A shop-floor terminal is often shared by three shifts, used with gloves on, and needed immediately when a job needs booking onto the system. That is exactly why shared device security needs a different approach from the policy applied to a named office laptop. The aim is not to make every device difficult to use. It is to protect production data, systems and traceability without creating delays that encourage people to work around security.
For manufacturers and engineering businesses, a shared PC, tablet or handheld scanner can be a route into ERP, MRP, quality records, maintenance systems and customer information. If a device is left signed in, connected to the wrong network or running unsupported software, one everyday shortcut can become a serious operational risk.
Why shared devices create a bigger security risk
Shared devices have blurred accountability. A workstation may be used by operators, supervisors, maintenance engineers and temporary staff throughout the day. Generic passwords are often introduced for speed, but they make it impossible to establish who changed a production record, downloaded a file or approved a transaction.
There is also a physical risk. Devices on the factory floor are more likely to be left unattended, moved between work areas or connected to removable media. In an office, an idle laptop may lock after a few minutes. On a production line, an aggressive lock-out setting can interrupt a process or delay an operator who is dealing with machinery. The right balance depends on what the device controls, where it sits and how long a task normally takes.
The consequences go beyond lost data. Ransomware entering through a shared terminal can affect scheduling, stock control, dispatch and access to technical drawings. A compromised account with excessive permissions may stop a line as effectively as a failed machine component.
Shared device security starts with knowing what is connected
Many sites have more shared technology than they first realise. This includes fixed production terminals, warehouse scanners, tablets, label printers, test benches, meeting-room PCs, engineering workstations and machines connected to older Windows devices.
Create an accurate device register that records the device owner, location, operating system, business purpose, network connection, installed applications and support status. Crucially, identify whether it can access production systems, business data or the internet. A terminal that only displays work instructions needs different protection from one that can amend bills of materials or release a job to production.
This inventory should include legacy equipment. Older operating systems are common around specialist machinery because an upgrade could affect CE-compliant configurations, vendor warranties or the control software itself. Replacing or patching these devices without planning can introduce downtime. Leaving them unmanaged is not a viable alternative.
Where a legacy machine cannot be upgraded, compensate with controls around it: network segregation, tightly managed access, restricted USB use, monitored jump machines and a clear recovery plan. The goal is to reduce exposure without interfering with the equipment that keeps the factory running.
Give people accountable access without slowing the line
A shared device does not have to mean a shared identity. Individual sign-in allows the business to trace activity and remove access promptly when someone changes role or leaves. For many environments, quick PIN-based sign-in, proximity cards or an approved badge-based method can make this practical at shift change.
The choice should reflect the work. A clean-room tablet, a noisy fabrication area and a warehouse handheld scanner all create different usability constraints. If individual sign-in adds too much friction, staff will naturally seek shortcuts. Test the process with the people using the device, not only the IT team.
Each user should have only the permissions required for their role. Operators may need access to job instructions and production confirmation, while supervisors need wider reporting and exception controls. Local administrator rights should be removed from shared endpoints wherever possible. They allow unapproved software installation and make it easier for malware to gain a stronger foothold.
For applications that genuinely require a common operational account, keep that account narrowly scoped. It should not have email access, broad file-share permissions or the ability to alter system settings. Pair it with device-level logging and a process that records who was responsible for the station during each shift.
Lock down the device, not the workflow
A well-configured shared terminal should do one job reliably. Kiosk mode or application allow-listing can prevent users opening personal email, browsing unsuitable websites or running unapproved software. This is particularly valuable on production terminals that only need an ERP screen, a browser-based quality system or a label-printing application.
Set automatic screen locking, but agree realistic time-outs with operations. A five-minute lock may be sensible for a warehouse terminal near a public access route. It may be impractical for a workstation where an operator steps away briefly to inspect a component. In higher-risk locations, consider screens that require a rapid re-authentication method rather than relying on a long idle period.
USB controls need similar judgement. Blocking all removable media can prevent malware, but engineering teams may need an approved route for machine updates, diagnostic files or supplier software. Use centrally managed, encrypted USB devices where needed, scan them before use and prohibit unknown personal devices.
Physical controls still matter. Mount fixed terminals securely, position screens away from visitors where possible and ensure portable devices are returned to charging cabinets or locked storage at the end of a shift. A device that disappears is both a replacement cost and a potential data incident.
Separate shop-floor devices from the wider network
Network segregation is one of the most effective protections for shared operational technology. A compromised office PC should not be able to browse directly to production equipment, and a shop-floor terminal should not have unrestricted access to every server or cloud service.
Segment networks according to business function and risk. For example, office users, guest Wi-Fi, production terminals, machinery, CCTV and administrative systems should sit in controlled zones with only the connections they require. This limits how far an incident can spread and makes unusual traffic easier to spot.
Remote support also requires control. Suppliers and technicians may need access to a machine or specialist application, but direct always-on remote access is difficult to justify. A managed jump machine, protected by strong authentication and logging, gives authorised engineers a controlled route in while keeping the rest of the environment isolated.
Wireless networks deserve the same attention. Warehouse tablets and scanners often rely on Wi-Fi, yet weak coverage can lead teams to connect to unsuitable networks or use personal hotspots. A properly designed, monitored wireless network supports both reliability and security.
Keep shared endpoints maintained and recoverable
Patching shared devices is not simply a matter of applying every update immediately. Production systems may rely on software versions that must be tested before deployment. However, delayed patching needs an owner, a reason and compensating controls – not an open-ended exception.
A practical maintenance plan groups devices by criticality. Standard tablets and PCs can usually follow a regular update cycle. Systems linked to machinery, test equipment or ERP integrations may need a test environment, vendor approval and scheduled maintenance windows. Monitoring should confirm that antivirus, endpoint protection, backups and critical updates are working as expected.
Backups are essential, but recovery is what protects output. Make sure the business can restore the configuration, applications and data needed to bring shared devices back into service. For critical stations, retain documented build instructions and know where installation media, licence details and supplier contacts are held. A replacement PC is of little use if the production application cannot be rebuilt quickly.
Make security part of the shift routine
Most shared-device incidents begin with ordinary behaviour: someone leaves a session open, plugs in an unknown USB stick or approves an unexpected prompt because they are trying to keep work moving. Clear, brief guidance is more useful than a long policy that never reaches the factory floor.
Train teams on the few actions that matter most: sign out or lock the device when leaving it, never share personal credentials, report missing equipment promptly and escalate unusual pop-ups, slow performance or requests for passwords. Supervisors should know who to call and what to do if a terminal appears compromised, including when to stop using it and move to an agreed fallback process.
Review the controls after operational changes. A new ERP module, revised shift pattern, machinery upgrade or warehouse expansion can all change how shared devices are used. Regular reviews prevent security settings from drifting away from the reality of the site.
Shared devices will always be a practical part of manufacturing. The right controls make them easier to trust: people can get on with the job, managers retain accountability, and a single exposed terminal is far less likely to disrupt the production schedule.
