Back to Blog
Industry Specific
4 min read

Manufacturing Cybersecurity: Downtime Is the Real Loss

The cost is measured in stopped lines, not stolen records. Segmentation, legacy equipment and the supplier requirements now arriving from customers.

GuardsArm Team

Security Experts

September 25, 2026

Manufacturing cybersecurity and production uptime

In manufacturing the loss function is different from most sectors. A data breach is damaging; a stopped production line is immediate, quantifiable and compounding, and for a plant running continuous processes the restart cost can exceed the outage itself.

That reframes the whole security case. Availability is the primary objective, and the argument for investment is an operations argument rather than a compliance one.

Downtime is the loss
Quantifiable, immediate and compounding
IT ransomware stops plants
Without ever touching a controller
Customers are the driver
Security as a condition of supply

Ransomware is the dominant scenario

Most manufacturing incidents that stop production do so through ordinary IT ransomware, not through a targeted attack on control systems. The mechanism is usually indirect: the ERP or MES goes down, so production cannot be scheduled, materials cannot be booked, and shipping cannot be documented — even though the machines themselves are unaffected.

How most manufacturing outages actually happenA phished office user leads to ransomware across the IT estate, which takes down ERP and MES, which stops production even though the machines themselves are unaffected.Phishoffice userRansomwareIT estateERP and MES downno schedulingProduction haltsmachines fine, plant stopped
The control systems were never touched. The plant stopped anyway.

That points at where the investment belongs:

  • Segmentation so an IT compromise cannot reach production systems
  • Recovery capability for the systems production depends on, tested
  • A documented manual mode — can the plant run for a shift, a day, a week without the ERP? For many plants the honest answer is no, and finding out during an incident is expensive.

Legacy equipment is normal and permanent

A CNC machine bought in 2004 with an embedded Windows controller is not going to be patched, and it may run for another decade. Manufacturers who frame this as a problem to be eliminated stay stuck; those who treat it as a permanent condition to be contained make progress.

ConstraintContainment approach
Cannot patch the controllerSegment it; restrict what can reach it
Vendor requires remote accessBroker it, time-box it, record it
No endpoint agent availableMonitor the network around it instead
USB is the only transfer routeControlled media, scanned at a kiosk
Shared operator accountPhysical access control compensates, and log at the network

USB remains a live transfer mechanism in plants, for good operational reasons. A scanning kiosk and a controlled-media policy is more realistic than a ban that operators will work around.


Intellectual property

For manufacturers with proprietary processes, designs or formulations, theft is a genuine and under-monitored risk. It differs from ransomware in being quiet — there is no outage to alert you.

Practical measures: know where design and process data lives, restrict access to it by role, monitor bulk access and egress, and treat departing engineers as a specific scenario in your leaver process. See insider threat monitoring.


Customer requirements are now the driver

Increasingly the reason manufacturers invest is that customers require it. Automotive, aerospace and defence supply chains push security requirements down through contracts, and larger customers audit.

Security is now a condition of supply
For manufacturers in automotive, aerospace and defence chains, customer security requirements arrive contractually and are audited. That makes the investment a revenue argument — the cost of remaining a supplier — rather than a risk argument competing with capital projects.

That includes TISAX in automotive, CMMC for defence work involving controlled unclassified information, and a widening range of customer-specific security schedules. See CMMC Level 1 versus Level 2 and NIS2 flow-down.

The commercial framing matters: this is a condition of remaining a supplier, which makes it a revenue argument rather than a cost one.


Where to invest, in order

For a manufacturer starting from a flat network and no dedicated security staff:

  1. Separate IT from production. One boundary, properly enforced, prevents the most common outage scenario.
  2. Protect the systems production depends on — ERP and MES — with immutable backups and a tested restore.
  3. Document and rehearse manual mode for at least one shift.
  4. Inventory the production floor, passively. You will find equipment nobody listed.
  5. Broker vendor access rather than leaving standing connections.
  6. Buy monitoring for the IT estate, because that is where the attack starts.

Steps one and two address the dominant loss scenario. Everything after them is refinement.


Multi-site and acquired plants

Manufacturers that have grown by acquisition carry a specific problem: inherited plants with their own networks, their own vendors, their own domain and their own security history, connected to the group network at some point for convenience.

Each acquisition is a fresh estate with unknown exposure. Treat integration as a security project with its own assessment rather than as a networking task, and segment the acquired plant until you know what is in it. See merging networks after M&A — the checklist transfers directly to industrial estates.


Where to start

Answer one question honestly: if your ERP were unavailable tomorrow, how long could the plant keep producing and shipping? Most manufacturers have never tested it, the answer is usually shorter than assumed, and it sizes both the segmentation and the recovery investment.

GuardsArm assesses manufacturing environments and designs IT/OT separation. See manufacturing solutions and OT and ICS security, or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Manufacturing Cybersecurity: Downtime Is the Real Loss”

Talk to the GuardsArm team about how these services apply to your environment.