TL;DR: Manufacturing trade secret loss often happens through routine file movement, not headline breaches, as CAD files, process recipes, supplier contracts, and AI prompts spread across engineers, contractors, plants, and personal accounts, according to Cyberhaven. The control gap is not storage alone but lineage-aware enforcement that follows sensitive data as it leaves trusted systems and enters collaboration channels.
At a glance
What this is: This is a manufacturing-focused analysis of how trade secrets are lost through ordinary data movement, with a focus on CAD files, process recipes, supplier data, and AI-assisted workflows.
Why it matters: It matters because identity, access, and data controls must account for engineers, contractors, and AI agents that can move sensitive files beyond the boundaries legacy DLP was built to watch.
By the numbers:
- 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches.
👉 Read Cyberhaven's analysis of preventing manufacturing IP theft and trade secret loss
Context
Manufacturing trade secret protection fails when security treats high-value intellectual property like ordinary business traffic. CAD files, process recipes, supplier terms, and tooling specifications often move across engineering systems, contractor workspaces, email, and AI tools, which means the risk is less about storage and more about uncontrolled movement. In practice, the primary challenge is preserving confidentiality without breaking the collaboration that keeps production running.
The article’s identity angle is real but indirect: engineers, contractors, and increasingly AI agents act as the conduits for sensitive files, so access governance and data controls have to work together. That makes this a useful case study for broader IAM and NHI programmes, especially where identity review alone does not tell you whether a file should have moved at all.
Key questions
Q: What breaks when trade secret controls rely only on content inspection?
A: Content-only controls miss the most sensitive manufacturing files when those files do not contain a recognisable pattern. CAD models, process recipes, and supplier specifications can be fully proprietary without looking like classic sensitive data. Effective protection needs provenance, destination awareness, and enforcement tied to how the file moved, not just what text it contains.
Q: Why do contractors and suppliers increase manufacturing IP risk?
A: They expand the number of places a protected file can be copied, stored, or forwarded. Each partner relationship creates another trust boundary, and each handoff adds a lifecycle problem if access is not removed when work ends. The risk is highest when permissions persist after the project has closed or when external workspaces are outside security visibility.
Q: What do security teams get wrong about DLP for manufacturing IP?
A: They often assume DLP should detect secrets by pattern alone. That approach works poorly for proprietary designs and process data, and it creates false positives that weaken enforcement. The better test is whether the file is leaving an approved workflow with an approved destination, which requires lineage and policy context.
Q: How should organisations govern AI-assisted work in engineering and operations?
A: Treat AI-assisted work as an identity and accountability problem, not just a productivity upgrade. Define which actions the AI may influence, which outputs require human verification, and which systems or data sources sit behind the workflow. Then align review, logging, and approval rules to the actual runtime path rather than the job title alone.
Technical breakdown
Why legacy DLP misses manufacturing trade secrets
Legacy data loss prevention tools are built around pattern matching. They look for known formats such as payment card numbers or identifiers that can be detected in text. Manufacturing IP often does not fit those patterns. A CAD file, a proprietary process recipe, or a supplier price model can be highly sensitive without containing a recognisable string. That leaves teams with broad keyword rules, false positives, and a tendency to relax enforcement. The result is predictable: the most valuable files are often the least visible to content-only controls.
Practical implication: do not rely on content inspection alone for trade secret protection.
How data lineage changes enforcement
Data lineage tracks where a file originated, how it has moved, and where it is used. That matters because origin context is often the only reliable way to distinguish a legitimate engineering file from a copied version headed to a personal account or unmanaged location. Lineage turns protection from static detection into context-aware enforcement. Instead of asking whether a file contains a secret pattern, the control asks whether this particular file should be leaving this workflow at all. That is a very different control problem, especially in collaborative manufacturing environments.
Practical implication: classify and enforce based on provenance, not just file contents.
Why AI tools and agents increase trade secret exposure
Generative AI tools create a new movement path for proprietary data because users paste designs, specifications, and formulas into prompts. Agentic AI raises the stakes further because agents can read repositories, summarise documents, and move files at machine speed. In that model, the security issue is not only what a human shares intentionally, but what a system with delegated access can surface or export without direct review. Governance now has to include AI system identity, delegated access scope, and prompt and output controls.
Practical implication: treat AI assistants and agents as data movers with governed access, not just productivity tools.
Threat narrative
Attacker objective: The objective is to remove proprietary manufacturing information in a form that can be reused, sold, or copied by a competitor.
- Entry occurs through ordinary collaboration channels such as email, shared drives, contractor workspaces, or AI prompts where sensitive manufacturing data is routinely handled.
- Escalation happens when a departing employee, contractor, or over-permissioned system copies designs, recipes, or process documents into personal storage or another external destination.
- Impact is the loss of trade secrets that can enable competitor replication, product copying, or downstream leakage across suppliers and partners.
NHI Mgmt Group analysis
Trade secret protection in manufacturing is a data movement problem before it is a storage problem. The article is right to focus on how CAD files, process recipes, and supplier specifications travel through normal business workflows. In identity terms, the people and systems moving the data are known, but the file's journey is what determines the real exposure. That means governance has to extend beyond access reviews into movement-aware control and provenance tracking.
Data lineage is the named control concept this category needs. Most organisations still think of DLP as a content filter, which is too narrow for manufacturing IP. Lineage gives security teams a way to ask whether a file came from a protected engineering system and whether its next destination is legitimate. That is a more defensible model for trade secret governance than trying to infer sensitivity from file text alone. Practitioners should treat lineage as the enforcement layer that makes classification operational.
AI assistants and autonomous agents turn intellectual property handling into an NHI governance issue. Once a prompt, connector, or agent can read and move engineering data, the question is no longer just who had access. It becomes what system identity was delegated, what scope was granted, and whether that scope was appropriate for the data involved. That intersection between NHI governance and data protection is now central to manufacturing risk management. Practitioners should include AI identities in the same control conversation as human users.
Supplier and contractor access creates the longest-lived exposure window in manufacturing programmes. The article correctly points out that every handoff creates another copy, but many teams still offboard project access too slowly or too loosely. This is where lifecycle governance matters: temporary collaboration access should not become persistent data reach. When external parties retain visibility after the project ends, trade secret loss becomes a lifecycle failure, not a one-off event. Practitioners should align partner access reviews with project completion, not calendar cadence.
What this signals
Manufacturing teams should expect trade secret risk to shift from isolated exfiltration events to continuous movement risk across engineering, supplier, and AI-assisted workflows. The practical challenge is to make provenance, destination, and delegated access visible in the same control plane, especially where human users and AI systems both move proprietary files.
Data lineage as control plane: when a file's origin and travel history become the enforcement signal, security teams can distinguish approved collaboration from leakage far more reliably. That makes lineage a governance requirement, not just a forensic feature.
Identity programmes also need to include contractors and AI agents in lifecycle thinking, because partner access and delegated system access often outlive the project that justified them. The strongest signal of maturity is not how many users were reviewed, but whether sensitive files can still leave controlled environments after those identities should have been retired.
For practitioners
- Map high-value files by origin and destination Inventory CAD repositories, process documents, supplier workspaces, and AI-connected storage. Classify files by where they originated and which destinations are approved, so policy can distinguish legitimate partner sharing from uncontrolled export. Suggested anchor for reporting is file origin and destination, because that context supports enforcement decisions.
- Add lineage-based controls to DLP Use data lineage to identify sensitive manufacturing files even when content patterns are weak or absent. Apply blocking or step-up review when a file leaves approved engineering, PLM, or supplier workflows and moves to personal accounts, removable media, or unmanaged cloud storage.
- Treat AI tools as governed data conduits Restrict which repositories AI assistants and agents can read, and separate summarisation from export permissions. Review prompt logging, connector scopes, and output handling so proprietary designs and recipes do not leave controlled environments through delegated access.
- Tighten partner offboarding after project close Require formal access removal for contractors and suppliers when a project ends, not when someone notices stale permissions. Pair project completion with access review, file sharing revocation, and confirmation that copies in external workspaces are no longer necessary.
Key takeaways
- Manufacturing trade secret loss is usually a workflow problem, not a perimeter breach.
- Lineage-aware enforcement matters because content-only controls cannot reliably classify proprietary engineering data.
- AI assistants, contractors, and departing staff all expand the identity and lifecycle surface for intellectual property loss.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | This article centers on protected secrets moving through uncontrolled channels. |
| NIST CSF 2.0 | PR.AC-4 | Partner and employee access to sensitive files is a least-privilege issue. |
| NIST SP 800-53 Rev 5 | AC-6 | Trade secret exposure depends on excessive access and weak enforcement. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance applies directly to manufacturing IP sharing paths. |
| GDPR | Art.32 | Personal data may appear in supplier and employee-linked manufacturing records. |
Use A.5.15 to formalise rules for contractor access, file sharing, and offboarding of project permissions.
Key terms
- Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
- Trade Secret: A trade secret is confidential business or technical information that creates competitive value because it is not public. In manufacturing, that often includes designs, recipes, process settings, and supplier terms that lose value quickly once they move outside controlled workflows.
- Deduplicated Access: Deduplicated access is the reduction of repeated or overlapping permissions so the same sensitive data is not reachable through multiple paths unnecessarily. In practice, it helps security teams shrink the number of copies, shares, and accounts that can expose the same proprietary file.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
What's in the full article
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- How Data Lineage is applied to recognise proprietary files even when content patterns do not match
- How Cyberhaven DSPM maps sensitive data across email, drives, and contractor workspaces
- How Cyberhaven DLP distinguishes approved supplier sharing from personal-account exfiltration
- How AI Security extends lineage tracking into prompts and agent-driven file movement
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It helps security and identity practitioners connect delegated access, lifecycle control, and governance across modern environments.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org