A packaging manufacturer we know rolled out EDR (Endpoint Detection and Response, the modern replacement for traditional antivirus) across their corporate environment without incident. Encouraged by the result, their IT team deployed the same agent, with the same configuration, to the HMIs (human-machine interface stations) on their production lines one weekend. By Monday morning, the EDR had quarantined legitimate SCADA executables that its machine learning model did not recognize, two lines refused to start, and a third line ran with degraded control because a critical process file had been isolated.
The IT team did what they had done on the corporate side. The production side needed a different approach. Endpoint protection on production-critical systems is not optional anymore, but deploying it the same way you deploy it on office laptops is a route to lost production.
Manufacturing is the most attacked industry sector for cybersecurity incidents, according to IBM X-Force’s ongoing threat intelligence. CISA advisories consistently recommend modern endpoint protection on industrial control systems. The challenge is not whether to deploy. The challenge is how to deploy without breaking production.
The Problem: Production Endpoints Are Not Office Endpoints
EDR products are generally designed with assumptions that fit corporate endpoints: systems running a current OS, connected to central management, with users who can tolerate occasional prompts, and workloads that look like office productivity software. Production endpoints often break each of those assumptions.
Typical production endpoints include:
- HMI workstations that must remain responsive to operator input in real time
- Historian servers that collect high volumes of time-series data from controllers
- Engineering workstations with specialized software (RSLogix, Siemens TIA Portal, Wonderware, Ignition)
- SCADA servers that orchestrate entire plant operations
- Older systems running legacy Windows versions (sometimes Windows 7 or even Windows XP) because the OEM supporting the equipment does not certify newer versions
- Systems with strict performance requirements, where a fraction of a second of latency affects control accuracy
- Systems with no room for prompts or user interaction, because they are unattended during production
Deploying EDR on these systems without preparation can cause false positive quarantines of critical executables, performance degradation under agent scanning, driver conflicts with industrial hardware, and production interruption during rollout.
And yet, not deploying is also not the answer. The CISA ICS advisories document ongoing attacks on exactly these endpoints.
Why It Matters to You Specifically
For the plant IT leadership or OT engineering team, the EDR conversation affects several areas:
Compliance and Insurance Expectations
Cyber insurance underwriters now ask whether EDR is deployed across your environment. So do defense customers subject to CMMC requirements. A blanket “no” on production endpoints raises questions. A qualified “yes, with specific architecture and exclusions” is a defensible answer.
Actual Risk Reduction
Attackers target production endpoints specifically. The historian has valuable operational data. The HMI is a control choke point. SCADA servers are crown jewels. Traditional signature-based antivirus does not detect modern attacker tooling reliably. Modern EDR does. Leaving production endpoints unprotected is leaving the most valuable systems in the least-defended state.
Operational Disruption Risk
Deploying EDR badly causes downtime. A production line stopped by a false-positive quarantine is not cheaper than ransomware response, and it erodes internal trust in the security program. Getting this right matters.
Long-Term Operations Burden
Poorly tuned EDR creates ongoing operational work: frequent false positives, exclusion management that grows unmanageable, performance complaints from operators. A well-designed deployment produces few alerts, none of them false, and does not impact operations.
What Good Looks Like
Successful EDR on the factory floor involves architectural choices, configuration tuning, and operational discipline.
Choose an EDR That Supports OT
Not all EDR products are equal on production endpoints. Products that explicitly support industrial environments, offer performance-tuned modes, and have documented exclusion patterns for common SCADA software are easier to deploy successfully. Examples include Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, and Trend Micro, among others. Evaluating OT support before purchase avoids late surprises.
Pilot on Representative Systems First
Deploy to a representative sample of each major production system type (HMI, historian, engineering workstation, SCADA server) and let it run in detection-only or monitoring mode for at least two weeks. This surfaces compatibility issues, performance effects, and false positive patterns before the full rollout.
Build a Tuned Exclusion Policy
Your SCADA vendors and historian vendors usually publish recommended EDR exclusions. Use them. Common exclusions include the SCADA runtime executables, real-time databases, communication drivers, and high-throughput log directories. Do not default to “exclude everything.” Tune to what each product actually needs.
Use Phased, Scheduled Rollout
Roll out during planned maintenance windows. Start with non-production systems (lab, test, staging). Move to production systems one line at a time or one area at a time. Keep rollback plans ready.
Separate Management for IT and OT
Manage EDR on production endpoints from a console that is visible to both IT security and plant operations. Alerts from production endpoints should reach plant operations quickly, not sit in a general IT security queue. The coordination between IT security and plant operations has to be explicit, not implicit.
Do Not Over-Block in the First Month
Run the EDR in detection-only mode on production endpoints initially. Review detections for patterns. Block only once you have confidence that blocking will not catch legitimate SCADA activity. Adjust quarantine behaviors to alert-and-review rather than auto-isolate for systems where isolation would stop production.
Plan for the Exception Cases
Some legacy systems cannot run modern EDR. Windows XP or early Windows 7 systems that cannot be upgraded, or equipment certified by the OEM to run only with specific software, are candidates for compensating controls: network isolation, application allowlisting, dedicated monitoring, and accelerated replacement plans.
Integrate With Incident Response
EDR generates telemetry that is useful for incident response. Make sure that telemetry reaches the IR team or managed security service. An EDR deployed but not actively monitored is a check-the-box implementation, not a security control.
Practical Takeaways
- Inventory your production endpoints. Count HMIs, SCADA servers, historians, engineering workstations, and other systems. Group them by OS, by software stack, and by criticality to production.
- Evaluate EDR products with OT fit in mind. Ask each vendor about their OT support, performance profile, and available exclusion playbooks. Request references from manufacturers using the product in production.
- Pilot before full rollout. A two-week pilot on representative systems saves months of rework that a blind rollout would require.
- Establish an OT exception and compensating-controls framework. Legacy systems that cannot run EDR need a documented alternative path, not just “we could not deploy it.”
- Link EDR telemetry to your incident response. The tool is only as valuable as the monitoring behind it.
Factory floor endpoint protection is not a check-the-box exercise. Done carelessly, it costs production. Done thoughtfully, it blocks the attack vectors manufacturers are actually being targeted through, without creating the operational problems people worry about.
If you want a conversation about designing and rolling out endpoint protection across your production environment, the HVR Cloud team supports manufacturers through exactly this kind of project. Get in touch and we can talk through what a rollout would look like for your plant.
