A production line does not need to be directly hacked to stop. A compromised office account can expose supplier data, a ransomware infection can take out scheduling systems, and a poorly secured remote connection can provide a route into operational technology. This manufacturing cyber security guide is designed for UK manufacturers that need practical protection without creating unnecessary friction on the shop floor.
For most small and mid-sized firms, the priority is not buying every available security tool. It is understanding where disruption would hurt most, then putting sensible controls around those points. The result should be technology that supports uptime, quality and delivery performance rather than adding another layer of operational complexity.
Why manufacturing is a distinct cyber security challenge
Manufacturing environments combine systems that were not designed together. Finance, procurement and HR systems may sit in the same IT estate as production planning, programmable logic controllers, sensors, engineering workstations and vendor-maintained machinery. Some assets can be patched quickly. Others need a planned maintenance window, specialist support or a full risk assessment before any change is made.
That difference matters. An IT security team may be used to applying an urgent update across laptops overnight. Doing the same to an industrial control system without understanding the equipment, process and supplier guidance could interrupt production or affect safety. Conversely, leaving known weaknesses unaddressed because a system is difficult to update is not a sustainable strategy.
The right approach is proportionate. Separate business systems from production systems, understand which equipment is critical, and make security decisions with operations, engineering and IT involved. Cyber security in manufacturing is as much about continuity planning as it is about preventing an attack.
Start with the disruption you cannot afford
A useful risk assessment begins with operational questions rather than technical jargon. What would stop dispatch? Which systems hold recipes, drawings, tooling data or quality records? Can production continue if the planning system is unavailable? How long could the business operate without access to email, shared files or remote supplier support?
Map the process from order to delivery. Include the systems, people, third parties and data involved at each point. This often reveals dependencies that are otherwise overlooked, such as a single workstation used to programme machinery or a shared account used by an external maintenance provider.
Your asset list should cover more than servers and laptops. At a minimum, record:
- production machinery, controllers and engineering workstations
- network equipment, wireless access points and remote access services
- business applications for planning, stock, finance and quality management
- cloud services, backup platforms and data held by suppliers or subcontractors
For each item, identify the owner, its business role, whether it is supported, how it connects to the network and what happens if it is unavailable. It does not need to be a perfect document on day one. It needs to be accurate enough to guide decisions when time is short.
Separate IT from operational technology
Network segmentation is one of the most valuable controls in a manufacturing environment. Put simply, a problem on an office device should not be able to spread freely to a production network. Equally, machinery and control systems should not have unrestricted access to business systems or the internet.
Segmentation can range from basic separation using firewalls and managed network rules through to more detailed zones for different production areas. The right design depends on the age of equipment, the way data needs to move and the tolerance for downtime. A site with modern connected machinery may need carefully managed data flows between production, planning and reporting. A legacy environment may require a more cautious staged plan.
Avoid treating this as a one-off network project. Document authorised connections, review them after equipment changes and remove old routes that are no longer needed. Remote access deserves particular attention. If a machine supplier needs access for support, it should be approved, time-limited where possible, protected by multi-factor authentication and logged. An always-open remote connection is convenient until it becomes the path an attacker uses.
Control access without slowing people down
Most serious incidents start with a stolen password, a deceptive email or an account with more access than it needs. Multi-factor authentication is now a baseline control for email, cloud services, remote access and administrator accounts. It will not prevent every attack, but it makes a password alone far less useful to a criminal.
Access should follow roles, not convenience. An accounts colleague does not need engineering system access, and a production operator does not need administrator rights on a shared workstation. Review accounts when staff move roles or leave, including contractor and supplier accounts. Shared logins should be replaced where practical because they remove accountability and make incident investigation much harder.
This is also where staff awareness has a direct operational value. Training should use realistic examples: a false delivery update, an urgent change to bank details, a quotation request with a malicious attachment, or a message appearing to come from a director. Brief, regular guidance is more useful than an annual presentation that people quickly forget. Staff should know how to report something suspicious without worrying that they will be blamed for raising it.
Patch with care, but do not accept permanent exposure
Patching is rarely straightforward on the factory floor. Older equipment may run operating systems that are no longer supported, and updates can affect specialist software or machine interfaces. However, a difficult patching process does not mean doing nothing.
Create a patching policy that distinguishes between standard IT assets and operational systems. Laptops, servers, firewalls and cloud applications should follow a regular, managed update cycle. For production assets, maintain a schedule agreed with engineering and equipment suppliers, test changes where possible and use maintenance windows that minimise operational impact.
Where a critical system cannot be patched, apply compensating controls. These may include network isolation, restricted access, application allow-listing, enhanced monitoring and a clear replacement plan. The key is to know the risk, document the reason for the exception and avoid allowing temporary workarounds to become permanent blind spots.
Back up what brings production back
A backup is only useful if it can be restored within the time your operation can tolerate. Many businesses back up office files but overlook configuration files, machine programmes, production databases, quality records and the documentation needed to rebuild a system.
Use the 3-2-1 principle as a practical starting point: keep three copies of important data, on two types of storage, with one copy kept separate from the main network. That separate copy is vital in a ransomware incident, where attackers may attempt to encrypt or delete accessible backups before making their demand.
Test restoration regularly. Do not limit the test to recovering a single file. Confirm that a key system can be rebuilt, that the right people know the recovery steps and that the restored data is usable. Recovery objectives should be set with operations leadership. Restoring a planning system in three days may be acceptable for one business and commercially damaging for another.
Prepare for an incident before one happens
When an incident occurs, uncertainty creates delays. A short, tested incident response plan gives people a route to follow. It should set out who can decide to isolate systems, who contacts the IT provider, how staff and customers are updated, and when insurers, legal advisers or relevant authorities need to be involved.
Include practical alternatives for essential processes. Can goods be received, picked or dispatched using controlled manual records? Where are current supplier and customer contact details held if email is unavailable? Who has authority to approve emergency expenditure? These are business continuity questions, but they determine how well the organisation withstands a cyber incident.
Run a tabletop exercise with senior leaders, operations and IT. Use a credible scenario, such as ransomware affecting planning and file shares at 6am on a Monday. The aim is not to catch people out. It is to identify unclear decisions, missing contact details and recovery assumptions before they affect a live order book.
Make cyber security part of operational management
The strongest manufacturing security programmes are reviewed alongside health and safety, maintenance and quality, not treated as an isolated IT task. Report on a small number of useful measures: completion of critical updates, multi-factor authentication coverage, backup recovery tests, unsupported systems, suspicious email reports and progress against agreed risks.
External partners should be held to the same practical standard. Ask suppliers how they secure remote access, how quickly they will support a recovery, and what happens if their own systems are compromised. Contracts and support arrangements should reflect the operational importance of the service, particularly where a supplier has access to machinery or sensitive design information.
For manufacturers with limited internal IT resource, a managed technology partner can bring the oversight needed to monitor systems, improve resilience and keep changes moving without distracting operations leaders. CETSAT’s approach is built around this balance: applying enterprise-grade security practices in a way that fits the day-to-day reality of a growing organisation.
The most useful next step is to choose one production-critical process and trace its dependencies from start to finish. The weaknesses that emerge will give you a clearer, more credible security plan than a generic checklist ever could.

