Can Zero Trust Solve the Manufacturing Security Crisis?

Can Zero Trust Solve the Manufacturing Security Crisis?

Kwame Zaire is a veteran in the manufacturing sector with a sharp eye for the intersection of heavy machinery and digital systems. As a thought leader in production management and predictive maintenance, he understands the high-stakes environment where a single minute of downtime costs thousands. Today, we sit down with Kwame to discuss how the industrial landscape is grappling with massive data breaches and the urgent need to bridge the gap between decades-old equipment and modern cybersecurity. We explore the friction between access and security, the reality of legacy hardware, and the emergence of “Zero Trust” as a solution to keep production moving safely.

The tension between operational efficiency and security protocols often leaves engineers waiting hours or even days for permissions to perform a task that takes twenty minutes. How do you see this bottleneck impacting the daily reality of production environments?

It is a massive source of frustration because, at the end of the day, production is king on the factory floor. When a controls engineer needs to troubleshoot a machine or a systems integrator has to connect to an HMI, every second they spend waiting for IT to grant access is a second the assembly line isn’t moving. We are seeing a constant clash where security and compliance teams want to lock everything down, while the operators are just trying to hit their quotas and get the equipment running. This conflict has become one of the biggest operational bottlenecks in modern manufacturing. We need a way to ensure that security does not become the very thing that halts the manufacturing output it is supposed to protect, especially when the actual technical fix is so brief.

Many plants are still running on hardware that is twenty or even thirty years old. Why is the industry struggling so much to secure these legacy assets without completely replacing them?

The reality is that these machines are workhorses that still produce high-quality products every single shift, and replacing them just because cybersecurity has evolved isn’t financially realistic for most companies. These programmable logic controllers and CNC machines were built for longevity and durability, not for a world where every sensor is connected to a cloud platform. When these systems were installed fifteen or twenty years ago, the idea of a remote cyberattack was almost science fiction. The challenge now is connecting these modern IT environments to legacy OT assets without creating new vulnerabilities that hackers can exploit. We have to find ways to modernize the network around the equipment we already own rather than tossing out perfectly good machinery.

You have seen cases where production data is literally moved via USB drives because the network isn’t secure enough for a direct connection. Can you walk us through the risks and inefficiencies inherent in that kind of manual process?

I recently looked at a food and beverage manufacturer that operated eleven North American facilities where nearly 400 devices averaged eighteen years in age. While their production was meeting goals, the operational data was effectively trapped inside those aging PLCs and historians because there was no secure way to move it. Engineers were spending a huge portion of their time maintaining old serial connections, and because they couldn’t move data securely into their analytics systems, they resorted to using USB drives. This isn’t just a slow and tedious process; it is a massive security risk because those drives are the perfect vehicle for moving malware across an air gap. When a company cannot move data in real-time to their manufacturing execution systems, they lose the ability to make fast, data-driven decisions that are essential for staying competitive.

The concept of Zero Trust is moving from IT offices to the factory floor. How does the philosophy of “never trust, always verify” actually change the way a technician interacts with a machine?

It completely shifts the mindset from building a big wall around the plant to assuming that an attacker might already be inside the network. Instead of a technician having a master key to the entire system, they are granted identity-based, least-privilege access to only the specific resources they need and nothing more. We have to move away from the old idea of “security by obscurity” because the explosion of connected IIoT devices and remote OEM support has erased those traditional boundaries. In a true operational zero trust environment, every user, every device, and every single connection must continuously prove it belongs there. This approach is vital because it prevents an intruder from moving laterally through the network if they do manage to find a way inside.

Solutions like the ES1000 edge gateway and Zentry are being framed as a security “overlay.” How does this approach solve the problem of visibility and cloaking for sensitive industrial assets?

What is impressive about this specific technology is that it performs two critical jobs simultaneously by bridging legacy protocols and securing the data flow at the same time. The ES1000 serves as a secure platform to move production data into modern MES and analytics platforms, while the Zentry software cloaks those assets so they aren’t even discoverable by unauthorized users. This means a manufacturer can establish a robust security posture in a matter of weeks rather than months, and they can do it without replacing a single PLC. It essentially creates a modern, invisible security architecture that sits on top of the existing infrastructure. By making the network dramatically harder to find and penetrate, you allow the legacy equipment to stay productive without being a liability.

The ransomware attack against Foxconn involved the theft of eight terabytes of data, highlighting how high the stakes are. How significant is it when a piece of hardware reports “zero findings” in a professional security test like those conducted by Rapid7?

It is almost unheard of in this industry to have a piece of industrial hardware come back with zero findings during a rigorous, independent security audit. When you consider that attackers are regularly stealing massive amounts of data, like the eight terabytes taken from Foxconn’s operations, having a “clean” test result is a massive confidence booster for any plant manager. It proves that the hardware was not just built for simple connectivity, but was engineered from the ground up to be a fortress against modern threats. That kind of validation is what finally convinces skeptical owners that they can bridge the gap between their old machines and the cloud without opening a back door for hackers. It changes the conversation from a fear of being breached to a focus on how much more data we can safely extract.

What is your forecast for the future of industrial connectivity over the next decade?

I believe we are going to see the total disappearance of the traditional network perimeter as every single component on the factory floor gains its own secure digital identity. In the next ten years, the manufacturers who thrive will be the ones who treat connectivity and security as the same discipline, rather than two separate departments that are constantly at odds. We will see a massive surge in the use of edge gateways that can handle complex protocols while keeping the underlying machines invisible to the public internet. Security will finally stop being viewed as a bottleneck and will instead be seen as the ultimate enabler of production, allowing for a level of transparency and efficiency we have never seen before. The “air gap” is officially dead, and the era of the invisible, zero-trust factory is just beginning.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later