Expertenthemenbeschreibung Cybersecurity

Cybersecurity

Trustworthiness of networked machines and systems

Photo
shutterstock

When it comes to security at the VDMA, everything revolves around protecting machines and systems in production, manufacturing or intralogistics from attacks and disruptions. The aim of these organizational and technical protective measures is to develop cyber-resilient machines and systems and trustworthy services while reliably maintaining their permanent operation.

Through this expert page, we are providing an overview of the various aspects, tasks and requirements concerning cybersecurity and industrial security. We refer to both VDMA recommendations and positions as well as concrete assistance from our members and partners.

Photo

shutterstock

Titel der Empfehlung: Cybersecurity

RecommendedTIPP
  • Supply Chain Security Document Series Guide
Shutterstock
The Industrial Security working group makes the complete Supply Chain Security document series freely available
Shutterstock

Podigee Player

From our content

From our content
Importance of industrial security in mechanical engineering

Industrial security is increasingly important in mechanical engineering as networked systems face growing attacks. The VDMA calls for EU-wide standards and SME support to meet security needs.

Cyber resilience on the rise - but no all-clear

A new VDMA study shows: for the first time, social engineering and phishing are the biggest cyber threats to companies, followed by human error and sabotage

Digitale Lösungen im und für den Maschinen- und Anlagenbau

Erleben Sie am 08.-09. Mai 2025 in Wien spannende Vorträge und Podiumsdiskussionen zu Digitalisierungslösungen im Maschinen- und Anlagenbau.

Cyber Resilience Act (CRA)

VDMA Power Systems is highlighting the topic of cyber security and the Cyber Resilience Act in this session of the event series "With new knowledge into 2025".

ISH 2025: New possibilities for building automation with BACnet/SC

SAUTER Germany and VDMA at the ISH 2025

Cyber Resilience Act comes into force - details have been finalized

New requirements apply to products with digital components. Manufacturers must now ensure cyber security throughout the entire product life cycle - even for integrated software! An update on responsibilities and deadlines.

Industrial & product security: complex, extensive, indispensable

On November 28, 2024, VDMA Austria held its annual exchange of experience on Industrial & Product Security in mechanical and plant engineering with 40 participants at the headquarters of the TGW Logistics Group in Marchtrenk.

Mechanical engineering in Baden-Württemberg: Resilient through crises

After the very weak economy in 2024, hopes are pinned on markets picking up in 2025 / Politicians must set business-friendly framework conditions

Cyber Resilience Act is published

The Cyber Resilience Act (CRA) was published in the Official Journal of the EU on 20.11.2024. The act is an EU Regulation that has legal effect in the European Union and the European Economic Area (EEA) without national implementation.

NIS2 contact point NRW

In order to prepare SMEs in NRW for the challenges of cyber security and to sustainably improve the IT security landscape, the state of NRW has created a NIS2 contact point that NRW companies can use.

Hannover Messe - Joint stand software and digitalization

From March 31 to April 4, 2025, the world's leading trade fair for industry will take place under the motto "Shaping the Future with Technology". VDMA Software and Digitalization members will have the opportunity to present themselves there.

Technology Stage powered by VDMA/ZVEI for SPS 2024

In 2024, the VDMA and the ZVEI are once again organizing a forum for the SPS, the "Technology Stage powered by VDMA/ZVEI" with many interesting presentations and panel discussions.

Overview of regulations: Your guide through the regulatory jungle

Regulations are instruments used to ensure the stability and integrity of markets and industries. They serve to protect consumers, promote fair competition and ensure compliance with legal stability.

Cyber Resilience Act (CRA)

Impact on mechanical and plant engineering in conjunction with electrical automation

Security Solutions for Industry

The mechanical and plant engineering industry does not have to think about cybersecurity alone. Companies that support the manufacturing industry with services and solutions can exchange ideas and cooperate within this expert’s circle.

SBOM: The list of ingredients for software applications

When the Cyber Resilience Act 2027 comes into force, software BOMs will also become mandatory. The VDMA recommends that companies prepare in good time so that they can continue to sell digital products seamlessly.

Cybersecurity according to IEC 62443

Take advantage of our seminar series "Cybersecurity according to IEC 62443", developed in cooperation with ISA Europe and Fraunhofer IOSB, to acquire your personal ISA certificate as an ISA/IEC 62443 Cybersecurity Expert.

VDMA FAQ on the EU Cyber Resilience Act available

Update! The Cyber Resilience Act (CRA) has been published and will enter into force on december 11th. The VDMA has compiled a FAQ document to provide support and non-binding guidance to its members.

OT-Risk Cookbook

The VDMA Industrial Security Working Group publishes the OT Risk Cookbook

Supply Chain Security document series

The Industrial Security working group makes the complete Supply Chain Security document series freely available

Cyber Resilience Act: New obligations for manufacturers - act now!

The European Union's Cyber Resilience Act affects many products and components in the mechanical engineering sector. Companies should quickly identify the extent to which they are affected and take measures to ensure compliance and product security.

Meet the Expert - Focus on digitalization

Meet the digitization experts at the VDMA Software and Digitization stand to exchange experiences.

Security.txt - mandatory exercise for supply chain security

A text file on the website for better cyber security? Manufacturers can achieve this with security.txt. A simple and essential step towards addressing vulnerabilities.

Extended protection against side channel attacks

The new safe lock standard offers enhanced protection against new attack methods.

Supply Chain Requirement Specification: Component Manufacturer

VDMA Informatik publishes the requirements specification for component manufacturers

Targeted prevention of attacks - overcoming financial resistance

VDMA Ost has set up an information technology working group. The kick-off event focused on IT security in day-to-day business. Experts raised awareness and gave tips on prevention and what to do in an emergency.

Radio Equipment Directive: New manufacturer obligations

Machine manufacturers are facing challenges. They must both manufacture cyber-secure machines and secure their own production environment. What obligations does this entail?

Pharmaceutical and cosmetic machines: new challenges in the future

In pharmaceutical companies, the need for fast, lean processes is increasing. In this context, digitization can help shorten market entry times, while maintaining and even improving product quality. However, players must also arm themselves against threats.

Title

Description

Now new: VDMA Cyber Awareness

How to turn your team into a human firewall!

Preparation for NIS2

These cybersecurity obligations are coming to mechanical engineering companies

Supplier self-disclosure on cybersecurity

The VDMA Supplier Self-Assessment is a standardised questionnaire that companies can use with suppliers regardless of specific procurement purposes. Highly topical with the mapping of regulatory requirements from MVO and CRA.

Close the net: Tips for more digital security in NRW companies

The first steps toward greater digital security can be implemented quickly and easily. The "Close the door on the net" campaign provides tips.

Door Closed on the Net" campaign for more digital security in NRW companies

The state of North Rhine-Westphalia wants to raise awareness of cybersecurity and is providing financial support of up to 15,000 euros for investments.

All information about our publication overview - compact and online

Our publications deal with various aspects of digitalization in mechanical engineering companies as well as cybersecurity and information security and serve as recommendations for action.

#HM25: Der Gemeinschaftsstand des VDMA Software und Digitalisierung

Erleben Sie die Zukunft des Maschinen- und Anlagenbaus! Besuchen Sie den Gemeinschaftsstand in Halle 15 F28 auf der Hannover Messe und entdecken Sie, wie digitale Softwarelösungen die produzierende Industrie revolutionieren!

NIS2: Mandatory cybersecurity requirements

The new version of the NIS directive will in future oblige manufacturers of "critical products" such as machines or control components to implement cybersecurity in their own operating environment.

Cybersecure procurement of machinery and equipment

The VDMA Supply Chain Security specification gives purchasers a standard-compliant aid to minimum requirements in accordance with IEC 62443, simplifying the process for both sides without sacrificing security.

China: New regulations on cross-border data transfer

Since September 1, 2022, new cybersecurity regulations have been in effect in China. VDMA's policy briefing shows the implications for the industry, especially for the transfer of personal data.

Cybercrime and the consequences

The number of hacker attacks in the mechanical and plant engineering sector is on the rise. More and more VDMA member companies are reporting attacks on office and production systems within the company. Already almost 40 percent of the attacks lead to production downtimes. How can medium-sized companies in particular arm themselves against attacks in advance or react correctly in the event of an actual attack?

Minimum recommendations for security in the supply chain

The recommendations are addressed to machine and plant manufacturers and describe a minimum of technical, organizational and procedural requirements for the implementation of security for products (such as machines, plants, digital systems for predictive maintenance & condition monitoring, ICS controls, ...) and processes.

Cybersecurity Use Cases in China

Updated guide with recommendations for data-centric business processes of European companies in China.

Security by Design reaches the machine tool

When the German Federal Office for Information Security (BSI) issues a cyber security warning of the highest alert level, industry is alarmed.

Policy Briefing Personal Information Processing (PIP) Law

On November 1, 2021, the Personal Information Processing and Protection Law (PIP Law) came into force in China. For this purpose, VDMA together with Sinolytics has prepared a policy briefing with the view of the mechanical engineering industry.

New Policy Briefing for VDMA Members

In recent weeks, the Chinese government has further specified the requirements for the handling of Important Data and cross-border data transfer. For this purpose, the VDMA has prepared a new policy briefing for VDMA members together with Tiffany Wong from Sinolytics.

Security Essen included in BMWi support programme

The "Trade Fair Programme for Innovative SMEs" supports small and medium-sized companies. Exhibiting companies benefit from this.

Jointly against cybercrime and cyber criminals

The Federal Criminal Police Office (BKA) and the VDMA have agreed to intensify their cooperation. Mutual exchange of experience and information is intended to ensure that more attention is paid to cybercrime in companies and to promote the prosecution of cyber criminals by German security authorities.

Digitization plays a major role

Digitization will also play a major role at the 12th Mechanical Engineering Summit in Berlin. How does digitalization affect mechanical engineering? What challenges do mechanical engineers have to deal with in the current times and what opportunities does digitalization offer?

Cybersecurity in capital letters

Steffen Zimmermann in an interview in the podcast "Digital genial" by proAlpha

New guidelines for dealing with security vulnerabilities in China

On September 1, 2021, the Data Security Law and the new requirements for dealing with vulnerabilities in networked products came into force in China. VDMA has already prepared a policy briefing on the Data Security Law. Together with the company Sinolytics, the VDMA is now also offering a policy briefing exclusively for VDMA members on the requirements for dealing with vulnerabilities.

Events

Events

Thu. 22.05.25 Thu. 22.05.25

exclusive

  • Industrial Security

The info day will focus on the implementation of CRA requirements in manufacturing companies.

Places available

Wed. 04.06.25 Thu. 05.06.25

  • Information Security

The core of the seminar is a live crisis team exercise that gives you a realistic insight into the necessary actions and measures of a crisis team in the event of a cyber attack. You will also receive a blueprint for a crisis plan, which you can then refine and implement in your own company.

Places available

Tue. 10.06.25 Tue. 10.06.25

exclusive

  • Industrial Security

In this web-based exchange of experiences, practical strategies for increasing the security of machines and systems while maintaining availability are presented

Places available

Wed. 25.06.25 Wed. 25.06.25

  • Industrie 4.0

Understanding regulations - implementing security: Learn about the requirements of NIS2, CRA and IEC 62443 and find out how to operate your IT and OT systems in a legally compliant and secure manner.

Places available

Thu. 26.06.25 Thu. 26.06.25

exclusive

  • Information Security

NIS2 and the NIS2UmsuCG

Places available

SambaCommittee

Groups & Working Groups

closed group

Technical Regulations & Standardization Working Group

VDMA Working Group Cybersecurity

The Working Group Cybersecurity reports to the VDMA Technical Affairs Committee and prepares proposals for positioning the mechanical engineering industry in the field of cybersecurity. The Working G

Consultant Technical Affairs and Standardization

Markert, Alexey

conditionally open group

Digitalization & Industrie 4.0 Working Group

Information security working group

The VDMA "Information Security" working group aims to raise awareness among VDMA members and promote the exchange of experience between working group members.

conditionally open group

Digitalization & Industrie 4.0 Working Group

Industrial Security Working Group

The VDMA "Industrial Security" working group has been a VDMA committee on security in industrial production environments and industrial products since 2012 and develops guidelines and practical aids

conditionally open group

Digitalization & Industrie 4.0 Working Group

EK Security Solutions for Industry

The "Security Solutions for Industry" expert group facilitates the exchange of experience in securing mechanical and plant engineering. It is aimed at companies that support the manufacturing indu

Asset Publisher

Documents & Downloads

More VDMA services

More VDMA services
VDMA cyber risk assessment
With the cyber risk check, you can easily check online how much risk your company is exposed to. If you so wish, you can receive a detailed assessment via email.
Corporate Cybersecurity Cyber-Newsletter
The Cyber Newsletter provides regular information on current cyber risks and developments. It also includes practical tips on IT security
Info portal for the Corporate Cybersecurity Initiative
"Corporate Cybersecurity" is an initiative launched in 2020 by the VSMA and the VDMA. The info portal supports its members by providing tips, working aids and the latest reports.
Online offering tool for the VDMA cyber policy
With this convenient online tool of the VDMA cyber policy, you can request an individual offer for industry-specific cyber insurance free of charge and without obligation
Industrial Security Working Group
The VDMA working group "Industrial Security" is a VDMA committee dedicated to security in industrial production environments and industrial products that has been in existence since 2012.
Information Security Working Group
The VDMA working group "Information Security" aims to promote awareness among VDMA members and to encourage the exchange of experience between working group members.
Cybersecurity Working Group
The Cybersecurity Working Group submits reports to the VDMA Technology Policy Steering Committee and prepares proposals on the mechanical engineering industry's stance in the domain of cybersecurity. The Cybersecurity Working Group follows legislative initiatives at a European and national level and maintains ties with policymakers in this area.

Asset Publisher

VDMA partners

Photo
MBI – Schulung Security
Photo
University4Industry
Photo
Allianz für Cyber-Sicherheit

Level 2 Minimal Contact Display