Ransomware-driven OT cybersecurity projects are moving from IT slide decks to plant-floor purchase orders in 2026. As manufacturers replace legacy PLC communication modules, HMIs, industrial PCs, managed switches, firewalls, and remote-access gateways, the upgrade itself can create a second problem: valuable automation surplus sitting undocumented in cages, cabinets, and maintenance storerooms.
Why OT Cybersecurity Refreshes Are Creating New Surplus
The cybersecurity trigger is now operational, not theoretical. In July 2026, the manufacturing and industrial sector is dealing with a sharper ransomware reality: NCC Group reported that industrials were the most targeted ransomware sector in Q2 2026, accounting for 30% of global attacks (NCC Group). Around the same period, Coca-Cola suspended U.S. Fairlife production after a ransomware incident, showing how cyber events can translate directly into production disruption, not just back-office inconvenience (Supply Chain Dive).
That pressure is accelerating controls refreshes. For plant managers and OT leaders, the question is no longer whether old network-connected assets are a cyber risk. The practical question is which assets must be segmented, patched, replaced, isolated, or removed from the architecture entirely. Projects that once looked like gradual modernization are now being pulled forward under ransomware response plans, insurer requirements, corporate standards, secure remote-access reviews, and IEC 62443 alignment.
The surplus appears in specific categories. Unlike a full line decommissioning, an OT cybersecurity refresh often removes equipment that still works mechanically and electronically. The surplus may include legacy HMI panels, industrial PCs, Ethernet communication cards, unmanaged switches, first-generation managed industrial switches, serial-to-Ethernet gateways, VPN appliances, cellular routers, remote-access boxes, DIN-rail firewalls, and PLC network modules. Some parts are removed because they lack secure firmware support. Others are removed because a new plant standard requires consistent logging, user authentication, segmentation, or hardened edge computing.
The inventory risk is misclassification. If these parts are treated as ordinary scrap or tossed into a mixed e-waste bin, the plant may lose resale value, warranty documentation, and traceability that buyers need. If they are left in storerooms without disposition, they become dead stock that consumes space while still carrying cybersecurity concerns if configuration data, IP addresses, or credentials remain on devices.
| Refresh driver | Typical equipment removed | Surplus risk if unmanaged | Recovery opportunity |
|---|---|---|---|
| Network segmentation | Managed switches, firewalls, VLAN-capable gateways | Duplicate assets with unclear firmware status | Consign documented industrial network gear |
| Secure remote-access replacement | VPN routers, cellular gateways, remote-access appliances | Stored devices may retain credentials or configs | Sanitize, document, and resell where supported |
| IEC 62443 standardization | Legacy HMIs, IPCs, PLC communication modules | Usable parts mislabeled as obsolete scrap | Match to buyers maintaining installed base |
| Edge security upgrades | Industrial PCs, protocol converters, embedded controllers | Data-bearing equipment handled inconsistently | Separate storage-media review from parts valuation |
📊 By the Numbers: When one sector accounts for 30% of global ransomware attacks, cybersecurity refresh surplus should be treated as a planned asset-recovery workstream, not an afterthought.
Build the Audit Around Cyber Risk and Resale Value
A normal MRO audit is not enough for OT cyber refresh surplus. Traditional storeroom cleanup focuses on whether the part is active, obsolete, duplicated, or slow-moving. For cybersecurity-driven removals, the audit must also capture whether the device stores configurations, credentials, network topology, firmware, licenses, or production data. That makes the audit both an asset-recovery exercise and a cyber-hygiene exercise.
Start with the removed-asset list, not the storeroom shelf. During an OT upgrade, every removed device should be captured at the point of removal with its source panel, line, asset tag, part number, firmware version if available, serial number, and reason for removal. A firewall removed because it lacks current security features should be labeled differently from a spare switch that was never installed and remains new in box.
Use four disposition categories. Before deciding whether to consign surplus industrial firewalls, sell used PLC communication modules, or hold spares, classify each item by both operational relevance and cyber sensitivity:
- Keep as controlled spare: Still supports an active installed base and does not violate the new security standard when stored or reinstalled under exception control.
- Consign for resale: No longer needed internally but likely useful to another facility maintaining the same platform.
- Quick sell for immediate recovery: Valuable enough to avoid scrap, but not worth months of internal handling or resale management.
- Destroy or recycle securely: Data-bearing, unsupported, damaged, or policy-restricted equipment that should not re-enter service.
Cross-check against standardization projects. NIST published manufacturing-sector cyberattack recovery guidance in 2026, with public comments due July 8, 2026, underscoring how recovery planning is becoming more formalized for manufacturing environments (NIST CSRC). If your plant is rewriting OT recovery plans, that is the right moment to decide which legacy devices are sanctioned spares and which are surplus created by the new standard.
Treat firmware and licensing as value signals. Buyers in the secondary market do not only care that a device powers on. They care whether the exact part number matches an installed base, whether firmware compatibility is known, whether accessories are included, and whether the item is cleanly documented. A used managed industrial switch with a readable model number, serial number, DIN-rail clip, power connector, and firmware note is easier to evaluate than a loose switch in an unmarked bin.
Connect the audit to broader MRO cleanup. If your plant is already reviewing automation spares, this cybersecurity refresh can be folded into a wider surplus PLC inventory audit or a multi-site duplicate-spares review. The difference is that OT network equipment should receive an added data-sanitization and credential-removal checkpoint before any resale decision.
🔑 Key Takeaway: Audit OT refresh surplus in two dimensions: technical resale value and cyber sensitivity. A high-value device may still require secure wiping, reset, or destruction before it can leave the plant.
Document Legacy PLCs, HMIs, IPCs, and Network Gear Before Value Disappears
Documentation is what separates recoverable surplus from ambiguous dead stock. A buyer evaluating surplus automation equipment needs confidence that the item is identifiable, usable, and not a mystery device pulled from a shutdown cabinet. For OT cybersecurity refreshes, documentation also protects the seller by showing that devices were reviewed before leaving the facility.
What to capture for PLC and network modules
For PLC communication modules, remote I/O adapters, and network cards, capture the manufacturer, full catalog number, series or revision, serial number, installed rack location, removed-from machine or panel, and whether the module was active at removal. If the module was replaced during an IEC 62443 automation upgrade surplus project, note whether the replacement was due to architecture standardization, lack of firmware support, protocol migration, or corporate security policy.
What to capture for HMIs and industrial PCs
For HMIs and industrial PCs, the documentation burden is higher because these devices may contain recipes, local project files, operator credentials, Windows images, network paths, or production history. Photograph the front, rear label, ports, accessories, and condition. Record whether storage media was removed, wiped, or left in place for internal reuse only. If the device contains a removable drive, memory card, or compact flash card, treat that media as a separate asset requiring its own disposition decision.
What to capture for firewalls, switches, and gateways
For surplus industrial firewalls, managed industrial switches, and remote-access gateways, configuration risk matters. Record whether the device has been factory reset, whether credentials were removed, whether VPN profiles were deleted, whether SIM cards were removed, and whether any certificates or keys were present. A device that still carries network identity should not move into a resale workflow until it has passed an internal sanitization step.
Photos are not optional. Take clear images of the full unit, nameplate, serial label, connector condition, accessories, packaging, and any visible damage. For new-in-box or unused spares, photograph sealed packaging and labels. For installed pulls, avoid overstating condition; describe them as used, removed from service, untested, tested, or powered-on only based on what your team actually verified.
Build a simple evidence package. For each line item, create a record with:
- Part number and manufacturer
- Quantity
- Condition category
- Serial number where available
- Firmware or revision where visible
- Cyber sanitization status
- Photos of labels and ports
- Reason for removal
- Packaging status
- Preferred disposition path
The goal is not perfect cataloging. The goal is enough documentation to prevent the default outcome: valuable surplus managed industrial switches and control modules being written off because no one can identify them later.
📋 Pro Tip: Add a required field called cyber cleared for resale to your surplus spreadsheet. If the answer is no or unknown, the item should not leave the facility until IT, OT, or security approves the disposition.
Choose Consignment, Quick Sale, Hold, or Secure Disposal by Asset Type
Not every cybersecurity refresh asset should take the same path. Some legacy PLC modules are valuable because thousands of plants still run the installed base. Some old HMIs are useful only if they are clean, identifiable, and compatible. Some remote-access devices should be destroyed because the security risk outweighs any recovery value. The decision should be structured, not emotional.
Consignment fits identifiable parts with ongoing installed-base demand. This is often the best path for surplus PLC communication modules, discontinued HMI panels, industrial Ethernet modules, DIN-rail power supplies, I/O adapters, and certain managed switches. These parts may not be needed by your standardized architecture anymore, but another plant may need the exact revision to keep a legacy line running. Consignment works best when the plant can wait for the right buyer and has the documentation to support a higher recovery value.
Quick sale fits urgency and cleanup pressure. If a cybersecurity refresh has created pallets of mixed automation surplus and the plant needs immediate space, budget recovery, or project closeout, a direct sale can make more sense than long-cycle remarketing. This is especially relevant when finance wants the project cleaned up in the same quarter, or when the maintenance team does not want removed OT equipment drifting back into cabinets without approval.
Hold only what is tied to a controlled exception. Keeping one or two legacy modules as emergency spares can be rational if the installed base still exists and the cyber team approves the exception. Keeping every removed device because someone might need it someday is how OT refreshes turn into slow-moving and obsolete MRO inventory. If the part is no longer permitted under the new architecture, it should not be quietly preserved as an unofficial spare.
Destroy when data or policy risk is too high. Some assets have low resale value but high security sensitivity. Remote-access gateways, firewalls with unknown configurations, industrial PCs with storage media, and cellular routers with SIM cards deserve careful review. In some cases, secure disposal is the right answer even if the hardware has residual market value.
| Asset category | Best-fit path | Why | Documentation priority |
|---|---|---|---|
| PLC communication modules | Consign or hold controlled spare | Exact revisions can support legacy installed bases | Part number, series, rack source, condition |
| Legacy HMIs | Consign, quick sell, or dispose | Value depends on model, screen condition, and data handling | Photos, storage status, power-on notes |
| Industrial PCs | Quick sell, consign, or secure dispose | Potential value, but higher data-bearing risk | Drive status, OS/license notes, condition |
| Industrial firewalls | Case-by-case | Useful if reset and supported; risky if configs remain | Factory reset proof, firmware, accessories |
| Managed switches | Consign or quick sell | Standard industrial models can retain demand | Port condition, power connector, firmware if known |
| Remote-access gateways | Often quick sell or dispose | Must clear credentials, VPN profiles, SIMs | Sanitization status, carrier accessories |
Use policy momentum while it exists. Honeywell highlighted OT cybersecurity themes at its 50th Honeywell Users Group event, reflecting how controls vendors and manufacturers are treating OT security as a mainstream operations topic, not a niche IT concern (Automation.com). When leadership is already focused on cyber risk, it is easier to get agreement on surplus disposition rules, device sanitization, and resale approvals.
Coordinate with procurement before buying new spares. A cybersecurity refresh often creates both shortages and surplus at the same time. The plant may be buying new standardized switches while removing older but still marketable equipment. Before procurement places blanket orders for new spares, compare the removed-asset list against active lines, sister facilities, and recovery options. That prevents duplicate spending and supports a cleaner MRO carrying-cost decision.
⚠️ Watch Out: The worst path is informal reuse. If a device was removed for cybersecurity reasons, it should not be reinstalled later because it happened to be sitting on a shelf.
What To Do Now
Turn the OT upgrade into a controlled surplus process. The best time to recover value is while devices are being removed, labels are still readable, and the project team still remembers why each part came out.
Export the OT refresh bill of materials and removal list. Flag every PLC module, HMI, industrial PC, firewall, managed switch, remote-access gateway, router, protocol converter, and network accessory removed since January 1, 2026. Add columns for reason removed, current storage location, data-bearing risk, and resale eligibility.
Create a cyber-cleared surplus folder. For each item that may be resold, store photos, part numbers, serial numbers, firmware or revision details, condition notes, and sanitization status. Separate assets with drives, memory cards, SIM cards, VPN profiles, certificates, or unknown credentials until security review is complete.
Decide the path by category before quarter-end. Keep only approved exception spares, consign identifiable controls and network modules with likely installed-base demand, quick sell mixed surplus that needs fast recovery, and securely dispose of devices where data or policy risk outweighs value.
🏭 On the Plant Floor: Do not let OT cybersecurity refresh surplus become another unlabeled pallet. Assign ownership before the integrator leaves and before the removed equipment disappears into maintenance storage.
If your 2026 OT cybersecurity refresh has created surplus PLCs, HMIs, industrial PCs, firewalls, managed switches, remote-access gateways, or network modules, Materialize can help you turn the documented inventory into recovery value through consignment or direct purchase options. Start at https://trymaterialize.com.

