Quick read

The manufacturing cyber risk hiding in plain sight

After almost 17 years working in digital forensics and incident response, I’m still surprised by how often manufacturers underestimate…

Published:  September 1, 2026
Share
Written by:
Picture of Harry Trick
Director
Forensic Services Leeds
featured image

After almost 17 years working in digital forensics and incident response, I’m still surprised by how often manufacturers underestimate the cyber risks sitting on the shop floor.

Stephen Phipson at Make UK recently highlighted the issue, and he is right to do so. Manufacturers have invested heavily in protecting finance systems, email platforms and corporate networks. Yet when incidents occur, it is often the production environment, the machinery, operational systems and connected devices that receive the closest scrutiny. Cyber risk in manufacturing is rarely confined to the office network. It sits across the systems that keep production moving, orders flowing and customers satisfied.

As manufacturers continue to automate operations and connect more devices across their facilities, the operational environment becomes increasingly difficult to understand, monitor and recover following an incident. Production equipment, sensors and connected systems deliver clear efficiency benefits, but they also create additional points of exposure and add complexity when organisations need to determine what happened, what has been affected and what needs to be restored.

The issue is rarely a complete absence of cybersecurity controls. More often, there is an assumption that existing reviews, audits and assessments provide comprehensive coverage across the business. In practice, operational technology can sit outside the scope of routine cyber assessments, leaving vulnerabilities undiscovered until an incident forces organisations to understand exactly how their environments are connected and where critical information resides. This challenge is particularly relevant in manufacturing environments where IT and operational technology increasingly overlap.

When manufacturing leaders think about cyber risk, the conversation often focuses on preventing an attack. From my perspective, the more important question is what happens next.

Cyber incidents are no longer rare events. The organisations that recover most effectively are not necessarily those with the most sophisticated technology. They are the businesses that understand their critical operations, know which systems and data are most important, have clear response plans, and can make informed decisions quickly when under pressure.

Human behaviour continues to play a significant role in many incidents. While attack methods evolve constantly, investigations frequently trace back to ordinary actions, a phishing email opened during a busy shift, a password reused, a process bypassed to keep production running, or a warning overlooked. This is not a criticism of production teams. It is a reminder that cybersecurity is ultimately about people as much as technology. A workforce that understands risks and follows consistent processes remains one of the strongest contributors to cyber resilience.

When a manufacturer is hit by a cyber incident, the first few hours are about establishing facts.
• What happened?
• What systems have been affected?
• What information may be at risk?
• Is the threat still active?
• What evidence needs to be preserved?

My team supports clients through that early triage and forensic fact-finding process. We help organisations understand the scope of the incident, assess operational and financial impact, and establish a clear evidence-based picture of events. We also support communications with insurers, lenders, legal advisers and other stakeholders who require accurate information to make decisions.

Alongside this, specialist cybersecurity providers focus on technical containment, eradication and recovery activities. Our role is complementary. We focus on helping leadership teams understand the facts, protect value, manage risk, preserve evidence and support commercial recovery while the technical response is underway.

For manufacturers, speed matters. Every hour of disruption can impact production schedules, customer commitments, supplier relationships and revenue. Decisions made in the early stages of an incident can influence recovery costs, regulatory obligations, insurance outcomes and the wider commercial impact. The faster organisations can establish reliable facts, the faster they can move from uncertainty to action.

Almost every cyber incident is different. However, the underlying weaknesses are often remarkably similar. Lack of visibility across operational environments, uncertainty around critical systems and data, limited preparedness for disruption, and gaps in decision-making processes appear time and again.

The manufacturers that navigate incidents most successfully are rarely the ones that never experience problems. They are the organisations that understand their operational environment, know what matters most to the business, and have considered in advance how they would respond when something goes wrong.

Cyber resilience is not simply about stopping attackers getting in. For manufacturers, it is about understanding where vulnerabilities exist, protecting critical operations, and being prepared to respond decisively when an incident threatens production. In an increasingly connected world, that means paying just as much attention to the systems on the factory floor as those in the office.
 

When manufacturing leaders think about cyber risk, the conversation often focuses on preventing an attack. From my perspective, the more important question is what happens next.

Straightforward advice based on robust analysis from experts you can trust

Trending Topics

Explore our insights, articles & podcasts. View all trending topics