
The recent Heathrow disruption offered a warning for every highly connected industry: a cyberattack does not have to take control of the most critical machinery to disrupt an entire operation. The attack targeted Collins Aerospace's MUSE software, which supports functions including electronic check-in and boarding. Heathrow confirmed it was among the affected airports. The disruption forced affected operations towards manual processes and contributed to flight delays and cancellations.
For mining, where autonomous fleets, intelligent equipment, remote operating centres and digital production systems are becoming increasingly interconnected, the question is no longer whether cybersecurity matters. It is whether the industry is treating cybersecurity as a shared operational responsibility.
That question is becoming increasingly important as mining companies depend on a growing ecosystem of original equipment manufacturers (OEMs), software providers, communications networks, cloud platforms, systems integrators and specialist technology companies. Sandvik's latest cybersecurity milestone provides a useful example.
The mining equipment manufacturer is among the first to achieve IEC 62443-4-1 Maturity Level 3 (ML3) certification for its secure product development lifecycle, independently validating that cybersecurity practices are systematically embedded in the development and maintenance of its mining technologies. The certification advances Sandvik Mining from Maturity Level 2 (ML2), achieved in 2025.
While ML2 demonstrated that Sandvik had established and managed defined secure-development processes, ML3 validates that those processes are systematically applied in day-to-day product development. For customers deploying increasingly connected mining equipment, that distinction matters. The security of a production-critical machine is no longer an isolated product issue. It can become part of the operational resilience of an entire mine.
Mining's digital transformation is changing the traditional boundaries between equipment, people and infrastructure.
An autonomous haul truck can depend on communications networks, positioning technology, control software and fleet-management platforms. A remotely operated drilling system can connect field equipment with a control centre. Processing plants increasingly depend on industrial control systems, sensors and data networks. The resulting architecture can deliver significant productivity and safety benefits. But it also creates dependencies.
A failure or cyber incident affecting one part of the system can potentially have consequences elsewhere. Consider an open pit mine operating a connected autonomous haulage fleet. A cyberattack would not necessarily have to involve an attacker taking direct control of a truck.
A disruption to communications, manipulation of equipment-status information or loss of access to fleet-management systems could potentially be enough to force operators to suspend autonomous operations while systems are investigated. The immediate consequence could be trucks standing idle. The secondary effects could extend to stockpiles, crushers, processing plants, rail loading and ultimately shipments. The same principle applies to other parts of the mining value chain.
A disruption to a drilling system could affect production scheduling. An attack on a processing plant's industrial-control environment could interrupt ore treatment. A compromised maintenance or equipment-monitoring system could reduce visibility of machine condition.
These are hypothetical scenarios, not claims that such attacks have occurred on Sandvik equipment. But industrial-control vulnerabilities documented by cybersecurity authorities demonstrate that operational technology can present consequences beyond the loss of conventional IT services.
The aviation industry provides a useful illustration of the problem. Earlier this month, a cyberattack targeting Collins Aerospace's check-in and boarding systems disrupted operations at several European airports, including London's Heathrow, Berlin Brandenburg and Brussels. The attack did not compromise aircraft flight systems.
Instead, it affected technology used for passenger processing and boarding. Yet the operational consequences were significant. Airports experienced delays, cancellations and long passenger queues, while airlines and airport operators had to use manual processes to keep operations moving. At Brussels Airport, 50 of 257 scheduled flights were cancelled on one Monday as the disruption continued.
The lesson for mining is not that airport systems and mining control systems are equivalent. It is that operational resilience depends on the resilience of the technology ecosystem around the core operation. A mine does not need its physical machinery to be taken over for a cyber incident to become a production problem. If a critical digital service becomes unavailable, the resulting disruption can still affect people, equipment, logistics and output. For an industry increasingly built around connected technology, that is an important distinction.
Sandvik's ML3 certification addresses the security of the technology before it reaches the mine. The assessment was supported by evidence from Sandvik Intelligent Control Architecture (SICA), the company's common control-system platform used across its i-series mining equipment.
The scope of the certification covers the Sandvik Mining Secure Development Lifecycle practised by SICA. IEC 62443 is an internationally recognised standard for cybersecurity in industrial automation and control systems.
At ML3, cybersecurity practices are systematically applied throughout the product lifecycle, from requirements and architecture through development and testing to maintenance and vulnerability management. For a mining customer, that means cybersecurity is not simply considered once equipment has been deployed. It becomes part of the process by which the technology is designed, developed, tested and maintained.
“Cybersecurity is increasingly inseparable from automation and digitalisation in mining,” said Riku Pulli, President, Digital Mining Technologies at Sandvik Mining. “As customers entrust more production-critical processes to connected and autonomous technologies, they need confidence that security is built in from the beginning and maintained throughout the product lifecycle.”
That lifecycle approach becomes increasingly important as equipment remains connected for years rather than simply being installed and left to operate independently.
The implications extend beyond Sandvik. Mining companies increasingly purchase technology ecosystems rather than individual machines. An autonomous mining operation may involve an equipment manufacturer, telecommunications provider, software developer, systems integrator, cloud platform and cybersecurity provider — all working alongside the mine's own IT and operational-technology teams. That creates a question that procurement teams will increasingly have to confront:
The answer cannot simply be the mining company's IT department. Nor can it be left entirely to an OEM. Cybersecurity must be addressed across the relationship.
That could mean mining companies asking technology partners:
These questions are increasingly as important to operational resilience as equipment availability, maintenance support and spare-parts supply.
The shift towards autonomy makes the issue particularly relevant. Automation is frequently presented to improve safety by removing people from hazardous environments. That potential remains significant. But when more production decisions and equipment movements depend on digital systems, the consequences of a technology failure can also become larger.
Imagine a mine where autonomous trucks, drills and loading equipment operate as an integrated fleet. If communications fail, the mine may have to transition from autonomous to manual processes. If a critical control platform becomes unavailable, production may have to stop. If equipment data is corrupted, operators may have to establish whether the information can still be trusted. Cybersecurity therefore becomes closely connected to safety, production continuity and business continuity.
The objective is not simply to prevent someone from accessing a system. It is to ensure that the mine can continue to operate safely and recover quickly when something goes wrong.
This also introduces a broader supply-chain issue. Mining companies have traditionally assessed suppliers around factors such as:
cost → productivity → reliability → safety → maintenance → availability
Cybersecurity increasingly needs to become part of that equation.
A highly productive piece of connected equipment that introduces an unmanaged cyber risk may create a different type of operational exposure. Equally, cybersecurity requirements need to be practical. Mining operations cannot simply patch production systems in the same way that an office computer can be updated. Updates must be tested, scheduled and deployed without compromising safety or production. That requires cooperation between the OEM and the mine. It is therefore a partnership that continues long after the equipment is purchased.
Sandvik's ML3 certification follows its ISO/IEC 27001 certification in May 2026 for its information security management system supporting global application delivery. The two certifications address complementary elements of Sandvik Mining's cybersecurity approach. IEC 62443-4-1 ML3 focuses on secure product development, while ISO/IEC 27001 addresses information-security management supporting digital application delivery. Together, they reflect the widening scope of cybersecurity as mining becomes more digitally dependent.
“Moving from ML2 to ML3 is about more than having the right cybersecurity processes documented,” said Jere Paavola, Product Development Manager, Control Systems at Sandvik Mining. “It independently demonstrates that we are practising them systematically in our everyday product development.”
For customers, he said, this provides greater assurance that cybersecurity is considered throughout the lifecycle of the technologies on which they depend.
The distinction between cybersecurity and cyber resilience is becoming increasingly important for mining. Security is about preventing and detecting attacks. Resilience is about ensuring the operation can continue safely and recover when prevention fails. That means asking not only:
"How do we stop an attack?"
but also:
These questions need to be answered before an incident occurs.
For Mining Indaba, this is where cybersecurity becomes part of the wider “Stronger Together: Partnerships in Practice” conversation. The digital mine is not being built by one company. It is being built through partnerships between miners, OEMs, technology companies, telecommunications providers, software developers, cybersecurity specialists and infrastructure providers. The same principle needs to apply to securing it.
Sandvik's move to IEC 62443-4-1 ML3 demonstrates how one OEM is strengthening cybersecurity within its own product-development lifecycle. But no certification can secure an entire mine on its own. The mine operator must secure its networks. Technology partners must manage their own systems. Suppliers must understand their dependencies. Operators must establish incident-response procedures. And all parties need to understand where responsibility begins and ends.
As mining becomes more automated, trust between technology partners will become an increasingly important component of operational resilience. The future mine will be autonomous, connected and highly intelligent. But its ability to remain productive when something goes wrong will depend on something much more human:
How effectively the organisations building that mine work together?

In this exclusive conversation with Ben Magara, CEO of Exxaro Resources, our Product Director, Laura Nicholson, discusses Exxaro’s growth and diversification into manganese and renewable energy.

Without intentional strategies to include smaller players, the benefits of innovation will continue to bypass much of the sector. The time to ensure no one is excluded from Africa’s mining technology revolution is now.
.webp?language=en)
An interview with Christophe Melkonian, Co-President of Aramine By Natallia Zhuk-Higgs, Key Account Director at Mining Indaba