Solutions for integrating functional safety and cybersecurity into safety components and systems

Reading time: 3 minutes - Difficulty: Medium
With the evolution of automation, cyber risks are impacting the functional safety of systems, with AI, IoT, and connectivity requiring integrated management from the very product design phase. System and machine manufacturers subject to European regulations (such as the Machinery Regulation and other related regulations including, for example, the AI Act, Data Act, Cyber Resilience Act, and NIS 2 Directive), whether CE-marked or not, can rely on international standards to ensure holistic compliance. In this article, we look at how safety and security regulations interact with one another and what is most advantageous to do in terms of system certification.

The logic governing system safety today

No longer just machines, motors, and PLCs, but also data. The use of AI in Industrial Internet of Things systems has shifted the role of these systems from being mere “sensors” to becoming “decision-makers,” enhancing their ability to interpret data through predictive maintenance actions, process optimization, and advanced quality control, with an obvious positive effect: more data, more intelligence, more efficiency.

However:

The technology that enhances production also enhances cyberattacks, with sophisticated phishing and ransomware attempts that impair the ability of safety systems to mitigate hazards for operators and to ensure production continuity.

In short, to prevent safety incidents (both physical and digital), it is necessary to combine the requirements of:

  • Machinery Regulation, which states how the machine must be made safe
  • AI Act, which indicates how the AI within it must be governed
  • Data Act, which sets out how the data generated by the machine must be managed
  • Cyber Resilience Act, which defines how the machine’s “digital core” and its software/hardware components must be secured
  • NIS 2 Directive, with reference to the IEC 62443 framework, which suggests how to orchestrate all this at the organizational and infrastructure level

In practical terms, what you can do is:

  • Rethink the risk assessment process, so that it considers both physical hazards (EN ISO 12100, Type-C standards, IEC 61511) and cyber risks (IEC 62443), applying the relevant standards to ensure compliance of your products and development processes.
  • Train your Functional Safety and Cybersecurity personnel to recognize and implement practices aimed at ensuring the overall safety of your products and your organization, through basic and advanced courses on IEC 61511, IEC 62061, and IEC 62443. Discover our Academy.
  • Certify systems according to international Functional Safety as well as Cybersecurity standards, with reference to standards covering the electrical part, safety-related software (IEC 61508), and cybersecurity (ISASecure/IEC 62443), so that part of the compliance work has already been completed when the manufacturer comes to apply the European regulations.