Compare

OEM-Independent vs OEM OT Security

The vendor that sells the controllers knows them best. That is exactly why it should not be the party deciding which ones to keep, which to replace, and who may reach them.

The short answer

Use the OEM for what only the OEM can do: hardening, patches, and support for its own equipment. Use an OEM-independent party for the decisions that touch the OEM's commercial interest: the modernization roadmap, segmentation across a mixed fleet, and governance of the OEM's own remote access. ISA/IEC 62443 already separates these as different stakeholder roles.

Side by side

Neither option is wrong in the abstract. The question is which decisions you are handing to whom.

Decision criterionOEM as security providerOEM-independent provider
Advice on what to replace and whenConflictedIndependent
Depth on the OEM's own controllers and firmwareStrongestCoordinated with OEM
Coverage of a mixed, multi-vendor fleetOwn products onlyWhole network
Governance of vendor remote accessGoverns itselfGoverns all vendors
Segmentation design across production areasWithin its scopePlant-wide
Accountability across many plantsPer projectNamed owner
Commercial modelAttached to productsService only

When each is the right call

The OEM is right when

  • The plant runs a single automation vendor end to end and was commissioned recently.
  • The work is product-specific: firmware hardening, secure configuration of that vendor's controllers, warranty-bound support.
  • You already have an independent owner setting the roadmap and the OEM is executing within it.

An OEM-independent party is right when

  • The fleet mixes vendors, generations, and integrator projects, which describes most cement, mining, and aggregates plants.
  • A large share of the equipment is End-of-Life and the replacement sequence is the biggest security decision on the table.
  • Vendor and contractor remote access has never been inventoried or governed.
  • Auditors, insurers, or corporate security want evidence that was not produced by a party with equipment to sell.

ISA/IEC 62443 already separates these roles

The standard does not describe one "security vendor". It describes distinct stakeholders with distinct responsibilities, and it puts requirements on each.

Asset owner
The operator accountable for the plant's security program, policies, and risk acceptance.
Who: You.
Product supplier
The maker of the controllers, switches, and software, responsible for secure development and support of its products.
Who: The automation OEM.
Service provider (integration and maintenance)
The party that integrates and maintains the system on the asset owner's behalf; 62443-2-4 sets the requirements for this role.
Who: Potenza, structurally separate from any product supplier.

When one company holds both the product supplier and the service provider roles, the standard's separation collapses in practice even if the paperwork keeps them apart. Potenza calls the alternative Structural Independence: the OT Service Owner cannot be the OT Vendor.

FAQ

Questions operators ask about vendor independence

Short answers. The longer ones come from a conversation about your fleet. Reach out to our team.

Get the twelve questions

The OT Cybersecurity Procurement Memo organizes the questions procurement teams should ask any provider in writing, including the OEM.

Get the Procurement Memo