For years, the cybersecurity conversation in manufacturing focused on IT. The concern was protecting emails, financial data, customer records, and business systems. Those risks still matter. But the more urgent threat has changed.
Cybercriminals have learned that the fastest way to create pressure is not always to steal information. It is to stop production.
$10.5 trillion. That's what cybercrime costs the global economy every year — more than the GDP of every country except the United States and China. It is growing at roughly 15% per year, faster than most legitimate businesses. And the primary engine of that growth is ransomware levied against operational technology.

For years, the cybersecurity conversation in manufacturing focused on information technology. The concern was protecting emails, financial data, customer records, and business systems. Those risks still matter. But the more urgent threat has changed.
Cybercriminals have learned that the fastest way to create pressure is not always to steal information. It is to stop production.
OT, or operational technology, includes the systems that control machines on the factory floor: programmable logic controllers, robotic controls, drives, motion controls, and the automation systems that keep production running. When those systems go down, the business stops. And a stopped production line creates leverage that cybercriminals have learned to exploit very efficiently.
US-based organizations account for 55% of global ransomware attacks. Not manufacturing operations in Asia. Not Europe. The United States. And ransomware attacks overall surged 58% in 2025 alone. For manufacturers, that is not an abstract threat. It is an accelerating one.
Why OT Ransomware Creates Such Acute Pressure
A cybercriminal does not need to understand your manufacturing process to cause damage. They do not need to steal your intellectual property. They only need to interrupt the systems that keep your machines running.
I have seen organizations experience ransomware events that stopped production lines and created losses measured in hundreds of millions of dollars. Paper companies unable to make paper. Auto assemblers unable to assemble vehicles. Printing companies brought to a complete halt because the controller running the production line was no longer available.
When that happens, the question is no longer theoretical. It becomes very practical, very quickly: How fast can we get running again?
There is something else worth understanding about how sophisticated these attacks have become. Once criminals are inside a network, they can learn a great deal about the organization. They can see the size of the company, the value of the assets, and the likely financial impact of downtime. That gives them the ability to calibrate their ransom demand around exactly what the organization can withstand.
I recently sat at an industry roundtable where the majority of CEOs in the room had experienced a ransomware event within the last three years. Most companies do not advertise it because it does not reflect well on them. But it is happening everywhere. This is not random mischief. It is economic pressure applied to operational weakness.
Remote Access Is Part of the Risk Conversation
Remote access to industrial machines has created real value for manufacturers and machine builders. For more than 20 years, it has allowed technicians to diagnose problems, reduce downtime, and support customers anywhere in the world. I often describe it as a very long programming cable. From your desk, you can reach out and connect to a machine across the state or on another continent.
That capability is valuable. But it has to be governed correctly, and that is where many environments have accumulated serious risk over time.
Across a single production environment or a global machine fleet, access may include cellular modems, jump servers, black-box devices with username and password access, direct VPN connections, and vendor-specific tools. I have spoken with customers managing 600 different access paths across their global fleet. Each one may have been reasonable when it was added. Together, they create a fragmented security problem that is very difficult to see and even harder to govern.
For IT and OT security teams, every one of those paths must be understood, monitored, controlled, updated, and audited. When there are hundreds of different methods, that is not a connectivity strategy. It is a vulnerability map.
Purpose-Built Protection for the Factory Floor
Industrial environments are not office environments. A programmable logic controller is not a laptop. A machine network is not a typical corporate network. Generic connectivity tools were not designed for the nuanced requirements of OT, and they are not enough.
What industrial environments need is connectivity designed specifically for operational technology. That means access must be controlled at the asset level. Security teams need to know who can connect, what they can reach, when they can connect, and what happened during the session. Activity logs need to be compatible with SIEM systems so enterprise security teams have full visibility into remote access events rather than leaving those events outside the security model entirely.
The goal is not to prevent service. The goal is to make service safe, controlled, and auditable.
Zero-Day Vulnerabilities Require Constant Vigilance
Ransomware defense is not something you set once and revisit annually. The threat environment changes constantly. One important example is the zero-day exploit: a software vulnerability discovered before a patch or mitigation is widely available. When that vulnerability becomes known, attackers can move within hours.

At ei³, we subscribe to government and industry vulnerability bulletins and when a relevant risk appears, our objective is to patch our full fleet of deployed devices rapidly, including over-the-air updates across devices in factories around the world. The goal is to get that distributed within 24 hours.
Industrial security is not only about choosing the right architecture on day one. It is about actively maintaining and defending that architecture over time, by people who understand both cybersecurity and the realities of OT.
Standardized Connectivity Reduces Exposure
One of the most important steps manufacturers and machine builders can take is to standardize how machines connect. When every machine has its own access method, security becomes fragmented. When connectivity is standardized, access can be governed through a consistent architecture. That creates real advantages:
- Access policies can be enforced consistently across the fleet
- Remote service activity can be logged and audited in a usable format
- Permissions can be managed centrally, including through enterprise Active Directory
- Connections can be limited to the specific asset being serviced
- Security teams can see what is happening instead of trying to interpret dozens of disconnected systems
This is why standardized connectivity is becoming part of the broader conversation around Cyber-Physical Systems Protection Platforms (CPS-PP). The edge is no longer just an access point. It is becoming the first layer of a broader protection architecture.
What Manufacturers Should Do Now to Stay Secure
Ransomware has changed the standard for industrial connectivity. It is no longer enough to ask whether a technician can reach a machine remotely. The better question is whether that access can be controlled, limited, logged, updated, and defended across the full life of the asset. For manufacturers and OEMs, remote access should be evaluated with the same discipline applied to any other critical infrastructure decision:
➤ Can access be granted only to the right person, for the right machine, at the right time?
➤ Can activity be audited in a format enterprise security teams can use?
➤ Can access be revoked quickly when roles, vendors, or service relationships change?
➤ Can devices be patched rapidly when new vulnerabilities emerge?
➤ Can the architecture scale across product lines, facilities, and global fleets?
These are not small technical details. They determine whether remote service strengthens your operation or quietly expands your exposure.
The factory floor will remain a target because downtime creates leverage. Manufacturers cannot remove that reality, but they can reduce the number of uncontrolled doorways into their production environment. That work starts with treating machine connectivity as part of the security architecture, not as an afterthought attached to a service request.
ABOUT THE AUTHOR
Spencer Cramer is the Founder and CEO of ei3 and has over 35 years of experience in manufacturing technology and automation. He founded ei3 in 1999, years before the term “IIoT” became widely used, with a vision to securely connect industrial machines. Since then, Spencer has worked closely with OEMs around the world to help shape remote service and digitalization strategies that improve efficiency, visibility, and machine performance across manufacturing environments.
Spencer Cramer
Connect with me on Linkedin
Find the right CPS Protection Platform for your operation
Our evaluation guide gives you a practical framework to assess and select the security solution that fits your plant floor without slowing production.
Frequently asked questions
Manufacturing has been the most targeted sector for ransomware for five consecutive years. The reason is straightforward: downtime creates immediate, measurable financial pressure. A stopped production line costs tens of thousands to millions of dollars per hour, and criminals know it. Unlike data theft, which may take time to monetize, stopping production creates leverage immediately. Attackers don't need to understand the manufacturing process — they only need to interrupt it.
IT ransomware typically targets business systems — email, financial data, customer records. OT ransomware targets the operational technology that controls machines on the factory floor: programmable logic controllers, robotic controls, drives, and motion controls. When OT systems are compromised, it's not data that stops — it's production. The business impact is immediate and physical: lines halt, shipments miss, customers face delays. Recovery is also more complex because OT systems often cannot simply be reimaged the way a laptop can.
Every remote access pathway into a machine network is a potential entry point for attackers. When organizations accumulate multiple connectivity methods over time — cellular modems, VPNs, jump servers, vendor tools — the attack surface grows with each addition. Attackers specifically target remote access pathways because they provide direct routes into OT environments. Without centralized governance, organizations often have no clear picture of how many access paths exist, who can use them, or whether credentials from previous service relationships have ever been revoked.
Zero-trust means no connection is trusted by default — every access attempt must be verified against defined policies before it is permitted. In an industrial context, that means access is granted only to a specific asset, for a specific person, within a defined time window, and every session is logged and auditable. This is fundamentally different from traditional VPN-based access, which typically grants broad network access once a user is authenticated. Zero-trust architecture dramatically reduces the blast radius if credentials are ever compromised.
The most impactful steps are architectural rather than reactive. Standardize how machines connect so access can be governed through a single platform. Ensure activity logs feed into your SIEM so security teams have visibility into remote access events. Implement asset-level access controls so technicians can only reach the specific machine they're servicing. Establish a process for rapid over-the-air patching when zero-day vulnerabilities emerge. And audit your existing access paths — if you don't have a clear inventory of every remote access method in your environment, that's the first problem to solve.