Licence to Operate: Why OT security compliance is a commercial imperative, not just a regulatory one

Image credit: Image provided courtesy of Harpoon Consulting Ltd

Editorial Brief
At a glance: AI-assisted overview, optimised for journalists, search & news aggregators

UK manufacturers are facing increasing operational technology (OT) security regulations, including the EU's NIS2 Directive, the UK's upcoming Cyber Security and Resilience Bill, and the IEC 62443 standard. Harpoon Consulting advises that these regulations, while appearing different, fundamentally require businesses to ensure their operational environments are secure and trusted by customers and partners. Compliance is not just about avoiding penalties but also about building commercial trust and maintaining a competitive edge in the market.

Press Release

LONDON, UK - June 24, 2026

UK manufacturers are navigating a growing body of operational technology (OT) security regulation. The EU’s NIS2 Directive, the incoming Cyber Security and Resilience Bill, and the internationally recognised IEC 62443 standard each carry their own requirements, timelines, and enforcement mechanisms. For many businesses, the instinct is to treat them as separate compliance exercises to be managed in sequence.

That instinct, according to OT security specialists, Harpoon Consulting, is the wrong one.

“The regulations look different on the surface,” says John Allen, Strategic OT Security Director at Harpoon Consulting, “but they are all asking the same fundamental question: can your customers, your partners, and your regulators trust that your operational environment is secure and resilient? That’s what compliance is really about. It’s not a box-ticking exercise. It’s your licence to operate. It’s about doing the right thing to protect the supply to the person at the end of your supply chain.”

A converging set of requirements

NIS2, which came into force in October 2024, applies to manufacturers classified as essential or important entities operating within the EU, with incident reporting obligations and supply chain security requirements at its core.

The UK Cyber Security and Resilience Bill, currently progressing through Parliament, will introduce equivalent obligations for UK businesses, with penalties of up to £17 million or 4% of worldwide turnover for the most serious breaches.

IEC 62443, meanwhile, is the internationally recognised technical standard for industrial automation and control systems security, providing a structured framework for how OT security is actually built and maintained rather than simply reported on.

Despite their differences in scope and emphasis, all three frameworks converge on the same underlying requirements: know what assets you have, understand your risk exposure, put appropriate controls in place, and be able to demonstrate all of the above to an external party. A manufacturer that builds a genuine OT security programme around these principles will find that regulatory compliance follows naturally, rather than requiring a separate exercise for each framework.

The gap between awareness and verified compliance

The challenge for UK manufacturing is not a lack of awareness. It is the gap between recognising that something needs to be done and building a programme that can withstand external scrutiny. More importantly, it’s about delivering a response to cyber security threats that could drastically impact your 3 R’s; Risk, Revenue and Reputation.

That gap is well documented in IT security. Government research shows that 30% of UK businesses self-report as compliant with the government-backed Cyber Essentials scheme, yet formal certification stands at just 3%. In other words, the majority of businesses that believe they are compliant cannot demonstrate it under independent assessment. In OT security, where the technical and operating requirements are more demanding and regulatory pressure has historically been lower, that gap is likely wider still.

Before founding Harpoon Consulting, Allen worked with manufacturers and critical infrastructure for nearly 30 years, and he frequently encounters businesses that believe they have addressed OT security adequately. “The thing is,” he notes, “a structured assessment of their posture usually reveals significant gaps, particularly around asset visibility, network segmentation and dealing with remote access and suppliers. The point being that good intentions and basic controls are not the same as a defensible programme.”

Doing the right thing, not just the compliant thing

The case for acting now, ahead of full legislative implementation, is not purely about avoiding regulatory penalty. It is about the commercial trust that a credible OT security posture builds with customers, insurers, and supply chain partners. Not to mention the positive impact it can have on share price.

The JLR cyberattack of late 2025 demonstrated in stark financial terms what it costs when that trust breaks down. Some businesses with no security failures of their own suffered significant losses because they were connected to an operation that could not contain a breach. In that environment, a manufacturer’s OT security posture is increasingly a factor in commercial relationships, not just a regulatory obligation.

Unfortunately, in the real world, cost is always a consideration, and Allen is sympathetic to those concerns. “It’s true that justifying the cost of a robust OT security transformation – one that includes people, processes, technology – can be a challenge,” he says. “It can have a direct impact on the cost of goods. But those organisations that recognise the importance of their security, especially with growing geopolitical agendas and bad actors seeing rich pickings in OT, are investing in sustaining their business now rather dealing with the cost of an attack further down the line.

“This is not just about following the rules,” he insists, “it’s about commercial advantage. OT security compliance is increasingly becoming a differentiator in procurement conversations, particularly in supply chains where large asset owners want to be assured about the security posture of their tier two and tier three suppliers. If you’re not thinking about this now, you risk losing out to those who are.”

Notes to editors

About Us

Harpoon Consulting is a UK-based pure-play OT security consultancy. The company works with industrial manufacturers to build defensible OT security programmes, with specialist expertise in asset discovery, network segmentation, IEC 62443, NIS2, and NIST CSF compliance. Harpoon embeds experienced OT security practitioners directly within client organisations, bridging the gap between regulatory requirements and operational reality on the factory floor. Further guidance on compliance frameworks and what they mean in practice is available in their OT security compliance resource library.

Get more news like this

Get more news like this on Google. Set News By Wire as a ‘Preferred News Source’ to get quicker access to news that’s important.

All done!
Thank you for subscribing.

Email Subscription