Connected factories are becoming one of manufacturing’s most consequential cyber risks, not because attackers are necessarily generating more noise than before, but because a smaller number of well-chosen paths can now reach systems that matter directly to production. SonicWall’s latest manufacturing threat findings point to a sector in which office networks, remote administration tools, surveillance cameras, industrial sensors, supplier connections, and plant-floor control systems are increasingly intertwined. That convergence creates operational benefits, but it also means that a stolen password or unpatched connected device can become the first step toward a production outage.
The headline numbers initially appear encouraging. Manufacturing intrusion prevention system activity fell 56.2% year on year in the first half of 2026, the steepest reduction among the industries tracked in the report. Yet the sector still recorded 474 million intrusion prevention events. That is not a small attack surface becoming quieter; it is a huge attack surface in which hostile activity may be growing more focused.
For manufacturers, the more important conclusion is that cyber risk is evolving from broad, opportunistic scanning into a problem of architecture, identity, and exposure. The most serious question is no longer simply whether an attacker can enter the corporate network. It is whether that access can be turned into a route toward production systems, engineering workstations, supervisory control infrastructure, or the Windows servers that support the factory floor.
Modern manufacturing depends on connectivity. Plants use remote dashboards to monitor output, vendor portals to support equipment maintenance, cloud analytics to predict failures, cameras to secure facilities, and industrial sensors to collect operational data. These systems can improve efficiency, reduce unplanned downtime, and give manufacturers faster visibility into production conditions.
The difficulty is that many of these connections were added gradually. A plant may have started with a tightly controlled operational technology environment, then added remote access for maintenance teams, a Windows-based reporting server for supervisors, an internet-connected camera system for physical security, and a link to enterprise resource planning software. Each change may have made business sense independently. Together, they can produce a network that is far more connected than its original security model anticipated.
This is the central concern behind the new manufacturing threat data. Operational technology, or OT, is no longer isolated by default. It increasingly shares identity systems, network infrastructure, remote-access services, monitoring platforms, and support personnel with corporate IT.
That does not mean every connected plant is insecure. It does mean that security teams must stop treating the factory as an extension of the office network. A plant is a different kind of environment, with different safety requirements, patching constraints, availability targets, and consequences when a system fails.
This distinction matters when security teams plan remediation. A routine Windows patch deployment, firewall policy change, endpoint agent update, or password reset campaign may be manageable in an office setting. In an operational environment, the same activity may require maintenance windows, vendor validation, production coordination, rollback planning, and safety review.
Attackers understand that imbalance. Manufacturers may have strong reasons to avoid taking systems offline, making delayed patching and long-lived exceptions more common. That creates opportunities for threats based on known vulnerabilities, weak credentials, exposed remote services, and poorly segmented devices.
A decline may reflect stronger blocking. It may also reflect attackers becoming more selective, relying on stolen identities, targeting internet-exposed assets that have already been identified, or using quieter techniques designed to evade broad detection patterns.
That is why the remaining 474 million events deserve attention. The volume still signals persistent reconnaissance, exploitation attempts, bot activity, and malicious probing across manufacturing networks. It also suggests that the sector remains a profitable target for attackers looking for organizations that cannot tolerate extended downtime.
That pattern fits the practical reality of factory environments. Connected devices often include:
The vulnerability is especially notable because it demonstrates the enduring value of old weaknesses. It was disclosed years ago, yet it remains attractive because vulnerable devices can be internet-facing, poorly maintained, overlooked by IT asset inventories, and treated as a facilities responsibility rather than a cybersecurity responsibility.
An IP camera may not look like a critical asset. However, if it has network access into the same environment as Windows servers, engineering systems, maintenance laptops, or shared network storage, it can become a pivot point. The danger is not limited to surveillance footage. An exposed camera can provide attackers with a foothold, a reconnaissance point, or a path into other systems.
Manufacturers should not assume that a device is harmless simply because it does not handle production data directly. Any system connected to the enterprise network can influence the security posture of the systems that do.
A useful inventory should go beyond device names and IP addresses. It should record:
The concern is not that every SCADA detection means an attacker has reached a control system. Detection activity can include probes and attempts blocked at the perimeter. Still, a high rate of activity aimed at industrial control environments should be treated as a strategic warning.
The answer is layered protection: tightly controlled network paths, identity controls, application allowlisting where appropriate, privileged-access management, passive monitoring, and tested incident response procedures that account for safety and production continuity.
These figures require careful interpretation. Detection hits are not a count of encrypted companies or confirmed ransomware incidents. A high count can result from repeated attempts, automated traffic, security signatures, and blocked activity. Nevertheless, the presence of multiple ransomware families confirms that manufacturing remains a target-rich environment.
Ransomware is uniquely dangerous for factories because disruption creates pressure. A manufacturer may face immediate consequences from halted production, missed shipments, unavailable inventory systems, delayed quality checks, disrupted supplier coordination, or inaccessible engineering documentation. Attackers do not need to compromise every machine to create leverage. They may only need to disable the systems that coordinate operations.
In a connected factory, Windows systems may serve multiple roles:
The most effective response is not to disconnect every Windows system from plant operations. It is to ensure that access is narrowly scoped, strongly authenticated, logged, and designed so that compromise of one identity does not automatically grant broad control over another environment.
The Log4j family of vulnerabilities became widely known because the affected Java logging component appeared in an enormous range of enterprise products, services, appliances, and operational technology software. For manufacturers, the challenge is compounded by indirect exposure. A company may not run Log4j directly on a Windows server but may still own a management application, remote-access appliance, industrial platform, monitoring product, or vendor-supported device that embeds it.
Manufacturers should treat persistent Log4j activity as a prompt to review several areas:
A plant can own capable firewalls, endpoint protection, backup software, and security monitoring services while still carrying excessive risk if its network design allows broad, implicit trust. If a vendor VPN account can reach too many systems, if an office credential can access an operational server, or if a camera network can communicate freely with production assets, then the architecture is enabling the attacker.
That model can turn a single compromised account into a universal entry badge. It is especially risky when external vendors, contractors, maintenance teams, and remote employees receive access that is more expansive than their specific job requires.
A safer model emphasizes application-level access rather than blanket network access. Users should receive access to a defined service, device, or management portal for a specific purpose, rather than being placed broadly onto a network from which they can discover other resources.
Segmentation should be based on explicit communication needs. A camera network may need to send video to a recording platform, but it should not need to initiate sessions to domain controllers, engineering workstations, or production databases.
A well-designed environment uses zones and tightly defined conduits between them. Firewalls should enforce allowlists for approved traffic rather than relying on broad “any-to-any” rules that become difficult to audit over time.
Sessions should be logged, and high-risk activities should be auditable. Organizations should also validate that vendor accounts cannot use broad file sharing, remote desktop access, or lateral movement paths beyond their assigned maintenance function.
When immediate patching is impossible, manufacturers can reduce risk through:
Backups should be protected from the same credentials and management systems that control production infrastructure. If attackers can compromise the primary environment and delete or encrypt backups using the same administrative account, the recovery plan may fail at the moment it is needed most.
Still, the report’s value lies in its pattern recognition. The coexistence of massive IoT activity, high SCADA targeting, persistent Log4j detections, ransomware signatures, and a lower overall IPS count paints a coherent picture. Attackers are not abandoning manufacturing. They are adapting to its growing connectivity and looking for the weakest links between corporate IT and operational environments.
The data should therefore be used as a prioritization signal, not as a reason for panic. It tells manufacturers where to look first: exposed devices, legacy software, remote access, unsegmented networks, over-privileged identities, and vendor connections.
The manufacturing sector’s cyber risk is increasingly defined by the links between systems rather than the systems themselves. A camera connected to the wrong network, an old software component hidden inside an appliance, an always-on vendor account, or a stolen office credential can become the starting point for an incident that reaches the production floor.
The most resilient manufacturers will treat OT security as a core business architecture challenge. They will inventory every connected asset, segment operational environments, restrict remote access to the smallest practical scope, harden Windows identity infrastructure, and prepare for recovery before an attacker forces the issue. In a factory where digital convenience and physical operations now meet, every connection must be treated as a security decision.
The headline numbers initially appear encouraging. Manufacturing intrusion prevention system activity fell 56.2% year on year in the first half of 2026, the steepest reduction among the industries tracked in the report. Yet the sector still recorded 474 million intrusion prevention events. That is not a small attack surface becoming quieter; it is a huge attack surface in which hostile activity may be growing more focused.
For manufacturers, the more important conclusion is that cyber risk is evolving from broad, opportunistic scanning into a problem of architecture, identity, and exposure. The most serious question is no longer simply whether an attacker can enter the corporate network. It is whether that access can be turned into a route toward production systems, engineering workstations, supervisory control infrastructure, or the Windows servers that support the factory floor.
Overview: Why Connected Manufacturing Changes the Security Equation
Modern manufacturing depends on connectivity. Plants use remote dashboards to monitor output, vendor portals to support equipment maintenance, cloud analytics to predict failures, cameras to secure facilities, and industrial sensors to collect operational data. These systems can improve efficiency, reduce unplanned downtime, and give manufacturers faster visibility into production conditions.The difficulty is that many of these connections were added gradually. A plant may have started with a tightly controlled operational technology environment, then added remote access for maintenance teams, a Windows-based reporting server for supervisors, an internet-connected camera system for physical security, and a link to enterprise resource planning software. Each change may have made business sense independently. Together, they can produce a network that is far more connected than its original security model anticipated.
This is the central concern behind the new manufacturing threat data. Operational technology, or OT, is no longer isolated by default. It increasingly shares identity systems, network infrastructure, remote-access services, monitoring platforms, and support personnel with corporate IT.
That does not mean every connected plant is insecure. It does mean that security teams must stop treating the factory as an extension of the office network. A plant is a different kind of environment, with different safety requirements, patching constraints, availability targets, and consequences when a system fails.
The Difference Between IT and OT Risk
Traditional IT security often prioritizes confidentiality, integrity, and availability in that order. In manufacturing, availability and safety can take precedence. A workstation outage in a finance department is disruptive; a compromised engineering workstation, a halted programmable logic controller environment, or an inaccessible human-machine interface can interrupt physical processes.This distinction matters when security teams plan remediation. A routine Windows patch deployment, firewall policy change, endpoint agent update, or password reset campaign may be manageable in an office setting. In an operational environment, the same activity may require maintenance windows, vendor validation, production coordination, rollback planning, and safety review.
Attackers understand that imbalance. Manufacturers may have strong reasons to avoid taking systems offline, making delayed patching and long-lived exceptions more common. That creates opportunities for threats based on known vulnerabilities, weak credentials, exposed remote services, and poorly segmented devices.
A Drop in Attack Events Does Not Equal a Drop in Danger
The reported 56.2% decline in manufacturing intrusion prevention events is significant, but it should not be interpreted as proof that manufacturers are safer. Intrusion prevention telemetry measures attempted or detected activity, not necessarily successful compromise. It can be influenced by changes in scanning behavior, threat actor priorities, defensive controls, telemetry coverage, and the signatures used to classify traffic.A decline may reflect stronger blocking. It may also reflect attackers becoming more selective, relying on stolen identities, targeting internet-exposed assets that have already been identified, or using quieter techniques designed to evade broad detection patterns.
That is why the remaining 474 million events deserve attention. The volume still signals persistent reconnaissance, exploitation attempts, bot activity, and malicious probing across manufacturing networks. It also suggests that the sector remains a profitable target for attackers looking for organizations that cannot tolerate extended downtime.
The Rise of More Deliberate Intrusion Paths
The most concerning attack chains rarely begin with an obvious attempt to disrupt a machine. Instead, they often follow a familiar sequence:- An attacker steals a user credential through phishing, password reuse, token theft, or a compromised third party.
- The attacker signs in through a remote access service, VPN, cloud application, or exposed management interface.
- They identify accessible Windows systems, file shares, identity infrastructure, engineering tools, or remote desktop services.
- They move laterally toward high-value systems or use the foothold to deploy ransomware, steal data, or interrupt operations.
- The organization discovers the incident only after production, scheduling, logistics, or plant support functions are affected.
Internet-Connected Devices Are Becoming a Persistent Entry Point
The SonicWall findings identify internet of things attacks as the second-largest attack category in manufacturing, with 46.2 million hits. More than half of the monitored manufacturing networks detected attempts to exploit these types of weaknesses.That pattern fits the practical reality of factory environments. Connected devices often include:
- IP cameras and network video recorders
- Environmental sensors
- Building-management controllers
- Badge readers and access-control systems
- Industrial gateways
- Remote-monitoring appliances
- Wireless access points
- Smart power systems
- Network-attached storage devices
- Vendor-installed diagnostic hardware
Why Cameras Are a Cybersecurity Problem, Not Only a Physical Security Tool
One of the starkest examples in the report is CVE-2021-36260, a command-injection vulnerability affecting certain Hikvision products. SonicWall recorded 43 million hits associated with this flaw during the first half of the year, making it the largest single IoT attack signature observed across the industries it tracks.The vulnerability is especially notable because it demonstrates the enduring value of old weaknesses. It was disclosed years ago, yet it remains attractive because vulnerable devices can be internet-facing, poorly maintained, overlooked by IT asset inventories, and treated as a facilities responsibility rather than a cybersecurity responsibility.
An IP camera may not look like a critical asset. However, if it has network access into the same environment as Windows servers, engineering systems, maintenance laptops, or shared network storage, it can become a pivot point. The danger is not limited to surveillance footage. An exposed camera can provide attackers with a foothold, a reconnaissance point, or a path into other systems.
Manufacturers should not assume that a device is harmless simply because it does not handle production data directly. Any system connected to the enterprise network can influence the security posture of the systems that do.
Asset Inventory Is the First Reality Check
Manufacturers cannot secure what they cannot identify. Yet accurate inventories are difficult in plants where devices are added during upgrades, left behind after vendor projects, or managed separately by engineering, facilities, physical security, and IT teams.A useful inventory should go beyond device names and IP addresses. It should record:
- Device owner and operational purpose
- Network location and VLAN or zone
- Firmware and software version
- Internet exposure status
- Vendor support status
- Known vulnerabilities and patch availability
- Authentication method
- Allowed communication paths
- Maintenance windows and operational constraints
- Dependencies on Windows servers, databases, or cloud services
SCADA Exposure Raises the Stakes
Manufacturing recorded the highest SCADA attack detection rate of the sectors covered in SonicWall’s analysis. SCADA, or supervisory control and data acquisition, refers to systems that monitor and control industrial processes. These environments can include supervisory servers, operator interfaces, remote telemetry units, historians, engineering workstations, and communications equipment.The concern is not that every SCADA detection means an attacker has reached a control system. Detection activity can include probes and attempts blocked at the perimeter. Still, a high rate of activity aimed at industrial control environments should be treated as a strategic warning.
Operational Technology Is Not a Conventional Server Estate
OT systems often have unique constraints:- They may run older operating systems or specialized software.
- They may require vendor-approved changes before updates can be deployed.
- They may depend on legacy protocols that lack modern authentication or encryption.
- They may need continuous availability.
- They may be maintained by external service providers.
- They may use shared accounts or long-lived credentials for operational convenience.
The answer is layered protection: tightly controlled network paths, identity controls, application allowlisting where appropriate, privileged-access management, passive monitoring, and tested incident response procedures that account for safety and production continuity.
Ransomware Remains a Manufacturing Threat
The report identified 10 ransomware families active against manufacturing networks in the first half of 2026. The Zhen ransomware family alone accounted for 22.2 million hits, concentrated on two devices.These figures require careful interpretation. Detection hits are not a count of encrypted companies or confirmed ransomware incidents. A high count can result from repeated attempts, automated traffic, security signatures, and blocked activity. Nevertheless, the presence of multiple ransomware families confirms that manufacturing remains a target-rich environment.
Ransomware is uniquely dangerous for factories because disruption creates pressure. A manufacturer may face immediate consequences from halted production, missed shipments, unavailable inventory systems, delayed quality checks, disrupted supplier coordination, or inaccessible engineering documentation. Attackers do not need to compromise every machine to create leverage. They may only need to disable the systems that coordinate operations.
Windows Infrastructure Can Become the Bridge
For Windows administrators, the manufacturing threat model should be especially familiar. Active Directory, file servers, Remote Desktop services, virtualization platforms, Microsoft SQL Server instances, endpoint-management tools, and backup infrastructure can all be attractive targets.In a connected factory, Windows systems may serve multiple roles:
- Hosting historian or reporting applications
- Running human-machine interface software
- Supporting engineering and design workflows
- Managing identities and permissions
- Providing remote access for administrators and vendors
- Storing recipes, specifications, quality records, or maintenance files
- Acting as jump hosts into restricted operational environments
The most effective response is not to disconnect every Windows system from plant operations. It is to ensure that access is narrowly scoped, strongly authenticated, logged, and designed so that compromise of one identity does not automatically grant broad control over another environment.
Log4j Shows Why Old Vulnerabilities Keep Returning
SonicWall recorded 13.8 million Log4j2-related detection events across manufacturing networks. That finding reinforces a difficult lesson: vulnerabilities do not disappear merely because they are no longer breaking news.The Log4j family of vulnerabilities became widely known because the affected Java logging component appeared in an enormous range of enterprise products, services, appliances, and operational technology software. For manufacturers, the challenge is compounded by indirect exposure. A company may not run Log4j directly on a Windows server but may still own a management application, remote-access appliance, industrial platform, monitoring product, or vendor-supported device that embeds it.
The Hidden Dependency Problem
Legacy vulnerabilities remain active when organizations do not have complete visibility into their software supply chain. A security team may patch a known application while missing a bundled component inside a device that is managed by another department or supported by a third-party vendor.Manufacturers should treat persistent Log4j activity as a prompt to review several areas:
- Internet-facing applications and appliances
- Vendor-provided management servers
- Java-based applications and middleware
- Remote support platforms
- Industrial software dependencies
- Cloud-connected gateways
- Dormant or rarely used systems that remain powered on
- Backup and disaster-recovery environments
The Architecture Problem: Flat Networks and Broad Trust
The report’s most important argument is that manufacturing has an architecture problem. That is a stronger claim than saying manufacturers need more cybersecurity tools.A plant can own capable firewalls, endpoint protection, backup software, and security monitoring services while still carrying excessive risk if its network design allows broad, implicit trust. If a vendor VPN account can reach too many systems, if an office credential can access an operational server, or if a camera network can communicate freely with production assets, then the architecture is enabling the attacker.
Why Legacy VPN Access Is Increasingly Hard to Defend
Virtual private networks remain useful in many organizations, particularly where they are required for controlled remote connectivity. The issue is not that every VPN is inherently unsafe. The problem arises when a VPN grants broad network-level access after one successful sign-in.That model can turn a single compromised account into a universal entry badge. It is especially risky when external vendors, contractors, maintenance teams, and remote employees receive access that is more expansive than their specific job requires.
A safer model emphasizes application-level access rather than blanket network access. Users should receive access to a defined service, device, or management portal for a specific purpose, rather than being placed broadly onto a network from which they can discover other resources.
Zero Trust Must Be Operationally Practical
“Zero trust” is often used as a marketing phrase, but its core ideas are highly relevant to connected factories:- Verify users and devices continuously, not just once at connection time.
- Require phishing-resistant multifactor authentication for privileged and remote access.
- Grant the minimum access necessary for a defined task.
- Limit access by application, protocol, time, location, and device posture.
- Record and review privileged sessions.
- Treat vendor access as temporary and explicitly approved.
- Assume that credentials can be stolen and design systems to limit the damage.
A Practical Security Program for Connected Factories
Manufacturers need a program that reflects operational reality rather than a generic enterprise checklist. The following priorities can reduce risk without demanding immediate replacement of every older system.1. Separate IT, OT, IoT, and Guest Environments
Network segmentation is foundational. Corporate user devices, industrial control assets, building systems, cameras, vendor networks, and guest wireless services should not share unrestricted connectivity.Segmentation should be based on explicit communication needs. A camera network may need to send video to a recording platform, but it should not need to initiate sessions to domain controllers, engineering workstations, or production databases.
A well-designed environment uses zones and tightly defined conduits between them. Firewalls should enforce allowlists for approved traffic rather than relying on broad “any-to-any” rules that become difficult to audit over time.
2. Protect Identity Systems Like Production Systems
Identity is now part of the production security perimeter. Manufacturers should prioritize:- Multifactor authentication for remote and privileged access
- Separate administrator accounts for administrative tasks
- Elimination of shared credentials where feasible
- Rapid disabling of departing employee and contractor accounts
- Regular reviews of group memberships and delegated rights
- Password protections that reduce reuse and phishing risk
- Privileged-access workflows for sensitive OT systems
3. Replace Permanent Vendor Access With Just-in-Time Access
Third-party support is essential in manufacturing, but persistent external accounts are a common weakness. Vendor access should be approved for a defined maintenance task, constrained to the target system or application, and removed or disabled afterward.Sessions should be logged, and high-risk activities should be auditable. Organizations should also validate that vendor accounts cannot use broad file sharing, remote desktop access, or lateral movement paths beyond their assigned maintenance function.
4. Build a Vulnerability Process That Respects Plant Operations
Patching remains vital, but it must be coordinated. A strong operational vulnerability program does not simply generate a list of critical CVEs and demand immediate changes. It classifies assets according to exposure, exploitability, operational importance, vendor support, and available compensating controls.When immediate patching is impossible, manufacturers can reduce risk through:
- Network isolation
- Firewall restrictions
- Disabling unnecessary services
- Removing internet exposure
- Restricting administrative interfaces
- Monitoring for known exploit patterns
- Applying vendor-recommended mitigations
- Planning replacement of unsupported equipment
5. Test Recovery Beyond Data Backups
A ransomware recovery plan must cover more than restoring files. Manufacturers should test whether they can recover identity services, virtual hosts, industrial application servers, configuration files, engineering documentation, and critical Windows endpoints in a safe sequence.Backups should be protected from the same credentials and management systems that control production infrastructure. If attackers can compromise the primary environment and delete or encrypt backups using the same administrative account, the recovery plan may fail at the moment it is needed most.
The Limits of the Threat Data
The SonicWall findings are valuable, but they should be read with appropriate caution. Security telemetry from a network of sensors shows what those sensors observe; it does not represent every manufacturing company or every attack worldwide. Detection counts also do not equal confirmed intrusions, compromised machines, successful ransomware deployments, or incidents that caused downtime.Still, the report’s value lies in its pattern recognition. The coexistence of massive IoT activity, high SCADA targeting, persistent Log4j detections, ransomware signatures, and a lower overall IPS count paints a coherent picture. Attackers are not abandoning manufacturing. They are adapting to its growing connectivity and looking for the weakest links between corporate IT and operational environments.
The data should therefore be used as a prioritization signal, not as a reason for panic. It tells manufacturers where to look first: exposed devices, legacy software, remote access, unsegmented networks, over-privileged identities, and vendor connections.
Conclusion: Convenience Must Not Become Implicit Trust
Connected factories are not going away. Remote monitoring, predictive maintenance, supplier integration, and data-driven production are now integral to how manufacturers compete. The objective is not to reverse digital transformation or isolate every system from the network. It is to make connectivity deliberate, visible, and constrained.The manufacturing sector’s cyber risk is increasingly defined by the links between systems rather than the systems themselves. A camera connected to the wrong network, an old software component hidden inside an appliance, an always-on vendor account, or a stolen office credential can become the starting point for an incident that reaches the production floor.
The most resilient manufacturers will treat OT security as a core business architecture challenge. They will inventory every connected asset, segment operational environments, restrict remote access to the smallest practical scope, harden Windows identity infrastructure, and prepare for recovery before an attacker forces the issue. In a factory where digital convenience and physical operations now meet, every connection must be treated as a security decision.
References
- Primary source: securitybrief.asia
Published: 2026-07-24T05:25:00+00:00
Manufacturers face new cyber risks from connected factories
Connected factory networks are widening the attack surface, with SonicWall warning that old flaws and weak access controls can expose production systems.
securitybrief.asia