
Can a cyber incident ultimately activate an ignition source?
A process installation may be mechanically intact. The Ex equipment may be correctly selected. Hazardous-area classification may be current, and inspections may confirm that the installation remains in good technical condition.
Yet an essential part of the explosion-protection concept can change without any physical modification being made to the installation.
Modern process plants increasingly depend on instrumentation, control and protective functions to maintain conditions that are directly relevant to explosion safety.
Consider ventilation systems that control concentrations of flammable vapours. Inerting systems that maintain oxygen below a defined safe limit. Temperature and pressure monitoring that keeps a process within its permitted operating envelope. Level and flow measurements that prevent unintended releases. Interlocks that place equipment or processes in a safe state when predefined limits are exceeded.
Explosion protection therefore no longer consists solely of steel, cables, glands and certified Ex equipment.
Sensors, software, logic, communications and final control elements can form part of the safety chain.
This leads to an important question:
What happens when the integrity or availability of such a function is compromised digitally?
A cyber incident does not have to be an ignition source itself. It may instead influence the conditions under which an explosive atmosphere develops or under which an existing potential ignition source becomes effective.
A manipulated temperature signal may prevent a shutdown from being initiated. A changed setpoint may move a process beyond its validated operating conditions. Loss of ventilation can affect the dilution of flammable vapours. Failure or manipulation of an inerting function can alter the oxygen concentration. A disabled alarm or trip can allow an abnormal condition to persist.
The sequence may therefore become:
cyber disturbance → loss or degradation of a safety function → changed process conditions → changed explosion risk.
For installations within the European Union, Directive 1999/92/EC requires employers to prevent the formation of explosive atmospheres where possible, avoid their ignition and mitigate the consequences of an explosion. These measures must be reviewed regularly and whenever significant changes occur. The Explosion Protection Document must be maintained accordingly.
The implication is important. If ventilation, inerting, shutdown logic or another instrumented function forms part of the explosion-risk reduction strategy, the integrity of that function becomes relevant to the continuing validity of the explosion-protection concept.
In Great Britain, the same management question arises under the Dangerous Substances and Explosive Atmospheres Regulations 2002 — DSEAR. DSEAR requires employers to assess risks from dangerous substances that can give rise to fire and explosion and to eliminate or reduce those risks so far as is reasonably practicable. HSE explicitly identifies DSEAR as the primary legislation for controlling workplace risks from dangerous substances capable of causing fires and explosions.
The result is that cybersecurity cannot automatically be treated as an isolated IT discipline when digital systems support explosion-risk controls.
A change to PLC logic, firmware, remote access, network architecture, alarm handling or a safety-related setpoint may be more than an automation change. Where that change affects a control measure relied upon for explosion safety, its consequence should also be considered within risk assessment and Management of Change.
The question is therefore no longer simply:
Is the protective function installed?
The stronger question is:
Can the organisation demonstrate throughout the installation lifecycle that the function on which explosion safety depends remains available, reliable and protected against unintended or unauthorised change?
This is where explosion protection, functional safety, OT cybersecurity, maintenance and asset management begin to converge.
For management, that convergence is significant. Cybersecurity is not exclusively an IT responsibility when cyber integrity supports physical risk controls. Equally, explosion safety cannot remain isolated within the ATEX discipline when its protective functions depend on automation and digital infrastructure.
The resilience of a modern Ex installation is determined not only by equipment designed to prevent ignition, but also by the integrity of the systems that keep the process within the conditions on which explosion protection depends.
Sources: Directive 1999/92/EC; Dangerous Substances and Explosive Atmospheres Regulations 2002 (DSEAR); HSE guidance on DSEAR and explosive atmospheres; IEC 60079 series.