CommunicationsIssue 60 - 2026Notebook IssueProduct

Secure by Design: What It Means When You Buy Industrial Components

By Tim Wheeler, Cybersecurity Manager, AutomationDirect

When customers purchase industrial components, they’re looking for more than a part number. They want products they can rely on in real-world machines, panels, process lines, and production environments where uptime, maintainability, and predictable operation matter every day. Increasingly, they also want confidence that those products were designed with cybersecurity in mind before they were ever installed on a network.

As industrial devices become more connected, cybersecurity is becoming part of the overall product-quality conversation. Controllers, HMIs, drives, communication modules, gateways, and other devices now routinely exchange data with enterprise systems, cloud services, remote operators, and third-party equipment. That connectivity creates new operational capabilities, but it also introduces new considerations around configuration, maintenance, updates, and long-term support.

To help explain what “Secure by Design” means from an industrial customer’s perspective, Automation Notebook spoke with Tim Wheeler, Cybersecurity Manager at AutomationDirect.

What does “Secure by Design” mean in industrial automation?

At a practical level, Secure by Design means cybersecurity is considered during product development instead of being treated as something added later. When a customer buys an industrial component, they’re not just buying hardware. They’re also placing trust in how that product was designed, documented, configured, maintained, and supported throughout its lifecycle.

For industrial customers, that matters because these products often remain in operation for many years. A PLC, HMI, industrial PC, or communication device may still be running long after the original installation team has moved on. The product should be designed so customers can understand how it operates, configure it correctly, maintain it over time, and apply updates when needed.

One misconception is that Secure by Design is mainly about compliance or regulations. Standards and regulations are influencing the conversation, but the bigger issue is operational confidence. Customers want products that are thoughtfully designed for connected industrial environments and supported throughout their operational lifecycle.

Secure by Design also doesn’t mean a product is automatically “secure” by itself. Customers still need good network design, segmentation, access control, backup procedures, and maintenance practices. What Secure by Design does do is give customers a stronger starting point before the product is ever installed on their systems.

Why has Secure by Design become a bigger topic in industrial automation recently?

Industrial systems today are much more connected than they were even ten years ago. Historically, many industrial devices operated in relatively isolated environments. Now, it’s common for systems to exchange production data with business systems, connect with remote support teams, communicate with cloud platforms, or integrate with Industrial Internet of Things applications.

As that connectivity has increased, cybersecurity expectations have also increased. Customers want to know how products are designed and supported because they understand that connected devices can become part of a much larger operational network.

At the same time, industry standards and regulations are evolving around products with digital elements. Frameworks like IEC 62443 and regulations such as the Cyber Resilience Act are helping shape expectations around secure development practices, documentation, vulnerability management, and lifecycle support. While most industrial customers don’t need to become experts in every standard or regulation, they should understand that cybersecurity is increasingly being treated as part of responsible product development.

How is Secure by Design different from traditional industrial cybersecurity approaches?

Traditionally, cybersecurity was often treated as something added around the outside of an industrial system. Companies focused heavily on perimeter defenses such as firewalls, segmentation, antivirus software, and remote-access controls. Those things are still important, but Secure by Design shifts some of the focus directly into components themselves.

For example, customers shouldn’t have to be cybersecurity experts to avoid obvious mistakes. A product designed with security in mind may disable unnecessary services by default, clearly document communication ports, support authentication options, provide a defined update process, and avoid hidden or unexplained access methods.

Those kinds of decisions help reduce unnecessary exposure before the product is ever placed into operation. It creates fewer unnecessary doorways into the device while making the product easier to understand and manage over time.

Why is lifecycle support so important in industrial environments?

Industrial systems tend to have very long operational lifecycles compared to many enterprise IT systems. Some industrial devices remain in service for ten, fifteen, or even twenty years depending on the application. Because of that, customers are evaluating more than initial functionality when they purchase a component.

They also need confidence that the supplier has considered long-term maintainability, software updates, documentation, and support processes. A product may perform well on the day it’s installed, but customers also need to know how it’ll be maintained several years later when networks, operating systems, and security expectations have changed.

Industrial environments also have operational realities that make maintenance more complicated. Many systems can’t simply be shut down during business hours for updates or configuration changes. For example, you wouldn’t want your PLC to do an “automatic” update like what your PC running Windows might do and shut down production as a result.

So, having more explicit control of how your device updates is crucial. Maintenance windows may be limited, production schedules may be tight, and some facilities operate continuously. Secure by Design recognizes those operational constraints and tries to make products more manageable within real industrial conditions.

What are some practical things customers should look for when evaluating industrial products?

One important area is documentation clarity. Customers should be able to understand how the product communicates, what services are enabled, how updates are handled, and what security-related configuration options exist. Clear documentation can help them make informed decisions during installation and maintenance.

Another consideration is whether unnecessary features or services are enabled by default. In many situations, customers only need a subset of a device’s capabilities for a particular application. Minimizing unnecessary exposure helps reduce risk and simplifies deployment.

Customers should also look at whether the supplier has a defined vulnerability response process. No product is completely immune from vulnerabilities over time, especially as technologies evolve. What matters is whether the supplier has processes in place for identifying issues, communicating with customers, and providing updates or mitigations when needed.

Lifecycle support also matters. Customers aren’t just selecting a device. They’re selecting the development practices and long-term support practices that stand behind it.

How does Secure by Design relate to product quality?

Industrial customers already understand product quality very well. They evaluate products based on reliability, uptime, maintainability, documentation, support, and predictable performance.

Cybersecurity increasingly fits into that same conversation. If a device is difficult to configure securely, lacks clear documentation, has poorly managed update processes, or exposes unnecessary services, those things can create operational problems just like poor hardware reliability can.

From that perspective, cybersecurity becomes part of overall product quality rather than a completely separate IT issue. A well-designed product helps customers deploy and maintain systems more confidently throughout the operational lifecycle.

Why can industrial cybersecurity be more complicated than traditional IT cybersecurity?

Industrial environments have different operational priorities. In enterprise IT environments, systems can often be updated or restarted more frequently without major operational consequences. Industrial systems are different because they may support continuous manufacturing processes, real-time control functions, or safety-related operations.

Many industrial environments also include legacy systems that were designed long before modern cybersecurity expectations existed. Customers often need to integrate newer connected technologies with older operational equipment that may still be functioning reliably from a production standpoint.

There’s also the challenge of balancing security with operational performance. Industrial systems frequently require deterministic communications and high availability. Any cybersecurity measures need to support those operational requirements without introducing unacceptable latency or instability into the process.

Because of those realities, industrial cybersecurity tends to require a more operationally aware approach than many traditional enterprise IT environments.

How is AutomationDirect approaching Secure by Design within its product and support philosophy?

One important part is helping customers make informed deployment decisions. That starts with practical documentation, transparency around product capabilities, and guidance that helps customers understand how products communicate and operate within connected industrial environments.

AutomationDirect is also mindful of abiding by global cybersecurity standards, such as the ISA/IEC 62443 standards that define requirements and processes for implementing and maintaining electronically secure automation and control systems. Our product development teams are now following these guidelines at the earliest points of their design and engineering.

Another area is reducing unnecessary complexity wherever possible. Customers should be able to configure products appropriately for their applications without having to reverse engineer how a device behaves on a network.

Lifecycle thinking is also important. Customers want products that can be maintained and supported over time, especially in industrial environments where systems often remain operational for many years. That includes considering update processes, vulnerability response practices, and long-term product support.

Education plays a role, too. Many industrial customers are still navigating how cybersecurity fits into their OT environments. Providing practical resources and guidance can help customers strengthen their overall approach without making cybersecurity feel disconnected from day-to-day operations.

How do you see customer expectations evolving over the next several years?

Customers are becoming more aware that cybersecurity is part of the overall lifecycle and operational readiness of industrial products. They’re asking more questions about support processes, software maintenance, update procedures, and long-term product management.

I also think customers increasingly expect better transparency from suppliers. They want clear information about how products communicate, what capabilities are enabled, and how vulnerabilities are handled when issues arise.

At the same time, industrial equipment continues to become more connected. More devices now support APIs, remote communications, cloud integration, and data-sharing capabilities that were uncommon years ago. That connectivity creates significant opportunities for efficiency and operational visibility, but it also means cybersecurity considerations will continue becoming more important during product selection.

At the end of the day, Secure by Design is really about helping customers make better-informed component purchasing and deployment decisions. It’s about giving them greater confidence before the product is ever installed on their network or production floor.