New EU Machinery Regulations in force - January 2027 - Are you ready? > Contact us for assistance with the transition.

Published 10/06/26

When the new (EU) Machinery Regulation enters into force in just over six months’ time, on the 20th January 2027, machinery manufacturers selling machines into the EU will mandatorily have to address cybersecurity implications through the new ‘Protection of Corruption’ Essential Health and Safety Requirement (EHSR 1.1.9).

Of course, simple machines with no internet connection, such as a hydraulic jack for a car, will not be affected by this specific new requirement. So there will be many manufacturers, of many types of machines, that will not need to address cybersecurity requirements. However, with the advent of ‘Internet of things (IoT)’, the never ending quest to enable internet connectivity of products and the ongoing progress of automation of machinery with monitoring and data logging functions, the future of machinery appears to be a world of ever increasing internet-connected machines.

Cybersecurity is the practice of protecting equipment, products, etc. and also includes software. Thus cybersecurity aims to minimise disruptions to machines and prevent data theft from them, or through them.

The paramount implication is whether a machine could be subject to an illegal cyberattack leading to remote operation or control of the machine by the cyber attacker. This would put the health and safety of the operators of the machine, and possibly the whole site where the machine is being used, at risk. Such a cyberattack would most likely compromise the safety systems of the machine.

Secondary to this would be the loss of production, given machines are normally used for direct or indirect creation of products, through either damage or down-time of the machine. The longer the period of non-operation of the machine, the more costly the implication to the owner of the machine. Similarly, a cyberattack where the machine is being ‘held to ransom’ by the cyber attacker, would also be extremely problematic.

A less likely problem, but still with the potential for significant consequences, were if the machine held confidential data of any form. A data breach can still lead to financial implications such as reparations to those whose data had been breached and fines for the breach of data. Therefore, machinery cybersecurity also requires data security to be ensured.

There are several cybersecurity standards available, plus many more presently being written. Some standards address cybersecurity requirements in general, whereas some will be unique for machines. However, irrespective of which standards are followed by the designer and manufacturer of the machine, a common requirement is to undertake a cybersecurity threat assessment. 

A machinery cybersecurity threat assessment is essentially determining what parts of the machine may be subject to a cyber threat, what the nature of the threat is, and determining a threat score, i.e. a measure of the severity of the threat. A threat assessment can then be used as part of a risk assessment, to determine the mitigating measures that will be required to be implemented to protect the machine or its sub-parts, from the specific cyber threats.

A combined cybersecurity threat assessment and risk assessment is the more useful tool to a machine manufacturer, but these two processes can be done separately, i.e. a cyber threat assessment followed by a cyber risk assessment.

The STRIDE threat analysis methodology, was created by Microsoft and is widely used by IT professionals. It is also supported in the UK by the National Cyber Security Centres (NCSC) and used as guidance for local authorities to use. STRIDE is an Acronym for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege. This methodology recognises the main types of threats (equivalent to machinery safety ‘hazards’) but there are other threat analysis methodologies available which can be equally as useful.

Whilst the UK government has presently not stated whether it will, or when it will, transpose the EU Machinery Regulation into UK law, it would be common sense good practice for internet connected machines manufactured and used in the UK to follow cyber security requirements, to ensure they are not subject to a cyber attack. Therefore it is recommend that all internet connect machine users undertake a cyber threat assessment. 

How Can We Help You?

Ask a question, or request a callback.
Please type your full name.

Invalid Input

Invalid email address.

Invalid Input

Invalid Input

Invalid Input

Please make a selection

Invalid Input

From time to time we would like to send you our newsletter. If you consent to us contacting you for this purpose please tick the following box. (Privacy Policy)
From time to time we would like to send you our newsletter. If you consent to us contacting you for this purpose please tick the following box. <a href="/privacy-policy-and-cookies-statement" target="_blank">(Privacy Policy)</a>
Invalid Input