Cyber-physical systems are systems in which computers, networks and software sense and control physical equipment and processes. They include industrial control systems (ICS) that run production lines, building management systems, connected medical devices, power and water equipment, robots and vehicles. Because these systems act in the physical world, a cyberattack or failure can stop operations, damage equipment or put people at risk. The term is used in research and by analysts and some security vendors as an umbrella for operational technology, connected devices and similar equipment.
At a glance
- Cyber-physical systems combine computing and networking with sensors and actuators that affect the physical world.
- The term spans industrial, building, healthcare, energy and transportation systems.
- It overlaps heavily with operational technology (OT) and the industrial side of the Internet of Things (IoT).
- Safety and availability usually come first, which shapes how these systems are patched, monitored and secured.
- Security approaches commonly focus on asset inventory, network separation, passive monitoring and controlled remote access.
What problem it solves
As a concept, cyber-physical systems gives organizations one way to think about all the connected equipment that controls physical things, which is often spread across separate owners. A manufacturer has production controllers run by engineering, a building system run by facilities, and IoT sensors installed by a vendor. A hospital has medical devices managed by clinical engineering. Each was often bought and connected without IT security involvement, and many run old software that can’t be patched easily.
These systems are increasingly connected to business networks, cloud services and remote vendors, which brings efficiency and new risk. Ransomware that starts on an office laptop can spread to, or force the shutdown of, the systems that keep a plant or building running. Treating them together as cyber-physical systems helps organizations build one inventory, one set of network rules and one incident plan, instead of leaving gaps between teams.
How it works
Sensing and control. Sensors measure temperature, pressure, position, flow or patient data; controllers decide what to do; actuators such as motors, valves and pumps make it happen. This loop often runs continuously and in real time.
Connectivity. Devices communicate over industrial, building and medical protocols, many designed without authentication or encryption, and increasingly over standard IP networks, wireless and cellular links to the cloud.
Security approach. Common practices include discovering and inventorying devices, often using passive monitoring that watches traffic without disturbing equipment; separating these systems from office networks through network segmentation and firewalls; controlling and recording vendor remote access; and monitoring for unusual behavior. Patching and changes are coordinated with equipment owners and manufacturers because of safety and certification concerns.
Device-level protection. Where devices can’t be patched or run security software, compensating controls such as network restrictions and monitoring do more of the work. IoT security practices apply to many connected sensors and devices.
When it matters for buyers
- When operations depend on connected equipment. Manufacturing, logistics, healthcare, utilities and large facilities all fit. Network separation with network firewalls, OT-aware monitoring through intrusion detection and a security operations center that understands these environments are common building blocks.
- When connecting equipment to the cloud or IT systems. Data projects create new paths into control networks.
- When customers, insurers or regulators ask. Questions about OT, medical device and building system security are increasingly common; requirements vary by sector and country.
- After an acquisition. Inherited sites often bring unknown equipment and flat networks.
- When consolidating security tools. Some platforms cover IT, OT, IoT and medical devices together; others specialize.
Questions to ask vendors
- Which device types, protocols and manufacturers in our environment can you discover and monitor?
- Is your monitoring passive, and what could cause it to disrupt equipment?
- How do you handle devices that can’t be patched or run agents?
- How do you control and record remote access by equipment vendors?
- Does your security operations team have experience with industrial, building or medical environments?
- Which frameworks do you align with, such as ISA/IEC 62443 for industrial systems?
- How do you coordinate changes with our operations and safety teams?
How it differs from OT security and IoT
OT security is the established discipline for protecting operational technology, especially industrial and building control systems. Internet of Things (IoT) refers to connected devices in general, many of which, such as cameras or office sensors, don’t control physical processes. Cyber-physical systems is an umbrella term that cuts across both, covering any system where computing directly controls the physical world, including medical devices and vehicles. In practice, buyers will mostly see products sold as OT security, IoT security or medical device security, and should compare them on which device types and environments they actually cover.
