A best practice is a method or technique that has consistently shown results superior to those achieved with other means, and that is used as a benchmark. ARC has conducted numerous best practice surveys over the past thirty years and has developed best practices for a large number of topics of interest to industry executives.

Jul
31
2025

Collaborative IT/OT Cybersecurity Strategies

Collaborative IT/OT cybersecurity can help industrial companies address major OT cybersecurity challenges like lack of resources, ransomware, sophisticated attacks, and the security risks in new digital transformation efforts. This report discusses recent ARC research around the adoption of collaborative IT/OT cybersecurity and the strategies companies are using to implement these programs.
Jul
24
2025
Larry O'Brien

Impact of EU NIS2 Cybersecurity Regulations on the Manufacturing Industries

The EU NIS2 Directive significantly enhances cybersecurity regulations for the manufacturing industry, expanding its scope to include both process and discrete sectors. This directive mandates comprehensive risk management, stringent incident reporting, and senior management accountability, aiming to elevate cybersecurity from a technical concern to a strategic imperative.
Jul
17
2025
Thomas Menze

Industrial Software: SaaS versus On-Premise

To support their operational excellence activities companies often rely on software, like business intelligence (BI) software, industrial data platforms or process analytics solutions. To implement and use this software over its lifecycle, end users can choose between two options.

Jul
17
2025
Thomas Menze and David Humphrey

Considerations for Converting Industrial Plants to Hydrogen Supply

Converting an industrial plant to a hydrogen supply involves several preliminary and practical considerations. An infrastructure assessment is crucial to evaluate the existing infrastructure and determine necessary upgrades or modifications to handle hydrogen safely.
Jul
17
2025
Larry O'Brien

The European Cyber Resilience Act (CRA): Impact and Roadmap for Automation Vendors

The European Cyber Resilience Act (CRA) introduces stringent new cybersecurity requirements for vendors of digital products in the automation industry, compelling a shift in compliance strategies. This regulation mandates risk management, vulnerability reporting, and CE marking, aiming to harmonize security standards across the EU and ensure products are secure by design and default.
Jul
03
2025
Thomas Menze

Champions Radar: European Industrial Cybersecurity Services

The European industrial cybersecurity threat landscape is becoming increasingly dangerous, with a rise in cyber-attacks on industrial plants and critical infrastructure. Consequently, a new market for industrial cybersecurity services is emerging, offering a range of services from implementation to post-attack recovery, including specialized applications for anomaly detection and compliance verification.
Jul
03
2025
Luciano Narcisi

Schneider Electric Highlights at the ARC European Industry Forum

This report highlights Schneider Electric’s insights at the ARC European Industry Forum 2025, on energy transition, AI, and digital transformation. These are essential for industry leaders seeking sustainable, innovative solutions in today’s rapidly evolving industrial landscape.
Jun
26
2025
Fabian Wanke and David Humphrey

AI with Purpose Summit 2025: Siemens’ Vision for Industrial-grade AI

The Siemens AI with Purpose Summit 2025 was filled with insightful speeches, panel discussions, and networking opportunities. The author shared his thoughts, “Days after the AI Summit, I’m full of insight, inspiration, and motivation to further explore what's coming to industrial-grade AI.”
Jun
12
2025
Craig Resnick

IT/OT Convergence in an AI World

IT/OT convergence is essential for improving business performance and achieving operational resilience, but it requires collaboration to bridge the gap between legacy OT systems and modern IT solutions while addressing challenges like differing system lifecycles and cybersecurity priorities.