OEM-Independent vs OEM OT Security
The vendor that sells the controllers knows them best. That is exactly why it should not be the party deciding which ones to keep, which to replace, and who may reach them.
The short answer
Use the OEM for what only the OEM can do: hardening, patches, and support for its own equipment. Use an OEM-independent party for the decisions that touch the OEM's commercial interest: the modernization roadmap, segmentation across a mixed fleet, and governance of the OEM's own remote access. ISA/IEC 62443 already separates these as different stakeholder roles.
Side by side
Neither option is wrong in the abstract. The question is which decisions you are handing to whom.
| Decision criterion | OEM as security provider | OEM-independent provider |
|---|---|---|
| Advice on what to replace and when | Conflicted | Independent |
| Depth on the OEM's own controllers and firmware | Strongest | Coordinated with OEM |
| Coverage of a mixed, multi-vendor fleet | Own products only | Whole network |
| Governance of vendor remote access | Governs itself | Governs all vendors |
| Segmentation design across production areas | Within its scope | Plant-wide |
| Accountability across many plants | Per project | Named owner |
| Commercial model | Attached to products | Service only |
When each is the right call
The OEM is right when
- The plant runs a single automation vendor end to end and was commissioned recently.
- The work is product-specific: firmware hardening, secure configuration of that vendor's controllers, warranty-bound support.
- You already have an independent owner setting the roadmap and the OEM is executing within it.
An OEM-independent party is right when
- The fleet mixes vendors, generations, and integrator projects, which describes most cement, mining, and aggregates plants.
- A large share of the equipment is End-of-Life and the replacement sequence is the biggest security decision on the table.
- Vendor and contractor remote access has never been inventoried or governed.
- Auditors, insurers, or corporate security want evidence that was not produced by a party with equipment to sell.
ISA/IEC 62443 already separates these roles
The standard does not describe one "security vendor". It describes distinct stakeholders with distinct responsibilities, and it puts requirements on each.
- Asset owner
- The operator accountable for the plant's security program, policies, and risk acceptance.
- Who: You.
- Product supplier
- The maker of the controllers, switches, and software, responsible for secure development and support of its products.
- Who: The automation OEM.
- Service provider (integration and maintenance)
- The party that integrates and maintains the system on the asset owner's behalf; 62443-2-4 sets the requirements for this role.
- Who: Potenza, structurally separate from any product supplier.
When one company holds both the product supplier and the service provider roles, the standard's separation collapses in practice even if the paperwork keeps them apart. Potenza calls the alternative Structural Independence: the OT Service Owner cannot be the OT Vendor.
FAQ
Questions operators ask about vendor independence
Short answers. The longer ones come from a conversation about your fleet. Reach out to our team.