Marc Nirari Kako Brændstrup

Siemens

Marc Nirari Kako Brændstrup, Simens A/S

EU’s Cybersecurity Trifecta: When Compliance Meets OT

NIS2, the Cyber Resilience Act (CRA), and the new Machinery Regulation are often treated as three separate compliance initiatives. In reality, however, they address different aspects of the same challenge: How do we create cybersecurity across organizations, products, and operational environments?
In this presentation, we examine how NIS2, the Cyber Resilience Act, and the Machinery Regulation impact OT environments in practice. Drawing on examples from industry and critical infrastructure, we explore what distinguishes OT from traditional IT environments and how IEC 62443 can serve as a common foundation for understanding and addressing the requirements across all three regulatory frameworks.

Participants will gain insights into:

  • What is the critical difference between IT and OT?
  • How NIS2, the CRA, and the Machinery Regulation affect OT environments.
  • How IEC 62443 can serve as a common foundation for translating regulatory requirements into practical cybersecurity measures.

The objective is not to implement three separate regulations. The objective is to establish one cohesive cybersecurity strategy that strengthens both security and the ability to meet compliance requirements.