Manufacturing operations guide

MES and OT cybersecurity

MES often connects enterprise IT to production OT, making it an important security boundary. Security decisions must preserve manufacturing availability and safety as well as confidentiality.

OT securityNIST SP 800‑82MES

Last reviewed: August 10, 2026 · By Marcus J. Calderwick

Know the architecture

Maintain an inventory of MES servers, clients, databases, gateways, interfaces, service accounts and remote-access paths.

Segment by function and trust

Do not expose MES or plant interfaces broadly to enterprise or internet networks. Use controlled network zones and approved communication paths appropriate to the plant architecture.

Manage identity

Use unique accounts, role-based access and managed service identities. Remove stale vendor and shared accounts where operationally feasible.

Patch with validation

MES depends on operating systems, databases, runtimes and connectors. Patch planning should consider vendor support, testing, production windows and rollback.

Back up for recovery

Recovery may require databases, configuration, certificates, interface definitions, scripts and deployment artifacts—not just a nightly database dump.

NIST guidance

NIST SP 800‑82 Rev. 3 is the current final Guide to Operational Technology Security. NIST opened pre-draft work for Revision 4 in January 2026, so Rev. 4 should not yet be cited as a final standard.

MES terminology and boundaries vary among plants and vendors. Validate data ownership, safety impacts, interfaces and change control against your actual manufacturing architecture and approved procedures.