The situation

A filling machine was installed fifteen years ago. Its HMI runs an operating system that stopped receiving security updates long ago. Several ports are open because nobody ever closed them. The machine works perfectly and the customer has no intention of replacing it.

Now two things happen. The customer falls under NIS2 and must show that it controls the risks in its plant, suppliers included. And the machine builder must, since September 2026, report actively exploited vulnerabilities in its products and inform the users, old products included.

Both look at the same machine and ask what can be done.

Three answers that do not work

“Update the software.” The HMI application was validated on that operating system. A new version means a new validation, often new hardware, sometimes a new PLC. For a machine in a pharma line it also means requalification.

“Sell a new line.” No customer accepts this as the answer to a security question, and no serious supplier proposes it.

“Put an enterprise OT firewall in front of each machine.” Enterprise OT firewalls are designed and priced for plant networks, not for a single machine. Builders tell us the cost is hard to justify on one machine, so they fall back on a basic switch with no protection.

What works: close the paths, not the machine

An attacker needs a path to reach the vulnerable software. If the path does not exist, the vulnerability is still there but it cannot be used.

1. List what the machine really needs

In production the machine talks to the MES and sends telemetry. During maintenance a service laptop connects. During remote support a VPN toward the supplier opens. During updates it reaches a firmware repository. Four states, a handful of flows.

2. Put a segmentation device at the machine

The device sits between the machine and the plant network. It forwards only the flows of the current state and blocks the rest. It works at layer 2, so you do not change IP addresses, VLANs or the PLC program.

3. Make the state change simple and recorded

The operator switches from “production” to “remote maintenance” with a push button. The VPN path opens for that window and closes again. Each change is logged.

4. Inspect what passes

The allowed traffic is inspected for attempts to exploit known vulnerabilities. Blocked attempts raise an alert.

5. Keep the evidence

You can now show the customer, and an auditor, which flows are allowed in which state, what was blocked and when the profile changed.

How Edge Shield does it

Edge Shield is a smart switch with a network probe and an intrusion detection system in one unit. The C6 model fits on a DIN rail inside the cabinet, runs on 24 V and works from -40 to 65 °C. The IT administrator defines the profiles once. The operator applies them with a physical button.

With Shield Lifecycle, the same profiles describe the attack surface of the machine. When a new vulnerability appears in the old HMI software, Shield Lifecycle checks if the path to it is open. If Edge Shield blocks that path, the vulnerability is recorded as mitigated and the customer receives an updated report. No patch, no downtime.

What this does not do

It does not make an old machine “CRA compliant”, and the CRA does not ask for that unless you substantially modify the machine. It does not remove the vulnerability. It removes the ways to reach it, and it gives you the record to prove it.