Safety Systems and Cybersecurity: Where the Two Teams Overlap

Safety and security teams share goals but rarely share meetings. Learn where they overlap in industrial sites and how to coordinate without raising risk.

3 min readBy Ironfield Cyber Team

At an industrial facility, a pipeline station, or a power site, safety is the first priority, and rightly so. Safety teams manage hazards, procedures, and protective systems that keep people and the public from harm. Cybersecurity teams, often sitting in IT, protect data and networks. For years these groups worked separately. Today they overlap, because the same digital systems that run a process can also be targeted, and a cyber incident can become a safety event.

This article explains where the two disciplines meet, what to coordinate, and how to avoid well-meaning security changes that undermine safety.

Why They Overlap

Modern control and safety systems often rely on networked equipment, software, and remote access. Operators use workstations that run Windows. Engineers connect laptops to controllers. Vendors support equipment remotely. Any of these connections can be abused or fail. If an attacker or a malfunction affects control or monitoring, the consequences may reach the physical world.

Safety instrumented systems, which are designed to bring a process to a safe state when conditions go wrong, deserve particular care. They are typically designed to be independent from basic control systems, and that independence should be preserved, including from a cybersecurity standpoint. Standards such as ISA/IEC 62443 discuss security for industrial automation and control systems, and industrial safety standards address functional safety; knowledgeable engineers know how the two relate at your facility.

Principles for Working Together

Safety takes priority

Any security action, whether patching, scanning, or access change, must be evaluated for its safety and operational impact first. If a change could affect a process, it needs engineering and operations review.

Preserve independence

Do not connect safety systems to broader networks for convenience, and do not add remote access paths without careful engineering review. Where connections exist, document and justify them.

Share a common language

Safety people think in hazards and consequences. Security people think in threats and vulnerabilities. Bring them together to build a shared view: what are the worst plausible outcomes, and how might a cyber event contribute?

Practical Steps

  1. Form a small joint group. Include operations, maintenance, control engineering, safety, and IT or security. Meet regularly, even briefly.
  2. Add cyber scenarios to hazard reviews. When reviewing hazards, ask whether loss of visibility, manipulated readings, or unauthorized commands could create or worsen a hazard.
  3. Inventory safety-related equipment and note how it connects to other systems.
  4. Control changes together. Use a single change process that captures safety, operational, and security review for modifications to controllers, networks, and remote access.
  5. Plan for degraded modes. Decide how operators will run or safely shut down the process if monitoring or control is unavailable, and practice it.
  6. Include cyber in drills. Tabletop exercises that begin with a cyber symptom, such as unusual values or loss of a display, test the response of both teams.
  7. Coordinate vendor access. Vendors who work on safety or control systems should follow agreed procedures with approvals, logging, and supervision.

Watch for Well-Intentioned Mistakes

  • Automatic patching of operator stations that restarts a system during operation
  • Aggressive scanning that disrupts fragile devices
  • Strict account lockouts that block an operator at a critical moment
  • Removing access that emergency procedures rely on without providing an alternative
  • Adding monitoring tools that load the network or require changes to controllers

Security measures should be designed so that they do not prevent operators from taking safe action in an emergency.

Incident Response Integration

An incident plan for an industrial site should tell people when to prioritize safety actions, who can authorize shutting down or isolating systems, and how and when to involve IT and external responders. Operations leadership should be part of that decision path. Include contact details and decision authority in the plan, and avoid assuming that email or normal networks will be available.

Training

Operators and maintenance staff are your first line of detection. Teach them what unusual behavior looks like and how to report it quickly. Security staff, in turn, should learn the basics of the process and the safety systems. A short site walk-through can build respect on both sides.

Documentation

Keep up-to-date network diagrams, equipment lists, and procedures, and ensure they are accessible during an incident. Review them whenever systems or procedures change.

Where We Fit

Ironfield Cyber supports energy and industrial clients with practical security that respects operational and safety requirements. We can help facilitate joint workshops, review remote access and change processes, and design tabletop exercises that bring safety and security teams to the same table.