Skip to main content
Industry

IT Advisory for Industry & Manufacturing

Manufacturers and machine builders face three regulatory regimes with different deadlines in 2026.

Overview

IT in Industry

The German NIS2 implementation act has applied since 6 December 2025 without a transition period. Machinery, motor vehicle and other transport equipment manufacturing, along with the manufacture of electrical equipment, appear in Annex 2 of the BSI Act and therefore count as important entities once the size threshold in section 28(2) BSIG is met: at least 50 employees, or an annual turnover and an annual balance sheet total each exceeding 10 million euro.

That triggers the ten minimum measures of section 30 BSIG, the 24-hour, 72-hour and one-month reporting chain of section 32 BSIG, and the management training duty under section 38 BSIG. In parallel the Cyber Resilience Act applies: since 11 September 2026 manufacturers must report actively exploited vulnerabilities in products with digital elements — early warning within 24 hours, notification within 72 hours, final report no later than 14 days after a corrective measure becomes available; full product obligations follow on 11 December 2027.

From 20 January 2027 the EU Machinery Regulation 2023/1230 replaces the Machinery Directive outright, with no option to choose between them, and requires documentation of software, network connectivity and remote maintenance. On the production floor IEC 62443 remains the reference standard for zones and conduits. Concretely: control systems, MES and office IT belong in separate segments with defined communication paths, not one flat network; supplier remote maintenance needs identity and logging, not open ports; backups must be immutable, because ransomware attacks them first.

That is where Alendris works. In manufacturing we built a hyperconverged cluster on Storage Spaces Direct with NVMe storage, segmented the network and modernised it to 10G — the server environment no longer has direct internet access — implemented Veeam with immutable storage and hardened Active Directory: daily rotating passwords via fine-grained password policies, Windows Hello for Business and YubiKey, gMSA instead of static service accounts, privileged access only through a jump host. A second manufacturing engagement added micro-segmentation, CIS benchmark hardening at level 1 estate-wide and level 2 for critical systems, Microsoft Intune with Autopilot, plus EDR and SIEM.

Context

Typical pain points

  • Outdated office IT meets cutting-edge Industry 4.0 systems — missing integration
  • OT/IT segregation: production networks (SCADA, MES, ERP) must be securely segmented from office IT
  • Ransomware risk with production downtime consequences (multi-million daily damages)
  • Microsoft licence complexity for engineering workplaces (CAD servers, RDS, specialist software)
  • Demographics: experienced IT staff retiring, knowledge transfer missing
Regulation

Relevant compliance frameworks

NIS2 / NIS2 implementation actsISO 27001IEC 62443 (OT security)German Supply Chain ActTISAX (automotive supply chains)