When Cybersecurity Becomes An Electrical Safety Issue
Key Highlights
- Connected OT and automation systems now play a critical role in electrical safety, making cybersecurity a maintenance and safety concern, not just an IT issue.
- NFPA 70B and NFPA 72 increasingly recognize cybersecurity as essential for maintaining trustworthy data, system integrity, and safety-related infrastructure.
- Manufacturers should map digital dependencies, strengthen change control, and apply Secure by Design principles to protect safety, reliability, and uptime.
Picture a maintenance team responding to an electrical issue during production. The physical assets may look familiar: breakers, motor control centers, drives, relays, control panels, monitoring systems, and the signaling interfaces that support facility safety. The work also sounds familiar: protect people, maintain equipment, restore operations, and prevent the same issue from recurring. What has changed is that many of the decisions behind that work now depend on digital systems that the maintenance team may not fully own, see, or trust.
In connected facilities, automation and operational technology (OT) systems increasingly support each part of the electrical safety lifecycle. They hold device settings, inspection records, alarm histories, condition-monitoring trends, remote access paths, configuration files, engineering workstation data, and system status information. When those systems are accurate, available, and well governed, they strengthen maintenance and safety. When they are unavailable, inaccurate, or exposed to unauthorized changes, the electrical safety cycle becomes weaker than it appears.
That is why cybersecurity is becoming a maintenance and safety issue. The concern is not only whether a facility can prevent a major cyberattack. The more immediate question is whether the systems, data, and access pathways supporting maintenance and safety decisions can be trusted when those decisions matter. If breaker settings are changed without documentation, inspection records are incomplete, condition-monitoring data is unavailable, or remote access to critical systems is poorly governed, the organization may have less confidence in its maintenance program than it assumes.
The National Fire Protection Association's (NFPA) Electrical Cycle of Safety provides a useful framework for this shift. The cycle connects NFPA 70, NFPA 70E, and NFPA 70B into a broader model of electrical safety: safe installation, safe work practices, and proper maintenance of electrical equipment. In the past, facilities may have viewed those elements primarily in terms of physical equipment, written procedures, and periodic maintenance. In modern facilities, each part of that lifecycle increasingly depends on connected automation and OT systems.
Trusted information is now part of safe maintenance
The traditional view of electrical safety asks necessary questions. Was the system installed correctly? Are workers protected from electrical hazards? Is equipment properly maintained? Are studies, labels, and procedures current?
Those questions still matter, but the answers increasingly depend on digital information that must be accurate, protected, and available.
Maintenance teams may use electronic inspection records to demonstrate that work was completed. Reliability teams may use condition-monitoring data to prioritize equipment repairs. Engineers may depend on relay settings, one-line diagrams, arc flash studies, and coordination studies that must reflect current system conditions. OT teams may enable remote access so internal or vendor experts can troubleshoot quickly when production is at risk. In each case, a digital dependency supports a maintenance or safety decision.
This is where the risk becomes tangible for plant leaders. A breaker may be physically maintained, but the facility’s risk profile changes if its settings are modified without documentation or backup. A monitoring platform may provide useful equipment data, but the team may act with false confidence if the data source, network path, or software platform is unreliable. A maintenance record may exist, but it may not support safety, compliance, or recovery decisions if the organization cannot demonstrate what was done, who completed it, and what corrective actions followed.
The issue is not that every connected asset represents an emergency. Rather, connected dependencies now require the same discipline that organizations already apply to physical inspections, testing, and safety procedures. If a facility depends on automation and OT systems to support maintenance decisions, cybersecurity is part of preserving the quality of those decisions.
NFPA 70B and NFPA 72 show where the standards are headed
NFPA 70B provides structure for electrical maintenance programs. The 2026 edition states that an electrical maintenance program should function in conjunction with the applicable electrical safety program. It identifies program elements such as equipment surveys and analyses, documented maintenance procedures, inspection and testing plans, records-retention policies, corrective measures, design for maintainability, and program review for continuous improvement, according to the NFPA.
Those program elements depend on trustworthy information. Equipment surveys depend on accurate asset data. Maintenance procedures depend on current equipment configurations. Inspection and testing plans depend on reliable records and information about system conditions. Corrective measures depend on documentation that can be tracked through completion. Program reviews depend on evidence that reflects what is actually happening in the facility.
The 2026 edition of NFPA 70B also makes the connection to cybersecurity explicit. The electrical maintenance program elements include a risk assessment of OT cybersecurity when industrial control systems or OT are not limited to a direct connection through a local, non-networked interface. NFPA’s annex material reinforces the point by stating that maintaining OT cybersecurity is an integral part of modern connected electrical, electronic, and communications systems and equipment. It also notes that industrial or process automation, control, and monitoring can be disrupted by cyber threats, according to the NFPA.
NFPA 72 points in a similar direction for fire alarm and signaling systems. The 2022 edition added Chapter 11, which requires cybersecurity for fire alarm and signaling systems, with guidance provided in Annex J. NFPA’s 2025 materials describe expanded requirements in Chapter 11 for protecting those systems from cyberattacks.
That matters because many facilities do not consider fire alarm, signaling, or emergency communications systems part of OT or automation, even though these systems increasingly rely on networked devices, software, communications paths, and integrations with other facility systems.
The lesson is not that every safety-related system should be treated exactly like a production control system. Rather, connected safety-related infrastructure carries cyber dependencies that should be understood, governed, and maintained. As electrical, automation, and life-safety systems become more connected, cybersecurity becomes part of maintaining trust in the systems that support safety, maintenance, and emergency response.
Secure by Design belongs in maintenance planning
Secure by Design principles help move this conversation upstream. In industrial automation, Secure by Design should influence how connected electrical, automation, and life-safety systems are specified, integrated, accessed, maintained, and supported throughout their lifecycles. The Cybersecurity and Infrastructure Security Agency (CISA) describes Secure by Design as an approach in which products prioritize security as a core business requirement rather than treating it as a technical feature added later.
For a facility leader, the practical question is straightforward: Can this system be operated, secured, maintained, updated, monitored, and recovered safely over time? That question matters because many maintenance and cybersecurity problems originate during design, procurement, or integration.
A connected electrical asset may perform its function on day one, but if it is difficult to patch, hard to back up, poorly documented, dependent on unmanaged remote access, or unsupported by clear ownership, future teams inherit the risk.
This connects directly to NFPA 70B’s emphasis on design for maintainability. Maintainability is no longer limited to physical access, spare parts, or testing procedures. For connected systems, maintainability also includes secure access, configuration management, logging, backup and recovery, vendor support, patching expectations, and lifecycle planning. A system that cannot be maintained securely over time can weaken the safety and reliability outcomes it was intended to support.
Automation teams see the dependencies first
Automation teams are often closest to the practical reality. They know which systems are connected, which devices are critical, which networks are fragile, which applications are outdated, and which remote access methods have developed informally over time.
They also understand that industrial systems cannot always be managed like ordinary enterprise IT systems because production availability, safety, timing, and process integrity matter. The National Institute of Standards and Technology (NIST) SP 800-82 describes OT as programmable systems and devices that interact with the physical environment by monitoring or controlling devices, processes, and events. It also emphasizes that OT security must account for unique performance, reliability, and safety requirements.
In industrial environments, cybersecurity is not only about protecting data confidentiality. It is also about protecting process integrity, equipment availability, operational continuity, and human safety.
One way to make the issue visible is to trace the chain of dependency. Connected assets support data integrity and system availability. That information supports maintenance decisions. Those decisions affect worker safety, equipment reliability, and uptime. If any link is weak, the entire chain is weaker. Poor data leads to poor prioritization. Missing records create false confidence. Uncontrolled access creates the possibility of unauthorized changes. Unavailable systems delay responses. Weak backup and recovery practices extend outages.
This is why automation teams should not be treated as peripheral to maintenance and safety planning. They are often the people who can identify whether the trust layer beneath the safety lifecycle is strong or fragile. Without their perspective, maintenance, environmental health and safety (EHS), and operations leaders may underestimate risk because the physical program appears more complete than the supporting digital infrastructure actually is.
Where to start
Organizations do not need to begin by purchasing another tool. They should begin by mapping the digital dependencies that support maintenance and safety. For safe installation, those dependencies may include drawings, models, studies, configuration files, and system documentation. For safe work practices, they may include labels, procedures, equipment status, access permissions, and alarm information. For proper maintenance, they may include inspection records, device settings, condition-monitoring data, backups, vendor access, and recovery procedures.
Once those dependencies are visible, they should be classified by criticality. A remote access pathway into a noncritical support system does not carry the same risk as a pathway into power distribution, fire alarm interfaces, production control systems, or safety-related equipment. Prioritization should consider worker safety, production impact, compliance exposure, recovery difficulty, and the organization’s ability to detect or reverse unauthorized changes.
The next step is to strengthen change control and protect the evidence. Relay settings, programmable logic controller logic, human-machine interface screens, network rules, firmware versions, user accounts, remote access permissions, and life-safety system interfaces should have clear ownership, approval, backup, and recovery expectations. Digital maintenance and inspection records should have appropriate access controls, retention periods, backups, audit trails, and recovery procedures. These practices may sound administrative, but they allow an organization to trust the information behind its maintenance decisions.
Secure by Design should also be applied to projects and upgrades. When adding connected electrical equipment, monitoring platforms, remote access capabilities, analytics tools, or signaling system integrations, cybersecurity and maintainability requirements should be incorporated early. Ownership, access control, change approval, configuration backup, update management, and recovery expectations should be defined before the system becomes part of daily operations.
Finally, electrical maintenance, automation, OT cybersecurity, EHS, facilities, and operations teams should regularly review the same risk profile. The discussion should address practical questions: What connected systems support maintenance and safety? What information do teams rely on? Where could a cyber issue affect safety, reliability, uptime, or emergency response? Which gaps create the greatest risk?
The new operating reality
The automation community does not need another broad warning about cybersecurity. Facility leaders need a practical way to connect cybersecurity to the work they already care about: safety, uptime, maintenance quality, and operational performance. NFPA’s Electrical Cycle of Safety provides a useful framework, and NFPA 72 reinforces that fire alarm, signaling, and emergency communications systems also carry cybersecurity considerations as they become more connected.
The connection is simple: Electrical safety depends on proper maintenance, and proper maintenance depends on trusted systems and data. In connected industrial facilities, automation and OT systems increasingly support each part of that lifecycle. If those systems are unavailable, inaccurate, or exposed to unauthorized changes, cybersecurity is no longer a separate technical concern. It is part of keeping the electrical safety cycle intact.

