Insights

The Recovery Path Is Now the Target

Written by NexusTek | Sep 16, 2026, 11:00:00 AM

Are you treating backup as insurance? Something that sits outside potential risks, ready to be restored when the worst happens. But what if access to that data isn’t enough to get production back online? Many teams are learning that cyber incident doesn't need to take down OT systems to stop production and what happens when the informational technology (IT) systems surrounding production, or the systems needed to recover them, become unavailable.

While Verizon’s 2026 Data Breach Investigations Report (DBIR) analyzed 2,713 confirmed manufacturing breaches, with ransomware the culprit in 61% of attacks,1 ransomware and deleted data are only one part of the story. There are plenty of other ways that production can be stopped. Enterprise resource planning (ERP) systems that feed production schedules, identity controls that determine access, or virtualized infrastructure spanning IT and OT can all be connected, and if one service goes down, the impact ripples throughout an organization.

It’s a weak spot, and while potential ransomware attacks may leave OT teams worried about their data, they should also be asking, "Are the systems needed to bring production back online available?" For manufacturers, resilience and prevention need to include understanding where an incident can spread, which dependencies can interrupt production, and what will be available when it's time to recover.

To help show how this can play out, let's look at another recent analysis of industrial ransomware activity, where researchers identified 1,140 incidents affecting industrial organizations. Manufacturing accounted for 65% of those incidents.2 But none of the cases involved reaching Stage 2 of the ICS Cyber Kill Chain or directly manipulating a control system. Disruption instead came from encryption or precautionary shutdowns of enterprise and virtualization systems that OT relied on.3

That means that a production outage does not necessarily mean someone took control the programmable logic controller (PLC) or systems that control machinery and physical processes. There can be other complications on the plant floor: OT doesn't always follow the same hardware lifecycle as IT.

 

Aging OT Throws a Wrench In the Mix

But because these environments interact with physical processes, performance, reliability, and safety must all be considered.4 That sometimes changes how the plant floor handles vulnerabilities and upgrades. An IT endpoint might be updated during a standard maintenance window, but OT may need vendor support, engineering review, testing, or something else before a change can be made.

For manufacturers, aging equipment can be an obstacle; some OT can't be easily patched, upgraded, or replaced on the same timetable as conventional IT and may remain in service for years, even as the surrounding environment becomes more connected.

 

IT/OT Connections Are Not Always on the Diagram

Plant managers can point to an IT/OT plan, but if the connections between environments, including remote support, engineering workstations, vendor access, identity services, and production data flows, aren't included, there will be gaps. Over time, new applications, equipment, and third-party access may add paths that were not part of the original design.

Federal OT guidance describes physical and logical network segmentation as part of a defense-in-depth architecture and recommends mapping the communications required between segments.5 Federal ransomware guidance similarly recommends maintaining separation between IT and OT to help contain a breach and limit lateral movement.6

An important question that increasingly applies to the teams managing recovery infrastructure becomes, "How are those connections controlled, and what else becomes reachable when one part of the environment is compromised?"

 

Access as Part of the Incident

Attackers often try to find and delete or encrypt accessible backups, so strong security calls for offline, encrypted copies and regular testing of backup availability and integrity.7 That's why recovery paths are only part of the security story. If production and recovery share credentials, administrative access or other paths, an incident affecting one environment may also reach the systems expected to restore it.

 

Ransomware makes the problem more pronounced because removing the recovery option can increase pressure on a victim. But the underlying issue extends beyond ransomware. A destructive attack, compromised administrative access or another cyber event can still leave a manufacturer dependent on its ability to restore critical systems, making recovery time another key factor.

 

Recovery Time on the Plant Floor

A 24-hour Recovery Time Objective (RTO) looks different in a recovery plan than it does on the plant floor. In a facility running around the clock, a 24-hour recovery could mean losing a full day of production, delaying orders, changing shipping schedules, and missing customer commitments.

An IT team measures recovery through systems and service levels; operations feels it as lost production time. A gap can also exist between the recovery plan and what's been tested. An RTO records the intended recovery time; a restore test records how quickly a system recovered. That gap can be hard to see, which is why answers to a few key questions can tell a more useful story.

 

Five Valuable Questions

  1. When was the last time a production-critical system was restored from backup? A completed backup job and a completed restore test measure two important things teams should know.
  2. Can credentials used in the production environment allow people to modify or delete recovery copies? The answer shows whether production and recovery unnecessarily share an administrative path.
  3. What does a recovery test include? Depending on the plant, production may rely on ERP, identity, virtualization and engineering applications, or systems inside OT.
  4. How does measured restore time compare with the documented RTO? The gap between the two shows operations how much downtime it needs to plan for.
  5. Who makes the business decisions if recovery exceeds the available downtime? A long disruption can involve operations, customer commitments, and executive decisions alongside the technical response.

Measurable Risk Reduction In Practice

The basics matter here, even if they aren't the projects that get attention. When production is running normally, they're easy to put off:

  • Keep recovery copies isolated from production credentials. Then test restores regularly to make sure they work.
  • Segment IT and OT networks to limit how far an incident can spread.
  • Maintain detection and response coverage around the clock.

How NexusTek Supports Manufacturing Resilience

For mid-market manufacturers, putting this all into practice can be tough with internal resources alone. NexusTek works with manufacturers to address the IT and security dependencies that can put production at risk, including the connections between IT and OT, as well as the systems and processes they depend on to detect, recover, and respond.

Managed Detection and Response services provide coverage backed by a 24/7/365 team of security professionals, connecting cybersecurity to what matters on the plant floor. It helps teams identify what can disrupt production and determine if the systems they rely on can be recovered when they're needed.

Learn more at https://www.nexustek.com/contact-us 

 

FAQs

Are successful nightly backups enough to protect a manufacturing environment?

Backups don't prove a system can be restored. Manufacturers must test whether backups are isolated from production and if restores work under real-world conditions.

Why is IT/OT network segmentation important in manufacturing?

Segmentation and controls limit lateral movement while allowing business and production systems to communicate.

What should a manufacturer prioritize first to improve cyber resilience?

Test production-critical systems, verify that credentials can't be used to modify or delete recovery copies, and compare measured restore times with documented RTOs.

 

Sources

  1. Verizon, 2026 Data Breach Investigations Report (DBIR), 2026
  2. Lexie Mooney and Abdulrahman H. Alamri, Dragos, Industrial Ransomware Analysis for Q2 2026, August 10, 2026
  3. Ibid.
  4. Keith Stouffer, Michael Pease, CheeYee Tang, et al., National Institute of Standards and Technology
  5. Ibid.
  6. Cybersecurity and Infrastructure Security Agency, #StopRansomware Guide, revised October 19, 2023
  7. Ibid.