
Manufacturing Cybersecurity: Downtime Is the Real Loss
The cost is measured in stopped lines, not stolen records. Segmentation, legacy equipment and the supplier requirements now arriving from customers.
GuardsArm Team
Security Experts

In manufacturing the loss function is different from most sectors. A data breach is damaging; a stopped production line is immediate, quantifiable and compounding, and for a plant running continuous processes the restart cost can exceed the outage itself.
That reframes the whole security case. Availability is the primary objective, and the argument for investment is an operations argument rather than a compliance one.
Ransomware is the dominant scenario
Most manufacturing incidents that stop production do so through ordinary IT ransomware, not through a targeted attack on control systems. The mechanism is usually indirect: the ERP or MES goes down, so production cannot be scheduled, materials cannot be booked, and shipping cannot be documented — even though the machines themselves are unaffected.
That points at where the investment belongs:
- Segmentation so an IT compromise cannot reach production systems
- Recovery capability for the systems production depends on, tested
- A documented manual mode — can the plant run for a shift, a day, a week without the ERP? For many plants the honest answer is no, and finding out during an incident is expensive.
Legacy equipment is normal and permanent
A CNC machine bought in 2004 with an embedded Windows controller is not going to be patched, and it may run for another decade. Manufacturers who frame this as a problem to be eliminated stay stuck; those who treat it as a permanent condition to be contained make progress.
| Constraint | Containment approach |
|---|---|
| Cannot patch the controller | Segment it; restrict what can reach it |
| Vendor requires remote access | Broker it, time-box it, record it |
| No endpoint agent available | Monitor the network around it instead |
| USB is the only transfer route | Controlled media, scanned at a kiosk |
| Shared operator account | Physical access control compensates, and log at the network |
USB remains a live transfer mechanism in plants, for good operational reasons. A scanning kiosk and a controlled-media policy is more realistic than a ban that operators will work around.
Intellectual property
For manufacturers with proprietary processes, designs or formulations, theft is a genuine and under-monitored risk. It differs from ransomware in being quiet — there is no outage to alert you.
Practical measures: know where design and process data lives, restrict access to it by role, monitor bulk access and egress, and treat departing engineers as a specific scenario in your leaver process. See insider threat monitoring.
Customer requirements are now the driver
Increasingly the reason manufacturers invest is that customers require it. Automotive, aerospace and defence supply chains push security requirements down through contracts, and larger customers audit.
That includes TISAX in automotive, CMMC for defence work involving controlled unclassified information, and a widening range of customer-specific security schedules. See CMMC Level 1 versus Level 2 and NIS2 flow-down.
The commercial framing matters: this is a condition of remaining a supplier, which makes it a revenue argument rather than a cost one.
Where to invest, in order
For a manufacturer starting from a flat network and no dedicated security staff:
- Separate IT from production. One boundary, properly enforced, prevents the most common outage scenario.
- Protect the systems production depends on — ERP and MES — with immutable backups and a tested restore.
- Document and rehearse manual mode for at least one shift.
- Inventory the production floor, passively. You will find equipment nobody listed.
- Broker vendor access rather than leaving standing connections.
- Buy monitoring for the IT estate, because that is where the attack starts.
Steps one and two address the dominant loss scenario. Everything after them is refinement.
Multi-site and acquired plants
Manufacturers that have grown by acquisition carry a specific problem: inherited plants with their own networks, their own vendors, their own domain and their own security history, connected to the group network at some point for convenience.
Each acquisition is a fresh estate with unknown exposure. Treat integration as a security project with its own assessment rather than as a networking task, and segment the acquired plant until you know what is in it. See merging networks after M&A — the checklist transfers directly to industrial estates.
Where to start
Answer one question honestly: if your ERP were unavailable tomorrow, how long could the plant keep producing and shipping? Most manufacturers have never tested it, the answer is usually shorter than assumed, and it sizes both the segmentation and the recovery investment.
GuardsArm assesses manufacturing environments and designs IT/OT separation. See manufacturing solutions and OT and ICS security, or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Manufacturing Cybersecurity: Downtime Is the Real Loss”
Talk to the GuardsArm team about how these services apply to your environment.


