Join our Newsletter — 33% off our NHI Course

Why do manufacturers continue to lag in cyber defence despite widespread digital transformation efforts?

Manufacturers often lag because their security programmes do not keep pace with the operational complexity of modern plants, where IT, OT, and business systems must all work together. Communication gaps between teams leave ownership unclear, classic security principles are applied inconsistently, and core identity and access controls are often weaker than the business exposure demands. That combination keeps attack paths open.

Why Manufacturing Cyber Defence Falls Behind Digital Transformation

Manufacturers usually do not lag because they lack technology. They lag because digital transformation expands the number of systems, interfaces, suppliers, and decision points faster than security governance matures. In plants, production uptime, safety, engineering change control, and vendor access often dominate priorities, so cyber controls are layered on after connectivity is already in place. That creates uneven control coverage across IT, OT, and business environments, which is why exposure persists even when modern tools are deployed. For a broader view of the threat environment affecting industrial organisations, CISA cyber threat advisories provide useful context.

In practice, many security teams discover the gap only after remote access, legacy OT dependencies, or shared administrative pathways have already been normalised.

How the Gap Persists Across IT, OT, and Plant Operations

The weakness is rarely a single missing product. It is a coordination problem across environments that were not designed to share the same security model. IT teams may assume endpoint visibility and centralized identity enforcement will carry into the plant, while OT teams may prioritise availability and vendor-supported configurations over strict access governance. Business teams often add cloud services, analytics platforms, and connected maintenance tools without a clear control owner, which leaves security exceptions to accumulate.

This is also where identity and access discipline becomes operationally important. If engineers, third parties, and service accounts all have long-lived access with weak segmentation, the organisation inherits more paths than it can reliably monitor or revoke. Strong cyber defence in manufacturing depends on knowing who can reach which system, under what condition, and with what traceability. That does not mean every plant must be rebuilt at once. It means the security model must be aligned with the actual production architecture, not the ideal one.

A useful way to think about the problem is to separate visibility, authorization, and resilience:

  • Visibility tells you what assets and pathways exist.
  • Authorization tells you who or what should be able to use them.
  • Resilience tells you what happens when a controller, vendor link, or identity path fails.

When those three are handled by different teams without a common operating model, controls drift. The result is usually not a dramatic failure on day one, but a growing mismatch between business exposure and the security assumptions used to govern it. That guidance breaks down when organisations cannot inventory their critical connections at all, because then they are trying to secure an unknown operational map.

Where Manufacturing Security Breaks Down in Practice

Tighter segmentation and access governance often increases administrative overhead, so organisations have to balance production flexibility against control consistency.

Common breakdowns appear when manufacturers treat plant connectivity as a project rather than a lifecycle. Temporary vendor access becomes permanent. Shared accounts remain in place because shutdown windows are scarce. Security exceptions become embedded in maintenance routines, and nobody revisits whether those exceptions still match the current production design. In many cases, the issue is not that controls are absent, but that they are not enforced consistently across plants, lines, or acquired sites.

There is also a well-known industry tension here: the more the environment depends on legacy controllers, specialist integrators, and uptime-sensitive operations, the harder it is to apply uniform hardening without operational trade-offs. That does not mean the trade-off should be ignored. It means the organisation should explicitly decide which systems can tolerate stricter access, stronger monitoring, or more frequent credential changes, rather than letting convenience define the standard.

Manufacturers also underestimate how quickly digital transformation multiplies trust relationships. A connected quality platform, a remote maintenance gateway, and a cloud dashboard may each look isolated, but together they create a broader access chain than any one team fully owns. When security teams cannot trace that chain end to end, attackers and simple misconfiguration alike benefit from the same blind spots.

Risk and Threat Considerations

The material risk is not just weaker defence in the abstract. It is the accumulation of exposed pathways across IT, OT, remote support, and third-party integrations, combined with inconsistent identity and access enforcement. That mix increases the chance that a compromise, misconfiguration, or inherited exception becomes a route into production-critical systems.

Failure mechanism: Attackers often exploit shared accounts, stale remote access, weak segmentation, or over-privileged maintenance access to move from a low-trust entry point into operational systems. Even without a sophisticated attacker, poorly governed access paths can persist because no single team owns revocation, monitoring, and exception review.

Impact: The consequence can be loss of production visibility, disruption of plant operations, unsafe process changes, exposure of proprietary process data, or delayed recovery because the organisation cannot quickly determine which access path was abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Manufacturing cyber lag is a governance and risk alignment problem.
Recommendation — Align plant modernization decisions to risk tolerance and security priorities.
CIS Controls v8 4 — Secure Configuration of Enterprise Assets and Software Persistent exposure often comes from inconsistent hardening across plants and systems.
6 — Access Control Management Weak ownership and long-lived access are central to the gap described.
8 — Audit Log Management Limited traceability makes it hard to detect and investigate operational access abuse.
Recommendation — Standardize secure baselines for critical manufacturing systems and remote access paths. Review and revoke unnecessary plant, vendor, and administrative access regularly. Centralize logging for critical OT and IT pathways so access changes are traceable.
MITRE ATT&CK T1021 — Remote Services Manufacturing exposure often persists through vendor and remote support routes.
Recommendation — Hunt for unnecessary remote services and constrain their use to approved sessions.

Practitioner Guidance

What to prioritise: Start with the access paths that connect business systems, remote vendors, and plant-critical assets. Those are usually the fastest route from governance weakness to operational exposure, and they are easier to reduce than a full plant-wide redesign.

What to verify: Confirm that every high-impact connection has a named owner, a current business justification, and a revocation path. If the team cannot show who approves access changes and who removes them, the control is not really in place.

What practitioners underestimate: Security debt in manufacturing is often organisational before it is technical. If IT, OT, and engineering still operate separate assumptions about uptime, change control, and third-party access, the environment will keep reintroducing the same weaknesses in different forms.

Practitioner takeaway: The fastest improvement usually comes from making access ownership and exception review explicit, because most manufacturing exposure persists where nobody is accountable for closing the gap.