Cybersecurity: Galdi’s strategy for complying with new EU regulations
A structured programme combining technology assessment, risk analysis and ongoing training
In today’s industrial scenario, cybersecurity has become a cornerstone of data protection while ensuring smooth operation of machinery and operator safety.
Galdi has embarked on a strategic process of adapting to new EU regulatory frameworks aimed at ensuring progressive compliance with existing and forthcoming regulations, bearing in mind the evolution and gradual transposition of relevant technical standards.
The new European regulatory landscape
The evolving legislative framework sets out strict standards on businesses, machinery and digital products.
Galdi is actively involved in monitoring and applying the following directives:
- NIS 2 (Network and Information Security Directive): This EU directive is aimed at significantly strengthening business cybersecurity. It requires the implementation of structured stringent measures for managing cyber risks and for reporting cybersecurity incidents in order to protect critical infrastructures, smooth operational flow and in-house IT systems. Galdi aims to achieve full compliance by October 2026.
- The New Machinery Regulation: Applicable from January 2027, it explicitly introduces the principle of ‘safety by design’ while requiring machinery to be designed in such a way that even anomalous events, including cyber-attacks or software malfunctions, cannot affect the safety of operators and other workers in close proximity to machinery.
- CRA (Cyber Resilience Act): This EU regulation introduces cybersecurity requirements covering the entire lifecycle of products containing digital components by applying the principles of ‘secure by design’ and ‘secure by default’, including secure development, attack surface reduction and maintainability. Reporting requirements will apply from September 2026, whereas full compliance is required from December 2027.
Security Level Methodology and Management
As a manufacturer of food packaging machines and lines, Galdi has launched a comprehensive cyber risk assessment process based on the international standards IEC 62443.
These standards set out different levels of protection, known as Security Levels (SL), ranging from 0 to 4 based on the ability of the system to withstand threats of increasing complexity and intent.
Galdi’s approach focuses on a detailed analysis of attack vectors. The company is currently working on establishing and implementing the most appropriate Security Levels relating to two critical scenarios:
- Close proximity access: Protection against attacks or tampering that might occur through direct physical access by operators or direct physical digital connection to machinery.
- Remote access: Strengthening resilience against all external threats to machinery via the network ingress and the data infrastructures of systems.
The goal is to fine-tune technological security measures so that each critical issue identified during risk assessment receives security protection consistent with actual operational needs and the requirements of international standards.
Corporate synergy and security culture
This Cybersecurity project is now being implemented throughout the entire company. With the support of the Automation, Machine Intelligence, IT and Product Certification teams, their respective areas of expertise are made available in an integrated and cross-disciplinary approach.
Furthermore, Galdi also believes that cybersecurity management must be backed by a strong corporate culture. Consequently, the company has rolled out internal cybersecurity training programmes for all its staff, including initiatives to raise awareness of the risks associated with phishing and data management.
Collaborating with the Supply Chain
Galdi is also committed to working closely with partners and suppliers to ensure that automation components and integrated IoT systems meet the same reliability criteria required by standards.
This coordinated effort aims to provide solutions designed in compliance with intrinsic security principles, thus ensuring that clients are equipped with machinery ready to face the digital challenges of the future.