In regulated production, validation is a strength. Anyone who has worked to GAMP 5 and EU GMP Annex 11 for years masters requirements specifications, risk assessment, test cases, traceability and change control. That discipline is rare. But it invites a fallacy: what is validated is assumed to be secure.
Intended use versus misuse
Validation answers the question of whether a system reliably does what it is intended to do in its environment. What gets tested is the intended flow: inputs, permissions, data integrity, audit trail, backup.
Attackers do not stick to the intended sequence. They exploit an unpatched vulnerability, a technical login several people share, or remote maintenance access left open for years. Nothing of this kind is in a test plan, because it is not part of intended use.
An MES can therefore be fully validated and still be vulnerable. Both are true at the same time.
What GxP rules do not require
Information security sets requirements that classic GxP rules do not cover, or only at the margin:
- Attack detection. GxP requires logging, but not continuous detection of attacks in the production network.
- Short reporting deadlines. Anyone covered by NIS2 has to report significant security incidents to the authorities within short deadlines. GMP has nothing at that pace.
- Supply chain security. Quality agreements govern data integrity, rarely how suppliers report incidents or vulnerabilities.
- Patching on a fixed cycle. GxP knows change control as an approval process, but no commitment on how quickly a security update is applied.
- Strong authentication. Multi-factor authentication is still the exception in many validated systems.
- Responsibility of management. GxP anchors responsibility in the quality organisation. Information security also anchors it explicitly with management.
The conflict in daily work
The gap is most visible with changes. Information security wants to apply a critical patch today. Quality assurance requires an assessment first and possibly revalidation. Both are right, and as long as there are two separate approval routes, standstill usually wins: the patch waits, the risk remains.
It is similar in production engineering. Network segmentation and monitoring are often seen there as a risk to availability. Yet they protect precisely the plants whose failure would cost the most.
What follows
The good news: anyone who can validate already has the tools. Change control, risk assessment and documentation are more mature in regulated production than in most IT departments. What is missing is not the method but the connection.
Three steps close the gap:
- One shared change process with a security category and a GxP category. Security-relevant changes get a defined, fast route without undermining validation.
- Security in the requirements. Security requirements belong in the URS and the risk assessment, not in a separate document that nobody connects to the system.
- A look at the interface between IT and production engineering. That is where, in my experience, the biggest open doors are.
GxP maturity is an excellent foundation for information security. It does not replace it automatically.