The Importance of Manufacturing
The manufacturing sector includes many societally essential industries. Consumer products, electronics, automobiles, pharmaceuticals, food and beverage, and heavy industries, all contribute to global circular economies in this way.
Production facilities in the industrial ecosystem are dispersed globally; every manufacturer also serves as a consumer and vice versa. As a result, a cyberattack on one organization might have an expensive knock-on effect throughout the ecosystem.
The ensuing threats are systemic, contagious, and frequently out of the grasp of any one entity’s comprehension or control. According to research, 98% of firms have relationships with third parties that have been compromised.
Globally, manufacturing companies now operate more efficiently and productively thanks to the expansion of cutting-edge technologies like the Industrial Internet of Things (IoT) and robotic process automation (RPA), as well as increased digitalization and connectivity brought on by the fourth industrial revolution.
However, this development has also made the manufacturing ecosystem more vulnerable to online threats. Considering the current pace of cyberattacks affecting the industry, manufacturers must work to minimize the impact these threats pose.
The Evolving Cyber-Threat Landscape
Manufacturing's top dangers haven't changed in kind, but they have intensified. According to recent industry analysis, phishing, ransomware, intellectual property (IP) theft, supply chain attacks, and Industrial IoT attacks remain the sector's top threats, now compounded by rapid, often ungoverned AI adoption on the factory floor.
There are many factors contributing to the evolution of today's cyber-threat landscape in the manufacturing sector:
- To escape detection, improve their success rate, and maximize profits, threat actors constantly refine their strategies. Ransomware has effectively industrialized: 119 distinct groups targeted industrial organizations in 2025, a 49% jump from 80 groups the year before, and the top five ransomware groups alone claimed more than half of all victims industry-wide in early 2026. Access brokers now sell entry into compromised networks on underground forums, letting affiliates skip reconnaissance and move straight to extortion.
- Cyberattacks are carried out for reasons that go beyond monetary gain. Nation-state-linked groups like KAMACITE and ELECTRUM (responsible for Ukraine's 2015 and 2016 power outages) expanded operations into the U.S. and Europe in 2025, while newer groups such as PYROXENE deployed destructive wiper malware during regional conflicts. Geopolitical instability continues to fuel more targeted, disruptive tactics against OT environments.
- The interconnectedness of businesses worldwide keeps pushing threats into the supply chain. Attackers are now exploiting vendors an average of seven days before a vulnerability is even publicly disclosed, and industry researchers now describe supply chain compromise as the dominant force reshaping the global threat landscape, ahead of ransomware itself.
Historically, manufacturing businesses had separate IT and OT environments. Because of IT and OT merging, previously isolated systems and processes are now subject to the same cyber threats as the online IT world. Manufacturing companies work in a highly integrated environment of vital infrastructures and supply chains and are no longer standalone enterprises.
Although manufacturers must integrate OT and IT security for effective risk management, OT and IT security silos pose risks and complicate matters. A 2026 industry survey found that 96% of OT security incidents now originate from IT-level compromises before cascading into operational disruption, yet nearly 4 in 10 security leaders still point to unclear governance and ownership as a top OT security challenge. The cultural and technological disparities between IT and OT teams remain the underlying cause of this mismatch, and the ongoing shortage of qualified talent, cited by nearly half of leaders as their top OT challenge, only widens the gap.
These significant variations have an impact on how IT and OT are managed. Reliability and availability are the core objectives of OT, which presents a massive problem in a sector where maintenance windows for vital systems can be severely constrained, limiting the amount of time security teams have to test and deliver critical fixes. That gap still shows up in the data: nearly 1 in 5 ICS/OT incidents took over a month to fully remediate in 2025, and industry-wide dwell time for OT ransomware incidents averages 42 days, compared to just 5 days at organizations with mature OT visibility. Uptime at any cost is unrealistic because OT hazards can jeopardize human health, safety, and corporate operations.
The Importance of Cyber Resilience
The manufacturing industry must become cyber resilient to protect itself from the evolving threat landscape and benefit from digitization. Cyber resilience differs from cybersecurity because its capabilities continue to work even after an attacker has breached a network’s security perimeter to compromise cyber assets.
For organizations, an investment in cyber resilience strengthens and improves their ability to withstand attacks and ultimately prevents interruptions and revenue losses. It also benefits society at large. Businesses that manage these infrastructures know that the closure of their activities may affect the entire region in which they are located.
Legislative Initiatives for Resilient Cyber Manufacturing
Governments and businesses have recognized the advantages of a cyber-resilient manufacturing sector, and legislative action has moved from proposal to active enforcement.
The Cyber Resilience Act is no longer just a proposal, it's binding law. The regulation entered into force in December 2024, and manufacturers of connected hardware and software sold in the EU are now facing real deadlines: vulnerability and severe-incident reporting obligations went live on September 11, 2026, requiring a 24-hour early warning and 72-hour full notification for actively exploited vulnerabilities. Full compliance, including CE-marking and conformity assessment, is required by December 11, 2027, with non-compliance fines reaching €15 million or 2.5% of global annual turnover.
Additionally, the NIS 2 and Critical Entities Resilience (CER) directives categorize specific manufacturing industries as critical or "essential entities," necessitating that they manage security risks and take steps to prevent or lessen the effects of incidents on their customers. Both missed their original October 2024 transposition deadline, and enforcement is now uneven but active: roughly two-thirds of EU member states have transposed NIS 2 into national law, with France, Ireland, Luxembourg, the Netherlands, and Spain still finalizing legislation as the European Commission pursues infringement proceedings against laggards. CER hit its own milestone on July 17, 2026, when member states were required to formally designate which entities in sectors like manufacturing, energy, and digital infrastructure qualify as "critical," starting a 10-month clock for those entities to implement resilience measures.
The United States government has also refreshed its national approach. In March 2026, the White House released a new six-pillar national cybersecurity strategy that shifts toward more proactive defense, including expanded offensive cyber operations, zero-trust modernization, post-quantum cryptography, and a push for domestic, "U.S.-made" technology in critical infrastructure, replacing the 2023 Biden-era strategy. On the standards side, the National Institute of Standards and Technology (NIST) is updating its manufacturing-specific implementation guidance to align with the Cybersecurity Framework (CSF) 2.0, which introduced a new "Govern" function and marked its second anniversary in February 2026. The draft Manufacturing Profile update adds guidance for supply chain risk management, platform security, and technology infrastructure resilience.
Many people believe the ISA/IEC 62443 is the most essential cybersecurity standard for industrial control systems, yet it's only grown more complex. The series has expanded from four to six categories, with a newly published part addressing Industrial IoT (IIoT) devices, reflecting how sensor and edge technology have outgrown the traditional layered "Purdue Model" of OT architecture. The SANS Institute's five ICS cybersecurity critical controls remain a practical starting point for the industry.
The patchwork of regulations and standards surrounding manufacturing cybersecurity and resilience provide the guardrails for the respective organizations. However, most requirements are prescriptive since every organization is different and faces unique challenges in its environment. Hence, manufacturing organizations must adapt and supplement the described measures to fit their business risks.
Roadmap to Cyber Resilience
The development of cyber resilience requires ongoing work. It is a continuous process because the threat landscape and technological advancements constantly evolve. Awareness has only grown sharper following recent, highly visible attacks and breaches.
First, businesses need to gain a better understanding of their systems. Building resilience begins with knowledge of operations, risks, and solutions. Owners and operators of these systems must create high-fidelity baselines for the network's devices and recognize even minor behavioral anomalies to achieve adequate visibility. Such minute adjustments may portend dangers and create dangerous circumstances. This isn't a hypothetical gap: Dragos estimates that fewer than 10% of OT networks worldwide currently have meaningful network monitoring in place, and separate research shows 96% of OT security incidents originate from IT-level compromises before they ever reach the plant floor.
Maintaining visibility and understanding of the critical IT and OT ecosystems is crucial for containing cyberattacks against these systems. History teaches us that attackers often target IT systems first and then move laterally into the OT domain to disrupt vital operations, and 2025 gave manufacturers a stark reminder of what that looks like in practice. In August 2025, Jaguar Land Rover suffered what the UK Cyber Monitoring Centre called the most economically damaging cyber incident in British history: attackers exploited a supplier vulnerability, moved laterally into core production systems, and halted manufacturing across three countries for five weeks, an estimated £1.9 billion in damage that rippled through more than 5,000 supply chain businesses. The perception that IT and OT systems are air-gapped is mistaken and may lead to wrong decision-making.
The second step is for businesses to adopt a zero-trust philosophy and architecture. Compared to now, networks were much less connected when most industrial OT systems were created. However, OT and IT systems are rapidly converging in the digital age. Organizations can switch from a "trust but verify" mentality to a "verify first" strategy to meet the shifting situation. This shift now has official backing: in April 2026, CISA, the Department of War, the Department of Energy, the FBI, and the State Department jointly released Adapting Zero Trust Principles to Operational Technology, guidance built specifically to help OT owners close the access-control gaps that groups like Volt Typhoon have exploited to compromise and maintain footholds in industrial environments. Manufacturing has room to catch up: it currently has the lowest zero-trust adoption rate of any major industry, at roughly 25%, even as organizations with zero trust in place saved an average of $1.76 million per breach compared to those without it. Threat actors are getting better at abusing trust. Defense-in-depth tactics and proactive threat detection can help assure quick threat detection and containment to stop lateral movement and lessen the damage of an attack.
Finally, organizations should study previous attacks on businesses, which can serve as case studies for the significance of developing resilience. Even though it is challenging to predict these events, manufacturing businesses can do many things to prepare for them. Organizations must increase their systems' responsiveness, control, and speedy recovery, but the data shows most aren't there yet: a 2026 benchmark study found only 18% of manufacturers actually meet their own recovery time targets after an outage, and three-quarters need more than two hours to resume operations, with downtime costing some organizations over $100,000 per hour. These tools can help you decide how to react to a significant disruptive incident. It can make all the difference to consider adding redundancy at critical places in advance. In a crisis, time is of the essence. Organizations must prepare by learning what to do, building the necessary skills, and practicing crisis response procedures.
How Fortra Can Help
Fortra's portfolio of security solutions can help manufacturing owners become resilient against increasing cyber threats. Many high-profile industrial companies trust Fortra because we're creating a simpler, stronger, and more straightforward future for cybersecurity, offering an integrated, scalable portfolio built specifically for the demands of industrial manufacturing environments, where IT, OT, and supply chain risk all intersect.
Fortra's Tripwire bridges the IT-OT gap by giving manufacturers the network visibility they need to map industrial environments, fix vulnerabilities sooner, and enforce security controls without disrupting live production.
Fortra's data protection solutions, including Fortra DSPM, help manufacturers discover, classify, and protect sensitive intellectual property such as blueprints, CAD schematics, and proprietary formulas, unstructured data types that many conventional security tools simply aren't built to recognize, but that remain prime targets for cyber and industrial espionage. The stakes are real: one global manufacturing and consumer goods company narrowly avoided an estimated $400 million breach after a departing research scientist downloaded more than 20,000 sensitive documents on his way out the door, an insider threat that Fortra was purpose-built to catch and contain.
Fortra's vulnerability management solutions help industrial organizations identify and prioritize security vulnerabilities based on real-world exploitability, not just severity scores, so security teams can focus remediation where it will reduce risk the most. [fortra.com]
Finally, as phishing remains involved in more than 90% of successful cyberattacks, Fortra's anti-phishing and email security software can help manufacturers keep emails, brands, and data safe from sophisticated phishing attacks, insider threats, and accidental data loss. In addition, manufacturing businesses can continuously train employees to recognize phishing attempts through simulations and engaging courses offered by Fortra Security Awareness Training.