Enhancing Industrial Resilience: NIS2-Compliant Architectures Through Early Warning Systems for OT Monitoring
The NIS2 Directive strengthens governance and time-bound incident reporting obligations for cybersecurity in critical sectors, while Industrial Ethernet and IT/OT convergence expose deterministic shop-floor networks to broader threat propagation. This paper introduces an engineering approach to the application of the NIS2 Directive for reducing the detection latency at the OT level without excessively increasing the costs. The proposed architecture is based on an innovative complementary device, the Early Warning System (EWS), tailored for OT monitoring and designed for integration with enterprise monitoring (Security Information and Event Management—SIEM) and operational response (SOC/MDR—Security Operations Center/Managed Detection and Response). The EWS adopts a silent device paradigm: because the honeypot has no production role, any interaction becomes a high-confidence signal, minimizing false positives. The EWS is freely available open-source and, to fit heterogeneous plants, it offers two deployment modes, both with zero impact on network latency and timing: Full Mode combines passive monitoring via SPAN/port mirroring with a low-interaction honeypot, while Light Mode provides a pure decoy for resource-constrained edge hardware. The implementation is containerized (Docker) and forwards events to an external SIEM. Two validation steps are presented: the first, on a real PROFINET robotic cell using the Full-mode, demonstrates the zero false positives in normal operations, the detection of reconnaissance scans, baseline deviations, and ARP spoofing attempts; while the second, on three emulated industrial control systems using the ICS-NAD dataset, shows the effectiveness in realistic industrial applications.