Industrial Cybersecurity Skills Are Now a Core Competency for Controls and Automation Engineers
Manufacturing systems are more connected than ever. Industrial Internet of Things (IIoT) devices, cloud-connected production systems, smart factory initiatives, artificial intelligence and remote access tools are creating new links between plant-floor equipment and enterprise networks.
Those connections can improve productivity, visibility and decision-making. At the same time, they also create new paths for cyberattacks to reach systems that control physical operations.
As a result, cybersecurity is no longer solely an IT responsibility. The silos between engineering and IT are being torn down as industrial control systems and automation engineers increasingly make design, integration and maintenance decisions that affect the security, resilience and reliability of manufacturing systems.
This shift is changing what manufacturers should expect from controls and automation engineers — they must now be able to secure what they build.
Industrial Cybersecurity Risks Change the Role of Engineering
Technical proficiencies with programmable logic controllers, human-machine interfaces, and supervisory control and data acquisition systems remain essential skills for controls and automation engineers. But the role now extends beyond making systems function and includes direct influence on how devices connect, how production data moves, who can access equipment and how systems respond when something goes wrong.
These new responsibilities to enable remote access, connect a new sensor or integrate a production line with the enterprise network create operational value while also introducing risk of cyberattacks. This means industrial cybersecurity must be top of mind during the engineering stage, rather than an afterthought once a system is designed and implemented.
Why Cyber Risk Also Puts Operational Technology at Risk
In manufacturing, an industrial cybersecurity incident can affect much more than data. Operationally, it can stop production, disable equipment, create quality issues and increase safety risks.
A cyber attacker who gains access to an engineering workstation may be able to alter control logic. A poorly managed remote connection may expose a production system to unauthorized users. Inadequate network segmentation may allow a compromise in one area to spread across multiple lines or facilities. The consequences may include:
- Emergency recovery costs
- Equipment damage
- Lost production
- Missed delivery dates
- Product defects or rework
- Safety or environmental risks
- Unplanned downtime
Traditional Hiring Criteria Are No Longer Enough
Many controls and automation engineering job descriptions still focus on technical experience with programmable logic controller (PLC) platforms, robotics, industrial networks and manufacturing processes. Those requirements remain important, but they do not fully reflect the demands of connected manufacturing and engineering. Today, a candidate should be able to program and commission a system and have a broad awareness of how that system should be protected.
However, it’s important to avoid creating unrealistic job descriptions that combine the responsibilities of an industrial control systems engineer, network architect and industrial cybersecurity specialist. The goal is not to find someone who can do everything. The winning strategy is to identify engineering candidates who understand how cybersecurity fits into their work and raise the flag when it’s time to involve IT.
Looking to Build a Team with Industrial Cybersecurity Skills?
Partner with Actalent to attract talent for your digital transformation initatives and projects.
Importance of Industrial Cybersecurity Skills
Controls and automation engineers do not need to become expert cybersecurity analysts. However, they do need enough cybersecurity fluency to account for cyber risk within the normal scope of their role, such as recognizing when a design choice could expose production systems. That includes an awareness of critical cybersecurity skills and concepts such as:
- Asset documentation
- Authentication and authorization
- Backup and recovery planning
- Configuration management
- Coordination with IT and cybersecurity teams
- Life cycle planning for aging equipment
- Secure vendor and remote access
- Security requirements during equipment selection
- Segmentation of critical systems
The choice between an engineer who can recognize these concepts versus one who can’t could be the difference-maker in how a manufacturer prevents a cyberattack or contains an incident and restores operations. Hiring managers should look for candidates with enough cybersecurity fluency to make everyday engineering decisions that reduce these risks.
Cybersecurity Skills to Look for in Engineering Candidates
Operational Technology and Industrial Control Systems Awareness
Strong engineering candidates should be able to explain how they would balance cybersecurity with operational realities. They should recognize that operational technology (OT), industrial control systems (ICS) and enterprise IT are not secured in the same ways. Manufacturing equipment may need to run continuously. Software updates may require planned downtime, vendor approval or extensive validation. Legacy systems may use older protocols. Safety and performance requirements can limit which security tools may be installed.
Cross-Functional Communication
In connected manufacturing, communication is a key factor in risk management. Industrial cybersecurity often depends on coordination among engineering, operations, maintenance, IT, cybersecurity teams and equipment vendors. Controls and automation engineers are often well positioned to facilitate collaboration among these groups because they understand both the physical process and the systems that control it.
Therefore, the best candidates need to be able to explain production constraints to cybersecurity teams and in turn translate security requirements into practical engineering actions. They must be capable of documenting risks, escalating concerns and communicating trade-offs to technical peers and business leaders alike.
Industry Standards Acumen
Hiring managers should look for engineering candidates familiar with key industrial cybersecurity standards, such as those from:
- International Society of Automation/International Electrotechnical Commission 62443 (ISA/IEC 62443)
- National Institute of Standards and Technology (NIST)
- Cybersecurity Maturity Model Certification 2.0 (CMMC 2.0)
- Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
Each of these frameworks increasingly shapes how manufacturers design, document and manage connected systems. Controls and automation engineers with this knowledge are better prepared to identify industrial control systems security requirements early, evaluate equipment and vendor risks, support audits and incident reporting, and reduce costly redesigns late in a project. They can also collaborate more effectively with IT, cybersecurity, compliance and operations teams, helping ensure cybersecurity standards are built into system requirements.
Build Industrial Cybersecurity into the Engineering Talent Strategy with Actalent
As manufacturing systems become more connected, industrial cybersecurity fluency will become a defining capability for controls and automation engineers. However, engineers with deep controls experience and advanced cybersecurity knowledge remain difficult to find. That makes access to specialized expertise a practical talent strategy for developing a resilient engineering team.
Actalent supports manufacturers through a network of controls and automation professionals who hold industrial control systems integration and manufacturing expertise. Our specialized recruiters help organizations attract this hard-to-find talent for digital transformation initiatives and projects.
Connect with Actalent to build a cyber-aware controls and automation workforce for your manufacturing organization.
