TechnologySeptember 21, 2026
How to Make Industrial Networks More Resilient
Mandatory implementation of verifiable security measures is now a requirement. The IEC 62443 series of standards, supplemented by European legislation such as the NIS 2 Directive and the Cyber Resilience Act (CRA), require operators and manufacturers to implement verifiable security measures.
While the increasing digitalization of industrial processes boosts efficiency and flexibility, it also makes modern production facilities more vulnerable to attacks. Cyberthreats no longer only target IT systems – they now increasingly affect operational technology (OT) as well. To ensure adequate protection, a growing number of standards and legal requirements have been established.
Among the key regulatory frameworks is the international IEC 62443 series of standards, which defines the requirements for components, systems, and processes in industrial automation. It is supplemented by European legislation such as the NIS 2 Directive and the Cyber Resilience Act (CRA), which require operators and manufacturers to implement verifiable security measures. NIS 2 extends responsibility beyond critical infrastructure systems to large parts of the industrial value chain. The CRA, on the other hand, addresses the cybersecurity of products with digital elements throughout their entire lifecycle. Together, these requirements aim to make industrial networks more resilient and ensure their continuous availability.

Figure 2: A comparison of the European NIS 2 and CRA legislation.
Securely developed devices with comprehensive security functions
Industrial networks consist of various components, each performing their own security-related role. Manufacturers such as Phoenix Contact offer solutions for these device categories that are developed using secure processes and are equipped with comprehensive security functions. Managed switches form the backbone of communication. They ensure the segmentation, prioritization, and stability of data traffic. Security routers with firewall functionality protect the boundaries between zones or network segments and control who is allowed to access what. Wireless infrastructures – from industrial WLAN access points to cellular routers – enable flexible applications and remote access. At the same time, however, they open up additional attack vectors via wireless technologies in the public sphere. Many of these devices operate over long lifecycles within heterogeneous system structures. Misconfigurations, inadequately secured interfaces, or firmware updates that have not been installed can, over time, expose critical vulnerabilities and thus become a major security risk.

Figure 3: Use of managed switches and security routers in the control cabinet.
Diverse requirements for network components
How can certified network components actually increase the cybersecurity of industrial networks? From the point of view of IEC 62443, components must contribute to achieving the security levels defined by the standard within a system. For network technology components, this means secure management access, role-based user and rights administration, cryptographically protected communication channels, firmware integrity checks, and traceable logging of security-related events. In addition, there are hardening measures such as disabling unnecessary services or ports, protection against brute-force attacks, and secure update mechanisms. Only when these capabilities are present at the device level can operators efficiently map the zone and line models described in the standard in practice.

Figure 4: Network components from Phoenix Contact are certified in accordance with IEC 62443.
The benefits of such functions are particularly evident in machine building and systems manufacturing. Today, production cells are typically designed as separate security zones with strictly defined communication relationships. Managed switches in these zones do more than just perform switching. They also logically separate the various machine components via VLANs, prioritize time-critical protocols (such as Profinet or EtherNet/IP), and support ring redundancy mechanisms to ensure high availability. Security routers installed at the boundary between the security zones enforce the strictly defined communication relationships mentioned above using integrated firewalls with stateful inspection. Remote service access can be enabled via IPsec or OpenVPN tunnels for a limited period of time and with unique authentication. This includes logging which connection was active when and which controllers were addressed.
Comprehensive protection of critical infrastructure and older systems
Public infrastructure and critical supply networks face even stricter requirements. Here, the control room, remote control, and field levels must be protected against both external attacks and misconfigurations. For example, managed switches ensure that only authorized devices are permitted access to specific ports (e.g., via port security, 802.1X, or MAC filters), thereby making manipulation attempts at Layer 2 level more difficult. Time-stamped logs and integration with central Syslog or SIEM systems make it possible to track security-related events in the control center.
A third common scenario involves retrofitting older systems. Many control systems were originally developed without a focus on security. As a result, they do not use encrypted protocols or modern authentication mechanisms. Here, operators use certified security routers as an upstream layer of protection to operate these components in isolated segments. Typical measures in this context include the strict allowlist configuration of permitted connections, the establishment of defined engineering access, and the restriction of remote access to clearly defined maintenance windows. In combination with switch functions such as the port security described above, this approach significantly reduces the attack surface without requiring a fundamental overhaul of the existing automation infrastructure.
Collaboration based on clear processes

Figure 5: Phoenix Contact offers a holistic 360-degree security concept
Certified individual devices alone are not enough, however. They only unleash their full potential within a coordinated system architecture, as specified by IEC 62443: defense in depth, zoning, defined communication paths, and consistent hardening measures. It is crucial that all stakeholders, such as operators, integrators, and manufacturers, speak the same language and act according to clear processes. Companies like Phoenix Contact therefore complement certified products with secure development processes, solution architectures, and incident response structures. For operators, this means they can rely on end-to-end security concepts that extend beyond the individual device. Furthermore, IEC 62443 supports operators not only in developing holistic security concepts, but also in complying with new legal requirements, such as the Cyber Resilience Act (CRA). This is because many of the new legal requirements are already addressed by IEC 62443.
Industrial cybersecurity is not a static state, but an ongoing process. Certified components provide a robust foundation for this. They enable networks to be built in accordance with recognized standards, minimize threats, and ensure compliance with regulatory requirements. In an era of increasing digitalization and standardization, certified security components are thus an indispensable building block for stable industrial value creation.
Certified cybersecurity from Phoenix Contact
Phoenix Contact offers a comprehensive portfolio of IEC 62443-4-2-certified products for industrial networks. These include the managed switches from the FL Switch 2000 series, security routers from the mGuard product family, and industrial cellular solutions such as the Cellulink routers for 4G/5G networks. Other series – such as the FL WLAN infrastructure devices with Wi-Fi 6/6E technology and the FL Switch 5900 series managed switches for 19-inch rack mounting – already meet key requirements of IEC 62443-4-2.
All products are developed using secure development processes, certified in accordance with IEC 62443-4-1. They comply with the security functions described for use in demanding OT environments. In addition to secure products and processes, Phoenix Contact’s 360-degree security strategy also encompasses secure solutions and active vulnerability management by a Product Security Incident Response Team (PSIRT). The company thus supports operators in holistically securing industrial networks – from planning and operation to incident handling.