a Subscription A software protocol gateway is a recurring bill, a server to manage and a box with security patches coming every Monday morning. A purpose-built protocol gateway is bought once and runs for years without anyone touching it.
47
Cost Factor
$400 Protocol Gateway
$1,500 Drop-In Gateway
Integrator Time Required
12 hours
2 hours
Integrator Rate
$225 / hour
$225 / hour
Extra Labor Cost
12 x $225 = $2,700
$450
Total True Cost
$400 + $2,700 = $3,100
$1,950
Figure 1 – The Real Cost of a Protocol Gateway
Bottom Line: Choosing the $400 gateway actually costs $1,150 more in integrator time. The right gateway saves time, reduces labor cost and gets the job done faster. Pay once or pay every year. Hint: pay once is the right answer. #5 Check the Supply Chain and the Lead Time A six-week lead time from across the Atlantic is not an answer when you need forty gateways for a build at the end of the quarter. In poker, you want four aces. When buying protocol gateways, you want in stock, fixed price, ships today. #6 Know Who Answers the Phone When It Breaks Plant floor engineers are focused on three things — 1) does it work and do what I want, 2) how easy is it to use and 3) can I reach a human if I need to — without dancing through a set of long, tortuous automated menus. Try calling for support before you buy. “What’s the price of the protocol gateway?” is the least important question to ask It’s amusing when someone asks the price of a protocol gateway. That’s like having a baby because you got a good deal on 100 jars of baby food. Other costs matter. On the factory floor, integration time is the real cost for everything, not just protocol gateways. Get a protocol gateway with great support that is easy to integrate, and you win. Buy something cheap, something you have to fight with and see your profit go out the window.
FAQs
1. Is subscription licensing becoming the norm for industrial gateways? Hardware-based protocol gateways, both rack-based and standalone, are still one-time purchases. Software-based protocol gateways, like many industrial software applications, are largely sold by subscription. Complexity, installation, support and total cost of
48
ownership all still favor hardware-based protocol gateways. 2. Standalone protocol gateway vs. PLC in-rack comms module — when do I use which? In-rack modules have a performance advantage due to their direct interface to a PLC backplane. Every other criteria favors the standalone protocol gateway: support, gateway protocol mix, cost, complexity and cybersecurity. 3. How do I evaluate a vendor’s cybersecurity claims without taking their word for it? Until there is standard IEC 62443 compliance verification, users should review the vendor’s IEC 62443 process, CVE history and third-party attestations. 4. Do I still need a protocol gateway if I already have an edge gateway / IIoT platform? Protocol gateways fill a different role than edge gateways. In a control system, the purpose of a protocol gateway is to ingest data from other non-compatible data sources and make it available to the programmable controller or historian. An edge gateway provides an interface from data internal to the control system to external databases and applications. 5. Aren’t protocol gateways all commodities? While they look interchangeable on the data sheet, they aren’t in the field. The differentiators that don’t show up in a data sheet: configuration UX, error messages that name the problem, support engineers who answer the phone and firmware update discipline. The real truth: a hard-to-use protocol gateway is a recurring tax on every project that touches it.
Conclusion
Protocol gateways are no longer a necessary evil to be minimized. In an AI-enabled plant, they are how the right data reaches the LLM. The quality of your AI is capped by the quality, consistency and completeness of the data feeding it — and that data arrives through protocol gateways that name it, normalize it, scale it and deliver it in a consistent data model. So, choose deliberately. Demand accessible, knowledgeable support and IEC 62443 security as table stakes. Insist on real normalization and scaling, not just byte-shuffling. Favor purpose-built hardware over recurring subscriptions, confirm the supply chain can deliver on your timeline and make sure a human answers when something breaks. Do that, and the protocol gateway disappears into the background, quietly doing its job for years. Buy on price alone and you’ll pay for it on every project that touches it. In 2026, the cheapest protocol gateway is almost always the most expensive one.
Need Help Finding a Protocol Gateway?
Real Time Automation, Inc. has been helping manufacturers move industrial data for over 30 years. RTA’s protocol gateways are used on factory floors across the world and are a valued part of in modern control systems because they are easy to setup, fast to deploy and are backed by live support. Contact RTA to find the best protocol gateway for your application. John Rinaldi, Chief Strategist and Director of Creating WOW!, Real Time Automation (RTA) Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: REAL TIME AUTOMATION
Technology
The Real Cost Isn’t the Gateway — It’s the Time Behind It
Technology
Using IP Routers to Simplify Industrial Machine Integration MODERN INDUSTRIAL AUTOMATION SYSTEMS consist of complex subsystems that communicate over Ethernet-based networks, many of which use the Internet Protocol (IP). A machine builder typically designs and validates their automation system using predefined IP addressing schemes. However, deploying the equipment at a customer site to match the network policies presents a challenge. This article outlines how industrial IP routers can streamline the integration of preconfigured machines into existing plant networks without changing their IP addresses. It also explains how Ethernet switches can be used alongside IP routers to expand a single Ethernet network and provide reliable, industrial-grade connectivity in demanding environments. Modern industrial machines are often made up of multiple subsystems that communicate over Ethernet/IP, Modbus TCP, PROFINET, BACnet/IP, or similar protocols layered on IPv4. During development and testing, a machine builder assigns fixed IP addresses to these subsystems and configures control applications accordingly. Reconfiguring IP addresses and modifying control software to comply with customer network requirements is time-consuming, increases the risk of configuration errors, and can significantly delay commissioning. The effort multiplies with each additional machine installed.
Segmenting Networks (LAN/WAN)
Industrial IP routers, such as Contemporary Controls’ EIGR Skorpion series, allow machines to retain their original IP configuration while integrating with the customer network. These routers link IP networks, segmenting the machine network and the plant network while allowing appropriate traffic to pass between them and blocking all other traffic. The LAN (Machine Network) is the internal network that hosts all machine-level devices using the original IP addressing scheme defined during development. The WAN (Plant Network) is the external network that connects to the customer’s infrastructure and is configured to comply with plant-level addressing, routing, and 09.2026
SOURCE: CONTEMPORARY CONTROLS
IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements. Using features, such as NAT, port forwarding, and network segmentation, they preserve validated configurations while complying with customer IT requirements.
IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements using advanced features. security requirements. The machine subsystems appear as a single device on the plant network but can be accessed individually using router features, such as port forwarding, port range forwarding, and Network Address Translation (NAT).
Eliminating the Need to Change IP Address During Commissioning
The routers include a 4-port switch on the LAN side for connecting devices, and a built-in stateful firewall passes communication initiated on the LAN side while blocking communication initiated on the WAN side. Port forwarding, port range forwarding, and NAT allow controlled access through the
i n d u s tr i a l e th e r n e t m a g a z i n e
firewall, enabling communication between external clients and internal devices. With these features, multiple internal devices can be accessed through a single IP address on the WAN side, eliminating the need for the customer’s IT department to assign multiple IP addresses. NAT translates IP addresses between different subnets. Typically, the routers map external (WAN-side) IP addresses to internal (LAN-side) addresses, allowing full access to LAN-side devices while hiding internal IP addresses from external networks. This adds a layer of security by making it more difficult for potential attackers to directly target individual devices. Using NAT, a WAN-side device can communicate with LAN devices through the
49
SOURCE: CONTEMPORARY CONTROLS
Technology IP routers streamline machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements firewall without requiring changes to the machine’s configuration. Different devices can be accessed using the same WAN IP address in combination with unique port numbers. Port forwarding allows a specific port on the WAN-side IP address to be mapped to a port on a specific LAN device, while port range forwarding supports applications that require a range of continuous IP ports. These features allow multiple machines with the same IP addressing scheme to be installed at a site by changing only the router’s WAN IP address, enabling the same network configuration to be reused without modifying device IPs and reducing commissioning time and troubleshooting effort.
Isolating Traffic and Improving Security
Industrial automation devices often generate multicast and broadcast traffic for functions, such as device discovery, time synchronization, and cyclic I/O updates.
50
Uncontrolled propagation of this traffic into plant networks can increase network load, degrade performance of critical systems, and trigger security alerts. EIGR IP routers mitigate these issues by isolating broadcast and multicast traffic within the machine (LAN) network, preventing unnecessary traffic from reaching the factory network. Allowlists provide additional security by permitting access only from WAN-side devices with approved IP addresses. This ensures that machine-level traffic remains localized, improving overall network performance.
Configuring Gateways and Supporting Legacy Devices
Some devices use a gateway address to communicate across different subnets. Communication packets destined for devices on the same subnet are sent directly. To communicate with devices on a different network, packets must be sent to the IP router, which forwards them to
the destination network. Therefore, the configured gateway address on an IP device is the IP address of the router serving that subnet. These devices must be configured with the correct default gateway to communicate outside their subnet; incorrect settings are a common cause of communication issues. The EIGR routers have a built-in DHCP server on the LAN interface that automatically assigns IP addresses, subnet mask, and default gateway. Any IP device with DHCP client ability automatically gets the correct Gateway IP address setup as part of the DHCP IP address lease provided by the IP router. For legacy devices that do not support gateway configuration, the EIGR routers provide a masquerade function that modifies IP packets, so communication appears to originate from the router that is on the same subnet as the device, enabling communication across subnets without device reconfiguration.
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: CONTEMPORARY CONTROLS
For increased security and isolation, IP routers can be cascaded to further segment networks. This approach allows automation networks to be separated from business systems, further reducing network congestion, limiting broadcast domains, and enhancing fault containment and security. Cascaded configurations also support the integration of legacy equipment into modern architectures. In this setup, each LAN-side subnet must have a unique address, while WAN-side IP address can be assigned using DHCP client or static IP addressing, depending on network requirements.
Technology
Implementing Cascaded Router Architectures
Supporting Dynamic Addressing and Hostname Resolution
Some customer sites do not allow fixed or static IP addresses. Instead, they want dynamically assigned addresses. EIGR routers feature built-in DHCP client that can request a DHCP assigned address for its WAN port. Hostname/DNS support allows network access via domain names instead of fixed IP addresses. This is particularly useful in environments where IP addresses are frequently reassigned or centrally managed by IT systems.
Enabling Remote Access and Diagnostics
Accessing machines at remote sites over the Internet can be a challenge because firewalls block incoming traffic. A virtual private network (VPN) provides encrypted communication, ensuring that only authorized devices can connect. This secure remote access allows systems integrators to perform troubleshooting, diagnostics, system monitoring, and data collection and analytics from the convenience of their home or office. It also supports the collection of plant data, which can be transmitted to the cloud for advanced analysis, process optimization, and predictive maintenance. The EIGR routers support VPN functionality. Contemporary Controls offers three VPN solutions to meet your remote access needs—our RemoteVPN subscription service, and our Self-HostedVPN and BridgeVPN solutions.
Evaluating Industrial Ethernet Switches
While IP routers connect Internet Protocol (IP) networks, Ethernet switches expand a single Ethernet network. Ethernet continues to evolve as the network of choice for automation systems due to its high speed, familiarity among users, and ability to 09.2026
While IP routers connect Internet Protocol (IP) networks, Ethernet switches expand a single Ethernet network. Ethernet continues to evolve as the network of choice for automation systems. easily connect to the Internet. Contemporary Controls’ CTRLink switches are designed for unattended operation in industrial environments. The Ethernet switches provide convenient DIN-rail mounting in control panels, 24 VAC/DC power, UL 508, improved EMC compliance and extended operating temperature ranges of 0–60°C. Switch types include: • Unmanaged Switches: Plug and play devices that can be put into service without adjustments and provide a simple, cost-effective method for expanding Ethernet networks. Most models include features such as auto-MDIX and auto-negotiation. • Diagnostic switches: Allow a network sniffer to connect to an unused port and monitor all network traffic. They retain all the virtues of switched Ethernet, except that address learning is disabled. All messages—directed, multicast, broadcast—are flooded to every port, enabling a protocol analyzer tool, such as Wireshark®, to observe all traffic on the network. These switches ensure predictable, time-sensitive communication and high availability in demanding industrial
i n d u s tr i a l e th e r n e t m a g a z i n e
applications.
Conclusion
IP routers simplify machine integration by allowing machine builders to maintain original configurations while meeting customer network requirements. Using features, such as NAT, port forwarding, and network segmentation, they preserve validated configurations while complying with customer IT requirements. Additional benefits include: • Reduced commissioning time and risk • Improved network performance through traffic isolation • Enhanced security • Simplified deployment of standardized machine designs • Secure remote access for diagnostics and maintenance When combined with industrial-grade Ethernet switches, this approach delivers a reliable, secure, and efficient networking framework for modern industrial automation systems. Kathy Neumeyer, Technical Writer, Contemporary Controls Learn more: Skorpion Gigabit IP Router
51
Technology
The Real Cost of Temperature Monitoring
SOURCE: MOORE INDUSTRIES
The true cost of a temperature monitoring system isn't fully visible on day one. It's the sum of what a facility pays to install it, what it costs to operate and maintain over years of service, and what it costs to expand as monitoring needs change.
A local, multi-channel temperature concentration approach, as demonstrated by the Moore Industries TCS Temperature Concentrator System, addresses all three cost stages together: wiring, lifecycle and room for growth.. It reduces installation cost by consolidating wiring, lowers lifecycle cost by reducing the number of field instruments requiring calibration and maintenance, and keeps expansion cost predictable through a modular architecture that scales with the facility rather than against it. PROCESS FACILITIES LIVE AND DIE BY TIGHT control over temperature. A few degrees of drift in the wrong direction can spoil a batch, trip a safety interlock, or put a facility out of compliance with limits it's required to hold. That stakes-driven reality is why so many points across a facility end up monitored in the first place, and why the high-density temperature monitoring system built around those points deserves scrutiny that goes beyond the price tag on the purchase order. For decades, the default architecture has been point-to-point: an RTD or thermocouple wired to its own dedicated transmitter, with a separate cable run from every measurement point all the way back to the control system. In hazardous areas, that architecture layers on further cost: explosion-proof housings, intrinsically safe
52
barriers, and marshaling infrastructure, required for every single point. What that architecture costs beyond the initial installation rarely enters the conversation. Three cost stages make up the full f in a n c ia l pictur e of a te m pe r a tur e monitoring system: what it costs to install, what it costs to operate over its working life, and what it costs to expand as monitoring needs grow. A local, multichannel temperature concentration approach changes the economics at each of these stages compared to traditional point-to-point architecture built around individual transmitters.
The Upfront Problem: The Cost of Wiring Every Point
In a traditional temperature monitoring architecture, every sensor is wired
individually to its own transmitter, and every transmitter is wired individually back to the control system. Older temperature monitoring designs required RTDs and thermocouples to be wired directly back to the control room, adding long-term costs due to expensive thermocouple extension wire that degrades over time and eventually requires replacement. For a facility monitoring dozens or hundreds of points, this means running dedicated extension wire, often over long distances, through cable trays, conduit, and marshaling cabinets, for every single measurement point. The cost drivers stack up quickly: copper wire, conduit, termination hardware, and the skilled labor required to install, terminate, and document each connection correctly. Beyond materials and labor, this
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: MOORE INDUSTRIES
Technology
wiring density creates its own risk during commissioning. When a wiring fault or crossed connection is discovered during startup, tracing it through a dense bundle of point-to-point cabling can consume days of a technician's time and delay a project's go-live. A facility bringing 80 to 100 new temperature points online in a single project can find that troubleshooting wiring issues, not the instrumentation itself, becomes the largest source of schedule risk. A temperature concentration system changes this equation by moving the aggregation point out into the field, close to the sensors themselves. With the Moore Industries TCS Temperature Concentrator System, up to 16 sensors connect locally to a single TCM Temperature Concentrator Module, which then transmits all 16 signals back to the control system over a single twisted pair or Ethernet connection. Instead of dozens of individual wire runs converging on a control room, a single digital link carries aggregated data. This shift from many discrete home runs to one consolidated connection can reduce installation costs by as much as 70%, while maintaining the signal integrity of every monitored point.
The Hidden Problem: What Happens After Installation
Installation is only the first cost a monitoring system commits a facility to. Every transmitter placed in the field becomes an ongoing obligation: a device that must be calibrated on a routine schedule, a component that draws power, a potential point of failure, and a line item in the spare parts inventory. As the number of transmitters grows, this maintenance burden doesn't scale in a straight line. Each additional device adds its own calibration cycle, its own failure probability, and its own documentation trail, so the operating cost of a large traditional system compounds well beyond what the point count alone would suggest. That compounding has a reliability dimension as well as a cost one. More field instruments statistically mean more opportunities for a single failure to interrupt monitoring on a process line and diagnosing which of dozens of transmitters is at fault takes time that a leaner instrument count doesn't demand. There's also a configuration cost that's easy to overlook: every traditional transmitter needs to be individually tagged, ranged, and configured within the control system, and that work repeats every time a device is replaced. Reducing the physical instrument count changes this cost profile directly. Because a single TCM manages up to 16 sensor 09.2026
In a traditional architecture, each temperature sensor is wired individually to its own transmitter, with a dedicated cable run all the way back to the control system. inputs, a facility monitoring 128 points needs only eight TCMs, rather than 128 individual transmitters, to calibrate, power, and maintain. Fewer devices in the field means fewer calibration cycles, less spare parts inventory to carry, and a simpler troubleshooting path when an issue does arise, since technicians are working with a consolidated, well-documented signal path rather than tracing faults across a large population of independent instruments. Over a 5-to-10-year equipment lifecycle, that reduction in recurring calibration labor, spare parts spend, and power infrastructure adds up to savings that installation cost alone doesn't capture.
The Future Problem: Planning for Growth
Facilities rarely stay static. New process units come online, monitoring requirements
i n d u s tr i a l e th e r n e t m a g a z i n e
expand, and points get added long after the original system was commissioned. In a traditional transmitter-based architecture, every new temperature point re-triggers the same cost problem the facility faced at initial installation: a new sensor requires a new transmitter, a new home-run wire pull, and new engineering and documentation work, regardless of how much spare capacity the rest of the system has. A modular temperature concentration architecture avoids re-triggering that cost. Because each TCM handles up to 16 channels, and multiple TCMs can connect to a single HMC HART-to-MODBUS Converter or HES HART-to-Ethernet Gateway System, adding monitoring capacity becomes a matter of adding a module rather than re-engineering the I/O architecture from scratch. A single-channel HES supports one or two TCMs, while a four-channel HES
53
SOURCE: MOORE INDUSTRIES
Technology The TCM Temperature Concentrator Module consolidates up to 16 sensor inputs into a single connection back to the control system, replacing dozens of individual wire runs with one digital link.
Monitoring 128 temperature points requires 128 individual transmitters and roughly 128 home-run wire runs in a traditional architecture, compared to 8 TCM modules and one 4-channel HES, for a total of 9 instruments with the TCS Temperature Concentrator System.
54
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: MOORE INDUSTRIES
Technology
Cumulative cost over a 10-year period. Traditional point-to-point architecture carries a higher installation cost and a steadily rising maintenance burden, while the TCS Temperature Concentrator System starts lower and grows at a flatter rate. scales to eight TCMs, supporting up to 128 temperature points through just nine total instruments. The scale of what that replaces is worth stating plainly. A facility monitoring 128 points with traditional transmitters would need 128 individual transmitters and 128 individual home-run wire pulls, potentially totaling thousands of feet of cable once distances across a typical plant are accounted for. The TCS accomplishes the same monitoring scope with nine instruments and a fraction of the wiring, and the engineering hours required to add a module to an existing TCS network are a fraction of what re-engineering a traditional I/O architecture demands for the same expansion. That difference compounds with every future project, since it means expansion cost scales with the number of points added rather than with the complexity of the existing system. There's a longer-term benefit here as well. A modular architecture protects the 09.2026
facility's original investment. Monitoring needs change over the life of a plant, and a system built to expand incrementally means a facility isn't stranded with infrastructure that must be replaced wholesale to accommodate new requirements. The system grows with the plant instead of becoming an obstacle to it.
Conclusion
The true cost of a temperature monitoring system isn't fully visible on day one. It's the sum of what a facility pays to install it, what it costs to operate and maintain over years of service, and what it costs to expand as monitoring needs change. A traditional transmitter-based architecture front-loads none of that cost transparently: it commits a facility to expensive dedicated wiring at installation, an escalating maintenance and calibration burden over time, and a repeat of the original wiring cost with every future expansion. A local, multi-channel temperature concentration approach, as demonstrated
i n d u s tr i a l e th e r n e t m a g a z i n e
by the Moore Industries TCS Temperature Concentrator System, addresses all three cost stages together. It reduces installation cost by consolidating wiring, lowers lifecycle cost by reducing the number of field instruments requiring calibration and maintenance, and keeps expansion cost predictable through a modular architecture that scales with the facility rather than against it. For facilities weighing not just what a monitoring system costs today, but what it will cost to operate and grow over its full working life, high-density temperature monitoring through concentration offers a cost structure that stays favorable at every stage, and a more dependable one along the way. Technical article by Moore Inustries
Learn Moore about the TCS Now
55
New IO-Link analog hubs, centralized enterprise and industrial orchestration, low-voltage DC options for rugged switching, scalable MPO fiber infrastructure and expanded life-safety cabling boost performance. SOURCE: BELDEN
Product News
Resilient and scalable IT/OT networks
The launch of new products and portfolio expansions is designed to help customers build more efficient, resilient and scalable IT/OT networks. Innovations from Belden include new IO-Link analog hubs, centralized enterprise and industrial orchestration, low-voltage DC options for rugged switching, scalable MPO fiber infrastructure and expanded life-safety cabling help modernize IT/OT networks from device to core. The launch of these products and portfolio expansions are designed to help customers build more efficient, resilient and scalable IT/OT networks—spanning industrial device connectivity, wireless orchestration, rugged switching and power options, high-density fiber infrastructure and life-safety cabling. Operational Technology (OT) environments across manufacturing, energy and transportation continue to evolve as operators connect more devices, support more applications and extend networks into harsher and more distributed locations. Belden’s latest launches are designed to simplify integration at the edge, strengthen network reliability and accelerate deployment and operations—while creating a stronger foundation for IT/OT convergence. Belden’s newest product launches and expansions include: Belden LioN-X IO-Link Analog Hubs connect analog sensors to any IO Link network via 4 configurable ports (voltage, current, resistance,
56
thermo-couple) plus 8 digital inputs on the same device. Powered over IO Link, no additional power supply or M12 L-coded connection is needed. Belden Wireless Orchestration is a softwarebased WLAN controller that manages enterprise and industrial access points from one dashboard and can be used to position unified wireless management. ProSoft 8-Channel HART Gateway (PLX51HART-8I) bridges 8 isolated HART channels to EtherNet/IP or Modbus, connecting up to 64 field devices to your control system without adding gateways to the panel. Belden ACX 4U Panel and 12 Port MPO Adaptor Strip (APAC only) extends the ACX family for high-density data center deployments. The solution supports preterminated and splice applications, delivering 384F and 192 MPO-12/8 ports in a 4U for MDA and IDA environments. The pull-out drawer design simplifies installation and maintenance. Hirschmann GREYHOUND GRS2000 Low Voltage powers network equipment straight from the low-voltage DC rail that already runs a substation, trackside or process site, with no separate converter required. The GRS2000 line extension adds a low-voltage DC power supply option, single or redundant, so the
switch connects directly to the rail. It is a straightforward migration path for sites moving off the Hirschmann MACH1000 and GRS1020/30 families, and for any site that needs DC power flexibility. Belden Safe T Line™ Expansion – EN 50200 PH120 & CPR Cca supports fire alarm, evacuation and emergency communication systems that require CPR-compliant, circuit-integrity cables that perform under pressure. This Safe T Line expansion adds CPR Cca (s1b, d1, a1) and EN 50200 PH120-certified cables in shielded and unshielded variants, purpose-built for building and infrastructure projects. Hirschmann IT MTS 2608/2708 Switches are now available in the Americas and EMEA. These entry-level 8-port Gigabit Ethernet managed switches are designed for IT/OT convergence in manufacturing, energy, transportation, and oil and gas environments. With 4x 1G SFP+ uplinks, ERPS ring redundancy and a comprehensive security suite, they give customers a costeffective way to build reliable, converged networks. The MTS2708 adds 802.3at PoE+ with a 125W power budget. Belden Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
Product News
One Cable Automation, PC Controls Hybrid connectors for one cable automation boost flexibility and efficiency. Beckhoff celebrating 40 years of PC-Based control from a technological revolution in 1986 to a global standard in automation today. With a deep and growing portfolio of hybrid connectors, Beckhoff has set a milestone in One Cable Automation (OCA). The company’s ECP and ENP connector series combine industrial power with signal and data communication via OCA to significantly reduce cabling work and expense. With emphasis on modularity, a uniform data core, and full compatibility in accordance with DIN EN IEC 61076-2-118, Beckhoff assures reliability for users and future viability with standard cabling and connector solutions. Beckhoff has already implemented hundreds of thousands of ECP and ENP interfaces in the field, underlining the outstanding practicality of hybrid connectors. Against the backdrop of more modular, distributed system concepts, Beckhoff’s hybrid connectors represent a futureoriented solution that offers an integrated, standardized, yet flexible connectivity platform based on the efficient OCA approach. T h i s p o r t f o l io c o m p r is e s connectors in sizes B12, B17, B23, and B40 for maximum flexibility. They transmit 24 V DC at the I/O level as well as up to 630 V AC/850 V DC and currents of up to 72 A for all your modular machinery needs. The ECP and ENP connector families thus form the technological foundation for a wide range of applications on the road to control cabinetfree automation in hardware platforms such as Beckhoff’s MX-System.
SOURCE: BECKHOFF
New Hybrid Connectors
ECP and ENP connectors are fully compatible with DIN EN IEC 61076-2-118 and assure reliability for diverse applications.
40 Years of PC-based Control
Beckhoff is also celebrating 40 years of PC-Based control from a technological revolution in 1986 to a global standard in automation today. When Beckhoff elevated the industrial computer to central control system status four decades ago, it was a paradigm shift in automation technology. For 40 years now, PC-based control has put the power of IT standards and Moore’s Law for integrated circuits directly into the hands of machine builders and automation engineers. By bundling PLC, motion control, and technologies such as measurement technology, robotics, and machine vision on a single integrated platform, PC Control users today benefit from outstanding performance combined with significant cost and space savings. In the 1980s, industrial manufacturing was dominated by the traditional, hardware-based PLC. The omnipresent PLC was considered reliable, but it was also 09.2026
PC-based control technology provides the ideal basis for IT/OT convergence as well as for emerging technologies such as machine learning and physical AI. inflexible, expensive, and offered limited computing power compared to personal computer (PC) technology. In 1986, Beckhoff responded to the limitations of hardware PLCs by delivering the first industrial PC-based machine control system, which gave the target application – a double miter saw – a significant boost in power and productivity. The decisive technological step was the abstraction of the PLC function from proprietary hardware to a highly flexible solution based on industrial IT components. These were design decisions made in the 1980s, and today the industry refers to this as “software defined automation”. Beckhoff ensured deterministic behavior
i n d u s tr i a l e th e r n e t m a g a z i n e
by developing its own real-time software extensions for standard operating systems – mainly Windows initially, but also others since then, including TwinCAT/BSD and Linux®. Machine builders benefitted directly from the rapid innovation cycles in IT and increasing processor performance. Ethernet communication opened up new possibilities in production and for integrating production into databases, ERP systems, and IoT solutions. Today, PC-based control forms the basis for physical AI everywhere from the factory to the distribution center. Beckhoff Automation Learn More
57
Product News
Expanded AI Portfolio with Agents New Ovation AI Agents enable operators to resolve complex issues in a fraction of the time for faster, smarter plant operations.
At A Glance
Designed to seamlessly integrate with the Ovation Automation Platform 4.0 release, the new Ovation AI Agents are embedded into native operational workflows and tools, eliminating the time-consuming need to switch between systems. Contextual recommendations are delivered directly within the operator’s control, alarm and maintenance workflows, replacing standalone analytics or manual data correlation for faster, in-the-moment action. AI agents compress diagnostic and analysis time from hours or days to minutes, addressing industry challenges including workforce transitions, increasing operational complexity and operator information overload. Human-in-the-loop design ensures operators always retain command; AI agents operate proactively in the background, analyzing plant conditions and recommending optimizations. “Ovation AI Agents deliver a major step change in our AI portfolio, representing a significant advancement in how we help our customers build more intelligent, efficient and resilient operations,” said Bob Yeager, president of Emerson’s power and water solutions business. “The AI-enabled agents handle complex data analysis and pattern recognition to monitor asset health, run simulations, forecast failures and prioritize interventions. These powerful tools enable operators to shift from reactive to proactive planning without disrupting daily workflows.”
58
SOURCE: EMERSON
Emerson has introduced new Ovation™ AI Agents for the power and water industries, expanding the AI capabilities of the Ovation Automation Platform 4.0 release. The five new agents – Sequence Assistant Agent, Alarm Insight Agent, Predictive Maintenance Agent, Root Cause Agent and Loop Performance Monitor Agent – will empower plant personnel with critical insights by continuously monitoring, analyzing and recommending actions across critical plant operations. This expansion builds on the success of Ovation Virtual Advisor and delivers new capabilities to Ovation’s growing portfolio of AI solutions for the power and water industry, transforming how operators make decisions. While Ovation Virtual Advisor provides real-time, AI-driven insights through natural language interaction, the new AI Agents are time synchronized with the Ovation 4.0 system and work autonomously in the background, continuously monitoring plant and equipment conditions and recommending optimizations. New Ovation AI Agents are embedded into native operational workflows and tools. The Ovation AI Agents will be deployed in phases, with the following included in the first wave: Sequence Assistant Agent: Provides AI guidance for sequence-function-driven control logic tools by generating contextaware prompts from real-time deviations and historical failures. During a steam turbine startup, for example, the agent can pinpoint why a sequence has stalled and alert an operator with recommended corrective action, resolving issues in seconds that traditionally could take hours of manual investigation. Alarm Insight Agent: Prioritizes and summarizes alarm context during alarm floods, helping operators focus on the most critical alarms and recommended actions rather than being overwhelmed by hundreds of alerts simultaneously. Predictive Maintenance Agent: Acts as an earlywarning system for critical plant equipment, detecting degradation, prioritizing maintenance and helping prevent unplanned failures. Root Cause Agent: Performs real-time root cause analysis that goes beyond the control system itself to analyze the running plant process. By correlating alarms, trips and live equipment conditions, the agent identifies root causes of critical asset issues – enabling maintenance teams to shift from reactive to proactive actions. Loop Performance Monitor Agent: Continuously
analyzes control loop performance to identify poor-performing loops, including for issues such as oscillation, deadband and deficient tuning, and generates evidence-backed recommendations for engineering review.
Integrated Architecture
Unlike chatbot-style interfaces or external analytics layers, Emerson’s new AI agents are designed to seamlessly integrate with the Ovation 4.0 Automation Platform – governed within the platform and backed by decades of power and water industry expertise. Built with human-in-the-loop design, the agents operate proactively, running in the background and alerting issues to operators – taking action with human approval. Every recommendation flows through human operators who retain full control. Early deployments demonstrate measurable impact. In one scenario, the Sequence Assistant Agent identified a failed permissive condition in seconds – a diagnosis that would have previously consumed hours of manual investigation across logic diagrams and point values. At another major utility, the Predictive Maintenance Agent captured subtle equipment anomaly before it became critical, preventing costly unplanned downtime. Emerson Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
Product News
Industrial Edge, New Switch PAC RADAR has ranked Phoenix Contact’s PLCnext Technology “Best in Class” for Industrial Edge Management for the fifth consecutive year. The analysts at PAC have once again ranked Phoenix Contact’s PLCnext Technology “Best in Class” in the “Digital Platforms for Industrial Edge Management” category in the PAC Innovation RADAR 2026. This marks the fifth consecutive time that the open automation platform has received this accolade. Key factors included, in particular, the platform’s high level of cyber resilience, its openness, and PLCnext Technology’s strong position in energy applications and critical infrastructure. PAC cites its consistent focus on cybersecurity, real-time capabilities, and openness as key strengths. Particular emphasis is placed on the role of PLCnext Technology in the energy industry and in critical infrastructure applications. With certifications in accordance with IEC 62443 and for secure communication in energy management systems, the platform meets high requirements in terms of security, availability, and regulatory compliance. PAC believes Phoenix Contact is wellpositioned in this environment. “No other provider in our assessment places such a high priority on meeting users’ diverse cyber resilience requirements through certifications.” This requires a significant amount of effort, but it is essential for serving users in the critical infrastructure sector worldwide. “Phoenix Contact stands out in this regard with its PLCnext Technology offering,” explained Arnold Vogt, Head of Digital & IoT at PAC.
SOURCE: PHOENIX CONTACT
PAC cites PLCnext Technology consistent focus on cybersecurity, real-time capabilities, and openness as key strengths. New switch offers seamless network redundancy in critical applications
PLCnext Technology “Best in Class” in “Digital Platforms for Industrial Edge Management”.
Seamless Network Redundancy in Critical Applications
New high-performance layer 2 managed switch enables zero-latency redundancy via HSR (High-availability Seamless Redundancy) and PRP (Parallel Redundancy Protocol). With the FL Switch 4300-4GSFP-RED, Phoenix Contact is extending its portfolio for high-availability industrial networks. As a high-performance layer 2 managed switch, it enables zero-latency redundancy via HSR (High-availability Seamless Redundancy) and PRP (Parallel Redundancy Protocol). This ensures uninterrupted network communication in applications where continuous operation is critical. The switch combines powerful redundancy features with a comprehensive set of layer 2 functions, enabling flexible integration into 09.2026
High-performance layer 2 managed switch enables zero-latency redundancy via HSR and PRP. industrial networks. With its various power supply options, the device can be adapted flexibly to different industrial environments. Other benefits include support for IEEE 1588v2 One-Step Transparent Clock for precise time synchronization, redundant power supplies for higher network availability, and single RedBox redundancy. With an operating
i n d u s tr i a l e th e r n e t m a g a z i n e
temperature range of -40°C to +85°C and a robust housing with an IP20 degree of protection, the switch is suitable for demanding industrial applications. Phoenix Contact Learn More
59
Pin-compatible MPUs enable scalable design on common PCB. 1 mW-level standby power and fast Linux wakeup enable always-connected applications. PCIe and TSN-capable Ethernet provide high-speed connectivity. SOURCE: RENESAS
Product News
Advanced HMI and IoT Edge Systems
TTTECH Industrial’s IIoT platform Nerve has been successfully certified according to IEC 62443-4-2. Renesas Electronics has expanded its RZ/G Series with new 64-bit generalpurpose microprocessors (MPUs) for Human Machine Interface (HMI) and IoT edge systems. The RZ/G3L and RZ/G3SE are pin-compatible MPUs that support a broad range of industrial and consumer HMI and IoT gateway and home gateway systems requiring high processing performance and high-speed network connectivity. The RZ/G3L integrates a GPU (Graphics Processing Unit) for 3D graphics rendering along with an H.264 video codec. This combination is ideal for powering smart retail terminals and medical HMI devices that demand rich graphics and video capabilities. The RZ/G3SE is designed for IoT devices with basic display requirements, such as EV chargers and industrial gateway devices that provide status indicators and configuration screens. Because the RZ/G3L and RZ/G3SE are pin-compatible, developers can reuse a PCB design across product variants, simplifying development and reducing time to market.
High Performance with 1 mW-Level Standby Power
These new products deliver high processing performance with a CPU cluster
60
incorporating up to four Arm® Cortex®-A55 cores running at up to 1.2 GHz, together with a Cortex-M33 coprocessor running at 200 MHz. At the same time, the third-generation RZ/G Series adopts a proprietary power management architecture that significantly reduces standby power. As a result, the new products can lower standby power to the 1 mW level in deep standby mode. They can remain in standby mode while retaining the Linux system in memory and resume operation quickly when needed. These power-saving features are well-suited for industrial and IoT devices that require always-on connectivity.
High-Speed Connectivity for Expanded System Capabilities
Equipped with high-speed interfaces such as PCIe, TSN-capable Gigabit Ethernet and USB, the new MPUs allow developers to add application-specific features and connectivity options. PCIe supports connectivity to 5G communication modules, Wi-Fi 6 modules and even external AI accelerators. TSN-capable Gigabit Ethernet enables low-latency and highly reliable communications required in industrial
networks, where real-time performance is critical. “As industrial and IoT devices grow more sophisticated, customers need to balance performance, power consumption, connectivity and design scalability,” said Hari Pendurty, Vice President of the EP Edge AI and Application Processors Business Division at Renesas. “The RZ/G3L and RZ/ G3SE were developed to help customers meet these evolving requirements and scale products more efficiently by leveraging a common hardware platform across different applications.”
A Rich Ecosystem Accelerates Development
Renesas offers ten ecosystem solutions, including GUI development environments, operating systems (OS), software and system-on-modules (SoMs). Renesas will continue to expand the ecosystem to provide customers with a broader range of validated software, tools and hardware solutions. Renesas Electronics Learn More
in d u s t r ial et h er ne t mag azin e
09.2026
Product News
New Ethernet/IP Interface SOURCE: HARTING
ODVA has specified the new compact and robust ix Industrial® Interface for Ethernet/IP. Its 75% smaller device interface is designed especially for industrial-grade network connections.
N-Tron NT7000 is built to minimize downtime with fast boot that passes traffic in less than 7 seconds and N Ring redundancy with ~20 ms healing, helping operations return to service quickly after network faults. The ODVA (Open DeviceNet Vendor Association) has officially specified the compact and industrial-grade ix Industrial® mating face for Ethernet/IP network applications. This completes the picture of standardization and referencing for the much smaller alternative to the classic RJ45 connector. In addition to Ethernet/IP, the ix Industrial® is already an integral part of leading industry standards, including PROFINET, CC-Link IE TSN, FL-net and GigE Vision. Consistent miniaturization combined with significantly increased robustness and performance for reliable data transmission take into account the paradigm shift in industry. ix Industrial® is the standardized miniature Ethernet connector of the next generation and replaces the ubiquitous RJ45. As an official IEC standard (IEC 61076-3-124), ix Industrial® is offered by three independent manufacturers – Hirose, HARTING and Amphenol. This guarantees users free market access, price diversity and long-term supply security without manufacturer dependency. The need for smaller, more robust interfaces is undisputed: RJ45, the previous standard in the industrial Ethernet market, 09.2026
is large, mechanically vulnerable and reaches its limits in modern compact devices. ix Industrial® solves this problem consistently. With an assembly pitch of only 10 mm and a volume reduced by around 75 % compared to RJ45, the connector enables a significantly higher port density in a confined space – a decisive advantage for manufacturers of industrial PCs, robot controllers, servo drives and FA cameras. Mechanically, ix Industrial® sets new standards: A robust double-row contact system, two metal locks and a highstrength PCB connection through THR shield pins ensure reliable operation even under harsh industrial conditions. Tested 5,000 mating/disconnection cycles at operating temperatures from −40 °C to +85 °C prove the durability. A pull-tab variant makes unlocking easier even in confined installation situations. Electrically, ix Industrial® offers Cat. 6A performance with 360° full shielding and is designed for data rates of up to 10 Gbit/s (10GBASE-T). In addition, it supports IEEE802.3bt PoE++ with 1.5 A current carrying capacity per pair – ideal for directly powering field devices via the Ethernet cable.
i n d u s tr i a l e th e r n e t m a g a z i n e
The product range is broadly based: in addition to standard sockets and angle variants, connectors with IDC or solder connection, IP65/67 versions with HARTING push-pull locking and variants with integrated magnetics (ix MAG) are available. Field-assembleable designs allow on-site assembly without the need for special tools. Cable assemblies – also known as ix-to-RJ45 transition cables – are available worldwide through distributors such as Sinbon and Misumi. Renowned companies such as Siemens, Beckhoff and B&R have already successfully integrated the ix Industrial® into their own products. Development teams that are now entering their next product developments should integrate ix Industrial® into upcoming devices as a robust, industrialgrade and significantly smaller alternative to the RJ45. The significantly smaller, internationally standardized interface offers the opportunity to make devices more compact, robust and future-proof. HARTING Learn More
61
Moxa’s New-gen Arm computers achieve IEC 62443-4-2 SL2 Certification to strengthen edge security.
Moxa has announced IEC-624434-2 Security Level 2 (SL2) certification under the International Electrotechnical Commission for Electrical Equipment (IECEE) Certification Body Scheme for its UC Series 64-bit Arm-based computers that run Moxa Industrial Linux 4 (MIL4) Secure OS. This milestone marks a significant shift from a single certified product to establishing a consistent security baseline for an entire product line, wherein our customers benefit from a verified security architecture across both data gateways and 5G edge-computing platforms. Moxa successfully launched the world’s first IEC 62443-4-2 certified host device, the UC-8200 Series Arm-based computers, in 2023. IEC 62443-4-2 provides an internationally recognized framework for verifying the cybersecurity capabilities. Building on this accomplishment, the entire UC Series 64-bit Arm-based “IEC 62443-4-2 provides a clear and operations and minimize unplanned securitycomputer portfolio is now certified to offer our customers a trusted operational internationally recognized framework for related costs. technology (OT) computing platform based on verifying the cybersecurity capabilities of “With an IEC 62443-4-2 SL2 certified industrial automation and control system a strong and secure foundation. computer, our customers can start their components,” said Maxi Tsai, General Manager projects with a pre-validated cybersecurity of DEKRA APAC DTS and Onward Security. foundation, allowing engineering teams From Voluntary Best Practice to “Moxa’s UC Series 64-bit Arm-based computers to focus on application deployment and Mandatory Gatekeeping have achieved IEC 62443-4-2 Security Level operational resilience,” said Casper Yang, Vice Currently, multiple regulatory timelines are simultaneously in effect across regions for 2 certification, demonstrating that the President, Product Business Group at Moxa. cybersecurity compliance. The EU Cyber products have been assessed against defined “Our standardized, secure-by-design platform international cybersecurity requirements. We provides customers with a consistent security Resilience Act (CRA) is expected to be fully implemented by the end of 2027, while Japan are honored to have supported Moxa through baseline backed by a 10-year OS support, be this certification process and will continue it for compact gateway to high-performance launched JC-STAR IoT Security Labeling Scheme in 2025. Although these regulations helping industrial equipment manufacturers 5G edge platforms. With our certified UC vary in name and the applicable region, their strengthen product cyber resilience and Series portfolio, customers should never technical core is closely based on the IEC market trust through our trusted certification have to compromise on specifications to services.” stay compliant, or risk compliance to get the 62443 standards. specifications they need. We enable them to In today’s market, customers face increasing reduce the effort required for security design, global scrutiny, not only regarding the IEC 62443-4-2 Certification Offers validation, and compliance, and instead machines or systems they purchase but also Secure-by-design Focus concerning the cybersecurity maturity of the As factories, energy, and oil & gas facilities focus their resources on accelerating solution entire supply chain. An IEC 62443-4-2 certified become increasingly software-defined and development and time-to-market.” Moxa IEC 62443-4-2 SL2 certified UC computer, for example, helps equipment interconnected, operators require a secure Series computers offer a secure-by-design manufacturers and system integrators foundation for deploying applications, demonstrate that cybersecurity is integrated virtualizing payloads, and leveraging edge foundation with MIL Secure OS. They also into the platform from the beginning, thereby intelligence. With the IEC 62443-4-2 SL2 feature hardware root-of-trust authentication reducing project risk, speeding up the certified UC Series, featuring the MIL Secure and Secure Boot to prevent system tampering and cyberattacks, and auto-recovery and qualification processes, enhancing customer OS, customers choose a computer without trust, and improving readiness for regulatory compliance risks. The computers provide dual-system for maximum uptime, alongside requirements and critical infrastructure needs. industrial-grade cybersecurity with secure- network protection to minimize the attack The certification was conducted by DEKRA, by-design features, hardening guides, and surface. the world’s largest independent, non-listed diagnostic tools. In addition, a 10-year expert organization in the field of testing, security commitment ensures long-term Moxa inspection, and certification, under the IECEE security maintenance and reduces life cycle Learn More CB Scheme. risks, helping operators simplify ongoing
62
in d u s t r ial et h er ne t mag azin e
09.2026
SOURCE: MOXA
Product News
IEC 62443-4-2 SL2 Certification
SOURCE: ARC INFORMATIQUE
A major release of PcVue addresses critical systems challenges: energy efficiency, operational performance, and cybersecurity.
Product News
Introducing PcVue 17
Major release addresses critical systems challenges: energy efficiency, operational performance, and cybersecurity.
ARC Informatique, publisher of the SCADA/ BMS PcVue platform, announces PcVue 17, a major release addressing critical systems challenges: energy efficiency, operational performance, and cybersecurity.
Driving Energy Flexibility
PcVue 17 improves the energy efficiency of buildings and industrial processes. By centralizing data from multiple sources within a unified ecosystem, it actively optimizes energy demand through optimized control scenarios that can include AI-based forecasting, thus avoiding consumption peaks and reducing energy costs.
Intelligent Assistance for Performance
PcVue 17 introduces intelligent assistance that enables users to configure workflows and orchestrate complex processes through low-code interfaces. By combining AI processing and real-time data analysis, it allows to automate routine tasks and accelerates decision-making across both systems and teams. On the engineering side, PcVue 17 helps you design faster and be more efficient with enriched object libraries, and flexible modeling capabilities.
09.2026
Major release addresses critical systems challenges: energy efficiency, operational performance, and cybersecurity.
Certifications for Critical Infrastructure Cyber-resilience
Backed by IEC 62443-4-1 and IEC 62443-4-2 certifications, ensuring secure development processes and robust product security for industrial automation systems, the platform not only offers high performance, but also
i n d u s tr i a l e th e r n e t m a g a z i n e
remains secure and resilient to cyber threats, thus ensuring operational confidence for critical infrastructures. Arc Informatique Visit Website
63
Industrial Ethernet magazine & blog The best of both worlds ... the in-depth technical features our readers expect, but now also a daily blog with the latest product news and industry updates. The Industrial ethernet magazine has been rebranded Industrial Ethernet, but it's still the only publication worldwide dedicated to Industrial Ethernet automation and machine control networking, the IIoT and Industry 4.0. The difference is a deepened focus on a daily blog to deliver more and deeper content (more product news, industry updates and technology focus) to keep our readers fully informed ... while also delivering the Industrial Ethernet magazine they have come to expect.
Industrial Ethernet Visit industrialethernet.net