Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do manufacturers get wrong when they rely…
Cyber Security

What do manufacturers get wrong when they rely on legacy systems and connected devices for data-heavy operations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Cyber Security

A common mistake is assuming older systems and IoT devices can be managed like modern enterprise platforms. Legacy environments often carry unpatched vulnerabilities, while connected devices may lack basic security controls and visibility. That combination creates blind spots in monitoring, access governance, and incident response, especially when those systems sit inside high-value production workflows and supply chain operations.

Why Manufacturers Misjudge Legacy and Connected Device Risk

Manufacturers often treat legacy controllers, embedded platforms, and connected devices as infrastructure that simply has to keep running, rather than as security-relevant assets with a lifecycle. That mindset hides the real issue: these systems usually sit in production paths where availability, integrity, and trust are more important than convenience. The EU Cyber Resilience Act is relevant here because it reflects the growing expectation that connected products be designed and maintained with security obligations, not treated as exempt because they are old or operationally sensitive.

What teams get wrong is assuming the risk is only about patching. In practice, the larger problem is that legacy estates and IoT-style devices often lack inventory accuracy, identity discipline, secure update paths, and usable logging. When those gaps exist inside production and supply chain workflows, the business impact is not limited to one vulnerable endpoint; it can affect line continuity, quality assurance, maintenance access, and incident containment.

In practice, many security teams discover that the real weakness is not the device itself but the absence of control around how it is tracked, accessed, updated, and recovered.

How the Operational Failure Mode Shows Up

Legacy and connected device environments usually fail in combinations. A manufacturer may have old Windows-based HMIs, proprietary PLC management tools, remote vendor access, and low-cost sensors or cameras all tied into the same operational network. Each component may be individually tolerable, but together they create a trust chain that is hard to observe and harder to segment.

The practical failure pattern is predictable. Older platforms often cannot support modern hardening baselines, and some devices cannot be patched quickly without testing or downtime. That pushes teams toward exceptions, permanent compensating controls, or informal workarounds. Once that happens, the environment starts depending on people remembering what is exempt, which network path is trusted, and which maintenance account still works. That is a governance problem as much as a technical one.

A useful way to think about it is:

  • inventory gaps make it unclear what is exposed
  • weak logging makes abnormal behaviour hard to prove
  • shared or inherited access makes accountability unclear
  • slow patch cycles make known issues linger longer than intended
  • flat networks let one compromised device become an entry point to more valuable systems

For manufacturers, this becomes especially difficult when operational technology and enterprise tooling overlap. A monitoring system can show that a device is online, but not whether its firmware is supported, whether its credentials are stale, or whether its data is trusted by downstream systems. The result is a false sense of control based on uptime rather than assurance.

The guidance breaks down when organisations try to secure these environments with generic IT controls only, because availability constraints, vendor dependencies, and embedded device limitations change what “good” actually means.

Where the Exceptions and Trade-offs Really Are

Tighter control over legacy and connected devices often increases operational overhead, so manufacturers must balance uptime and integration convenience against containment and traceability.

Not every legacy asset can be replaced, and not every connected device can be isolated without affecting production. In some cases, the best available answer is compensating control, but that should be an explicit decision, not an accidental state. Industry consensus is strongest on the need for segmentation, asset visibility, and controlled access; there is less consensus on how quickly brownfield manufacturing environments can be brought to a modern baseline without disrupting throughput.

The most common edge case is the “supported by vendor but not secure by design” device. It may still function perfectly in production while remaining weak on authentication, update integrity, or telemetry. Another edge case is the maintenance path that exists only for engineering convenience. If that path is not governed as carefully as production access, it becomes the easiest route into high-value systems. Manufacturers also underestimate how quickly a single connected device can become a dependency for multiple processes, making replacement or isolation more disruptive than expected.

When this answer stops working, it is usually because the organisation has allowed exceptions to become permanent architecture rather than short-term risk acceptance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 1 — Inventory and Control of Enterprise AssetsLegacy and connected device risk starts with not knowing what is deployed.
CIS 4 — Secure Configuration of Enterprise Assets and SoftwareOld systems and connected devices often fail because baseline hardening is absent.
Recommendation — Inventory manufacturing assets continuously and flag unmanaged legacy or IoT devices for review. Apply hardened configurations where device capability allows and document exceptions where it does not.
NIST CSF 2.0ID.AM-1 — Physical devices and systems within the organization are inventoriedThe question centers on visibility gaps across operational devices.
PR.AC-4 — Access permissions and authorizations are managed, incorporating the principles of least privilegeShared maintenance access and weak device governance amplify exposure.
Recommendation — Maintain an accurate device inventory and use it to drive containment decisions. Restrict maintenance access to least privilege and remove inherited or shared accounts.
MITRE ATT&CKT0887 — Exploitation for Defense EvasionUnpatched and hard-to-monitor devices can be used to blend malicious activity into operations.
Recommendation — Hunt for exploitation paths that hide inside routine device and maintenance traffic.

Practitioner Guidance

What to prioritise: Start with asset visibility, network segmentation, and access control around the devices and systems that sit closest to production impact. If a team cannot clearly name what is connected, who maintains it, and how it is updated, it does not yet have a defensible risk picture.

What to verify: Confirm which assets can actually be patched, which depend on vendor support, and which rely on shared credentials, unmanaged remote access, or undocumented maintenance paths. Manufacturers should treat those conditions as operational exposure, not just technical debt.

Common mistake: Treating a working legacy environment as a safe one. Stability is not assurance, and long-lived devices often remain in place precisely because they are hard to change, not because they are well controlled.

Practitioner takeaway: The real decision is not whether legacy and connected devices can keep running, but whether the organisation can prove they are contained, monitored, and replaceable without turning production into a blind spot.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org