
atvise® Security Check
8 weeks, 8 measures
Secure systems are not built on a single feature but through many small decisions made during commissioning and operation. Each week one of these decisions will be highlighted.
Why this Series?
Security in automation is usually discussed as a broad topic – architecture, network segmentation, and zoning concepts. In practice, however, it is often much smaller details that determine how resilient a system really is: whether an account has a password, whether a port is open, or whether a certificate was renewed on time. atvise® already covers all these topics, providing the foundation for implementing security requirements in projects.
These points are included in the security white paper. However they are grouped together across numerous pages – and based on experience they are more likely to be needed during commissioning. Therefore the series presents them individually: one topic per week, each accompanied by a specific action step.
In addition the EU Cyber Resilience Act will place cybersecurity requirements for digital products under much clearer scrutiny in the coming months – for manufacturers as well as for operators and integrators. Several parts of this series are therefore explicitly dedicated to this question: what the CRA requires, which responsibilities each party bears, and how vulnerabilities and security updates are handled.
What this series will cover
The series follows the path an attacker would take:
- Access and Identity – Engineering Access, User Accounts, Password Policy, and Two-Factor Authentication
- Cyber Resilience Act – deadlines, division of responsibilities, handling vulnerabilities and patches
- Encryption – HTTPS in visualization, certificates, and secure OPC UA connections all the way to the data source
- Network and Storage – Ports, Cross-Origin Resource Sharing, directories, and database encryption
- Operations – License servers, backup and restore, behavior in the event of a power outage, personal data
Each section is self-contained. You must start with the relevant section and read the remaining sections later.
Schedule and Conclusion:
Preview of Measure 1:
Strong passwords need clear rules
Part 1 shows how the atvise® password policy enforces secure access by defining requirements for minimum length, password complexity, validity period, as well as account lockout and delays after failed login attempts. It also covers securing the predefined root user with a password before commissioning and deliberately disabling its visualization login.

