
IT security for manufacturing and industry
Customer questionnaires, a grown toolset and an IT lead who already carries everything else. Where we start in Swiss manufacturing.
The situation
Swiss engineering and metalworking firms are still waiting for a recovery. In Swissmechanic's May 2026 business barometer, about three quarters rate their business situation as unfavourable, the business climate index sits at around minus 30 points, and four in ten firms saw falling EBIT margins in the first quarter of 2026.
That is the real context for every security conversation in this industry. In a year with that order book, no board signs off a new full-time position, least of all for a function that brings in no revenue. Anyone arriving with a job profile or a tool list has lost the conversation before it started.
The requirements do not go away, though. Large customers send supplier questionnaires with deadlines, insurers attach conditions to the policy, and on the shop floor control systems and office IT keep growing together. The pressure comes from outside while the budget shrinks from inside.
That squeeze is exactly where we work. Not with more technology, but with clear responsibility and a stocktake that asks first what can go.
What we find in this industry
- Security sits with the IT lead who already carries everything elseOperations, ERP, projects and support run through the same person. Security is not in bad hands there, it is simply the task that always comes last. That is a capacity problem, not a competence problem, and training does not fix it.
- Customer questionnaires decide who gets the orderIf you cannot evidence supply chain, emergency planning and access control, you drop off the bidder list before anyone talks about price. With EU customers, NIS2 requirements arrive through the contract, not through the law.
- Machines run for 15 years and moreControllers on old software versions cannot simply be updated, because the vendor has not approved it or the line would have to stop. The standard office-IT answer, just patch it, does not work in production.
- OT and IT are long since the same networkMachine builders' remote maintenance access, production data capture and quality systems sit on the same infrastructure as mail and ERP. The separation often exists only on the org chart.
- The toolset grew, it was never designedFirewall, endpoint protection, backup and monitoring come from different years and overlap. With margins shrinking, that is real money buying no additional protection.
- One day of downtime costs more than the annual security budgetThat is the real argument on a shop floor, and it is a commercial one, not a regulatory one. Expressing security in lost production hours rather than threat levels is what gets the discussion onto the board agenda at all.
Typical trigger
A major customer sends a security questionnaire with a deadline and nobody inside can answer it. Or the cyber insurer attaches new conditions at renewal.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
Assigned responsibility without creating a position
A mandate of one to four days a week costs a fraction of a permanent CISO and can be scaled back once the programme stands. That is the cost structure a board will approve even with headcount frozen.
Your IT lead keeps operations. We take on security leadership, prioritisation and reporting to management and the board, in business language rather than technical terms.
Count what you already have before you invest
For a fixed CHF 9,800 we measure maturity, surface duplicate licences and prioritise by business risk rather than product catalogue. The price is published so approval does not stall on an open-ended invoice.
In most companies what gets cut pays for a good part of what is missing. That is why this service comes first, not last.
The questionnaire becomes an answer that is already on file
An ISMS answers customer and audit questions once, in a structured way, instead of assembling them from scratch each time. Supply chain and NIS2 requirements from EU customers are covered with it.
The certificate is the visible part. The practical benefit is that sales no longer waits for IT when a tender comes in.
Remote access and suppliers under control, without stopping the line
We bring order to access, permissions and vendor maintenance, and put structure into how suppliers are assessed. Measures are planned around the production schedule, not the other way round.
Your people stay in operations. We work off the backlog and hand over so it does not build up again.
Who it is for
- Manufacturers with 50 to 500 employees and no dedicated security role
- Suppliers who have to answer security questionnaires from large customers
- Companies with a grown toolset and the suspicion that they are overpaying
- Firms where OT and IT are converging and nobody has the full picture
Related engagements
- CISO mandate for an international industrial company (1,600 employees)
- Gap assessment against CIS Controls at an industrial company with 3,600 employees
- Zero-Trust programme across all of IT
- Ransomware recovery after full encryption
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
We already have an IT manager. Why add an external security role?
Because they are two different jobs. IT management keeps operations running. Security leadership means assessing risk, setting priorities and representing them to management and customers. In most industrial SMEs the second job is assigned to nobody and simply hangs on the side.
Can we secure machines at all if we are not allowed to patch them?
Yes. When a system cannot be updated, the work is to segment it, control access to it and plan for its failure. That is standard practice in manufacturing and needs no vendor approval.
A customer is asking for ISO 27001. How long does that take?
Depending on the starting point and scope, usually nine to eighteen months to certification. More relevant for ongoing sales: the answers to the questionnaire are available much earlier, because they are produced along the way.
We are on short-time work right now. Is this the wrong moment?
For a new position yes, for a stocktake no. This is exactly when it pays to look at which licences and contracts overlap. In our experience the clean-up funds part of what is missing.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

