FEATURE Cybersecurity
CYBERSECURITY IS A DESIGN REQUIREMENT
Ian Bramson, vice president, Global Industrial Cybersecurity, Black & Veatch, says automation readiness is a design challenge, not a technology problem, with strong cyber foundations essential from the outset
L
ong before a facility ever deploys advanced automation, project teams define how systems connect, how data moves and how operational technology (OT) environments are structured. Increasingly, those early design decisions matter more than the technology itself, and can determine not only performance, but how securely, resiliently and intelligently a facility will operate over time.
By the time cybersecurity enters the conversation, however, many of the underlying design choices have already been made. This gap persists because cybersecurity is treated as a downstream responsibility rather than a design requirement. Owners assume the equipment supplier has addressed it. Project teams assume the cybersecurity group will deal with it later on. Ultimately, the operations teams inherit the result. But today’s facilities are designed very
differently than they were a decade ago. Remote access is often expected and data is meant to move beyond the control room. Cloud services, advanced analytics and AI are increasingly part of day-to-day operations as organisations move beyond traditional automation. Decisions that once affected only reliability or performance now also determine how securely those capabilities can be deployed and expanded. In the rush to build the “factory of
tomorrow” companies forget to put cybersecurity hygiene in today. The next generation capabilities, such as AI-driven analytics and increasingly connected OT environments, need to have a strong cyber foundation built in from the beginning. As facilities move toward dark operations with AI taking on more responsibility, insider threat becomes a design consideration in ways it never was before.
8 July/August 2026 | Automation
Cybersecurity impacts how safely and
reliably a facility will operate. As facilities become more connected, the consequences of those decisions become more significant. That’s why cybersecurity belongs in the engineering design conversation from the beginning.
That means making deliberate cybersecurity decisions about connectivity, data flows, system boundaries, visibility, third-party access and monitoring. It also means establishing a way to verify that the asset was built and handed over securely. Retrofitting cyber capabilities into a live operating environment is rarely simple. Network architecture and segmentation, asset inventories, remote access controls, and monitoring points and baselines are straightforward to incorporate during design. They become far more disruptive once a facility is operating and production schedules, outages and safety considerations enter the equation. Organisations see these decisions play out during the design and delivery of industrial facilities across the full asset lifecycle. Projects that address these requirements and integrate cybersecurity early are far better positioned to support future automation because those capabilities are built into the asset rather than added later through costly and challenging retrofit projects. Designing the right architecture is only half the job. The asset still has to make it through construction, commissioning and start-up without introducing new risk. A lot can happen between design and start-up. Most of that work is routine. But without oversight, even routine activities can introduce issues that become more difficult and expensive to address after start-up.
Most companies acknowledge that cyber is better built in from the beginning, but few integrate a full cyber program during design and construction. At the core of this problem lies organisational stovepipes, lack of cyber representation in early stages and an inherent reflex to push cyber accountability to someone else.
Modern automation depends on systems sharing information. Data flows between equipment, control systems, remote operators and cloud-based applications. That connectivity creates new opportunities, but it also creates new vulnerabilities. The stronger the cyber foundation, the more resilient the operation.
Many owners and operators are moving beyond generative AI toward more agentic AI in operational environments. The challenge is that cyber is not often part of the decisions or design of those capabilities. When an owner decides they want
predictive maintenance, autonomous operations or AI-enabled decision support, the discussion naturally turns to platforms, software and analytics. But those technologies depend on strong cyber foundations that need to be built in from the beginning. Those are not just software questions. They
are design and configuration questions. That’s why cybersecurity needs a voice alongside engineering, construction, operations, procurement and finance. The solution is to involve operations, OT cybersecurity and digital stakeholders from the beginning so cyber, AI and operational requirements become design requirements, not retrofit projects.
Black & Veatch
www.bv.com
automationmagazine.co.uk
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40