AMSJ » Stricter requirements: Safety expertise in the digital age
Automation EMERGING ISSUES IN MINING SAFETY Programmable Systems

Stricter requirements: Safety expertise in the digital age

functional safety requirements are changing. Cybersecurity of plant is fundamental
Functional safety requirements are changing and ensuring competence of those who access and control software must also change

By now, most have realized that industry 4.0 is not just hype that will disappear by itself. Fundamental functional safety processes will change, if they haven’t already, especially in automation technology. For plant manufacturers and operators, this also means that legal requirements will become stricter.

When I started my first project as a safety engineer ten years ago, the situation was very different. IEC standards were still quite new and not effectively implemented, and no one was talking about cybersecurity.

Requirements have become much greater

Since then, the scope of functional safety has become considerably greater and the innovation cycle significantly shorter. Demonstrating safety has become a much more complex undertaking, involving many different tasks.

Take for instance the development of software for plant control. In the past, people simply developed what was needed for functional safety. Today that is unthinkable.

First of all, comprehensive specifications must be drawn up. What functions are needed? How should these be implemented? How will they be tested? What dependencies could occur with other systems and plants? What risks can you expect, and what can be done to minimise them? These are all considerations that must be answered in advance.

Plants that must adhere to the Seveso III Directive or emissions regulations will need to provide inspection organisations with the answers to these questions.

But even in cases where the plant manufacturer or operator is not yet obliged to comply with applicable standards, they should still do so. In the event of an incident, a state prosecutor will quickly become involved. Any company that has not worked in accordance to standards will have a problem.


A reverse onus clause applies and the operator must prove that they are not responsible for the accident. Honestly speaking, would you be able to prove that you were not responsible in such a situation?

A single action is not enough when it comes to functional safety

So how can you face these heightened demands? First of all, you need to examine these three areas more closely:

  1. Technology: To gain certification, newly developed safety controllers must ensure safety by design and fulfil requirements that are much stricter than in the past. Cybersecurity will play an increasing role in this, which we will explore later in this article.
  2. Organisation: Do your existing processes fit the changing safety situation? Is your risk management measured sufficiently? There is no answer to these questions that will apply across the board – they require detailed analysis.
  3. Qualification: Do you have sufficient up-to-date safety expertise or are you able to access it from external sources? Even if this is this case, it is important to ensure knowledge is regularly refreshed and shared, for example in certified training courses.

One-off actions are not enough, especially with regard to organisation and qualification. At the latest, plants and processes that are subject to Seveso III must be subjected to risk analysis and assessment every five years. With this, you can also see whether new risks have emerged or document any unnecessarily hazardous operations.

In times of increased cyber attacks, it is likely that this time period will shorten in the future. Hackers are using ever more sophisticated methods in order to gain access to systems. Since the TRISIS/TRITON attack at the end of 2017, the industry can no longer ignore the issue.

Two options for better plant safety

There are two ways to address the changing safety market. It is possible for you to establish the necessary competencies yourself. There are training courses on offer for individual safety engineers as well as whole teams. You will, of course, require the staff resources for this. This path can be difficult to plan, especially in view of the worsening labour market.

Another way is to outsource the three areas mentioned above. Your supplier for safety controllers must then ensure that any hardware you use meets all requirements and can be adapted to meet future standards.

They should also have the knowledge to advise you on creating a comprehensive safety concept and even develop it if required.

Engineers supplied by the external service provider must be guaranteed as certified, and the supplier should be able to prove this.

Cybersecurity requires experience – but it is rare

In light of the abovementioned cyberattacks, it is worth choosing a service provider that has gained expertise in cybersecurity over many years. Since the issue has been covered in all kinds of media, corresponding safety services are growing in presence all over.

It certainly makes sense to question whether they are backed up with sufficient experience in functional safety and cybersecurity.

Ivo Hanspach, Director of Product Management, HIMA

Read more Mining Safety News

Add Comment

Click here to post a comment

AMSJ April 2022