---
title: "Protect an old machine you cannot patch | Edge SDN"
description: "Old machines run unsupported software and cannot be updated. How to cut their exposure at the network level without replacing the line or touching the PLC."
url: https://www.edge-sdn.com/use-cases/protect-a-machine-you-cannot-patch/
last_updated: 2026-09-19
---

CRA · NIS2 · IEC 62443 · Machine builder · Plant operator

# Reduce the attack surface of an old machine: protect what you cannot patch

By Aldo Campi, co-founder and CEO of Stoorm5 · Published 19 September 2026 · Last updated 19 September 2026

How do I secure a legacy industrial machine that cannot be patched?

Isolate the machine at the network level. Put a segmentation device between the machine and the plant network. Allow only the flows the machine needs in each operating state. Block and inspect everything else and keep a record. The machine keeps running and the vulnerable software can no longer be reached.

Where are you against 20 January 2027? [Take the Check 2027](https://www.edge-sdn.com/check-2027/): seven questions, three minutes.

## Key facts

- The CRA product requirements apply to products placed on the market from 11 December 2027. Older products must meet them only if they are substantially modified after that date. [\[Regulation (EU) 2024/2847, Article 69(2)\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- The CRA reporting duty covers products already on the market: actively exploited vulnerabilities must be reported within 24 hours and users must be informed. [\[Regulation (EU) 2024/2847, Articles 14 and 69(3)\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- NIS2 asks operators in critical sectors for risk management measures that include supply chain security. [\[Directive (EU) 2022/2555, Article 21\]](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng)

## The situation

A filling machine was installed fifteen years ago. Its HMI runs an operating system that stopped receiving security updates long ago. Several ports are open because nobody ever closed them. The machine works perfectly and the customer has no intention of replacing it.

Now two things happen. The customer falls under NIS2 and must show that it controls the risks in its plant, suppliers included. And the machine builder must, since September 2026, report actively exploited vulnerabilities in its products and inform the users, old products included.

Both look at the same machine and ask what can be done.

## Three answers that do not work

**“Update the software.”** The HMI application was validated on that operating system. A new version means a new validation, often new hardware, sometimes a new PLC. For a machine in a pharma line it also means requalification.

**“Sell a new line.”** No customer accepts this as the answer to a security question, and no serious supplier proposes it.

**“Put an enterprise OT firewall in front of each machine.”** Enterprise OT firewalls are designed and priced for plant networks, not for a single machine. Builders tell us the cost is hard to justify on one machine, so they fall back on a basic switch with no protection.

## What works: close the paths, not the machine

An attacker needs a path to reach the vulnerable software. If the path does not exist, the vulnerability is still there but it cannot be used.

### 1. List what the machine really needs

In production the machine talks to the MES and sends telemetry. During maintenance a service laptop connects. During remote support a VPN toward the supplier opens. During updates it reaches a firmware repository. Four states, a handful of flows.

### 2. Put a segmentation device at the machine

The device sits between the machine and the plant network. It forwards only the flows of the current state and blocks the rest. It works at layer 2, so you do not change IP addresses, VLANs or the PLC program.

### 3. Make the state change simple and recorded

The operator switches from “production” to “remote maintenance” with a push button. The VPN path opens for that window and closes again. Each change is logged.

### 4. Inspect what passes

The allowed traffic is inspected for attempts to exploit known vulnerabilities. Blocked attempts raise an alert.

### 5. Keep the evidence

You can now show the customer, and an auditor, which flows are allowed in which state, what was blocked and when the profile changed.

## How Edge Shield does it

[Edge Shield](https://www.edge-sdn.com/products/edge-shield/) is a smart switch with a network probe and an intrusion detection system in one unit. The C6 model fits on a DIN rail inside the cabinet, runs on 24 V and works from -40 to 65 °C. The IT administrator defines the profiles once. The operator applies them with a physical button.

With [Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/), the same profiles describe the attack surface of the machine. When a new vulnerability appears in the old HMI software, Shield Lifecycle checks if the path to it is open. If Edge Shield blocks that path, the vulnerability is recorded as mitigated and the customer receives an updated report. No patch, no downtime.

## What this does not do

It does not make an old machine “CRA compliant”, and the CRA does not ask for that unless you substantially modify the machine. It does not remove the vulnerability. It removes the ways to reach it, and it gives you the record to prove it.

## Frequently asked questions

### Does the CRA force me to update machines I sold ten years ago?

No. The product requirements do not apply to machines placed on the market before 11 December 2027, unless you substantially modify them after that date. The reporting duty does apply to them, and your customers may ask you to secure them because of their own NIS2 duties.

### Why not just put a firewall in front of the machine?

A firewall at the plant border does not see traffic between machines on the same network, and enterprise OT firewalls are sized for plant networks, not for one machine. Segmentation at the machine closes the paths inside the plant too.

### Will the machine stop during installation?

Edge Shield works as a transparent layer 2 switch, so IP addresses, VLANs and the PLC program stay as they are. The installation is a cable change that you plan in a normal maintenance window.

Product

### Edge Shield

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

Product

### Shield Lifecycle

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Related use case

### Same model, two machines, one exposed: find which shipped machines a new CVE hits

[Read](https://www.edge-sdn.com/use-cases/find-which-machines-a-new-cve-exposes/)

Related use case

### Prepare for point 1.1.9: what your machine must know about its own software from 20 January 2027

[Read](https://www.edge-sdn.com/use-cases/machinery-regulation-point-1-1-9/)

This article is a summary for practitioners and not legal advice. Always check the official text for your case.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
