search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
TECHNOLOGY FOCUS Industrial cybersecurity


DELIVERING SECURE DIGITALISATION


Simon Merklin, Product Security Marketing Lead, Endress+Hauser Digital


Solutions, says interoperability, regulation and trust are redefining digitalisation, as industry faces increased exposure to cyber threats


O


ver the last few decades, digitalisation has transformed the process industries. The rise of digitally connected


measurement devices and cloud connectivity is revolutionising the sector by delivering clear operational benefits. However, the use of modern technologies, like Bluetooth and web servers, increase exposure to cyber threats. Cyber incidents can have far-reaching consequences, including production downtime, safety risks, regulatory violations, and reputational damage. As a result, cybersecurity is no longer an add on. Securely developed measurement equipment has become a fundamental prerequisite for plant operators. Security by design is therefore not just a technical detail, but the condition that allows digital ecosystems to grow safely, predictably, and sustainably. Endress+Hauser understands that cybersecurity is evolving and becoming a key discussion point across the industry. Therefore, the goal is not only to deliver innovative digital solutions that help boost productivity but, with the new ProtectBlue security trademark, but also ensure they can be seamlessly integrated into existing plants, comply with regulatory requirements, and remain secure throughout their lifecycle. New regulations are influencing how cybersecurity is implemented in industrial environments. One of the most significant developments is the European Cyber Resilience Act (CRA), coming fully into force 11 December 2027. The CRA establishes mandatory cybersecurity practices for products with digital elements, covering the entire lifecycle, from design and development to update and vulnerability handling processes. Endress+Hauser views the CRA not as


a burden, but as an opportunity to grow, strengthen trust, and create reliability for


22 June 2026 | Automation


customers. That’s why the company has established group-wide working groups to ensure a harmonised and efficient CRA implementation across the whole portfolio. All industrial communication protocols, from HART to PROFINET, have been evaluated to ensure compatibility with customers’ installed base. As a result, products will remain available and compliant when CRA requirements come into force. Endress+Hauser helps to shape cybersecurity practices beyond its portfolio by driving alignment across the industrial ecosystem. As the lead of the Standards Developing Organization (SDO)-wide joint working group “Industrial Security Harmonization Group”, the company works with other SDOs to align specifications, terminology, and secure deployment guidance across industrial communication standards. In parallel, Endress+Hauser contributes to security innovations in key standardisation initiatives, including PROFINET Security, to ensure that security mechanisms remain robust, implementable in real plants, and compatible with existing installed bases. In addition, Endress+Hauser collaborates closely with industry partners and associations, such as NAMUR (NE201) and ZVEI working groups, to accelerate alignment, practical adoption, and drive harmonisation work across the industrial ecosystem. For Endress+Hauser, cybersecurity is


treated as a lifecycle responsibility from product design and development to operation,


vulnerability handling, and long term support in the field.


Hence, the Endress+Hauser Group has had its


Secure Development Lifecycle certified according to IEC 62443-4-1 by TÜV Rheinland and also received ISO 27001 certification from SQS for its IIoT development centre. Furthermore, the IIoT ecosystem Netilion meets the requirements of ISO 27017. These accreditations help to ensure the compliance of customers and deliver high-quality and secure products. With the launch of the ProtectBlue framework,


Endress+Hauser introduces a clear, portfolio wide security label that makes built in device protection visible and comparable for customers. ProtectBlue reflects a holistic approach by embedding cybersecurity directly into devices and development processes.


The framework combines portfolio-wide security requirements (based on IEC 62443 4 2) with a secure development lifecycle under IEC 62443 4 1. Furthermore, standardised security software components are leveraged to harmonise operation and secure access management across the entire ProtectBlue product portfolio, helping customers implement security efficiently and reduce security-related outages. Cybersecurity in the process industries cannot be tackled by manufacturers or operators alone. It requires collaboration across the value chain, clear standards, and a shared understanding of risks and responsibilities.


Endress+Hauser www.uk.endress.com/en


automationmagazine.co.uk


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40