Why manufacturing data security starts at the connections
In a factory, data flows are operational infrastructure. When the MES stops receiving orders or the warehouse cannot confirm stock, production waits. The flows carry the operation, so protecting the operation means protecting the flows, not just the systems at either end.
Manufacturing landscapes make that harder than most. Systems accumulate over decades, equipment often predates today's security standards, and external connections multiply with every supplier and carrier. Each connection was built to whatever standard its era and its author knew, which is the general data security problem every connected business carries, concentrated in an environment where the consequences are physical.
Regulation now reflects those stakes. NIS2 classifies manufacturers as essential or important entities and requires demonstrable security measures, with incident reporting on a 24-hour clock. The five practices below apply one principle to that reality: treat every connection between systems as an asset to be governed, not plumbing to be forgotten.
Five best practices for securing manufacturing data flows
1. Map every data flow, including the ones that reach the shop floor: you cannot protect a connection you don't know exists. Inventory every integration: what it connects, what data it carries, who owns it, and what access it has. Include the flows that touch production systems, because those are the ones a plant discovers last and misses most.
Tip: start from the systems inward. Ask what reads from and writes to the ERP, then repeat for the MES and the warehouse system. Undocumented connections surface fast this way.
2. Make integrations respect network segmentation: plant security is built on defense-in-depth, independent layers of protection so that no single failure exposes everything. Keeping the shop floor separated from business systems is one of its load-bearing layers, and every ad-hoc integration that crosses that line directly is a hole punched through it. Consolidate cross-zone data movement through one governed route instead of letting each new connection open its own.
Tip: when a new system needs shop-floor data, the answer is “connect to the integration layer," never “open a direct line to the machine network.”
3. Hold every flow to one security standard: every connection should get only the access it genuinely needs, carry its data encrypted, and be possible to shut off cleanly when something changes. The plant-floor challenge is applying that uniformly around equipment that cannot meet it, because a machine installed fifteen years ago will never satisfy today's standards. The honest trade-off is containment: keep the old interface behind the governed layer, so its limitations stay local instead of becoming everyone's exposure.
Tip: the oldest connections usually have the broadest access. Start standardizing there.
4. Govern supplier and logistics connections as supply-chain risk: order links from suppliers, connections to logistics providers, and partner portals are doors into your landscape that you do not fully control, and NIS2 explicitly makes supply-chain security your obligation. Route them through the same governed layer as internal flows, with their own limited access and monitoring, and review them on a schedule.
Tip: the connection set up for a supplier trial three years ago is still live unless someone switched it off. Reviews catch what memory does not.
5. Monitor every flow with the incident clock in mind: NIS2 gives you 24 hours to file an early warning after a significant incident, and you cannot report what you cannot see. Central monitoring across all flows makes that clock realistic, with alerts ranked by operational impact: a problem on the flow feeding production outranks one on a reporting feed.
Tip: alert on absence too. A supplier feed that stops arriving can signal trouble on their side, and NIS2 makes their security your problem.









