Arockia.
Back to blogIT/OT Security

Securing a Greenfield Factory: Cybersecurity by Design in Manufacturing

July 22, 20263 min read

Most industrial cybersecurity work is retrofit work: bolting segmentation, monitoring, and access controls onto operational technology that was designed decades ago with zero security assumptions, on a production line that can't afford downtime for the fix. Spearheading the cybersecurity strategy for a Greenfield Lithium-ion Gigafactory was a genuinely different kind of project: the chance to build security into the architecture before a single machine was commissioned.

Why greenfield is a different discipline, not just an easier version

Retrofit security is fundamentally a negotiation: how much can we improve without disrupting what's already running. Greenfield security is a design discipline: every architectural decision, from network topology to vendor selection to how remote access gets provisioned for commissioning engineers, is still open. That's an opportunity, but it's also a much higher-leverage moment to get wrong, because early decisions calcify into the plant's operating model for years.

What Zero Trust looks like when you're not retrofitting it

Starting from a blank architecture meant network segmentation between IT, OT, and the DMZ could be designed as the default topology rather than layered on top of a flat network after the fact. Identity for both people and machines could be built in from commissioning: every vendor, contractor, and system integrator accessing the environment during build-out got a verifiable identity and scoped access, rather than the more common pattern of broad, shared credentials during construction that never get cleaned up once the plant goes live.

The specific challenges of a Gigafactory-scale build

Vendor and integrator sprawl during commissioning. A facility this size involves dozens of equipment vendors and system integrators, each needing some form of access during build-out. Getting ahead of this with a standardized onboarding and access process for third parties, rather than ad hoc access granted under construction-timeline pressure, prevented a huge amount of technical debt that's brutally expensive to unwind after go-live.

Industrial control systems with long procurement lead times. Unlike IT hardware, OT equipment is often selected and ordered years before commissioning, on procurement cycles that don't naturally sync with a security review. Getting security requirements into vendor and equipment selection criteria early, rather than trying to retrofit them once hardware was already on order, was one of the highest-leverage interventions in the whole program.

Designing for the plant's full lifecycle, not just launch day. Security architecture decided during construction has to still make sense five and ten years into operation, as the plant scales, as OT systems get patched (or, more often, don't), and as remote monitoring and predictive maintenance increasingly pull operational data into cloud analytics platforms. Designing segmentation and monitoring with that future state in mind, not just what launch-day operations required, avoided a second retrofit a few years down the line.

The broader lesson

Very few security leaders get a genuine greenfield opportunity, and it's worth treating it as what it is: a chance to prove that security-by-design is materially cheaper and more effective than security-by-retrofit, with hard evidence from your own environment. That evidence is the strongest argument for why the next facility, and the one after that, deserves the same approach from day one.