SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Transicon issues five-step OT cyber security guide

Transicon issues five-step OT cyber security guide

Tue, 8th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Transicon has published a five-step guide to help small and medium-sized manufacturers improve operational technology cyber security, as cyber incidents continue to disrupt UK manufacturers.

The Telford-based automation and control systems specialist set out the advice through Senior Project Engineer Niall Sephton, who said smaller businesses can make progress by breaking a complex issue into manageable steps.

The guide begins with staffing and governance. Cyber security should not sit with a single person or department, Sephton said, but should be treated as a shared responsibility across the business.

He urged manufacturers to identify "site champions" with an interest in the subject, even if they lack deep technical knowledge, to promote awareness and link operational staff with management. Businesses with limited internal expertise can also seek support from outside specialists.

Figures cited in the guidance suggest a wide gap between the scale of the threat and leadership ownership. Research referenced in the guide found that 78% of UK manufacturers suffered a cyber security incident in the past year, while 95% of those affected reported business disruption. The same research found that only 22% of manufacturing organisations assign responsibility for cyber security to board or executive leadership.

Asset visibility

The second step focuses on understanding what equipment is connected within an operational technology environment. Manufacturers should create a full inventory covering devices such as PLCs, sensors, drives, HMIs, servers, networking equipment and communications links, Sephton said.

The process should also include older or undocumented assets, which can create vulnerabilities if overlooked. He also called for logical network diagrams showing how systems communicate and how data moves across a site, along with checks for physical risks such as unsecured control panels and exposed cabling.

According to the guidance, automated asset discovery tools can help simplify documentation, particularly for businesses that have inherited legacy systems over many years.

Risk priorities

The third part of the framework centres on assessing risk and setting priorities. Sephton said manufacturers should focus scarce budgets first on systems whose failure would have the greatest impact, with human safety taking precedence over all other concerns.

Production-critical systems should come next, he said, and companies should avoid treating cyber security as a single project with a fixed end point. Instead, the guidance calls for a phased roadmap that can stretch over several years if needed.

"The most important thing is to recognise that there are issues out there. We all know there are. Accept that and start chipping away," Sephton said.

Security controls

The fourth step is to introduce practical controls once a business has a clear view of its assets and risks. Network segmentation is among the priorities highlighted, with plant-level systems separated from historians and data management layers.

Sephton also pointed to backup discipline as a basic requirement for resilience. The guidance recommends the 3-2-1 rule: three copies of data, on two different media types, with one copy stored off site.

Backups should be tested regularly so businesses know they can restore systems quickly if an incident occurs. This reflects a broader concern in manufacturing that recovery plans often exist on paper but are not routinely rehearsed in live operational conditions.

Continuous process

The final step is ongoing monitoring and review. As equipment is upgraded and sites change, manufacturers need to revisit risk assessments and security measures regularly.

Threats also evolve over time, making controls that were once considered sufficient less reliable as systems change. The guidance says monitoring tools can help firms track issues, but frames resilience as a cycle of continuous improvement rather than a one-off exercise.

Founded in 1967, Transicon works in industrial automation and control systems for manufacturers across the UK. Its work includes design, manufacture, installation and commissioning across drive systems, PLC and SCADA systems, mechatronics and robotics. It also advises manufacturers on operational technology security practice.

"Regular reviews and maintenance are essential to protecting long-term operations - so accept where you are, start chipping away and never stop," Sephton said.