80% of French packaging machine manufacturers surveyed by Geppia are currently analyzing new requirements. Some, like ergonomics, have already been integrated and are a differentiating factor. Others, such as human-machine interaction and tamper protection, will require adjustments. How can this phase be used to create opportunities, particularly in cybersecurity? Geppia's team posed this question to Hervé Bodinier, CEO of eXcelsior Safety and an industrial safety specialist.
It is important to remember that the new European Regulation will replace Directive 2006/42/EC and that its primary concern is the safety of persons. The EESS (Essential Health and Safety Requirements) have been revised in light of technological developments and identified shortcomings.
One of the major changes to highlight is the requirement for the most dangerous machines (listed in Annex I of the regulation) to undergo third-party certification, instead of self-certification. Whether or not they consider themselves affected, manufacturers should begin any compliance process by reading this annex.
Cybersecurity, on the other hand, concerns everyone. And it is (finally, some would say) making its strong entry into the machinery regulations. "Cyber risk has been taken into account by Operators of Vital Importance (OIVs) since the 2015 Military Programming Law (LPM) and by Operators of Essential Services (OSEs) since 2018 by the French National Cybersecurity Agency (ANSSI). It will become a major issue for 25,000 companies in France, including many food processing companies and subcontractors, with the arrival of NIS 2, scheduled for October 2024 and expected for June 2025. Manufacturers will have no choice but to demonstrate and document how they have addressed and managed the cyber risks of their machines," explains Hervé Bodinier, who adds: "This concerns new machines, but not only them; existing installations will have to comply with the cybersecurity requirements of NIS 2, LPM, IEC 62443, etc., and in the event of machine modifications, they will also have to take into account the new machinery regulations." It is high time for end users and integrators to also conduct a cybersecurity audit of all machines in operation to prepare for their upgrade, because this will not happen overnight
For him, the new European regulation is an opportunity rather than a constraint: “Cybersecurity is always best ensured by prioritizing hardware over software whenever possible. The Machinery Regulation and the NIS2 Directive can be an opportunity to intelligently secure our industrial facilities and transition smoothly to Industry 4.0. But the various stakeholders and departments within the company will need to be able to understand each other's needs. This point is, in my opinion, all the more crucial in the food industry, where many very different machines are connected.”
For Hervé Bodinier, the security of production lines ultimately results from a delicate balance between openness (data requests under the CSRD directive, for example) and closedness (network security under NIS2). "I don't believe we can imagine doing without connected machines or AI: manufacturers need to transmit data, and builders may need data or even software to improve their machines. At the same time, cybercriminals are ahead of the curve because they've been using AI for a long time; therefore, even stricter security procedures are necessary as soon as information flows down to the machines. And above all, a business continuity and disaster recovery plan is essential to quickly restart the machines when an attack occurs. Because it will occur," he concludes.
