Cyber Security for COMAH sites

Expert support for COMAH sites: navigating HSE OG86 compliance, integrating cyber security with safety risk management, and securing industrial control systems across complex operational environments.

Protecting Critical Operations, Ensuring Compliance

COMAH sites face unprecedented cyber security challenges as industrial control systems become increasingly connected. A successful cyber attack could compromise production, trigger safety incidents, or result in unlimited fines with personal liability for directors.

Arcanum brings proven expertise in securing these complex environments and achieving HSE OG86 compliance.

Want to understand your risk? Request a COMAH-specific assessment.

 

Why OT Cyber Security is Uniquely Challenging

Unlike standard IT environments, operational technology in COMAH sites presents fundamental barriers to conventional cyber security approaches:

Cyber Essentials Plus - #1

Safety Integration

Cyber security measures must work alongside safety instrumented systems without creating new hazards or compromising operational safety.

Cyber Essentials Plus - #2

Legacy Infrastructure

Most OT systems span decades of organic growth with incomplete documentation, unknown connections, and critical knowledge held only by long-serving engineers.

#5

24/7 Operations

Industrial control systems cannot be taken offline for updates or patches, making standard security maintenance procedures impractical or impossible.

#4

Skills Gap

Securing industrial automation requires combined expertise in OT operations, cyber security, and safety risk management—a combination that takes years to develop and is rarely available internally.

#5

Regulatory Complexity

Organisations must navigate HSE OG86 alongside existing safety risk assessment processes (HAZOP studies, LOPA analyses) and potentially NIS Regulations, creating risk of conflicting requirements and duplicate assessments.

Read more about the challenges of cyber security for senior managers with responsibility for control of major accident hazards (COMAH).

COMAH Cyber Security over Image

22nd September 2025

The cyber security and compliance challenges for operators of COMAH sites

How Arcanum Helps

Arcanum brings deep expertise in COMAH cyber security, helping operators achieve compliance and protect critical operations:

Cyber Essentials Plus - #1

OT Risk Management

We identify and assess cyber risks across industrial control systems, aligning security strategy with your operational requirements and safety frameworks.

2

Asset Discovery and Network Architecture

Complete visibility into industrial control systems across single or multiple sitesthe foundation for effective risk management and incident response. 

3

HSE OG86 Compliance

Our consultants ensure readiness for HSE inspections by mapping OG86 requirements to your existing safety processes and other regulatory requirements. 

4

Cyber Security Management System

Strategic CSMS implementation based on ISA/IEC 62443 standards, integrated with your existing safety management systems. 

5

Penetration Testing and Assessments

Vulnerability testing tailored to the most sensitive industrial environments, uncovering threats without compromising safe, continuous production.

6

Incident Response Planning

OT-specific response procedures that balance cyber security with operational safety and regulatory compliance requirements.

Clients we serve

Arcanum is trusted to provide cyber security expertise at the highest level by clients including the UK government, the nuclear power industry, major manufacturers and other industrial and commercial organisations.

Cybersecurity governance for the Space industry

Download our 3-piece blog which covers the vital role of cybersecurity governance in the commercial Space industry.

    Here’s your download

    Expertise you can trust

    As a NCSC Assured Service Provider, Arcanum delivers cyber consultancy that meets the highest national security standards. Our Operational Technology (OT) specialists have worked extensively in rail, aviation, energy, defence, and other safety-critical sectors.

    We provide strategic insight and technical depth to help you secure, future-ready COMAH sites.

    ISA Cybersecurity Expert 62443
    GICSP e1711538780629
    Consultancy Risk Management
    NCSC Consultancy Risk Management. Penetration Testing Company UK
    NCSC Consultancy Audit and Review
    Screenshot 2025 06 17 at 12.15.27
    Consultancy Risk Management
    NCSC CHECK Penetration Testing
    Industrial plant with extensive pipework and storage tanks, representing operational technology infrastructure at a COMAH site.

    FAQs

    What is COMAH and why does cyber security matter for COMAH sites?

    COMAH (Control of Major Accident Hazards) regulations are designed to protect people and the environment from catastrophic incidents such as chemical spills, explosions, or major disruptions. Increasingly, the risk of these events is tied to cyber security. Modern COMAH sites rely on operational technology (OT) and industrial control systems, which are vulnerable to cyber attack. A successful intrusion could disable safety systems, disrupt production, or cause uncontrolled processes. For this reason, the HSE now treats cyber security as a core part of COMAH compliance.

    What are the HSE cyber security requirements for COMAH sites?

    The HSE requires COMAH operators to demonstrate that their exposure to cyber risk is “as low as reasonably practicable”. Inspectors expect to see a structured approach to cyber risk management, clear documentation of decision-making, and evidence that senior leaders understand and act on these risks. The benchmark guidance is OG86 – Cyber Security for Industrial Automation and Control Systems, which aligns with the NCSC’s Cyber Assessment Framework and the ISA/IEC 62443 series of standards.

    What is OG86 and why is it important for COMAH operators?

    OG86 is the HSE’s operational guidance on cyber security for industrial automation and control systems. It sets the expectations for how COMAH operators should secure their OT environments. Achieving OG86 “basic” maturity is the minimum requirement, which means having a rational, systematic approach to cyber risk that can withstand scrutiny in an enforcement situation. For COMAH operators, OG86 compliance is not optional — it is the standard inspectors will measure you against.

    How does IEC 62443 apply to COMAH site cyber security?

    IEC 62443 is the international standard for industrial cyber security, and it forms part of the foundation for OG86. While you are not legally required to use IEC 62443 specifically, demonstrating alignment with its security levels can provide strong evidence of compliance with HSE requirements. Many COMAH operators map OG86 against IEC 62443 controls to ensure consistency across safety, IT, and OT risk management frameworks.

    What does “as low as reasonably practicable” mean for COMAH cyber risk?

    The phrase means you must show that cyber risks have been reduced as far as is reasonably possible, taking into account cost, effort, and technical feasibility. For COMAH operators, this doesn’t mean eliminating all cyber risk — but it does mean you must be able to justify your decisions. If you reject certain security measures, inspectors will expect documented evidence of your reasoning and proof that alternatives are in place.

    What are the penalties for failing to meet COMAH cyber security requirements?

    Non-compliance carries severe consequences. The HSE has the authority to issue prohibition notices that can suspend or shut down operations entirely. Courts can impose unlimited fines, and in some cases senior executives may be held personally liable. Beyond the legal consequences, enforcement action can damage reputation, interrupt supply chains, and create significant financial losses.

    Why can’t IT security tools be applied directly to OT systems?

    IT networks are designed for agility, frequent updates, and resilience to downtime. OT environments are the opposite — they are engineered for continuity, uptime, and physical safety. Tools such as automated patching, intrusive scanning, or real-time detection can destabilise control systems, trigger false alarms, or even compromise safety-critical processes. Cyber security for COMAH sites requires approaches tailored to OT, not the direct application of IT practices..

    How should COMAH operators prepare for a cyber security inspection?

    Preparation should begin with a clear understanding of your OT assets, network architecture, and risk exposure. You should be able to explain your approach to risk management, show how it integrates with existing safety and compliance processes, and provide evidence of informed decision-making. Inspectors will look at both the condition of your systems and the logic behind your decisions. Having external specialists validate your approach can provide confidence before an inspection.

    What are the biggest cyber threats facing COMAH sites today?

    COMAH sites face threats from ransomware, supply chain compromises, and targeted attacks on industrial control systems. Real-world incidents include hackers manipulating water treatment dosing, disrupting petroleum pipelines, and holding manufacturing operations to ransom. The convergence of IT and OT — for example through cloud analytics, IIoT, or remote vendor access — has opened new pathways for attackers. This evolving threat landscape makes it essential for COMAH operators to go beyond traditional network isolation strategies and adopt proactive OT-specific cyber security.

    Partner with Arcanum to secure your systems

    Whatever your cyber security challenge, we can provide advice and expertise to help you achieve regulatory compliance and avoid serious cyber incidents. Please complete the contact form below or contact us: