Manufacturing: cybersecurity's biggest unfinished job?
19th November, 2026 • Online
Manufacturing's exposure is structural, and it is getting worse as factories digitize. What are the economically viable solutions?
Industry needs industrial-strength security
For the fourth consecutive year, manufacturing is the most attacked sector globally, responsible for around one in four of all recorded cyber incidents. Ransomware attacks against manufacturers surged by more than 60% in 2025 alone and things are arguably getting worse. The last twelve months have supplied the most damaging run of manufacturing cyber-Incidents on record.
JLR's recovery from possibly the most damaging cyber incident in UK history was still running well into this year. Then, in March 2026, the threat escalated in kind, not just degree. Stryker, one of the world's largest medical device manufacturers, was hit by a destructive wiper attack. More than 200,000 devices were destroyed across multiple continents, global manufacturing was halted, and hospitals cancelled surgeries. There was no ransom demand and no path to negotiation — the objective was destruction.
Weeks later, in May 2026, West Pharmaceutical was forced to take systems offline worldwide following a ransomware intrusion, while Foxconn confirmed an attack on Its North American factories in which the Nitrogen group claimed to have stolen eight terabytes of data — reportedly including hardware schematics and network topologies belonging to its largest customers.
Four incidents, four different adversaries, four different motives — extortion, geopolitics, data theft, supply-chain leverage. One common victim profile: the modern connected manufacturer.
And yet the sector's defences remain, by common consent of analysts, insurers, and the manufacturers themselves, well behind those of best practice sectors such as banking.
So what do CISOs in this critical sector need to do:
Foundational — fix the unlocked doors first
- Build a complete OT asset inventory. You cannot defend what you cannot enumerate. Replace 'institutional’ knowledge and spreadsheets with automated, OT-safe discovery of every controller, HMI, and engineering workstation on the plant network — the prerequisite for every control that follows.
- Get Identity right, everywhere. With roughly a quarter of sector losses traced to misconfigured MFA and nearly another tenth to its absence, hardening multi-factor authentication — including in shared workstation, shop-floor environments — is the single highest-return investment available.
- Eliminate default and shared credentials. Factory passwords still live on controllers years after installation, and generic vendor accounts erase all accountability. Enforce unique, managed credentials across the OT estate as a matter of basic hygiene.
Structural — close the seams attackers actually use
- Replace standing vendor access with governed remote access. Trust-based, always-on VPN tunnels for equipment vendors am now a primary ransomware entry point. Move to role-based, time-limited, monitored sessions with full recording and privilege management — remembering that 65% of industrial sites still show insecure remote access conditions.
- Segment the network — properly. A phished office laptop should never sit on the same flat network as a safety-critical PLC. Implement zoning and conduits to ISA/IEC 62443, progressing toward zero-trust architectures adapted for deterministic industrial protocols.
- Contain what you cannot patch. Windows XP and 7 remain commonplace on production floors and can't run modern endpoint protection. Apply compensating controls — virtual patching, isolation, strict access mediation — around legacy systems, knowing breaches involving them take roughly half as long again to identify and contain.
Operational resilience — assume compromise, engineer for recovery
- Deploy OT-native threat detection and response. IT tooling is blind to attacks that manipulate legitimate industrial commands. Baseline normal process behaviour across industrial protocols and detect the subtle deviations -a changed setpoint, an anomalous command sequence — before physical consequences occur.
- Engineer recovery for wiper-class attacks. Immutable backups must extend beyond corporate data to PLC logic, robot configurations and historian data, with tested restoration measured in hours rather than weeks. JLR's £1.9 billion loss is the benchmark for what unpreparedness now costs.
Strategic — secure the extended and intelligent enterprise
- Extend assurance beyond the factory gate. With supply-chain-focused attacks doubling in 2025 and adversaries specialising in compromised third-party credentials, continuously monitor supplier security posture, and treat every external connection as a potential breach path — JLR's loss began in someone else's software.
- Convert compliance into competitive advantage. Regulators, insurers, and defence customers are making cyber maturity a condition of doing business through regimes such as NIS2 and CMMC. Build a continuously evidenced security programme rather than an annual audit scramble.
- Secure the smart factory by design. IT/OT convergence, cloud analytics on machine data, and IIoT sensors are expanding the attack surface faster than teams can respond. Embed security into Industry 4.0 architectures from the design stage, protecting data flows from sensor to cloud.
The e-Crime & Cybersecurity Manufacturing Summit will take place online and will look at how cybersecurity teams are tackling the latest challenges. Join our real-life case studies and in-depth technical sessions and help make manufacturing secure.
Key Themes
Achieving visibility across OT/IT hybrid networks
Manufacturers struggle to maintain a unified, realtime view of assets spanning OT environments and IT infrastructure. Blind spots create exploitable gaps, while siloed monitoring tools generate fragmented intelligence. Can vendors deliver a single pane of glass that discovers and monitors every connected asset without disrupting production?
Patching the patchwork
Production lines depend on decades-old PLCs, HMls and control systems running unsupported operating systems that cannot be patched or taken offline. These assets represent the soft underbelly of the plant floor. How can you provide compensating controls that protect unpatchable equipment without compromising uptime or safety?
Held to ransom: is there a better way to build protection?
Ransomware groups target manufacturers, knowing that every hour of downtime costs millions. Traditional endpoint protection often can't run on industrial systems. Are there detection, containment and recovery capabilities designed specifically for production environments, where restoring operations quickly matters as much as stopping the initial attack?
Securing Agentic Al
Agentic systems don't just generate content — they act. CISOs must address model manipulation, prompt injection, data poisoning, tool-chain abuse and privilege escalation within Al agents executing transactions. Governance must extend beyond ML pipelines into runtime controls, behavioural monitoring and kill-switch design.
Zero trust for the industrial environment
Zero trust principles were designed for IT, yet flat OT networks with implicit trust remain the norm on the plant floor. Retrofitting identity-based controls onto deterministic industrial protocols is complex and risky. What's the roadmap for applying zero trust to OT without breaking production processes?
Securing critical remote access
Remote maintenance access has become essential, yet VPNs, jump servers and vendor-supplied remote tools create persistent attack pathways into control networks. Credential theft and session hijacking are rife. Can you deliver secure, auditable, time-limited remote access that satisfies both operational urgency and security policy?
Making the best use of threat intelligence
In a pre-emptive security model, timing is everything - success depends on detecting and neutralizing threats before they become active incidents. To do this, security operations can't just rely on internal telemetry (e.g., endpoint or network logs). They need external, real-time context about emerging threats - where do they get it?
Securing lloT, cloud and edge
Smart manufacturing initiatives are flooding plants with lloT sensors, edge computing and cloud analytics platforms - each expanding the attack surface faster than security teams can respond. Digital transformation and security pull in opposite directions. So, how to embed security into Industry 4.0 architectures from design onwards, protecting data flows from sensor to cloud?
Navigating NIS2, IEC 62443 and converging compliance demands
Manufacturers face an expanding web of regulation -NIS2, IEC 62443, the Cyber Resilience Act - each demanding evidence of governance, risk management and technical controls. Compliance teams drown in overlapping frameworks and manual audits. How can vendors help turn this regulatory burden into a structured, continuous security programme?
The power of automation
There's too much manual intervention in security. SOAR pulls data from SIEMs, EDRs, firewalls, cloud APls, ticketing systems threat intelligence feeds, and even email servers and coordinates actions across tools via APls and prebuilt integrations and intelligent playbooks. Well, that's the theory. How does it work in the real world?
Adversary simulation and behavioural analysis
Automated adversary simulation Identifies telemetry blind spots. They provide prioritized remediation guidance and control effectiveness metrics. They track progress trends and validate security ROls as well as providing board and audit reporting. How well do they work in practice?
Securing the supplier
Manufacturers depend on hundreds of suppliers, integrators and maintenance contractors, many with privileged access to critical systems. A single compromised vendor can cascade through the entire supply chain. But what can realistically be done? How can CISOs control third-party access, and detect malicious activity originating from trusted external connections before it reaches production?