Cybersecurity in the ink room: from risk to control

In the first part of this series, we examined emerging cybersecurity risks associated with the connected ink room. Connections between business software, production networks, machine controls and external services improve accuracy, traceability and efficiency, but they must be managed carefully.

Protecting this environment requires more than antivirus software or occasional updates. It requires a layered approach in which technical controls, access rules, recovery procedures and lifecycle planning work together.

Separate IT and OT networks

Network segmentation – where a computer network is split into smatter, isolated parts – is one of the most effective ways to improve cybersecurity in industrial environments.

GSE dispensing systems are typically connected to a dedicated Operational Technology network, linked to the customer’s IT network through managed switches or firewalls. This limits unnecessary exposure between office systems and production equipment.

For older systems that do not support modern operating systems, some customers choose complete isolation from the corporate network. This reduces the attack surface, but it also prevents remote support and software updates. Isolation should therefore be a deliberate lifecycle decision.

Control system interconnectivity

GSE Ink manager can exchange planning, production and recipe data with ERP, MES, MIS and colour-formulation systems through the customer’s internal network. It can also connect to cloud applications, ink-supplier platforms and logistics systems.

These connections should be reviewed in terms of authentication, access rights, data ownership and responsibility. Cloud-service security is typically managed between the provider and the customer, while GSE connects through the existing corporate infrastructure.

Within the dispensing system, GSE Ink manager communicates with the machine controls through a dedicated internal network. The industrial PC connects to the Real-Time Controller, which manages machine operation. Production data is not permanently stored on the controller.

Secure remote access

Remote support must be encrypted, controlled and approved.

GSE systems can use TeamViewer Host with encrypted communication, secure authentication and multi-factor authentication for support engineers. Access should only be available to authorised personnel and should follow the least-privilege principle.

Physical access also requires control. Industrial PCs, USB ports and machine controls can introduce risks when local access is unmanaged.

Manage users and permissions

Individual accounts and role-based access reduce the risk of unauthorised changes.

GSE Ink manager supports user groups, centrally managed permissions, password protection and automatic logout. These controls help protect recipes, production data and system settings while improving traceability.

Shared accounts should be avoided because they make it difficult to identify who changed a recipe, created a component or adjusted a setting.

Monitor, log and recover

Remote sessions should be logged, while audit trails should record actions such as recipe changes, base-component creation and dispensing operations.

Recovery planning is equally important. GSE systems are supplied with recovery media containing a system image, boot files and backups. Database backups can retain multiple generations and can also be stored automatically on the customer’s IT server.

A backup is only useful when it can be restored. Recovery procedures should therefore be tested, documented and assigned to responsible personnel.

Protect and maintain endpoints

New GSE systems run on Windows 11 IoT Enterprise LTSC and include Microsoft Defender. Additional controls can be applied by the customer’s IT department in line with company policy.

Industrial updates must be managed carefully. Security patches should be tested before deployment, and software updates should be planned to avoid disrupting production. Customers with a software subscription or support contract can receive updates for GSE Ink manager and the Real-Time Controller.

Make cybersecurity part of lifecycle management

Dispensing systems are built for long service lives, but the digital environment around them continues to change. Operating systems, control PCs, databases and integrations all require periodic review.

Through GSE’s Extended Life Program, existing systems can be modernised with upgrades, refurbishment, software updates and preventive maintenance. This supports security, performance and production continuity without requiring immediate full replacement.

Cybersecurity in the ink room is not a one-time project. It is an ongoing operational discipline that must evolve with the system.

Want to learn more? Subscribe to the InkConnection newsletter for future articles in this series or contact our team at info@gsedispensing.com or +31 575 568 080 to discuss your system’s lifecycle and cybersecurity requirements.