Skip to main content Skip to search Skip to main navigation

1. Initial Situation: Cybersecurity in Operational Technology (OT) (Industrial Cybersecurity, OT Risks)


Cybersecurity is a critical issue – not only for corporate IT, but increasingly also for operational technology (OT). OT was originally a largely isolated environment in which PLCs, networks, and control components were interconnected to perform a specific task. In this context, the term “security” primarily referred to safe operation rather than protection against cyber threats.

However, this changed fundamentally with the discovery of the “Stuxnet” worm in 2010. The attack on PLCs clearly demonstrated that OT environments can also become targets of cyberattacks. Traditionally, these environments were “air-gapped” and not connected to external networks. Today, however, OT networks are often connected to IT systems or the cloud via Ethernet or Wi-Fi.

With the convergence of IT and OT, factory automation and industrial applications must be prepared to withstand current and future cybersecurity threats. While IT incidents occur more frequently, OT incidents are often significantly more destructive and can endanger human life as well as entire companies. The technological gap between IT and OT systems also makes it difficult to simply transfer established IT security mechanisms to OT environments.

FAQ - Security and CRA
What does “CRA-compliant” mean for a product?
A CRA-compliant product meets the essential cybersecurity requirements of the Cyber Resilience Act (CRA), has undergone a cybersecurity risk assessment, and is supported by processes for vulnerability handling and security updates. Following a successful conformity assessment, compliance is documented in the EU Declaration of Conformity and the product is CE marked accordingly. All products that fall within the scope of the CRA and are placed on the EU market (i.e. sold) from 11 December 2027 onwards must comply with the CRA.

Do Helmholz products that are already installed need to be replaced?
No. As a general rule, the CRA does not require products that have already been installed to be replaced. Products sold before 11 December 2027 are generally not retroactively subject to the CRA product requirements. However, a substantial modification to a product after this date may require a new conformity assessment.
Will all Helmholz products be CRA-compliant?
All current Helmholz products that fall within the scope of the CRA will comply with the applicable CRA requirements.
When will Helmholz products comply with the CRA?
From 11 December 2027, all current Helmholz products will comply with the applicable requirements of the Cyber Resilience Act.
Will the products be revised for CRA compliance?
Yes. Many products will undergo a redesign. The products will be modernized and migrated to a state-of-the-art technical platform while retaining their form and functionality. The new platform will also enable a longer support period.

What will happen to the existing products?
Product variants affected by a redesign will be discontinued in due course. However, discontinued products will continue to receive security patches and may still be supplied as spare parts after the end of 2027. The CRA expressly provides for an exemption for spare parts in this context.
Are there products that will no longer be available under the CRA?
There are some very old products, such as the MPI Adapter or CAN 300 PRO, that will only be available as spare parts from the end of 2027 onwards. A list of these products will be published in due course.
What is the support period for the products?
The support period will be defined and documented for each product as part of the CRA conformity assessment. We are currently aiming for a support period of approximately 10 years from the product release date. The support period will be documented as a specific end date, for example: “This product will receive security updates until 31 December 2037.” Helmholz may voluntarily extend the originally defined support period for individual products at a later date, for example when adding new functionality.
What happens after the security support period ends?
After the published end date of the security support period, Helmholz is no longer obligated to provide new security updates. Helmholz therefore recommends replacing the product in good time with a successor product that is still supported or implementing appropriate compensating security measures.
Where is product security documented?
Guidance on the secure use of a product is provided in the product’s Security Guideline, which can be found either in the product manual or as a separate document. The Security Guideline describes the conditions under which the product can be used securely (intended use), the security capabilities provided by the product, and how these capabilities should be configured.
What does the customer need to do to ensure secure operation?
The CRA considers product security and secure operation together. Products must be used in accordance with their intended purpose, configured securely, and integrated into an appropriate network architecture. Further information is provided in the respective Security Guideline.
Where can I find vulnerability advisories for Helmholz products?
Vulnerability advisories for Helmholz products are published via CERT@VDE:https://certvde.com/de/advisories/vendor/helmholz/
Where can I find firmware updates?
The latest firmware versions are available on the Helmholz website on the respective product page. Helmholz does not distinguish between security updates and functional updates.
Is a firmware update provided for every vulnerability?
Under the CRA, a vulnerability does not necessarily have to be resolved by means of a firmware update. Depending on the vulnerability, the associated risk may also be mitigated by compensating measures outside the product. Such compensating measures may include, for example, changes to the product configuration or changes to the way the product is integrated into the network. Such solutions will also be documented in an advisory and in the product manual.
Are security updates subject to a fee?
Security updates provided to address vulnerabilities are generally made available free of charge.
How can I report vulnerabilities to Helmholz?

Identified or suspected vulnerabilities in Helmholz products can be reported to the Helmholz PSIRT team at any time: psirt@helmholz.de https://www.helmholz.de/en/service-support/service/security-psirt/

Alternatively, vulnerabilities can also be reported via CERT@VDE.

Does Helmholz provide an SBOM for its products?
Helmholz creates and maintains a Software Bill of Materials (SBOM) for relevant products as part of its internal technical documentation and vulnerability monitoring processes. The CRA does not require the SBOM to be made publicly available or routinely supplied to customers, and Helmholz currently does not plan to do so. The SBOM will be provided to the competent authorities, such as the German Federal Office for Information Security (BSI), as required by law.
How does Helmholz ensure secure product development?
Helmholz develops its products using a secure development process in accordance with IEC/EN 62443-4-1 and the additional requirements of the CRA. Certification of the development process is currently being carried out by TÜV NORD. Helmholz develops its products entirely in-house, including both hardware and software, and also manufactures them in its own production facilities. This enables product security to be addressed throughout the entire process, from development through to manufacturing.
Which standard applies to the products?
All products falling within the scope of the CRA are developed in accordance with IEC/EN 62443-4-2.
What Security Level do the products achieve according to IEC/EN 62443-4-2?
All products falling within the scope of the CRA achieve at least Security Level 2 (SL 2). Some products, such as firewalls and routers, achieve Security Level 3 (SL 3).
How are legacy protocols addressed?
Legacy protocols, such as Modbus TCP or RFC 1006, cannot be made inherently secure for technical reasons and due to the need to maintain compatibility with existing communication partners. When such protocols are used, the network must be appropriately secured by the machine designer or customer, for example by using a firewall and implementing strict access restrictions for the affected devices.
How secure is Helmholz as a company?
Helmholz is classified as an “important entity” under NIS2. ISO/IEC 27001 certification is planned for 2027.

PSIRT - Product Security Incident Response Team

The PSIRT team is your direct contact for Helmholz components.
E-mail: psirt@helmholz.de
Phone: +49 (9135) 7380-0

Contact us now

You can find further information on our page on PSIRT.

CERT@VDE is a partner for the publication of security incidents in Helmholz products. Here you will find published advisories, and via RSS feeds you can integrate messages directly into Outlook to stay up-to-date.

How Helmholz protects industrial communication.

Guide for machine manufacturers and operators on
current EU legislation.

Download Whitepaper

Subscribe to our newsletter now!

Receive regular news on products, promotions and solutions from the world of Helmholz.