Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should manufacturers contain ransomware once an IT…
Threats, Abuse & Incident Response

How should manufacturers contain ransomware once an IT workload is compromised?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Threats, Abuse & Incident Response

Manufacturers should contain the first compromised workload immediately, then prevent the attacker from moving laterally into other systems. The practical control is Zero Trust Segmentation with default-deny east-west access, especially between IT and industrial environments. That approach limits blast radius, blocks ransomware from reaching controllers and sensors, and preserves operations while teams investigate the intrusion.

How to stop a ransomware foothold from spreading across manufacturing environments

The containment objective is not to clean the compromised host first, it is to stop the infection path. In manufacturing, that means isolating the affected IT workload, preserving business-critical services that must keep running, and preventing any path from that system into adjacent servers, identity services, file shares, backups, or OT-connected networks.

That separation matters because ransomware operators often depend on reachable east-west paths more than on the first compromised machine itself. If the original foothold can still talk freely to other systems, the incident can turn into a wider encryption event before responders have enough visibility to understand scope.

Why default-deny east-west segmentation is the practical control

Zero Trust Segmentation works because it changes the default assumption from trusted internal movement to explicitly approved communication. A default-deny posture between workloads, and especially between IT and industrial environments, limits blast radius and forces the attacker to prove every path rather than inheriting access through flat network trust.

For manufacturers, the most important design choice is where to draw the boundary. The boundary should not be an abstract network zone, it should map to real operational dependencies, such as ERP, engineering, historian, backup, remote administration, and plant support services. If the policy model is too coarse, teams either block needed operations or leave broad exceptions that ransomware can exploit.

Segmentation also preserves response options. When east-west traffic is tightly constrained, defenders can quarantine one workload without taking down the whole environment, and they can do so while keeping the minimum set of systems required for production continuity reachable.

What containment should include once the compromise is confirmed

Immediate containment is a control sequence, not a single action. First, break the compromised workload’s lateral paths. Then verify whether the host had access to shared credentials, management interfaces, backup systems, or remote tooling that could extend the compromise. Finally, confirm which production services depend on the isolated workload so that the isolation does not create an avoidable outage.

The containment plan should assume the attacker may already be probing for adjacent targets. That means logging and network telemetry need to be treated as containment tools, not just investigation aids. The faster teams can see denied attempts and unusual east-west connections, the faster they can decide whether the blast radius has been successfully contained.

Manufacturers should also treat OT adjacency as a separate risk condition. If an IT workload can reach industrial-support services, engineering jump points, or systems that bridge into plant networks, the containment boundary needs to be reinforced before recovery begins. Reintroducing the host into the same trust zone without changing the path structure simply recreates the original exposure.

Risk and Threat Considerations

Ransomware containment fails when internal trust is too broad or when exception paths are left open for convenience. In manufacturing, that creates a high-risk condition because a single compromised IT workload can become a stepping stone toward shared services, backups, and OT-adjacent systems that the business cannot afford to lose.

Failure mechanism: The attacker uses permitted east-west connectivity, over-privileged service paths, or weakly segmented IT and industrial zones to move laterally, discover higher-value systems, and encrypt or disrupt more than the original host.

Impact: The incident expands from one compromised workload into production downtime, loss of recovery options, wider credential exposure, and a materially larger blast radius across manufacturing operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SC-7 — Boundary ProtectionSegmentation and boundary enforcement are central to containing lateral spread.
AC-4 — Information Flow EnforcementDefault-deny east-west access depends on controlling permitted information flows.
Recommendation — Enforce boundary controls to restrict east-west movement between compromised and protected systems. Apply information-flow rules to block unauthorized cross-zone communication.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureContainment here depends on never trusting internal network location by default.
Recommendation — Design trust boundaries so every internal connection is explicitly authorized and continuously verified.
CIS Controls v8CIS-12 — Network Infrastructure ManagementSegmentation and network control are the primary containment mechanism in this scenario.
CIS-8 — Audit Log ManagementContainment depends on visibility into denied and unusual east-west activity.
Recommendation — Segment networks to prevent compromised workloads from reaching adjacent systems. Collect and review logs to confirm lateral movement is being blocked.

Practitioner Guidance

What to prioritise: Contain first, investigate second. The first decision is whether the compromised workload can still reach anything that matters, not whether the malware sample has been analyzed. If the answer is yes, isolate the path immediately and keep the affected system from touching shared identity, backup, remote admin, or industrial bridge services.

What to verify: Validate that segmentation rules actually enforce default-deny for east-west traffic, including temporary exceptions created for support or production continuity. A policy that exists on paper but still permits broad internal reach is not containment, it is an assumption.

Practitioner takeaway: The most effective manufacturing containment move is to shrink reachable trust boundaries fast enough that ransomware cannot turn one IT foothold into a plant-wide outage.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org