CyOne Security AG
Steinhausen
Cyber-Physical Production Systems (CPPS) – Agile but Vulnerable
- 07 August 2026
- 100%
- Permanent position
- Steinhausen
Job summary
Industrial manufacturing is increasingly data-driven, yet cyber-physical systems (CPPS) present significant risks.
Tasks
- Understand how CPPS operate and their vulnerabilities to cyber threats.
- Learn effective strategies for manufacturers to manage rising cyber risks.
- Explore the importance of secure IIoT devices and continuous monitoring.
Skills
- Familiarity with IIoT, cybersecurity measures, and industry standards.
- Ability to integrate security in IT/OT systems effectively.
- Proficiency in monitoring and identifying cybersecurity anomalies.
Is this helpful?
About the job
Industrial manufacturing today is largely data-driven in many places. However, the so-called cyber-physical production systems (CPPS) present a large attack surface for cyber criminals. In this blog post, you will learn how CPPS are structured and how manufacturers and operators can effectively manage the growing cyber risks in industry.
Production machines that autonomously recognise workpieces, process them, and keep the warehouse database up-to-date – this is already everyday life in many factories. In the so-called "Smart Factory," the separation between Information Technology (IT) and Operational Technology (OT) gives way to comprehensive networking through cyber-physical production systems (CPPS).
Characteristics of digitised production include:
Modular IT/OT integration: Corporate, planning, and control levels converge in hybrid, modular system landscapes
Intelligent field devices: Field devices, i.e. sensors for control, interact with process equipment – thus creating autonomous cyber-physical systems (CPS) for local data collection and analysis.
Real-time ecosystems: Suppliers, manufacturers, and customers access production data (e.g. utilisation, quality metrics) live via cloud platforms, remote access, or API interfaces – often fully integrated.
This intensive networking creates a complex, often autonomously operating ecosystem of the "Industrial Internet of Things" (IIoT), enabling customised, smart products at the same time as lower unit costs.
Increased attack surface due to networking
However, networking in the IIoT also entails dangers: Cyber-physical production systems are a particularly attractive target for cyber criminals. The real-time data exchange between internal teams, suppliers, and customers creates complex data flows with different access rights and levels of authority. At the same time, access to the data occurs via many external connections, remote accesses, and machine-to-machine connections.
This complex environment – many users and many access points – opens numerous entry points for attackers. Ransomware can be introduced, which paralyses production processes or enables access to sensitive data and intellectual property.
The 3 essential IIoT security aspects
Secure connections between field device and control via TLS, or across the entire network via VPN, are not sufficient alone to protect agile IIoT ecosystems. They only secure data traffic but not the devices themselves. In other words: They prevent data theft but do nothing if attackers gain access to the network through hacking.
For comprehensive protection against cyber threats, three prerequisites are therefore central:
Secure IIoT devices with hardened firmware, automatic updates, and strong authentication
Know-how for seamless, segmented integration into existing IT/OT networks
Continuous monitoring for early detection of anomalies and vulnerabilities
Operators and manufacturers must think security together
When acquiring network-capable IIoT devices, a look at functionality and price alone is not enough. Operators should thoroughly examine manufacturers regarding connectivity, product hardening, integration security, update strategy, and data management – only in this way will the IT/OT infrastructure remain protected against new risks.
Manufacturers gain a clear competitive advantage with consistent security by design: Secure products facilitate market access, reduce liability risks, and extend the service life for customers. Operators benefit from reliable, durable solutions with lower operational risks. Close collaboration is therefore worthwhile for all – now more than ever in view of increasing attack numbers.
Which security measures must be implemented on the way to Industry 4.0 can be read in the knowledge update "Industry 4.0 – Revolution puts security to the test."