Insights

The 46% Ransomware Surge in OT: A Compliance Wake-Up Call for Pharma Manufacturing

Written by NexusTek | Sep 18, 2026, 11:00:00 AM

When ransomware attacks targeting industrial operators jump 46% in a single quarter, it gets a lot of attention. It’s especially eye-opening because a lot of those operational technology (OT) systems were once largely isolated and protected.1

For pharmaceutical manufacturers, the stakes couldn’t be higher. Newly connected systems now control production and processes that directly affect product quality, putting drug and therapeutic production continuity, data integrity, and regulatory compliance on the line.

The challenge they face is how to turn that pressure into practical priorities that strengthen IT/OT security without disrupting the manufacturing environment they protect.

The Threat Has Moved Off Your IT Network and Onto Your Production Floor

For years, pharmaceutical manufacturers could rely on that physical separation to help protect production systems. OT assets largely operated on their own, including programmable logic controllers (PLCs), distributed control systems, manufacturing execution systems, and environmental monitoring technology.

Digital transformation changed all that.

Connected systems never designed for today’s threat environment now drive process optimization, remote access, and supply chain integration. As many as 70% of OT systems in manufacturing are expected to soon be connected to corporate IT networks, giving attackers more attack vectors between the business network to the production floor. 2 That expanding attack surface puts the 46% ransomware spike into context.

The consequences are now all too real. An attack that reaches production control or enterprise systems can cost pharmaceutical manufacturers between $200,000 and $2 million per incident.3 But beyond the financial impact, in a GMP (Good Manufacturing Practice) environment a production disruption can impact everything from data integrity and product quality to documentation and regulatory compliance.

FDA’s OT Focus Changes the Compliance Calculus

As these risks grew, FDA expectations grew along with it. FDA’s cybersecurity guidance for 2026 focuses on the new OT security challenges and puts the pressure on manufacturers to ensure they can handle cybersecurity incidents impacting their systems.4

For pharmaceutical manufacturers, OT security goes beyond a traditional IT concern and move closer to the compliance program. That means not just having controls in place but being able to demonstrate what they’re protecting, how it’s protected, and what happens when something goes wrong.

Three areas come into sharper focus:

  • Visibility and inventory. An accurate, current inventory of assets is needed, including how assets connect to production systems along with the appropriate documentation.
  • Network segmentation and access controls. Defined boundaries between corporate IT and production environments including controlled access and safeguards that can be validated.
  • Detection, response, and documentation. Cybersecurity event detection, response, and documentation for incidents affecting production systems, and tested capabilities with the ability to produce the evidence for auditors or inspectors.

The IT/OT Security Gap Is Now a Compliance Gap

Most pharmaceutical manufacturers know how to secure their IT systems. The harder question is what to do with older technology that’s still running production.

A controller or manufacturing system installed 10 or 20 years ago may still work perfectly well, but it may not support today’s security tools or software updates. Replacing or changing it isn’t always easy. In a regulated production environment, even one technology change can mean testing, documentation, and validation are required before anything goes live.

That leaves manufacturers with a real tradeoff: leave an older system in place and carry the cybersecurity risk, or change it and potentially create production and compliance work.

The answer isn’t necessarily to replace everything. Manufacturers can isolate higher-risk systems, tightly control who and what can connect to them, monitor for unusual activity, and plan upgrades around production and validation requirements. The point is to reduce the cyber risk without creating a new compliance or production risk in the process. That’s where the regulatory requirements have to become practical infrastructure decisions.

Turn the Regulatory Roadmap into Infrastructure Priorities

For pharmaceutical manufacturers, three priorities can reduce OT risk while working without the realities of a regulated production environment.

1. Visibility starts with a validated inventory. You need to know what is connected to the production environment, what it does, what it communicates with, and who has access to it. In a regulated manufacturing environment, that inventory also needs to be current, documented, and defensible.

2. Segmentation and access control product the IT/OT boundary. As production systems become more connected to corporate IT, that boundary becomes a primary attack surface. Properly designed, validated, and documented does two jobs: it limits how far an attacker can move and provides evidence that access to critical manufacturing systems is controlled.

3. Detection, response, and recovery have to preserve integrity. FDA guidance raises the bar beyond simply having an incident response plan. Manufacturers need to be able to detect an event, respond to it, and recover production systems without compromising the integrity of the environment or its data.

From OT Risk to an Action Plan

The regulatory direction in pharmaceutical manufacturing can’t wait for the next equipment refresh or compliance finding. NexusTek's Life Sciences practice builds OT security and IT infrastructure solutions designed specifically for GMP manufacturing environments, with current Good “x” Practice (cGxP)-trained professionals who understand both the security architecture requirements and the regulatory documentation obligations. If you are evaluating where your current OT security posture stands against FDA's updated expectations, NexusTek's Life Sciences IT Readiness Assessment provides a structured gap analysis and a prioritized roadmap, at no cost and with no commitment.

Sources:

1. Honeywell, Ransomware Attacks Targeting Industrial Operators Surge 46 Percent In One Quarter Honeywell Report Finds, June 2025
2. Infosecurity Magazine, IT/OT Convergence Fuels Manufacturing Cyber Incidents, February 2025
3. Industrial Cyber, Omdia detects 80 percent of manufacturers hit by rising cyber threats, while only 45 percent are prepared, February 2025
4. FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, February 2026