November 30 marks International Computer Security Day, a perfect occasion to reflect on the critical role of security in industrial environments, especially at a time when data, digitalization, and automation form the backbone of any production plant.
Recent cases, such as the cyberattack on Asahi Group Holdings, which at the end of September 2025 paralyzed much of its operations in Japan, demonstrate that even global giants are not immune to digital threats.
In this context, cybersecurity in MES systems ceases to be an add-on and becomes a shared responsibility between providers and clients. Keeping these systems secure not only protects information but also ensures operational continuity and the competitive advantage of companies.
In this interview with Àngel Cabezudo, Product Director at Mapex, we explore how we tackle this challenge from within, ensuring software that is secure, robust, and prepared for any threat.
Interview with Àngel Cabezudo, Product Director at Mapex
Why is it so important to talk about security in MES systems right now?
Security is essential because MES manages critical production information and operates at the heart of the plant. Our clients know this, which is why cybersecurity is also an absolute priority for us.
Protecting data, ensuring operational continuity, and maintaining controlled access are fundamental in any industrial environment.
What type of critical information are we talking about?
An MES handles various types of critical information.
On one hand, there is static information, such as recipes, formulas, process parameters, or technical documentation, which can remain valuable for decades. If this information is leaked or tampered with, the impact on intellectual property is enormous.
On the other hand, there is real-time information: production metrics, quality data, traceability, or maintenance. These data reflect the actual performance of a plant and provide a direct view of its competitive capacity.
Additionally, there is financial information, client and supplier data, credentials, and system configurations which, if compromised, could allow unauthorized access or even manipulation of production processes.
How is security integrated into product development at Mapex to prevent these breaches?
Our approach is based on security-by-design: security is part of our MES architecture from day one.
It is not an add-on but a cross-cutting layer that influences how we design, deploy, and operate the system, both in on-premise and cloud environments.

What differences exist between on-premise and cloud environments? What cybersecurity measures do you apply in each deployment?
In local environments, we adapt to the client’s infrastructure and provide clear guidelines so that the MES operates securely.
We work with clients to ensure Mapex complies with their industrial and corporate policies, including recommendations on network segmentation, access control, best maintenance practices, and integration with other systems.
In the cloud, we further strengthen security through automation and continuous monitoring. In these deployments, we implement data encryption in transit and at rest, managed backups, regular updates, and strict separation between environments to ensure a much higher level of protection and availability.
Could you give a couple of examples of basic requirements the Mapex MES platform incorporates to provide security to its clients?
At Mapex, we use MFA (multi-factor authentication) to reinforce identity security and LDAPS to securely integrate with clients’ corporate directories.
We also implement a structured role model that ensures each user accesses only the functions necessary for their work.
Additionally, we have monitoring and response processes that allow anomalies to be detected and addressed quickly. Our goal is to ensure service continuity, minimize risks, and support client teams in both prevention and incident management.
What role does client awareness play in preventing cybersecurity incidents?
Security is a joint effort. It is not just about tools or technology but about corporate culture.
Many incidents could be avoided by following basic practices: always maintaining the latest MES version, training employees, establishing clear access and operation policies, and having incident response protocols in place.
We provide technology, processes, and expertise; our clients provide knowledge of their operational environment. Working hand in hand is the best guarantee for maintaining a secure, stable, and future-ready MES environment.



