The critical state of cybersecurity in the manufacturing industry

Manufacturing companies are faced with unique challenges when it comes to protecting their digital environments. An MSP can help cover the OT and IT without strain on internal teams.

banner image

Manufacturing's new ranking should alter a resourcing approach to security

Manufacturing has taken first place on a list no one wants to lead. For multiple years, independent threat intelligence has ranked manufacturing as the most targeted industry for cyberattacks. For the better part of the last decade, healthcare held first place.1 This paints a picture of increasing cyber threats to the manufacturing industry. Suddenly, they’ve become more attractive prey.

Ransomware attacks against manufacturers rose roughly 61% year over year, and the financial damage is concentrated almost entirely on that one attack type. Ransomware now accounts for more than 90% of the sector's total losses, despite representing only about 12% of overall claims.2 The industry is more digital, more connected, more exposed, but it’s not the whole story.

Cybersecurity in healthcare vs cybersecurity in manufacturing industry

Healthcare's digital environment is built almost entirely on standard information technology (IT) infrastructure, relying on servers, networks, and endpoint systems. Upgraded, modernized cybersecurity in a hospital network gains the same category of defense as a bank or retailer. The underlying architecture is fundamentally similar, and the cybersecurity industry has spent decades improving protection for this infrastructure. This advantage doesn’t apply equally across other industries, especially those with large amounts of operational technology (OT).

Attackers are practical; they go where the resistance is lowest relative to the payoff. As healthcare defenses matured, the focus of cyberattacks shifted, and manufacturing landed right in the crosshairs.

Cybersecurity in manufacturing industry must cover OT

Cybersecurity threats in manufacturing look different than other industries. A large share of manufacturing's attack surface is OT, the programmable logic controllers (PLC), supervisory control and data acquisition (SCADA) systems, and industrial control systems that run the plant floor. Many of these systems predate modern networking and rely on PLC or SCADA setups that date back to the 1980s and 1990s.3 They were engineered for reliability and uptime, for decades on end, not resistance to cyberattack. That is a categorically different design problem than anything standard IT security was built to solve.

Legacy equipment often runs on operating systems that are no longer supported by their vendors, meaning there's no patch coming even when a vulnerability is known. When a patch does exist, applying it typically means taking a production line offline.4 Replacement parts and expertise in legacy systems are also increasingly scarce. Equipment is often too deeply embedded in the physical production process to swap out, without significant cost and extended downtime.5

For a long time, cybersecurity threats in manufacturing were minimal, because these systems were physically isolated from the corporate network and the internet. Now, manufacturers are connecting OT to enterprise IT and cloud platforms for better visibility, remote monitoring, and data-driven efficiency. In doing so, they are exposing equipment that was never built to be reachable.6

Cyberattacks on manufacturing companies

The cybersecurity threats in manufacturing industry are increasingly apparent, especially after recent targeted attacks. In July 2026, Coca-Cola disclosed that it’s ultra-filtered milk subsidiary, Fairlife, suspended all U.S. production after a ransomware attack. A company filing described, "unauthorized access by a third party to a portion of its systems, including its production-related systems." Weeks into the incident, Coca-Cola still hadn't determined if the intrusion reached the plant floor itself.7

Cyberattacks on manufacturing companies aren’t limited to food production, Jaguar Land Rover (JLR) lived a version of the same story. In August 2025, attackers gained a foothold in JLR's IT environment and reached systems (central enough to production) that JLR made the call to proactively shut down its global IT environment to contain the intrusion. The UK's independent Cyber Monitoring Centre later called it the most economically damaging cyber event in British history, modeling the total impact at £1.9 billion and identifying more than 5,000 affected UK organizations across JLR's supply chain. The CMC's own report noted the loss be even higher if operational technology was significantly impacted.8

The boundary between IT and OT is hard to pin down, even for companies with substantial resources. It's an even harder problem for a mid-sized manufacturer, running the same vintage of legacy equipment, with a fraction of the staffing. This is a bandwidth and organizational design problem, nested within a genuinely hard technical problem.

Two paths forward for cybersecurity in manufacturing industry

Effective security requires continuous threat monitoring, current knowledge of an attack landscape, and the discipline to treat detection and response as a full-time job. A generalist IT resource can’t carry that load, and they lack the specialization in legacy OT systems.

Establishing better cybersecurity in the manufacturing industry doesn’t mean building an internal security operations center overnight. There are two credible ways to close the gap, and the right one depends on the company's size, risk profile, and existing IT maturity.

  1. Build and name the function internally: For manufacturers with the scale to justify it, cybersecurity should be established as its own accountable function. This requires a named leader, a real budget, and a mandate that doesn't compete with keeping the network lights on. Given the OT reality described above, this also means budgeting for OT-specific expertise, not just general IT security skills — a distinct discipline with its own tools, protocols, and risk models.
  2. Outsource the parts that require constant vigilance and specialized skill, and free internal IT to do what it does best: Threat detection and monitoring is a strong candidate for third-party ownership on its own merits. It requires round-the-clock coverage, constantly updated threat intelligence, and specialized tooling that's genuinely difficult for an internal generalist team to replicate cost-effectively. Specialized providers are also more likely to have built detection capabilities for legacy industrial protocols. Handing that function to a partner built to do nothing else lets internal IT stay focused on keeping systems running, supporting the business, and managing the day-to-day technology needs of the plant and the enterprise.

Improving cybersecurity in manufacturing industry

Healthcare's transformation from top target to hardened industry happened because the industry treated the threat as existential. They resourced it accordingly for over a decade. That playbook is a genuine starting point for manufacturing industry cybersecurity. Even so, it’s only a starting point, because manufacturing needs to defend terrain that healthcare never had to.

The choice in front of manufacturing leaders isn't whether cybersecurity deserves dedicated, specialized attention. The data has already answered that question. The choice is whether that attention comes from a properly resourced and appropriately skilled internal function, a specialized third party built for exactly this kind of environment, or some deliberate combination of both.

To learn about how CAI solves problems for companies in manufacturing industry, fill out the form below.


Endnotes

  1. “2026 Data Breach Investigations Report.” Verizon Business. https://www.verizon.com/business/resources/reports/dbir/.
  2. Eric Geller. “‘Fundamental tension’ undermines manufacturers’ cybersecurity.” Cybersecurity Dive. April 28, 2926. https://www.cybersecuritydive.com/news/manufacturing-cybersecurity-threats-resilience/818680/.
  3. “IT vs. OT Security: Key Differences & Best Practices.” SentinelOne. April 22, 2026. https://www.sentinelone.com/cybersecurity-101/cybersecurity/it-vs-ot-security/.
  4. Justin Turner, Heather Harrell. “Manufacturing’s OT Security Challenges: Rising Threats, Legacy Risks and the Path to Resilience.” Protiviti. January 16, 2026. https://blog.protiviti.com/2026/01/16/manufacturings-ot-security-challenges-rising-threats-legacy-risks-and-the-path-to-resilience/.
  5. Franck-Emanuel Goguer. “IT/OT convergence is now the industrial attack path, and the 2026 data proves it.” Brixio. May 28, 2026. https://brixio.io/blog/it-ot-convergence-risks-2026/.
  6. Goguer. “IT/OT convergence…” https://brixio.io/blog/it-ot-convergence-risks-2026/.
  7. Maxwell Templeton. “Fairlife Ransomware Attack Stops All US Milk Production: IT-OT Breach Unconfirmed.” Tech Times. July 17, 2026. https://www.techtimes.com/articles/320868/20260717/fairlife-ransomware-attack-stops-all-us-milk-production-it-ot-breach-unconfirmed.htm.
  8. “Cyber Monitoring Center Statement on the Jaguar Land Rover Cyber Incident.” Cyber Monitoring Centre. October 2025. https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/.

Let's talk!

Interested in learning more? We'd love to connect and discuss the impact CAI could have on your organization.

All fields marked with * are required.

Please correct all errors below.
Please agree to our terms and conditions to continue.

For information about our collection and use of your personal information, our privacy and security practices and your data protection rights, please see our privacy policy and corresponding cookie policy.