Your Plant Will Restart in Days or in Weeks. IT-OT Cybersecurity Decides Which.

On 16 July 2026, Coca-Cola told the US Securities and Exchange Commission that its dairy business Fairlife had been hit by ransomware affecting, in the filing’s words, “a portion of its systems, including its production-related systems.” Every American plant went quiet. A week later, the question that mattered most was still open: did the attackers reach the machinery, or did production stop because nobody could yet prove they hadn’t?

That unresolved detail is the difference between a restart measured in days and one measured in months. It is also the clearest picture available of what IT-OT cybersecurity for manufacturing has actually become. Plant leaders are usually sold prevention. What they get judged on is how fast the line runs again.

The Only Security Number a Plant Head Should Track

IT-OT cybersecurity for manufacturing keeps the office network and the plant network connected enough to run the business, and separated enough that trouble on one side cannot quietly become trouble on the other. Its purpose is not to make an attack unlikely. Manufacturing has been the world’s most targeted sector for five consecutive years, accounting for close to 28% of all investigated incidents in a 2026 global threat intelligence report. Its purpose is to give you certainty during the incident: documented proof of where an intruder could and could not reach, so you restart the lines you can vouch for instead of freezing the whole site and guessing. Recovery speed is the metric. Everything else is a means to it.

The Floor Was Never Going to Follow IT Rules

In an office, the worst outcome is stolen data. On a floor, it is a stopped line, a ruined batch, or a machine that hurts someone. That gap changes what good security even looks like. IT teams patch aggressively and lock things down hard. Try that on a press that has run untouched for nine years and you become the outage you were hired to prevent.

The consequence most plants underestimate is that an attack does not need to touch a single controller to stop production. It only needs to take out the systems that tell the floor what to make, in what sequence, against which order. When scheduling, dispatch and material release go dark, the line has no instructions worth trusting, and a supervisor is left choosing between running blind and running nothing. This is why the control layer sitting inside your ERP deserves the same seriousness as the machines themselves. A first-quarter 2026 industrial ransomware analysis counted 1,020 incidents against industrial organisations in three months, with manufacturers making up 62% of the victims, and a large share of those plants never had an attacker anywhere near a PLC.

Yet governance has not caught up with the risk. A 2026 global cybersecurity outlook found that only 16% of organisations with industrial environments raise OT security issues to their board, and just 20% keep a dedicated OT security team. Plant security is still being treated as an IT department problem, which is roughly like handing your maintenance budget to finance because both involve numbers.

You Cannot Restart What You Cannot Account For

Plant engineer reviewing connected device inventory on the factory network

Here is the uncomfortable test. If your site went dark tonight, could your team produce, by tomorrow morning, an accurate list of every device on the plant network, what software it runs, and whether anything outside the plant can reach it? Not roughly. Exactly.

Most manufacturers cannot, and the gaps follow a pattern: a panel PC nobody remembers commissioning, a contractor’s laptop still sitting on the line VLAN two projects later, a machine running an operating system that stopped receiving updates before the current shift supervisor was hired. During normal operations these are invisible. During an incident they are the reason your investigators cannot draw a clean boundary, and an investigator who cannot draw a boundary will always advise the safest answer, which is to shut everything.

Remote access is where the list usually breaks first. Vendors log in to diagnose equipment, engineers check batch progress from home, integrators need temporary access during a commissioning window. All of it is legitimate and none of it is the problem. The problem is the access that was never closed afterwards, quietly outliving the project that justified it. This is the same trap as the efficient processes that quietly become your biggest security risks: the convenience is real, and so is the exposure it leaves behind. Grant access for a defined window, expire it automatically, require a second factor on every login including vendor logins, and route external connections through one gateway your team can actually watch. A stolen password should never be a free pass to the systems that run your line.

Segmentation Is a Recovery Decision Before It Is a Defence

Network segmentation diagram for IT-OT cybersecurity in manufacturing showing isolated production zones

If a manufacturer fixes one thing this year, make it this. Separate the office network from the plant network, then separate zones inside the plant so a compromised line does not become a compromised site. IEC 62443 and the NIST guidance for industrial systems already describe how to do it properly, so the architecture is not the hard part.

What most people miss is that segmentation pays out twice. The first payout is the obvious one: malware landing on a front office laptop hits a wall long before it reaches a filling line. The second payout is the one that saves your quarter. Clear boundaries are what let you tell an investigator, with evidence rather than optimism, that the intrusion could not have crossed into Zone 3, which means Zone 3 restarts while the rest of the site is still being cleaned. Sites without those boundaries recover as one indivisible unit, at the speed of their slowest question. When unplanned downtime runs to roughly $260,000 an hour by 2026 industry benchmarks, the difference between partial and total shutdown is not an IT preference. It is margin.

The same boundary logic applies to the partners who reach into your plant. Equipment builders, integrators and maintenance contractors each carry a slice of your access, and each one is a trust decision somebody made, often years ago, sometimes verbally. Recent figures suggest more than half of manufacturers never formally assess the security of the third parties connected to them, which is a striking number given how many incidents now arrive through a supplier’s software update rather than through the front door. Give every vendor a named account instead of a shared one, keep a live register of who holds access and why, and put that register in the hands of someone inside the plant rather than someone in a corporate office three cities away. This is the practical end of managing third-party and supply chain risk as your operations scale, and it is worth asking suppliers how they protect their own systems, because their breach becomes your breach.

The Backup You Have Never Restored Is Not a Backup

Detection tools built for industrial networks can now watch plant traffic passively, learn what normal looks like, and flag the abnormal: a controller taking instructions from a device it has never spoken to, data leaving the site at 3am. That warning is valuable, but it only converts into a fast restart if what comes next actually works.

Almost every plant has backups. Far fewer have ever restored one onto real hardware and watched the machine come back correctly. Backing up a factory system is not backing up a spreadsheet. It means capturing the exact controller configuration, the calibration values, the recipe parameters and the interlock settings that let a process run safely, not just the data sitting around them. A backup that restores the application but not the safety logic is a false sense of readiness, and you find out which kind you own on the worst possible day. Schedule restore tests during planned maintenance windows, on the lines that would hurt most if they stopped, and record how long the restore actually took. That number is your real recovery time. Everything else is an assumption.

Rehearse the Shutdown Call, Because Someone Will Have to Make It

At some point during a live incident, one person has to decide whether to stop the line. That call carries safety consequences, ruined work in progress, missed dispatches and contractual penalties, and it usually has to be made with incomplete information at an inconvenient hour. A response plan copied from a corporate IT playbook offers almost nothing here, because it was written for a world where pausing a system costs a meeting, not a shift.

Build the plan for the floor, jointly, with your security people and your plant engineers in the same room. Decide in advance who is authorised to halt production, what evidence is enough to restart a zone, who tells customers, and how you keep operating manually if the systems that schedule work are unavailable for a week. Then rehearse it, ideally during a shutdown, until it feels routine. The manufacturers who recover fastest are almost never the ones with the most advanced tooling. They are the ones for whom the bad day is not the first time anyone has practised the conversation.

Where This Actually Starts

The wiring between your office and your floor is not going away, and no plant leader is going to trade throughput for isolation. That was never the choice on offer. The choice is whether, on the day something goes wrong, you are running an investigation or an argument.

The manufacturers who will restart fastest in 2026 are building that capability now, quietly, in the least glamorous places: an accurate device register, an access list somebody owns, a boundary you can prove, a restore you have timed with a stopwatch. None of it looks like security spending on a board slide. All of it looks like production capability the moment a filing somewhere uses four careful words about production-related systems.

Start with the register. Find out precisely what is connected to your plant network tonight, and how much of it you could vouch for by morning. Every other decision in this article depends on that answer, and you do not want to be assembling it while the line is down.

More
articles