Cybersecurity Industry 4.0: A Pact of Giants
Cybersecurity · 19. Februar 2026 · Joseph Flesh
The new alliance between Indra and Leonardo is transforming cybersecurity for Industry 4.0. What SMEs need to know about OT security now.
Last week, an old acquaintance called me, the managing director of a medium-sized stamping plant in Sauerland. 'Klaus,' he said, his voice sounding as if his soul had been ripped out, 'we're at a standstill. For three days. Not a single part is leaving the hall. Some scoundrel has hijacked our systems and is demanding a ransom.' He wasn't talking about his email server or accounting software. No. He was talking about the controls of his presses and the robotic cell he had bought only last year for half a million euros. The things were suddenly just expensive scrap.
This is not an isolated case. This is the new, bitter reality in German manufacturing. While we philosophize in glossy brochures about the blessings of AI in process optimization and digital twins, many forget the foundation on which this entire house of cards called Industry 4.0 stands: security. Our factories – once isolated castles with thick walls – have become glass manufactories with hundreds of digital windows and doors. And precisely here, at this Achilles' heel of German SMEs, the game is being reshuffled.
The Wake-Up Call from Rome: Why Cybersecurity for Industry 4.0 is Now a Top Priority
So, two big players have now joined forces – the Spanish company Indra and the Italian company Leonardo. José Vicente de los Mozos and Roberto Cingolani shook hands in Rome in mid-February. The official press release speaks of a 'Memorandum of Understanding' to strengthen European 'Cyber Defence'. Sounds like military, espionage, big politics, right? It is. But it's about much more. It's about my acquaintance's factory floor in Sauerland. And yours.
Because what the two corporations intend to do is, at its core, an attempt to forge a kind of digital shield for Europe's critical infrastructure. And what is a highly networked, just-in-time manufacturing factory other than critical infrastructure? The days when 'security' meant the gatekeeper making his rounds at night are definitively over. The partnership aims at networked operations centers, real-time exchange of threat data, and joint training environments. It is a desperate but absolutely necessary attempt to finally get one step ahead of the attackers technologically again. Indra, for example, is bringing its 'IndraMind' initiative to the table – a sovereign AI developed precisely for such defense tasks in complex environments. This is no longer a pipe dream. This is the new reality.
The danger is real, and it no longer just sits in the office, where it might encrypt accounting data. No, it has made the leap to the production level – into what is known as Operational Technology (OT). This is the world of machine controls (PLCs), control systems (SCADA), and industrial robots. A world that for decades operated on the principle of 'never touch a running system'. An update? A security patch? Far too risky, it might disrupt production. This fatal misconception is now becoming a boomerang for many.
The Fallacy of the 'Secure' Machine Network
I hear it again and again when I visit companies: 'Our machines aren't even connected to the internet.' That is one of the most dangerous sentences a managing director can say today. The separation of IT (office network) and OT (production network) is often just an illusion. Honestly: How do new milling programs get onto the machine? Via a USB stick from the programming station. How does the manufacturer's service technician perform remote diagnostics? Via a VPN tunnel. And just like that, you've built a bridge that attackers are only too happy to cross. The following table should open everyone's eyes.
| Aspect | Old World (Industry 3.0) | New Reality (Industry 4.0) |
|---|---|---|
| Networking | Isolated systems, 'air gap' as a protective barrier | Fully networked (IIoT), cloud connection, remote maintenance |
| Attack Vector | Physical access, infected data carriers | Phishing, compromised supplier access, unsecured sensors |
| Damage Potential | Failure of a single machine or cell | Complete production standstill, manipulation of processes, sabotage |
| Responsibility | Maintenance manager, production manager | COO, CIO, managing director – a matter of corporate governance |
Many medium-sized businesses still believe their OT systems are secure because they 'aren't directly connected to the internet.' This is a fatal misconception. A single infected maintenance laptop or an unsecured remote access is enough today to shut down an entire production line for days or weeks. We are seeing an increase in attacks on the manufacturing industry of almost 200% in the last two years.
— Dr. Eva Lindner, Head of OT Security at CyberProtect GmbH
European Sovereignty: More Than Just a Buzzword
When Indra and Leonardo speak of 'sovereign, open, and interoperable capabilities,' it's not just PR talk for Brussels. Behind it lies the stark realization that in Europe, we cannot afford to be dependent on American or Chinese providers for such critical technology as cybersecurity. It's about ensuring that 'critical knowledge and technological property remain under EU control.' During my last visit to the Siemens plant in Erlangen, I felt exactly this attitude. There, the 'Charter of Trust' is lived, an initiative for more cybersecurity that many global players have now joined. The big players have recognized the signs of the times. They know that a 'Made in Germany' will soon also have to include a 'Secured in Germany'.
But what about the traditional machine builder in Balingen or the automotive supplier in Lippstadt? They don't have their own cyber army in the basement. They often don't even have a dedicated OT security officer. According to a recent VDMA survey, 58% of medium-sized machine builders state that they do not have a specialized person for the security of their production facilities. The responsibility usually lies somewhere between IT and maintenance – and thus often falls between the cracks. It is precisely this gap that attackers eagerly exploit.
The Hard Truth: Is the Mittelstand Being Left Behind?
All well and good, this pact of giants. But let's be frank: Will any of this reach German SMEs? Or is it just another strategic alliance at the executive level, from which only Airbus, Rheinmetall, and electricity grid operators will ultimately benefit? I doubt that the 'sovereign, interoperable capabilities' mentioned in Rome will protect Mr. Schmidt's 10-year-old CNC milling machine from Sauerland tomorrow. This is putting the cart before the horse to some extent.
As long as managing directors in SMEs do not treat this issue with the same priority as the utilization of their machines or the margin on a new order, all these high-level initiatives will remain just a gentle breeze. Whether it is really so easy to transfer the complex solutions of corporations like Indra or Leonardo to the grown, heterogeneous machine landscape of a typical SME remains to be seen. In my experience, many massively overestimate their own resilience. The thought 'There's nothing to gain from us' is the first nail in your digital coffin.
From Hoping to Acting: 5 Concrete Steps for Your Manufacturing
There's no point in waiting for the big European solution. You need to act today. Here are five steps every manufacturing company can and should take immediately:
- 1. Inventory instead of ostrich policy: Do you even know which devices are communicating in your production network? Create a complete list of all controllers, panels, sensors, and gateways. Every single device is a potential point of entry. Without visibility, you're fishing in troubled waters.
- 2. IT and OT? Two strictly separate worlds!: Ensure clean segmentation of your networks. The accounting printer must under no circumstances be on the same network as the control system of your paint shop. Use firewalls specifically to strictly control communication between segments.
- 3. Activate the 'Human Firewall': The biggest vulnerability is and remains people. Train your employees – not just those in the office, but also those in production! A machine operator who connects an unfamiliar USB stick to their operating terminal can cause more damage than a fire. Regular training on phishing and social engineering is mandatory.
- 4. Establish patch management for production: Yes, it's annoying, and yes, it carries risks. But operating a 15-year-old control system with a known security vulnerability is like playing Russian roulette. Create a plan for when and how you can install security patches without endangering production. Talk to your machine manufacturers.
- 5. Prepare an emergency plan (and test it!): What do you do if it does happen? Who is informed? How are systems taken offline? How do you restore backups? Developing such a plan only in a crisis is negligent. Run through the scenario so that everyone knows what to do in an emergency.
Your Playbook for the Ideal Customer Profile (ICP) Identify the right industrial customers who understand the value of cyber resilience and are willing to invest in it. Define your Ideal Customer Profile with our playbook and specifically target the companies that truly need your solutions.
Frequent Questions about OT Security in SMEs
Is cybersecurity even relevant for us? We only produce simple metal parts.
Absolutely. Attackers are often not interested in your product data, but in disrupting your operations. Every day your machines are down due to a ransomware attack costs you real money and damages your reputation as a reliable supplier. The complexity of your product plays no role here.
Our machines are old. Can they even be protected?
Older systems (legacy systems) are a major risk, as they often lack modern security features and are no longer supported by the manufacturer. Network segmentation is crucial here: Isolate these machines in their own, strictly controlled network segment, so they are cut off from the rest of the corporate network. Monitor network traffic to and from these machines particularly closely.
Who is supposed to do all this for us? We don't have the staff for it.
That is the crucial question. If you don't have the expertise in-house, get it from outside. There are specialized service providers for OT security who can support you with analysis, conception, and implementation. This is an investment, not just a cost. An investment in the survival of your company.
Honestly: The partnership between Indra and Leonardo is just a press release for now. A signal. But it's the right signal at the right time. It shows that the issue has reached the highest level. The time of naive networking and blind trust in the digital world is over. The smart factory needs smart – and above all robust – fortress walls. Anyone who doesn't understand that today might not produce anything tomorrow. And I bet that in three years, we won't just be talking about cycle times and OEE, but about the 'Mean Time to Recovery' after a cyberattack. That will be the new hard currency in manufacturing. There's no way around it.