Manufacturing Cybersecurity: Holding the Line When an Attack Gets Through

NexusTek_Manufacturing_Cybersecurity_Holding_the_Line_When_an_Attack_Gets_Through_Blog_Main_Draft_v1.0C_0826

Digital transformation is changing everything, including the factory floor. It wasn’t that long ago that operational technology (OT) flew solo, operating largely on its own. But the benefits of connecting it to corporate IT became hard to resist, and increasingly important to stay competitive: better visibility, remote monitoring, predictive maintenance, and tighter supply chain integration.

Like most innovation, that progress comes with a trade-off. The same connections that make manufacturing smarter can also give cybercriminals new paths to the OT systems that directly control production.

IT/OT convergence means cybersecurity has a bigger job now. It’s not only has to keep threats out. It has to be ready to act the moment something gets through.

That Shift Changes Everything

Convergence may be an inevitable change, but the speed at which IT and OT are coming together is surprising. Nearly half of manufacturing OT systems are already connected to corporate networks, with that figure projected to reach 70%.1 And every new connection creates another new potential path for a cyber incident to operational problem.

According to the 2025 SANS State of ICS/OT Security Survey, four in 10 ICS/OT cyber incidents turned into an operational disruption.2 Now the attack surface including the programmable logic controllers (PLCs) and industrial control systems (ICSs) that keep production running.

Once production is affected, the costs add up quickly. According to Omdia, a resilience or availability issue can typically cost manufacturers $200,000 to $2 million,3 and the biggest losses come when production control or enterprise systems are affected.

For any manufacturer, when production is on the line, cybersecurity takes on a whole new level of importance.

Prevention Is Still Necessary. It’s Just No Longer Enough.

Keeping threats away from the shop floor is still the first line of defense, with security tools including multi-factor authentication (MFA), network segmentation, and endpoint detection. But IT/OT convergence is expanding the environment those controls are tasked to protect.

But in modern plants, new connections are now part of normal production operations, each creating another potential route into the production environment, from software suppliers pushing updates and equipment vendors connecting remotely to infrastructure partners supporting systems and data moving freely between IT and OT.

The changes of an attack getting through are higher, so manufacturers need to plan for the attack that does, focusing on questions such as: How quickly will we see it? Can we contain it before it reaches production? If a line goes down, how long before it’s running again?

The answers to those questions can tell how much production is at risk, making lost production hours, containment time, and recovery time new measures of cybersecurity and resilience.

Cyber resilience: not giving up on prevention, but being ready when prevention isn’t enough.

What Cyber Resilience Looks Like on the Plant Floor

Cyber resilience gets very practical on the factory floor. A few capabilities can make the difference between an incident you can contain and one that stops production.

  • Segmentation that contains the damage. If something is compromised on the corporate network, it should not have a straight path to production. The right boundaries between IT and OT environments keep the problem contained before it can reach critical data or equipment.
  • Architecture that works for OT. You can’t always secure a production environment the same way you can secure corporate IT. Equipment may run for decades, patches may need planned downtime, and taking a systems offline may stop a line. Security has to work around those realities.
  • Monitoring that sees both sides. Once IT and OT are connected, watching them separately leaves a gap. Teams need visibility across the environment so unusual activity can be spotted before it becomes a production problem.
  • Incident response that starts with the plant. A response plan needs to answer some very practical questions: What can we isolate? What has to stay running? Who decides whether equipment comes offline? And how do we bring it back safely?
  • Third-party access you can see and control. Vendors, software suppliers, and remote support teams often have legitimate reasons to connect to production systems. Manufacturers need to know who has access, when they’re using it, and what they can reach.

The point is not to make the plant impossible to breach. It’s to make sure one breach doesn’t become a plant-wide shutdown.

Put Production at the Center of the Security Case

Because those resilience capabilities now help keep the plant running, they can be viewed very differently when budget season comes around.

As anyone who has pitched cybersecurity to the CFO knows full well, it can be a hard sell because it’s usually presented as overhead, a compliance requirement, or just another security line item. But today’s converged IT/OT environment changes all that. Security is now part of what keeps production running smoothly.

Seen through that lens, disaster recovery, 24/7 monitoring, segmentation, and incident response soon stop looking like standalone security expenses. They become critical investments to help ensure operational reliability and production continuity across the business.

Resilience in Action: Two Manufacturer Case Studies

Case study: Addressing aging infrastructure before it affects production

An industrial tank manufacturer had aging servers, switches, and firewalls across multiple locations, with some equipment approaching end of life. Waiting for some thing to fail was becoming a risk to the business.

The company modernized key infrastructure, added monitoring, and strengthened disaster recovery across its locations. The result was a more reliable environment and a way to address vulnerabilities before they could turn into downtime or disrupt production.

Case study: Building a security program before a problem forces one.

After two data breaches, a mid-size consumer goods manufacturer needed a more structured way to manage cybersecurity risk across the business rather than continuing to address issues one at a time. The company started with a virtual Chief Information Security Officer (vCISO) assessment based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework. From there, it put formal security governance, vulnerability management, and ongoing oversight in place. The result was less exposure, clearer ownership of security risk, and a stronger foundation for keeping a cyber incident from becoming a business disruption.

Build Resilience Into the Line

Manufacturing cybersecurity doesn’t stop at keeping threats out anymore. It also has to help address and protect the organization if a threat breaks through.

At NexusTek, our team of IT/OT cybersecurity specialists work with your team to map out where connections are exposing your factory, how fast you can contain a threat, and what it takes to keep operations running.

Learn more. https://www.nexustek.com/contact-us 

Sources:

1. Infosecurity Magazine, IT/OT Convergence Fuels Manufacturing Cyber Incidents, February 2025
2. SANS, SANS Report Warns of Rising Gap Between Fast Detection and Slow Recovery Across Critical Infrastructure, November 2025
3. Industrial Cyber, Omdia detects 80 percent of manufacturers hit by rising cyber threats, while only 45 percent are prepared, February 2025