Industrial Cybersecurity
Industrial Cybersecurity Myths We Still Encounter in the Field
The most important improvements often begin with correct network design, clear access paths, and layered protection.

The problem often starts before a security appliance is installed
After a major cyberattack, the first questions often focus on firewalls, software, or the newest security product. Those tools have a place, but many significant improvements cost little. They begin with designing industrial networks correctly and challenging assumptions about how systems are connected.
Manufacturers, municipalities, water systems, and other industrial facilities can take security seriously and still carry hidden risk when trusted devices or support processes create overlooked pathways.
Five myths worth challenging
Myth 1: Our PLC is not connected to the Internet
The PLC may have no direct Internet connection, while an engineering workstation, HMI, remote support computer, historian, reporting server, cloud dashboard, or vendor remote-access package does.
An attacker may only need access to a trusted device that already communicates with the PLC. Map every pathway into the control network, not only the PLC's public exposure.
Myth 2: We have a firewall, so we are secure
A firewall is an important layer, but it is not the complete architecture. Effective protection can include VPN-only remote access, strong authentication, segmentation, least privilege, secure support procedures, logging, monitoring, and routine maintenance.
Design the system so other protections continue to reduce risk if one layer fails.
Myth 3: We are too small to be a target
Small manufacturers, municipal water and wastewater systems, grain facilities, and local industries can all experience cyber incidents. Many attacks are automated and search broadly for vulnerable systems.
Organization size does not remove exposure. Security posture and reachable pathways matter.
Myth 4: Our vendor handles cybersecurity
Equipment, network, and firewall manufacturers can provide capable components, but no single vendor automatically knows how the entire facility is connected.
Security comes from integrating devices, networks, remote connections, engineering workstations, and support processes correctly. That is an engineering responsibility.
Myth 5: Nothing has happened, so we must be secure
Years without a known incident do not prove that the architecture is secure. An exposed path may simply remain undiscovered.
Preventive cybersecurity works like preventive maintenance: remove unnecessary risk before it affects operations.
Good security should support daily work
Operators still need to operate. Maintenance personnel still need to troubleshoot. Authorized engineers still need to provide support. A properly designed system preserves those workflows while preventing unauthorized access.
The objective is not complexity or fear. It is thoughtful engineering: understand communications, limit unnecessary exposure, plan remote access, and build multiple layers of protection around the people and infrastructure that depend on the system.
How can BEA help?
BEA can help industrial teams review network pathways, remote-access practices, segmentation needs, engineering workstations, and support workflows. The goal is a practical security approach that protects operations without obstructing authorized users.
Read the original source article for the full field perspective.