---
title: "Machine builder adds Edge Shield to its machines | Edge SDN"
description: "A European machine builder put Edge Shield at the boundary of its machines, under its own brand, to protect PLCs and HMIs and answer customers who ask for security."
url: https://www.edge-sdn.com/success-cases/machine-builder/
last_updated: 2026-10-04
---

Machine building · Edge Shield · Machinery Regulation · NIS2 · IEC 62443

# Build network security into your machines and sell it as your own

European industrial machinery manufacturer

Network security sold as part of its own machines

In short

A European machine builder had to protect PLCs, HMIs and sensors that have no security of their own. Customers asked for it, citing the Machinery Regulation, NIS2 and IEC 62443. The builder replaced the basic switch at the machine boundary with Edge Shield, under its own brand, and controls it from the machine HMI through the REST API.

## The challenge

- PLCs, HMIs, actuators and sensors with no built-in security
- Customers and new rules ask for security on the machine
- A strong automation team, but no network security specialists

## What did not work, and what did

What they tried
- Firewalls and IDS switches cost too much per machine
- Tools that need security experts
- Products that do not fit the builder's control software
- Security that gets in the way of PLC programmers

What worked
- Edge Shield as the boundary switch, under the builder's brand
- Security profiles for each machine state
- Controls inside the machine HMI, through the REST API
- Normal operation and maintenance unchanged

## How we did it

1. **Replace the boundary switch**Edge Shield takes the place of the basic switch at the edge of the machine.
2. **Define the machine states**Write a security profile for each state, using the documentation.
3. **Integrate with the HMI**Call the REST API from the machine's own control software.
4. **Offer it on new and installed machines**Sell the upgrade on new machines and as a retrofit.

## The results

- **More markets**Sells where customers ask for cybersecurity evidence.
- **Fewer service calls**Fewer network misconfigurations and needless maintenance calls.
- **New revenue**Security upgrades on new machines and retrofits.
- **Stronger position**Known as a supplier of secure machines.

### Read the full story

## The situation

The builder makes industrial machines for international markets. Its machines are more and more digital, and each new piece of software is a possible weak point. Essential parts such as PLCs, HMIs, actuators and sensors have little or no security of their own.

Three teams felt the pressure. **Quality** saw security become a customer requirement. **Sales** saw it as a way to win. The **technical department** had to meet different standards in different countries without slowing down engineering.

## What they needed

The builder looked at many industrial security products. Firewalls and switches with intrusion detection were too expensive for one machine. Other tools needed security experts the company did not have. Large vendors’ products did not integrate with the builder’s control software. Some got in the way of PLC programmers and maintenance technicians.

The builder needed something it could present as part of its own machine, that works with its control system and that its engineers can manage.

## What we did

The builder replaced the basic network switch at the machine boundary with [Edge Shield](https://www.edge-sdn.com/products/edge-shield/), supplied without our brand so it sells as the builder’s own technology.

Its engineers wrote **security profiles for each machine state** with our documentation. They built the controls into the machine **HMI through the REST API**, so the operator never leaves the machine’s own interface.

## What changed

The builder now protects its machines without changing how they run or how they are serviced. It sells security upgrades on new machines and as retrofits on machines already installed. Fewer network misconfigurations mean fewer needless service calls.

Above all, it can tell customers how the machine is protected against network attacks that would stop production, and it can adapt as rules change in each region.

**Machinery Regulation from 20 January 2027**

Annex III point 1.1.9 covers protection against corruption: connecting another device to the machine, directly or remotely, must not create a hazardous situation. [\[Regulation (EU) 2023/1230, Annex III point 1.1.9\]](https://eur-lex.europa.eu/eli/reg/2023/1230/oj/eng)

Product used

### Edge Shield

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

Related use case

### Prepare for point 1.1.9: what your machine must know about its own software from 20 January 2027

[Read](https://www.edge-sdn.com/use-cases/machinery-regulation-point-1-1-9/)

Related use case

### Reduce the attack surface of an old machine: protect what you cannot patch

[Read](https://www.edge-sdn.com/use-cases/protect-a-machine-you-cannot-patch/)

The customer is not named on this page. Results describe this project and depend on each network.

## See a critical CVE hit a machine

We show you the moment that matters: a new vulnerability lands. One machine is exposed and the other is not. The customer notice is ready to send.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
