Cyber Security Services, 20th July 2026
The Increased Attack Surface in Manufacturing
Manufacturing businesses are becoming more connected than ever before adopting newer technologies across every aspect of their business to increase productivity and efficiency. Production lines, warehouse systems, stock systems, office networks, cloud platforms, remote access tools, handheld scanners, smart sensors, connected machines, supplier portals and shop-floor terminals all now play a role in keeping manufacturers moving and remaining competitive in their industries.
Increased connectivity brings huge benefits to productivity and efficiency, allowing for increased visibility and optimisation of the entire production process, reducing waste, providing predictive analysis, automated stock ordering and much more. However, with increased connectivity across the manufacturing estate it also creates a much larger attack surface.
For manufacturing businesses, cyber security is more than just about protecting emails, laptops and servers. It is about protecting systems across the manufacturing process, keeping production running, orders moving, stock visible, machinery available and customers supplied.
Why is manufacturing becoming a bigger target?
Manufacturing environments are often complex, with no two in the same industry being alike. A typical manufacturing business may have standard office IT, production systems, operational technology, servers, engineering workstations, barcode scanners, label printers, machine terminals, warehouse devices, cloud applications, IoT devices (Example: Rasperry Pi or Arduino), and that is just naming a few. But in many cases, this can also involve third-party remote access from suppliers or maintenance partners to ensure that their equipment is working, optimised, up to date or just supported when the business experiences issues.
The problem?
Each of these systems can become a potential entry point for cyber criminals if it is not properly managed, secured and monitored.
The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses reported experiencing a cyber security breach or attack in the previous 12 months, across more than 5.19 million attacks. Phishing remained the most common entry point for cyber criminals, accounting for 93% of entry points for impacted businesses.
For manufacturers, the concern is not simply if their data that could be stolen or if cyber criminals can target their systems. It is the operational disruption that could follow.
Make UK research found that production stoppages were the most common result of a cyber attack on manufacturers, reported by 65% of affected businesses. But a cyber attack does not always stop at the manufacturing level, with the same survey finding that 43% of manufacturers also experienced reputational damage as a result.
Increasingly we are speaking with businesses across a wide range of industries (including manufacturing) who are finding that their customers are requiring reassurance around cyber security before signing contracts, usually in the form of Cyber Essentials Plus Certification to prove that manufacturers are following best practices when it comes to their cyber security tools, services and strategy.
The reason why?
Because cyber attacks on manufacturers can have knock on impacts throughout the wider supply chain.
Why is Cyber Security for Manufacturing more challenging?
One of the biggest cyber security challenges in manufacturing is the number (and variety) of endpoints that sit outside the “normal” office technology lifecycle.
In a typical office environment, laptops and desktops are usually replaced, patched or upgraded on a more predictable schedule. With complete device refreshes every 5(ish) years. However, in manufacturing, that is not always cost effective or even possible in many cases. Some “shop-floor” terminals, machine-connected PC’s, Human-Machine Interfaces (HMI’s), production workstations and specialist control systems may rely on older machinery or use vendor-specific software that is tied to unsupported/outdated operating systems.
In many of these cases, the machine itself will likely still perform perfectly well for its use case, but the computer or operating system supporting it may no longer receive operating system or security updates to patch known vulnerabilities that cyber criminals could use to target businesses. This creates a difficult balance between operational practicality and cyber security risk.
Older unsupported systems are a major cyber security concern because known vulnerabilities in older software or operating systems will likely never be patched, however those same machines require connectivity to either an internal network to operate or may require an external connection for manufacturer support. The National Cyber Security Centre warns that obsolete devices should be treated as untrusted and given limited access to your business network, and that unpatched devices that could be exposed to malicious content (in this case from remote access to those machines) are likely to become compromised. Attackers can use these older devices to gain initial access into your business, providing them with a potential back door to launch further attacks if you do not have the right security in place.
For manufacturers, this matters because older systems are often positioned close to production and are likely tied directly into other internal systems relating to client orders, stock/vendor management, and potentially personal or financial data from this. This could allow cyber criminals to not only steal this data, but also potentially launch further attacks (such as ransomware) as a result.
Why does a flat network increase the risk of attack?
Many manufacturing businesses have grown their networks over time. New systems are added when required, new machinery is connected, suppliers are given remote access, and production data is linked into business systems such as ERP, finance, stock/asset management and even other customer service platforms.
Without a proper network design that takes into account all devices, users and potential use cases or risks, this can lead to a “flat network”. A “flat network” is where too many systems exist on a single subnet and can communicate with too many other systems throughout your wider business infrastructure on that same network.
Why is this a problem?
The risk with a “flat network” is that if one endpoint becomes compromised, it could potentially grant an attacker access into other parts of the business.
A phishing email opened by an office user should not be able to impact production machinery. And a vulnerable shop-floor terminal should not be able to communicate freely with finance systems, domain controllers or backup platforms.
The NCSC describes “zoned” or “segmented” network architecture as one of the most effective strategies for reducing the impact of compromise. By dividing networks into smaller, functionally isolated subnets, that provide limited (or no) access to the rest of your business network, businesses can contain threats within the zone where they originate and reducing the opportunity for lateral movement.
In a manufacturing environment, this means separating Office IT Equipment, Production Networks, Manufacturing Machinery, Guest Wi-Fi, Supplier Access, Backup Infrastructure and other Critical Operational Systems into separate networks with only the access to what they require for essential function wherever possible.
The operational and financial impact of cyber attacks
A cyber attack in manufacturing can quickly become a business continuity issue.
If production systems are unavailable, orders may be delayed. If warehouse systems are offline, stock movements may be affected. If labelling, scanning or dispatch systems cannot be trusted, deliveries may stop. If suppliers or customers are impacted, the problem can quickly spread across the wider supply chain.
The financial impact can include lost production, missed deadlines, overtime, recovery costs, contractual penalties, emergency consultancy, reputational damage and increased insurance scrutiny.
The 2025 Jaguar Land Rover (JLR) cyber attack showed how severe this can become at scale. Reuters reported that the incident cost the British economy an estimated £1.9 billion and affected more than 5,000 businesses, with the majority of the financial impact linked to lost manufacturing output at JLR and its suppliers.
Whilst not every incident will be on that scale, it is an important example and lesson for every manufacturer that they are never too big or too small to be targeted by cyber criminals, and the impact of such attacks can have lasting effects.
Cyber Security incidents are not “just an IT issue”, they can stop production, impact suppliers, affect cash flow and damage the reputation of your business amongst customers and suppliers alike.
Why is Cyber Security Compliance becoming more important?
Over the past couple of years, we have begun to see a major shift for manufacturing businesses, especially those working with larger organisations, regulated sectors, public sector contracts or supply chain frameworks, with many of these now requiring some level of cyber security compliance and assurance.
Cyber Essentials is the minimum standard of cyber security recommended by the UK Government for businesses of all sizes. It is built around five technical controls designed to prevent the most common cyber security threats.
Those five controls cover secure configuration, user access control, malware protection, security update management and firewalls.
Cyber Essentials Plus goes further by applying the same protections but with more rigorous, independent technical testing of the tools and solutions that are in place, providing greater assurance that the controls are not only documented, but working in practice.
However, despite the increasing requirement of manufacturers to become certified, the UK Government Cyber Breaches Survey shows that the number of UK Businesses with Cyber Essential Certification only stands at 5% on average. Thankfully adoption is increasing, the proportion of UK businesses (as a whole) holding Cyber Essentials rose from 3% in 2024/2025 to 5% in 2025/2026, with Larger Businesses rising from 21% to 35% and Small Businesses from 5% to 12%.
For manufacturers, Cyber Essentials is not only increasing being required for contracts, but it is an essential way to build customer trust, gain better insurance rates, but can also benefit procurement and supplier assurance.
How can manufacturing businesses reduce cyber security risks?
The first step is visibility. Do you know where your cyber security risks are?
When is the last time your business undertook a cyber security risk assessment?
In 2025, only 30% of businesses (and 27% of charities) undertook a cyber security risk assessment.
By having regular formal independent reviews of your business infrastructure, it will allow you to identify risks and put solutions or processes in place to be able to patch vulnerabilities.
Not only should Manufacturing businesses maintain an up-to-date asset inventory that includes office devices, production endpoints, servers, cloud systems, network equipment, remote access tools, software versions, operating systems and other supplier-managed systems. But it is also important to identify any other connected machinery, such as manufacturing equipment which requires network or internet access. By doing so, it ensures that all of these devices (and use cases) can be accounted for as part of a review of your business cyber security strategy. The NCSC says that if businesses cannot see or understand what is involved in their operational technology environment, they cannot truly defend it from the latest threats.
As part of this, it is essential that you identify unsupported, end-of-life or other high-risk systems. This is especially important for manufacturing terminals, connected machines and production devices running older operating systems or software. Where it is possible, they should be upgraded, replaced or moved to supported platforms. However, for the many occasions where this is not possible, they should be technically isolated, heavily restricted and actively monitored.
Manufacturers should avoid “flat networks” at all costs. Office IT, production systems, guest access, supplier access, backup systems and critical devices for business operation should be separated using VLANs (additional secured subnets), firewall rules, user/device access controls and clear network boundaries. This ensures that users and/or devices should only be able to communicate with the systems they genuinely need and only access the data that is necessary for that user/device.
If your business has not reviewed its endpoint security, maybe you should do so sooner rather than later. Studies have shown that traditional anti-virus solutions were only 30% to 40% effective against modern polymorphic and metamorphic style cyber security threats. This is why it is important to ensure that your business has a far more holistic layered approach to endpoint security, including extended endpoint detection & response solutions, zero-trust endpoint and network solutions, active email threat protection, identity access management solutions (including multi-factor authentication, policies of least privileged access ), patch management, cyber security operations centre monitoring, and much more. For older systems that cannot support modern security tools, compensating controls become even more important.
For manufacturers, it is also important to remember that remote access should be tightly controlled. Many manufacturing machines/terminals are often pre-loaded with remote access software from the vendor/supplier for remote support. Whilst this is convenient if you experience an issue, it can also present a supply chain security vulnerability. What could happen if the vendor suffered a cyber attack? Could cyber criminals use these remote connections to launch attacks on your business? Supplier and maintenance access should use multi-factor authentication, named accounts, have time-limited access, be monitored, involve an auditable log and approval have strict approval workflows (such as your business having the administrator credentials to type in authentications). Shared accounts, local administrators and always-on remote access create unnecessary risk.
Backups are often one of the first things that cyber criminals target. Why? Because they know that without your backups that you are more likely to pay in a ransomware style attack. Manufacturing businesses should ensure backups are secure, immutable, tested, separated from the main network where appropriate and designed around your wider business continuity strategy.
As cyber attacks evolve and industry requirements for cyber security become stronger, it is important that Cyber Essentials and Cyber Essentials Plus should be treated as more than tick-box exercises and should be embedded as part of a wider cyber security compliance approach. For manufacturers, they provide a useful framework for improving cyber hygiene, identifying weaknesses and proving to customers, suppliers and insurers that your business is taking cyber security seriously.
How TwentyFour tailor our solutions for Manufacturers
At TwentyFour we understand that every business is different. We don’t just mean businesses across different industries, we mean every business. No two manufacturers are alike, and as such it is essential that manufacturers ensure that their solutions are tailored for their business and how they operate. Production systems may require careful change control, planned maintenance windows, vendor involvement and operational testing before updates and security controls are applied, minimising disruption to the business, whilst maximising their security.
That does not mean cyber risk should be accepted without question.
Manufacturing businesses need a practical, risk-based approach that protects their business without creating unnecessary disruption. The goal is to understand which systems are critical, where your vulnerabilities lie, which networks should be separated, which users need access, and how quickly the business can recover if something goes wrong.
Yes, the attack surface in manufacturing is increasing, but so is the ability to manage and mitigate those threats. With the right visibility, network security, endpoint protection, monitoring, compliance planning and business continuity measures, manufacturers can significantly reduce their risk without impacting production.
Cyber Security is no longer just a technical requirement, it’s a part of operational resilience, customer trust and long-term business performance.
Contact us for our no obligation cyber security audit to identify your risks and vulnerabilities.
Enquire Here


