Digital transformation is changing everything, including the factory floor. It wasn’t that long ago that operational technology (OT) flew solo, operating largely on its own. But the benefits of connecting it to corporate IT became hard to resist, and increasingly important to stay competitive: better visibility, remote monitoring, predictive maintenance, and tighter supply chain integration.
Like most innovation, that progress comes with a trade-off. The same connections that make manufacturing smarter can also give cybercriminals new paths to the OT systems that directly control production.
IT/OT convergence means cybersecurity has a bigger job now. It’s not only has to keep threats out. It has to be ready to act the moment something gets through.
Convergence may be an inevitable change, but the speed at which IT and OT are coming together is surprising. Nearly half of manufacturing OT systems are already connected to corporate networks, with that figure projected to reach 70%.1 And every new connection creates another new potential path for a cyber incident to operational problem.
According to the 2025 SANS State of ICS/OT Security Survey, four in 10 ICS/OT cyber incidents turned into an operational disruption.2 Now the attack surface including the programmable logic controllers (PLCs) and industrial control systems (ICSs) that keep production running.
Once production is affected, the costs add up quickly. According to Omdia, a resilience or availability issue can typically cost manufacturers $200,000 to $2 million,3 and the biggest losses come when production control or enterprise systems are affected.
For any manufacturer, when production is on the line, cybersecurity takes on a whole new level of importance.
Keeping threats away from the shop floor is still the first line of defense, with security tools including multi-factor authentication (MFA), network segmentation, and endpoint detection. But IT/OT convergence is expanding the environment those controls are tasked to protect.
But in modern plants, new connections are now part of normal production operations, each creating another potential route into the production environment, from software suppliers pushing updates and equipment vendors connecting remotely to infrastructure partners supporting systems and data moving freely between IT and OT.
The changes of an attack getting through are higher, so manufacturers need to plan for the attack that does, focusing on questions such as: How quickly will we see it? Can we contain it before it reaches production? If a line goes down, how long before it’s running again?
The answers to those questions can tell how much production is at risk, making lost production hours, containment time, and recovery time new measures of cybersecurity and resilience.
Cyber resilience: not giving up on prevention, but being ready when prevention isn’t enough.
Cyber resilience gets very practical on the factory floor. A few capabilities can make the difference between an incident you can contain and one that stops production.
The point is not to make the plant impossible to breach. It’s to make sure one breach doesn’t become a plant-wide shutdown.
Because those resilience capabilities now help keep the plant running, they can be viewed very differently when budget season comes around.
As anyone who has pitched cybersecurity to the CFO knows full well, it can be a hard sell because it’s usually presented as overhead, a compliance requirement, or just another security line item. But today’s converged IT/OT environment changes all that. Security is now part of what keeps production running smoothly.
Seen through that lens, disaster recovery, 24/7 monitoring, segmentation, and incident response soon stop looking like standalone security expenses. They become critical investments to help ensure operational reliability and production continuity across the business.
Case study: Addressing aging infrastructure before it affects production
An industrial tank manufacturer had aging servers, switches, and firewalls across multiple locations, with some equipment approaching end of life. Waiting for some thing to fail was becoming a risk to the business.
The company modernized key infrastructure, added monitoring, and strengthened disaster recovery across its locations. The result was a more reliable environment and a way to address vulnerabilities before they could turn into downtime or disrupt production.
Case study: Building a security program before a problem forces one.
After two data breaches, a mid-size consumer goods manufacturer needed a more structured way to manage cybersecurity risk across the business rather than continuing to address issues one at a time. The company started with a virtual Chief Information Security Officer (vCISO) assessment based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework. From there, it put formal security governance, vulnerability management, and ongoing oversight in place. The result was less exposure, clearer ownership of security risk, and a stronger foundation for keeping a cyber incident from becoming a business disruption.
Manufacturing cybersecurity doesn’t stop at keeping threats out anymore. It also has to help address and protect the organization if a threat breaks through.
At NexusTek, our team of IT/OT cybersecurity specialists work with your team to map out where connections are exposing your factory, how fast you can contain a threat, and what it takes to keep operations running.
Learn more. https://www.nexustek.com/contact-us
Sources:
1. Infosecurity Magazine, IT/OT Convergence Fuels Manufacturing Cyber Incidents, February 2025
2. SANS, SANS Report Warns of Rising Gap Between Fast Detection and Slow Recovery Across Critical Infrastructure, November 2025
3. Industrial Cyber, Omdia detects 80 percent of manufacturers hit by rising cyber threats, while only 45 percent are prepared, February 2025