Cyber security
The plant floor is not an office: securing operational technology
26 June 2026 · 8 min read · 2 public sources

IBM X-Force’s threat intelligence reporting put manufacturing at 27.7% of all attacks it observed in 2025 — the most targeted sector for the fifth consecutive year. Extortion accounted for the largest share of attack objectives within the sector, followed by data theft. The reason given is unglamorous: manufacturing tolerates downtime badly, which makes it a reliable payer, and its control systems are frequently old.
Why office controls fail here
An agent that quarantines a file mid-process, a patch that requires a reboot, or a scanner that floods a fieldbus with traffic can each stop a line or, worse, interfere with a safety function. Equipment commonly runs for fifteen or twenty years, may be supported by a vendor that requires an unchanged configuration to honour warranty, and may run an operating system that stopped receiving updates a decade ago. None of that makes the risk acceptable — it makes the standard toolkit inapplicable.
What works instead
- Segment the network so control systems are not reachable from the office estate, and record every legitimate crossing point.
- Inventory what is actually connected, including the vendor laptop that arrives for maintenance and the modem nobody documented.
- Prefer passive monitoring over active scanning on control networks; watch traffic rather than probe devices.
- Compensate where patching is impossible: isolation, strict access control, and tighter monitoring, with the exception recorded and reviewed.
- Control remote access for suppliers explicitly — time-limited, individually attributed, and logged.
Use the standard written for this
IEC 62443 exists precisely because industrial environments need their own model. Its zone-and-conduit approach — grouping assets by required security level and controlling the defined paths between them — maps onto how plants are actually built, and gives engineering and IT a shared vocabulary. That shared vocabulary matters more than the certificate: most failures in this space come from the two functions holding different assumptions about who is responsible for a device.
Plan the incident with production in the room
The decision to isolate a segment or halt a line is a business decision with safety implications, not an IT call. Agree in advance who makes it, what the safe shutdown sequence is, how it is communicated to operators, and how production resumes. Rehearse with the people who run the plant. An incident plan written entirely in a server room will not survive contact with a running process.
The objective is not to make a plant look like an office network. It is to make the risk visible and bounded in an environment where the consequences are physical.
Sources and further reading
This article summarizes publicly available research. Source findings retain their original geographic and sector scope.
- [01]The operational technology threat landscape: insights from X-ForceIBM X-Force · 2025
- [02]Manufacturing saw the most cyberattacks of any industry in 2025: IBM X-ForceManufacturing Dive · 2026
Put this thinking to work
Tell us about your estate and we’ll map what to build, secure, or fix first.
Keep reading
More insights

Cyber security
Business email compromise: verify the payment, not the email
11 August 2026 · 7 min read

Infrastructure
AI’s electricity bill, and why power now decides where compute goes
10 August 2026 · 8 min read
