secria.eu

Security questionnaire in the metal and manufacturing industry: which questions recur?

Suppliers in the metal and manufacturing industry are often presented with the same questions about their production environment. This article sets out the recurring categories, with production systems connected to the network as the core.

A questionnaire from a client in the metal and manufacturing industry almost always revolves around the same theme: how is your production environment secured, and what happens if that environment is affected by a failure or an attack. This is no accident. Machines, operating systems and measuring equipment are increasingly connected to the same network as office automation, and it is precisely this connection between production and IT that a client is asking about.

The questions themselves vary by client, but the categories are remarkably constant: which systems have you mapped, is your production network separated from the office, how do you deal with outdated machines, who has remote access for maintenance, and what do you do if a production line stops due to a failure. Those who recognize these categories need not experience a questionnaire as a surprise.

Why the production environment is central

A metal processing company or machinery manufacturer operates equipment that often lasts for years or decades: CNC machines, PLCs, SCADA systems. This equipment was rarely designed with an internet connection in mind, but in practice is connected anyway, for example for remote monitoring or for transmitting production data. A client who themselves falls under the duty of care of the NIS2 Directive must assess what risks their suppliers bring with them. A production environment connected to the network without clear separation from the rest of the infrastructure is an obvious point of attention in this regard.

This explains why questionnaires in this sector more often than elsewhere go into detail on the distinction between IT (the office environment) and OT (operational technology, the production systems). A general question such as "do you have an information security policy" is in the metal and manufacturing industry almost always supplemented with a more specific one: "is your production network logically or physically separated from your office network".

The questions that almost always recur

In questionnaires to suppliers in this sector, a few subjects recur remarkably often. First, the overview: do you have a current inventory of all systems connected to your production environment, including machines that are no longer supported by the manufacturer. Then the separation between networks, and the question of whether a separate segment exists for systems that can no longer be patched.

A third recurring section concerns remote access: which suppliers or service technicians can log in remotely to your machines, and how is that access secured and logged. A fourth section concerns continuity: what happens if a production line stops due to a technical problem or an attack, and how quickly can you resume. Finally, a client often asks about incident recording: do you document when something goes wrong in your production environment, and who within your organization is informed of it.

Those wishing to check whether their own organization encounters this kind of questions through the supply chain, and in which category they fall, will find in a few questions that provide a first indication in a few minutes a starting point for that explanation.

Older machines are not always straightforward to answer

For many companies in this sector, the most difficult part is not the question itself, but the answer to it. A machine that is fifteen years old often runs on software that is no longer updated, and replacement is expensive. A questionnaire does not necessarily ask you to replace that machine, but to demonstrate that you understand where the risk lies and what measures you have taken to manage it—for example, by placing the device in a separate network segment without direct internet connection.

That distinction—between 'eliminating the risk' and 'knowing and managing the risk'—is precisely what a client is usually looking for. The Directive itself and the national laws derived from it, such as the Cybersecurity Act, describe this type of due diligence measures in general terms; the regulator additionally publishes practical guidance. An overview of what these concepts mean in detail can be found in the topics developed for each situation.

Remote access as a separate focus area

Remote maintenance is often unavoidable in the metals and manufacturing industry: a machine supplier sometimes needs to be able to observe remotely when a malfunction occurs. Questionnaires deliberately give attention to this, because it is one of the most common ways a problem at one organization can affect another. A clear answer describes who has access, how that access is granted and revoked, and whether a log is maintained of who logged in when.

What you do with an incoming questionnaire

A questionnaire from a client is first and foremost a request for insight, not an exam with a fixed number of points. A clear answer, even if it means a measure is still under development, is generally better received than a list of checkmarks without justification. For questions about what a client may precisely ask and how far that question may go, it is advisable to consult the regulator's publications or involve a lawyer; secria.eu prepares answers and documents, but never files or registers on behalf of the client.

More background on how this information is structured and which sources are used can be found on the page showing where the information comes from. Answers to frequently asked questions about questionnaires and the role of suppliers can be found via the collection of frequently asked questions.

Would you like to know whether your company will be affected by this kind of questionnaire through the supply chain, or are you looking for clarification on a specific term from a questionnaire you have already received? The free quick-scan and knowledge base provide an initial overview in half an hour, without requiring an account.

This article is general information and not legal advice.