Cybersecurity-by-Design Gains Momentum as Industrial Regulations Tighten
Cybersecurity is now an integral part of industrial automation. The manufacturers are putting more effort into incorporating security features into products at the design stage. In line with this...
Cybersecurity is now an integral part of industrial automation. The manufacturers are putting more effort into incorporating security features into products at the design stage. In line with this change, Panasonic Industry has received certification of IEC 62443-4-1, an international standard which certifies secure product development lifecycle processes for industrial automation and control systems.
The certificate applies to the company’s Industrial Device Business Division, which is a developer of products for the industrial automation field. In preparation for the European Union’s Cyber Resilience Act (CRA), Panasonic Industry has also established a dedicated product security website, which gives customers access to its security policies, vulnerability handling procedures and security advisories.
The CRA, which will be in full effect starting in 2027, mandates that manufacturers of connected products have to take cyber security measures throughout the product lifecycle – from vulnerability management to software updates to transparent disclosures of the product’s security features.
Industry context
With the growing trend of industrial automation, more and more devices are becoming connected to the Internet, cloud platforms, and remote access, creating a larger target area for potential attacks. Therefore, cybersecurity is becoming a necessity for product development for manufacturers of industrial equipment, making it a concern for IT.
New international IEC 62443 standards are becoming the de facto standard for creating secure industrial products, which are also helping manufacturers to develop a process for managing risk, securing software manufacturing, managing vulnerabilities and providing lifecycle support.
That’s all the more so with the introduction of regulations like the EU Cyber Resilience Act.
As regulatory requirements change, businesses providing automation products and services to a global market are increasingly looking to invest in secure-by-design development practices, increased transparency regarding vulnerabilities and enhanced support and monitoring after deployment. This is in line with the broader industry shift in which cybersecurity is shifting from a regulatory requirement to a competitive differentiator for companies.





