IWILL in Engineering Review
In a new bylined article for the Bulgarian engineering journal Engineering Review (“Инженеринг ревю”), Vasil Toshkov of IWILL looks at NIS2 through one concrete question: what happens to a critical process when an industrial terminal, network device or workstation fails?
The article, “Ready for a NIS2 audit? Industrial hardware is part of the answer”, explains why preparation does not end with a cyber-security policy or an installed firewall. For manufacturing and logistics organisations it includes architecture, access control, visibility of events and a demonstrable ability to recover.
Practical topics covered
- separating the corporate IT network from OT systems – SCADA, PLCs, HMIs and production machines
- managing and recording remote access by external service engineers
- the role of logs in audits and incident analysis
- up-to-date backups, compatible spare devices and a recovery procedure tested in advance
- assessing industrial computers and touch panels as part of the critical process lifecycle
The main conclusion: NIS2 does not prescribe a specific hardware model, and owning a device does not by itself ensure compliance. What matters is that an organisation can show how its infrastructure limits risk, how it maintains continuity and how it will restore operations within an acceptable time.
The article also offers five practical questions teams can use to start an internal review of their infrastructure – from the list of critical assets to the real recovery time after a failure.
Why it matters for UK organisations
NIS2 is EU legislation, but the same questions apply to UK operators under the NIS Regulations, to businesses with EU sites or customers, and to anyone working towards Cyber Essentials or IEC 62443. The hardware side of the answer – segmented networks, controlled remote access, industrial endpoints with a known lifecycle and tested spares – is the same.
Read the full article (in Bulgarian) on engineering-review.bg, or start with our English guides below.
