Back to Blog
    Still frame from a Mekotek FLC 1530 enclosed fiber laser video

    What to Ask Before Putting a Laser Cutting Machine on Your Network

    By Brad Cairns

    Published Updated

    Share this article:

    A supplier says the machine is "IoT-ready" or "connected." Before that changes anything on your floor, it is worth working out what that actually means for your network, your data and your maintenance contract. This is a list of the questions to put to a supplier, an IT lead or a controls integrator before any production machine is wired into a network — laser cutting or otherwise. It does not describe what any specific machine does; it describes what to confirm before treating a connectivity claim as a reason to buy.

    What machine data is actually worth having

    Vendors market dashboards. What a shop needs from a machine is often narrower and less glamorous than a dashboard suggests.

    • Machine state and uptime. Is the machine cutting, idle, in alarm, or in a changeover? A running log of state transitions, even a simple one, tells you more about real capacity than almost any other single data source.
    • Alarms and fault codes. A timestamped alarm history lets you find repeat failures and compare them against maintenance records, instead of relying on an operator's memory of "it does this sometimes."
    • Consumable counters. Nozzle, lens and gas usage tied to hours or cut length supports a real maintenance schedule rather than a calendar guess.
    • Program and job records. Which program ran, on which material, for how long. This is the data that lets you reconcile quoted time against actual time on a part.

    A dashboard that shows a machine icon turning green and red is not the same thing as any of the above. If a sales conversation stays at the level of a dashboard screenshot, ask to see the underlying data fields and how far back they are retained.

    Questions for the supplier before you connect anything

    Put these in writing and get written answers, not a verbal assurance during a demo.

    1. What protocol does the machine speak, and to what? OPC UA, MTConnect, a proprietary API, or a vendor-hosted cloud service are different commitments. A proprietary format that only the vendor's own software can read is a form of lock-in worth pricing in.
    2. Where does the data live? On a local historian you control, or on a vendor's cloud platform? If it is the vendor's cloud, ask what jurisdiction the servers are in and what happens to your historical data if you stop paying for the service.
    3. Who owns the data, contractually? Not "who generated it" — who has the legal right to export it, delete it, and use it, including after the contract ends.
    4. Can you export it in a usable format, on demand, without the vendor's involvement? A yes with a documented method beats a yes with no method.
    5. Does the machine need outbound internet access to function, or only to report data? A machine that stops cutting when it loses an internet connection is a different risk profile than one that simply stops reporting.
    6. Who can remotely access the control, and how is that access granted and revoked? Ask specifically whether a service technician's remote session requires your explicit approval each time, or whether the vendor holds standing credentials.
    7. What happens at end of contract or end of support? Does data collection stop, does the control revert to local-only operation, and do you retain what was already collected?

    If a supplier cannot answer these in specific terms, that is itself useful information about how mature their connectivity offering actually is.

    Keep the machine off the office network

    Whatever the machine reports, the network it sits on is a separate decision from what data it produces. Industrial control equipment, including CNC and laser cutting controls, should not share a flat network with office workstations, email and general internet browsing. A compromised laptop on the same broadcast domain as a machine control is a realistic path to downtime that has nothing to do with the machine's own software.

    The practical version of segmentation for a smaller shop does not require an enterprise security team:

    • Put production equipment on its own VLAN or physically separate network segment.
    • Restrict outbound internet access from that segment to only what is required — a specific vendor endpoint, not general web access.
    • Require any remote access to go through a monitored gateway or VPN with logging, not a standing connection into the control itself.
    • Keep a record of every third party with any form of access to the network segment, and review it at renewal time along with the service contract.

    NIST's guidance on cybersecurity for smart manufacturing systems and its foundational cybersecurity activities for IoT product manufacturers both treat segmentation, credential management and data governance as baseline practice, not advanced hardening — see Sources below.

    Patching and the reality of end-of-support hardware

    Industrial controls are not laptops. A control platform can run for a decade or more, and the underlying operating system or communication module may reach end of vendor support well before the mechanical machine is retired. Before connecting anything:

    • Ask what operating system or firmware the control or any connected module runs, and what the vendor's patching cadence and end-of-support date are.
    • Ask what happens if a critical vulnerability is disclosed in that platform after support ends — is there a compensating control, or is the machine expected to run unpatched.
    • Treat an unpatchable, internet-facing control as a segmentation problem to be solved with network isolation, not a software problem the vendor will eventually fix.

    None of this is a reason to avoid connectivity outright. It is a reason to treat it as an IT and contracts decision with the same rigor as any other capital purchase, not as a feature that arrives free with the ability to plug in an ethernet cable.

    The discipline the data still requires

    Collecting machine data does not by itself produce insight. A state log is only useful if someone reviews the alarm history weekly and acts on repeat faults. A consumable counter only prevents a failure if the replacement is ordered before the counter runs out. Before adding connectivity, it is worth asking who on staff will own that review, and whether the shop already tracks the same information manually with enough consistency that a connected system would genuinely improve on it, rather than just digitizing a habit that does not exist.

    If you are evaluating machine data as one piece of a larger shop-floor visibility effort, Industry 4.0 in a fabrication shop covers the sequence a shop needs to get right before integration adds value.

    Backups and what "recovery" actually means

    Ask what happens if the control's storage fails or a program is corrupted: is there an automatic backup of programs, offsets and settings, and where is it kept. A vendor that answers "the cloud backs it up" should be asked how quickly a backup can be restored to a replacement control, and whether that restoration has ever been tested rather than assumed. A shop that has never actually restored from a backup does not know whether it has one.

    A short checklist before signing

    • Data fields, retention period and export method confirmed in writing.
    • Data ownership and post-contract rights confirmed in the contract, not a sales deck.
    • Network segmentation plan agreed before the machine ships, not after an incident.
    • Remote access policy — who, when, and how it is logged — documented and reviewed annually.
    • Patching and end-of-support dates for the control platform on file.
    • A named person on staff responsible for reviewing whatever data is collected.

    None of this requires refusing a connected machine. It requires treating connectivity as a contract term and an IT decision, evaluated with the same care as the machine's mechanical specification.

    Sources

    These sources support generic cybersecurity and IT-governance context for industrial equipment; they are not a description of any Mekotek product's capabilities.

    #laser cutting machine network security#industrial control system cybersecurity#machine data ownership#network segmentation manufacturing#remote access industrial equipment

    See the machines behind the article

    Browse the full Mekotek product brochure, or book a live demo and watch a Mekotek fiber laser cut your own material.

    Related Articles

    Mekotek FLW handheld fiber laser welding system
    Technology & InnovationAug 2110 min

    Fiber Laser Welding Guide: Process, Fit-Up and Power Selection

    Handheld fiber laser welding trades broad heat input for narrow, concentrated heat — and it demands tighter fit-up than arc welding to deliver that benefit.

    Still frame from a Mekotek FLP 6020 pipe and profile fiber laser video
    Technology & InnovationAug 218 min

    Tube Laser Cutting: Dedicated Machine or Sheet + Tube Combo

    How round, square, rectangular and open-profile tube is cut on a laser, and how to decide between a dedicated tube machine and a sheet-plus-tube combo.

    Mekotek FLP 6016 pipe and profile fiber laser with automatic loading system
    Technology & InnovationJun 216 min

    Material Handling Around a Laser: From Manual to Automated

    The laser spends part of every shift waiting on metal to be moved, not cut. A stage-by-stage look at handling sheet and tube, and when automating it is justified.