Manufacturing has been the most attacked industry for five years running, even as security ownership more than tripled. The connectivity that modernises a factory is what exposes it.
Manufacturing has been the world’s most attacked industry for five years running. IBM’s X-Force Threat Intelligence Index put it at 23% of all attacks in 2021, 24.8% in 2022, 26% in 2024 and 27.7% by 2025, ahead of every other sector it tracks, including finance and healthcare. Dragos’s separate tracking of industrial ransomware confirms the same pattern from a different angle: manufacturing accounted for 68% of industrial ransomware incidents it recorded in early 2025, rising to 72% by the third quarter. The usual explanation is that manufacturers are behind: older equipment, thinner security budgets, nobody senior enough owning the risk. That explanation is true as far as it goes. It is also the wrong diagnosis, because the sector’s own governance numbers show manufacturers closing that exact gap faster than almost any industry on record, and getting hit more anyway.
Start with who actually owns operational technology security inside these businesses. Fortinet’s annual survey of OT professionals found 16% of organisations had a CISO or equivalent security chief directly responsible for OT security in 2022. That reached 17% in 2023, 27% in 2024, 52% in 2025 and 53% by 2026 (this specific series comes from one consistent source; no independent survey tracks the same measure over the same period, so it is reported here as a single, if long-running, source). Taking that figure from 16% to over half in four years is a faster ownership shift than most regulated industries manage in a decade, not a sector dragging its feet on governance.
If underinvestment in security leadership were the real driver of manufacturing’s attack numbers, that figure should have started falling as ownership spread. It has not. IBM’s attack-share number crept up by fewer than 5 percentage points over the same five years that CISO ownership more than tripled. Whatever keeps pulling attackers toward factories, it is not chiefly a governance gap that appointing a security chief closes.
The part governance cannot fix is physical. Programmable logic controllers and SCADA systems installed 15 to 30 years ago still run production lines at most established manufacturers, and Schneider Electric’s own estimate, produced with ARC Advisory Group, an industrial-market analyst firm rather than a management consultancy, puts roughly $65 billion of industrial automation assets past their useful working life. Manufacturers built these devices for uptime and safety, not authentication or patching. Most cannot run a security agent. Many cannot be patched at all without stopping the line, and stopping the line is exactly what a security team exists to prevent.
That estate used to be safe through isolation. It rarely is now, and not because manufacturers got careless. Every credible piece of factory modernisation depends on pulling data out of that old estate: a digital twin needs a live feed from the machine it models, predictive maintenance needs sensor data reaching a cloud analytics platform, a real-time production dashboard needs the shop floor talking to the same network as the order book. Make UK, the manufacturers’ trade body, said as much directly in its August 2026 report on the sector: digital transformation has widened the attack surface through IT and OT convergence, compounded by the legacy technology already in place. The connectivity that makes a factory more capable is the same connectivity that makes it reachable.
Clorox’s 2023 breach shows how little of that old estate an attacker now needs to touch. According to Clorox’s own lawsuit against its IT services provider, Cognizant, an attacker reached the company by phoning its help desk and talking an agent into resetting an employee’s password and multi-factor authentication with no identity check, then repeating the trick over the following two days until they held domain administrator access across Clorox’s core IT environment. The attacker never breached a PLC. They never touched a SCADA system. But because Clorox’s plants depend on that same IT environment for order processing and production scheduling, the company reverted to manual operations anyway and has since disclosed costs of $356 million. In the UK, KP Snacks lost weeks of deliveries to a Conti ransomware attack in 2022 for much the same reason: the attack likely never reached a single piece of production machinery, only the systems that told the machinery what to make and where to send it.
None of this excuses the governance gaps that are still real. Make UK found that 30% of UK manufacturers had a cyber incident, directly or through their supply chain, in the past year, that fewer than a quarter have a dedicated security chief, that only around half have a tested incident response plan, and that nearly a third have no cyber insurance or do not know whether it covers disruption. Closing those gaps helps. But treating them as the whole problem invites a specific mistake: budgeting for cybersecurity as a one-off catch-up project, something brought up to standard once and then left alone.
Manufacturing’s exposure will not get caught up, because it scales with the connectivity manufacturers keep adding on purpose. Every new sensor feed, every new remote access point for a vendor, every new dashboard pulling shop floor data into a corporate system is a deliberate decision to expose more of a decades-old control estate to a network that nobody built to defend itself. That is not a debt to be paid off once. It is a recurring cost of every worthwhile transformation programme, and it needs its own budget line and its own segmentation plan before the project goes live, not after the first incident.
Fortinet’s OT professionals expect this to become compulsory rather than optional, with 89% now expecting new OT-specific regulation within five years, up from 66% the year before. That squares with the direction of UK policy: the Cyber Security and Resilience Bill is moving through Parliament to widen the scope of the existing NIS Regulations. But the Bill’s current scope targets large infrastructure operators, data centres and their designated critical suppliers, not the manufacturing sector broadly. What that produces in practice is not direct regulation of most factories. It is contractual pressure passed down from the primes that are in scope to the suppliers that are not, which is exactly how a mid-sized manufacturer without a compliance budget ends up carrying risk that a regulator aimed at someone else.
Sources
- IBM, X-Force Threat Intelligence Index (2022, 2023, 2025, 2026 editions)
- Dragos, Q1 2025 and Q3 2025 Ransomware Reports
- Fortinet, State of Operational Technology and Cybersecurity Report (2022-2026 editions)
- Make UK, Cyber Security in Manufacturing (August 2026)
- Schneider Electric / ARC Advisory Group, industrial automation asset lifecycle estimates
- Clorox Company v. Cognizant Technology Solutions, lawsuit filings, reported by BleepingComputer
- Clorox Company, cyberattack cost disclosure, reported by IndustryWeek
- BleepingComputer, “KP Snacks giant hit by Conti ransomware, deliveries disrupted” (2022)
- UK Parliament / GOV.UK, Cyber Security and Resilience (Network and Information Systems) Bill, summary
