Why Manufacturing Cybersecurity Lags Behind (And What Attackers Know About It)
Manufacturing is facing a cybersecurity paradox. The sector drives global supply chains, protects valuable intellectual property, and operates critical infrastructure.
Yet, it consistently ranks as the most targeted and least prepared to defend against modern cyber threats. According to the 2025 IBM X-Force report, 27% of all cybersecurity incidents targeted manufacturing, with 45% of those attacks resulting in financial extortion or operations disruption.
Attackers understand this gap. They know manufacturing organizations face unique operational constraints that make security investment difficult, IT focused solutions impractical, and downtime catastrophically expensive. Traditional cybersecurity solutions focus on IT infrastructure and workforce, resulting in risky trade-offs between security capabilities and OEE due to a lack of manufacturing alignment.
These structural cybersecurity weaknesses make manufacturing an ideal target for ransomware, espionage, and supply chain attacks.
The operational reality that creates security gaps
Above all, manufacturing prioritizes availability, reliability, and safety. Aberdeen Research found that unplanned downtime averages manufacturers $260,000 per hour across every sector.
This economic reality shapes every security decision. Patching a vulnerability might require shutting down a production line for hours or days, testing new security controls could disrupt just-in-time delivery schedules, and replacing legacy equipment could mean retooling entire factory floors.
Security teams in other industries can push updates overnight, or temporarily take systems offline for hardening. Manufacturing operations rarely have that luxury. A chemical plant can't pause mid-batch, and an automotive assembly line can't halt without cascading effects across the supply chain.
Organizations understand the risks, but can't address them without accepting production losses that exceed the potential cost of a breach.
This creates an environment where known vulnerabilities persist for months or years, as well as the losses.
When attacks hit the factory floor
The threat isn't theoretical. In September 2025, Jaguar Land Rover suffered a breach that shut down global IT systems, halted manufacturing at its Halewood facility, and sent employees home during one of the UK's highest-volume vehicle sales days. Stolen credentials were the entry point.
That same month, Bridgestone confirmed a cyberattack disrupting North American manufacturing operations, a repeat incident for the company following a 2022 LockBit ransomware attack. And earlier in May 2025, Nucor, the largest steel producer in the United States, took parts of its network offline to contain an attack that temporarily halted production across multiple facilities.
Three attacks, three global brands, all within the same calendar year. The common thread across each: attackers found a way in through access that should have been controlled.
The IT/OT security gap
The gap between IT security maturity and OT security capabilities continues to widen as attackers develop more sophisticated techniques faster than manufacturers can modernize their infrastructure.
Attackers exploit this reality by targeting older systems, knowing patches won't be applied quickly or at all. They look for equipment running unsupported operating systems that can't be upgraded without risking operational stability.
But exploiting unpatched systems is no longer the only path in, and increasingly, not the preferred one. According to IBM's 2025 X-Force Threat Intelligence Report, compromised credentials are involved in 30% of all cybersecurity incidents.
Attackers aren’t hacking; they’re logging in
In manufacturing environments where shared workstations, rotating contractor access, and legacy authentication are the norm, identity has become the most reliable entry point.
For manufacturers, an identity-focused Zero Trust approach addresses this directly, closing the access gaps attackers count on most without requiring changes to production systems.
Resource constraints and competing priorities
Manufacturing organizations often operate on thin margins. Capital investments focus on production capacity, efficiency improvements, and meeting customer demand. Cybersecurity competes for budget against equipment upgrades, workforce expansion, and facility maintenance.
Industry analysis tells us that manufacturers typically invest less in cybersecurity as a percentage of revenue compared to financial services or healthcare organizations. This is because business leaders feel the pressure to balance immediate operational needs against potential future threats, not because they don't recognize the risks.
Expanding attack surface, constrained budgets
Smaller manufacturers face even steeper challenges. They lack dedicated security staff, rely on IT generalists who support both business systems and production environments, and struggle to justify security spending when profit margins are already compressed.
What makes this increasingly urgent is the pace of change. As Industry 4.0 adoption, AI-driven automation, and connected systems expand the attack surface across production floors, smart manufacturers are treating security as a condition of growth, not a cost to defer.
Why attackers see manufacturing as high-value, low-resistance targets
Manufacturing organizations hold exactly what attackers are after: valuable intellectual property, high downtime costs, and security gaps they can exploit. KELA reports that 2025 saw Manufacturing attacks surge 61%, faster than any other industry.
1. Trade secrets and competitive intelligence
Product designs, manufacturing processes, and proprietary formulas represent years of research and competitive advantage. Nation-state actors target this intellectual property for economic espionage. Competitors pay for stolen designs that could take years to develop independently.
2. Willingness to pay ransoms
Attackers know manufacturing organizations will consider paying ransoms when production stops. Every day of downtime costs millions in lost output, brand degradation, and potential customer defections. Multiple 2024-2025 incidents demonstrate this calculation: manufacturers often pay to restore operations faster than recovery from backups would allow.
3. Complex supply chains create multiple entry points
Manufacturing depends on numerous suppliers, rotating contractors, field service partners, and logistics providers. A breach at any partner organization can provide access to the broader network. Attackers exploit these trusted relationships, knowing smaller suppliers often have weaker security controls than their larger manufacturing customers.
Moving from reactive to proactive security
The fastest path to risk reduction doesn't require touching production systems. Unifying identity proofing and passwordless authentication across IT and OT environments satisfies ISA/IEC 62443 access control requirements without disrupting operations.
For CISOs, that means measurable risk reduction. For Operations Directors, it means no downtime and no retooling.
Identity security offers a practical starting point that works within these constraints:
Eliminates shared credentials at workstations and HMIs without requiring production downtime
Secures third-party access through real-time monitoring and person-level accountability
Unifies identity governance across PLCs, SCADA, and HMIs through a single platform, closing the visibility gaps between IT and OT that attackers count on.
Manufacturing organizations can't eliminate every vulnerability immediately, but they can take the steps to close the access gaps that attackers exploit most while avoiding downtime.
Download our Manufacturing Identity Guide to learn how identity security addresses operational constraints and strengthens defense against credential-based attacks.
About the author

Josh Connor
Director of Product Strategy, Manufacturing
Josh leads initiatives to grow market share at the intersection of Operational Technology and cybersecurity. With 15 years of experience spanning consulting, digital transformation, and product innovation, he specializes in developing identity and access solutions for the manufacturing industry.





