Cybersecurity
OT Cybersecurity in Automotive Manufacturing: Robotic Lines and Supply Chains Under Attack
Automotive is among the sectors most exposed to OT attacks: robotic lines with proprietary protocols, MES/ERP integration and vendor remote access create a wide, hard-to-control attack surface.

The automotive sector in the eye of the OT storm
Automotive manufacturing is among the sectors hit hardest by cyberattacks on OT networks. This is not a matter of bad luck: it is structural. Automotive production lines are among the most automated in manufacturing, integrated with IT systems, dependent on suppliers with remote access, and built on heterogeneous protocols, many of which were born before cybersecurity was a priority.
The documented incidents are numerous. In 2017 WannaCry hit Renault and Nissan, halting production lines in France, Slovenia and Romania. In 2019 a ransomware attack forced Toyota to shut down 14 plants in Japan. In 2020 Honda suffered a SNAKE/EKANS attack, malware designed specifically to terminate ICS processes, with impact on plants in Europe, North America and Japan. These are not isolated events: they are the signal of a structural vulnerability.
For the Tier 1 and Tier 2 suppliers in the Italian supply chain, dozens of companies producing components for the major OEMs, the risk is just as real, often with fewer security resources and even tighter uptime pressures.
Proprietary protocols and industrial robots: the invisible surface
Modern automotive assembly lines are dominated by the major robotics brands: Fanuc, KUKA, ABB, Yaskawa. Each manufacturer uses proprietary protocols to communicate with its own robots (FANUC FOCAS, KUKA KRL, ABB RAPID), alongside open standards such as OPC-UA and EtherNet/IP for system integration.
The problem is that these protocols are rarely monitored. Generic security solutions cannot decode them. A parameter change in the welding program of a KUKA robot triggers no alert in most traditional security architectures. An attacker who modifies the logic of an assembly robot, altering tolerances, handling sequences or process parameters, can cause physical damage to products or people without any IT security system noticing.
The situation is made worse by the fact that many industrial robot management interfaces expose web interfaces or unprotected network services. Security research published in recent years has documented vulnerabilities in the administration interfaces of industrial robots from all major manufacturers: default credentials, open Telnet services, web servers without authentication. These attack vectors have existed for years and, in many plants, have still not been closed.
MES/ERP integration as the breaking point of IT/OT separation
The reference model for industrial security, the Purdue Model with its sharp separation between IT networks and OT networks, does not survive modern production integration. Automotive lines are designed to be integrated: the MES (Manufacturing Execution System) talks to the PLCs to collect production data in real time; the ERP connects to the MES to update production orders, bills of materials and scheduling plans.
Every IT-OT connection is a potential lateral path for an attacker. Ransomware that hits the corporate Windows domain can cross the IT/OT boundary through the MES server. A supply chain attack that compromises the ERP software can reach the PLCs through the same connections used for production management.
In practice, these paths are not theoretical: EKANS/SNAKE, the malware that hit Honda, carried an explicit list of ICS processes to terminate, which presupposes knowledge of the target architecture acquired through a reconnaissance phase that crossed the IT network toward the OT network.
The countermeasure is not to eliminate integration, impossible in modern automotive, but to make it controlled: application firewalls that filter MES-PLC traffic at the content level, not just at the port level; segmentation that limits which IT systems can reach which OT systems; visibility into the traffic that crosses the boundary.
Vendor remote access: the hardest vector to control
Every major OEM requires its production line suppliers to provide remote access for maintenance. FANUC must be able to update the firmware of its robots. System integrators must be able to diagnose problems on the line. SCADA vendors must be able to intervene remotely in case of faults.
This access is necessary and hard to eliminate. The problem is how it is implemented: often with generic VPN solutions or, worse, with TeamViewer or RDP connections exposed directly to the internet, without MFA, without access logging, without segmentation that limits which systems the vendor can reach.
The risk chain is concrete: a compromise of the vendor's system (which may have an even worse security posture than the customer) automatically becomes a compromise of access to the production line. The SolarWinds case showed how software vendors can become attack vectors against their own customers; in the automotive supply chain the same principle applies to industrial automation vendors.
Securely managing vendor remote access requires: a dedicated solution (not generic VPNs) with strong authentication, recorded sessions, time-limited access, visibility into what the vendor does during the session, and segmentation that restricts access to only the systems for which the vendor has documented authorization.
Visibility as a prerequisite: inventory and monitoring in automotive networks
Before any active security measure, automotive organizations must answer a fundamental question: what is on the OT network? In many plants the answer is "we don't know for sure". The OT asset inventory is often incomplete, out of date, based on manual documentation that does not reflect how the lines have evolved over time.
Passive monitoring of OT traffic makes it possible to build this inventory non-invasively: listening to network traffic, identifying devices from communication patterns, cataloguing firmware versions, mapping the communication relationships between systems. This process, when carried out on complex automotive networks, typically reveals forgotten assets, undocumented connections and active protocols that should not be active.
Only with an accurate inventory is it possible to prioritize: which systems have known vulnerabilities? Which robots are running outdated firmware? Which PLCs communicate with unexpected destinations? Visibility does not solve the problems, but it makes it possible to solve them in the right order.
Tier 2 cannot afford to ignore the problem
The major OEMs have the resources to build structured OT security programs. Large Tier 1 suppliers are starting to do so. But the Italian automotive manufacturing fabric is made up largely of Tier 2 and Tier 3 companies: component suppliers with tens or hundreds of employees, one or two production lines, zero or one IT staff and no specific OT expertise.
For these companies the risk is twofold: they are directly exposed to the same attack vectors (robots with unpatched vulnerabilities, unmanaged remote access, MES integration without controls), and they are an access vector toward the Tier 1 suppliers they are connected to. An attacker who cannot break directly into a large automotive supplier may choose to compromise one of its Tier 2 suppliers and move laterally through the supply chain connections.
NIS2 and the security requirements that large players are beginning to impose contractually on their suppliers are turning OT security into a business requirement, not just good intentions. For the SMEs in the automotive supply chain, building visibility and control over their own OT network is no longer optional.
The complexity of the problem must not lead to paralysis. The priorities are clear: build an accurate inventory of OT assets, gain visibility into industrial network traffic, manage vendor remote access in a controlled way, and segment IT/OT connections. These are concrete steps, achievable even with limited resources, that significantly reduce the attack surface of an automotive line.
The MON5 angle
The article says it plainly: in many automotive plants the answer to "what is on the OT network" is "we don't know for sure". MON5 starts exactly there: passive discovery of industrial traffic on native OT protocols such as PROFINET, EtherNet/IP and OPC UA, to build a continuous inventory of PLCs, robots and the actual connections between MES and line, without stopping production.
On the same foundation, correlating CVEs, EPSS scores and real exposure indicates which line vulnerabilities deserve priority, while NDR monitoring detects lateral movement from IT toward OT before it becomes a line stoppage. Even for a Tier 2 supplier with limited resources, starting from an OT assessment is a sustainable step.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Cybersecurity
OT Cybersecurity in the Chemical Industry: Where Cyber Security and Physical Safety Meet
In the chemical industry a cyber incident can cause the release of hazardous substances, explosions and harm to people. Safety/security convergence is no abstraction: the Triton attack on Safety Instrumented Systems proved the last physical line of defense can be compromised.

Cybersecurity
OT cybersecurity in food & beverage: traceability, digital HACCP and production lines under attack
Italian food & beverage has a wide, poorly protected OT attack surface: dosing lines, digital HACCP systems, connected cold rooms for traceability. An OT attack here can compromise food safety and brand reputation.

Cybersecurity
OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover
Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.