search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
FEATURE Packaging


HUMAN+DIGITAL- THE FUTURE OF CYB


As digitalisation reaches maturity in industry, Consumer Packaged Goods (CPG) businesses must evolve to meet upcoming regulations, says Lee Carter, Cyber Security Product Manager, SolutionsPT


C


yber security for operational technology (OT) entered a new era in 2026 with longstanding legislative frameworks being refreshed and


expanded. In turn, OT professionals must understand the differing requirements and how they apply at all stages of the digitalisation journey. Big brands in CPG are prime targets for sophisticated cyber threats seeking to disrupt production lines, packaging operations, and supply chain networks. With that in mind, here’s a short breakdown


of the regulation changes most important for OT professionals.


Cyber Security and Resilience Bill (CSRB):


CSRB replaces the European Network and Information Systems Directive (NIS 1.0) and closely aligns with NIS 2.0 which came into force in the EU as of January 2023. More OT environments are likely to fall into regulatory scope than with NIS 1.0, with specific regulations focused for OT rather than just following the recommendations of IT only security frameworks. Any IT/OT cyber incidents will require formal reporting, with stronger enforcement powers including fines. The regulation will create a greater strain on the time of OT professionals, expecting demonstrable outcomes in security practices, resilience and recovery, along with wider enterprise responsibilities in reporting, incident response, governance, and managing supply chain risk.


Cyber Resilience Act (CRA) : CRA is


an EU regulation to ensure software and hardware products placed on the market meet cyber security requirements. It will affect UK businesses that supply products, equipment, devices, or software systems into the EU region. Failure to meet CRA requirements can result in fines, restrictions, and potential exclusion from the market.


One of the biggest changes is that any equipment supplied needs to be supported and


18 July/August 2026 | Automation


maintained for a minimum of five years for security and 10 years for safety.


Cyber Assessment Framework (CAF) 4.0: Published by the National Cyber Security Centre (NCSC), CAF provides guidance on security-based outcomes, rather than being a piece of legislation itself. Version 4.0 includes new information on cyberattack methods and motivations, guidance on software security, threat monitoring and AI-related risk. The biggest change from the previous version of 3.2 is that the process moves from a check box approach to a proactive, threat informed, and evidence-based posture. Government Cyber Action Plan 2026: This sets the UK’s cross-government agenda for improving cyber resilience, especially for public services and critical infrastructure. Although this action plan won’t directly impact all OT professionals, it does show the UK’s top-level commitment to managing cyber risk, with OT resilience being viewed as a national concern.


Staying up to date with regulation change can be hard work, but it’s positive to see how cyber security regulations are catching up to the modern reality of OT. Each framework increases the burden on OT professionals but brings an opportunity to strengthen operational resilience.


Government Cyber Resilience Pledge


2026: Announced at Cyber UK April 2026 in Glasgow, the Government is taking proactive steps to counter cyber-crime by inviting UK companies to pledge to three following actions: 1. Make cyber security a board responsibility by implementing the Cyber Governance Code of Practice and training board members.


2. Sign up to the NCSC’s early warning service within one month of making the pledge.


3. Require Cyber Essentials certification


across supply chains. Companies can register on the NCSC’s Cyber Essentials Supplier Check Tool, audit their supply chain and take a risk-based approach for instances where compliance is not needed or possible. The challenge for OT professionals is moving awareness into action and embedding cyber security at every stage in the long lifecycle of facilities, including system design, asset management, and incident response. Cyber security must also form part of every digital transformation initiative, rather than be seen as separate or standalone projects. One outcome of cyber threat is that the job


roles of OT teams has evolved with a new requirement to understand what assets are connected, how they communicate, and where vulnerabilities lie. OT teams are now also responsible for defining escalation paths and demonstrating response capabilities, which were traditionally IT-only responsibilities. The CAF framework provides a strong starting point for OT cyber security but as every OT professional knows, there is no one size fits all approach. As cyber security regulations move


towards enterprise-wide protection, OT teams are best placed to understand the daily realities of operations and how to apply new requirements across new and legacy equipment. But moving from compliance to resilience means OT teams must apply that knowledge to proven practical strategies and find ways to make cyber security simple by


automationmagazine.co.uk


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40