A machine tool bought in the late nineties can be in excellent condition today. The castings are fine, the ways are true, it holds tolerance, and with maintenance it will outlast the people operating it. What has not aged as well is the controller — an industrial PC running an operating system that stopped receiving security updates a long time ago, attached to a network that did not exist when it was installed.
This is the ordinary condition of manufacturing, not an outlier. Capital equipment is depreciated over decades and the software governing it was current for a few years, and the gap between those two numbers is where the entire problem lives.
You cannot patch what you cannot stop
The instinct from an IT background is to update it, and that instinct runs into three walls in order.
The equipment cannot stop. A line producing to order has no maintenance window that IT would recognise, and taking a cell down to test a patch costs real output against a schedule with penalties attached.
The vendor may be gone, or may have withdrawn support, or may void the machine warranty if anything on the controller changes. A great deal of industrial software is validated as a system — the controller, the drives, the safety interlocks — and modifying one part invalidates the validation, which in regulated production is not a paperwork problem but a legal one.
And the replacement is not a software purchase. Bringing a controller up to date frequently means retrofitting the machine, which costs a meaningful fraction of a new machine that would produce the same parts no faster.
What responsible operators do instead is accept that the endpoint is unfixable and defend around it. Network segmentation so the cell cannot reach the internet or the office network. A one-way data path out for the telemetry the business wants. Removable media controls, because the infection vector on an air-gapped line is almost always a USB stick carried by a contractor. Documented, tested recovery from a known-good image, on the assumption that the machine will eventually be compromised rather than that it can be prevented.
None of that is satisfying and all of it is cheaper than the retrofit. It is also increasingly what the insurer expects to see: cyber insurers have become the de facto regulators of corporate security, and the questionnaire now asks about operational technology specifically, because that is where the losses have been.
The pressure is about to increase from an unexpected direction. Companies adding automation are connecting old cells to new systems — warehouse automation is reaching firms that could not previously afford it, and the integration layer is what removes the isolation that was protecting the old controller. The upgrade to the new part increases the exposure of the old one.
It is the same shape as the trillion-dollar rewrite nobody can postpone, with a harder constraint: a mainframe application can be modernised incrementally over years, and a stamping press either runs today or the customer does not get their parts.


