A machine still running Windows 7, an ageing HMI that only one supplier can support, or an ERP integration nobody wants to touch can all be vital to production. The objective is not simply to replace every old asset. To secure legacy systems in manufacturing, you need to reduce their exposure, control who can reach them and make sure a failure does not stop the factory.
For many manufacturers, legacy technology is a commercial reality rather than an IT oversight. A replacement may require machine downtime, software revalidation, engineering changes and a significant capital decision. The risk comes when these systems are treated like ordinary office devices, connected to the same network and given broad, unmanaged access to users, suppliers and the internet.
A practical security plan accepts the equipment’s limitations while putting strong controls around it. That protects output now and gives the business a measured route to modernisation.
Why legacy systems create a production risk
Unsupported operating systems no longer receive security updates for newly discovered vulnerabilities. Older machinery may also use protocols that were never designed for a connected environment, shared local administrator accounts or applications tied to obsolete hardware. Those weaknesses are concerning on their own, but their operational impact is what matters most.
A ransomware incident that begins with a phishing email can move through a flat network to a file share, an engineering workstation or a production server. Equally, an unplanned Windows update, failed anti-virus installation or supplier remote session can disrupt a machine that has run reliably for years. Security measures that ignore production conditions can create the outage they are meant to prevent.
The right question is therefore not, “Can this system be patched?” It is, “What could reach it, what does it depend on, and how would we continue operating if it failed?” The answers shape proportionate controls and help directors prioritise investment by business impact rather than the age of a device alone.
Secure legacy systems in manufacturing by mapping what matters
Start with a reliable asset and dependency register. This should cover more than PCs and servers. Include PLCs, HMIs, industrial PCs, barcode scanners, label printers, switches, wireless access points, engineering laptops, virtual machines, backup devices and externally hosted applications.
For every critical asset, record its operating system or firmware, physical location, owner, supplier support status, network connections, user access and recovery method. Identify whether it supports a production line, quality process, warehouse operation, ERP or MRP workflow, or a safety-related function. A machine that cannot be replaced quickly deserves a different level of protection from a non-critical workstation.
Dependencies are often where surprises sit. An old application might rely on a specific SQL server, a mapped network drive, a USB licence key or a single desktop in the engineering office. Documenting those links exposes single points of failure before they become an urgent production issue.
This register should be actively maintained, not filed away for an audit. When machinery changes, suppliers visit or an application is upgraded, update the record and review the security implications.
Separate the shop floor from the office network
Network segregation is usually the most effective control for older industrial systems. A legacy device should not be able to communicate freely with every office computer, guest wireless device or internet service simply because it is plugged into the same estate.
Create separate network zones for office IT, production equipment, servers, guest access and, where appropriate, individual lines or cells. Firewalls between those zones should permit only the traffic the process genuinely requires. For example, an HMI may need to communicate with a specific PLC and a designated data collection server, but it rarely needs unrestricted web access or access to every user device.
This work needs careful planning. Blocking a port without understanding the production process can stop data collection or prevent an engineer from accessing a machine during a fault. Monitor existing traffic first, agree rules with operations and engineering, then make controlled changes during an appropriate maintenance window.
Wireless networks need the same discipline. Shared shop-floor tablets and scanners should not sit on the same wireless network as visitors or unmanaged personal devices. Strong authentication, separate SSIDs and properly configured firewall rules help contain an incident before it reaches critical equipment.
Control remote access and privileged accounts
Remote support is often essential for specialist machinery, but it is also a common route into industrial environments. Suppliers should not have permanent, unrestricted access to production systems. Access should be approved for a defined purpose, limited to the relevant systems and removed when the work is complete.
A jump machine provides a safer route. This is a tightly controlled, monitored device used to access the production environment rather than allowing direct connections from an office laptop or supplier network. Pair it with multi-factor authentication, named user accounts and session logging so you can see who accessed what and when.
Shared accounts are particularly risky on the shop floor because accountability disappears. Where older software cannot support individual logins, protect the surrounding environment instead. Restrict physical access, keep credentials in a controlled process, limit the account’s permissions and record use for maintenance activities.
At a minimum, review administrator accounts, disable old supplier credentials and remove local admin rights from everyday office users. These are straightforward actions that can significantly reduce the spread of malware.
Use compensating controls where patching is not possible
Patching remains valuable, but it must be handled cautiously on production technology. A patch may be unsupported by the machine vendor, affect a validated application or require downtime that cannot be justified during a busy period. Leaving a critical system untouched is not a plan either.
Where direct patching is unavailable, use compensating controls to reduce the likelihood and impact of compromise. These commonly include:
- strict firewall rules and no direct internet access
- application allowlisting, so only approved software can run
- modern endpoint protection where it is compatible with the device
- removable-media controls for USB devices and engineering laptops
- heightened monitoring of unusual connections, failed logins and privilege changes
The balance depends on the equipment. Endpoint protection may be suitable for an older Windows workstation but not for a highly sensitive HMI with limited processing capacity. In that case, segregation, access restrictions and close monitoring may provide better protection without affecting machine performance.
Do not assume a legacy device is invisible because it is old or sits on the factory floor. Attackers look for the easiest route, and an unpatched workstation with broad network access is often exactly that.
Protect the data and practise recovery
Production continuity relies on more than keeping devices online. You also need recoverable data: ERP and MRP databases, machine configurations, recipes, drawings, quality records, licence information and network configurations. If these are only stored on the affected server or a permanently connected backup drive, ransomware can make a bad situation worse.
Use backups that are monitored, encrypted and protected from routine user access. Keep copies separate from the main environment, and retain them for long enough to recover from a delayed discovery of compromise. For critical machinery, retain tested copies of PLC logic, HMI projects and configuration files alongside clear instructions for restoration.
A backup is only useful if it can be restored within the time production can tolerate. Test recovery regularly, including the dependencies around it. Restoring a virtual server is not enough if the application also needs an old database version, a licence server and a specific network path to operate.
Create a concise incident runbook for the people who will be on site during a disruption. It should state who can isolate equipment, who contacts machine suppliers, where recovery credentials are held and how production will be prioritised. Clear responsibilities prevent valuable hours being lost to uncertainty.
Build a staged modernisation plan
Security controls buy time, not an unlimited extension to the life of unsupported technology. Use your asset register and risk assessment to create a lifecycle plan that ranks systems by production impact, security exposure, supportability and replacement complexity.
Some assets can be replaced quickly. Others need a longer programme involving machine vendors, software integrators and planned shutdowns. Set realistic milestones, budget for testing and make the case in terms of reduced downtime, supplier dependency and recovery risk, not technology for its own sake.
An experienced manufacturing IT partner can coordinate this work across office IT, the shop floor and third-party suppliers. Syn-Star supports this approach with managed monitoring, segregated networks, legacy-hardware support and clear ownership of the controls that protect continuity.
The best time to address a legacy system is while it is still working and production can be planned around the change. Put sensible protection around it now, test how you would recover it, and make each future upgrade a controlled business decision rather than the result of an avoidable outage.
