Table of Contents:

65% of Industrial Ransomware Victims Are Manufacturers

|
Last Updated: Aug 27, 2026

Rising ransomware exposure is forcing manufacturers to treat operational technology security as a procurement decision instead of just adopting a general IT contract because they are dealing with a cybersecurity problem that requires much more than just that.

Dragos recorded 1,140 ransomware incidents impacting industrial organizations in just a single quarter of 2026, noting a steep rise in digital attacks. But it doesn’t just end there. IBM’s 026 X-Force Threat Intelligence Index found that manufacturing accounted for the majority of the cybersecurity incidents observed in 2025.

These findings show that it is the most targeted industry for the fifth consecutive year. This calls for stronger security practices in all domains. Learn more about this with this article.

OT Risk Does Not Stay on the Plant Floor

Operational technology creates a different security challenge from enterprise IT.

Factory environments can include adjustable logic controllers, industrial control systems, engineering workstations, and equipment that may remain in service for years. Security changes therefore have to account for uptime and physical operations, not just data.

The divide does not mean IT and OT issues stay separate.

In the SANS 2025 ICS/OT Cybersecurity Budget survey, 58% of respondents described an IT compromise spreading into OT as the leading initial attack vector for ICS and OT incidents.

Dragos has found the visibility gap remains substantial. Its 2026 OT Cybersecurity Year in Review reports that 56% of assessed OT systems could not see below the IT/OT boundary, while 88% struggled with detection and response.

https://www.linkedin.com/posts/dragos-inc._otthreats-icssecurity-manufacturing-activity-7454953093001220097-VXT7

Those findings matter when industries decide what an MSP is responsible for.

A contract that covers the corporate network but leaves the IT/OT boundary ambiguous may still leave one of the organization’s most damaging attack paths without a clear owner.

OT Is Getting Its Own Budget

Spending patterns already indicate that OT security is becoming a distinct business decision.

SANS found 55% of organizations had increased their ICS/OT cybersecurity budgets during the previous two years. Here’s a detailed post about the same:

https://www.linkedin.com/posts/opswat_icsot-security-budgets-increasing-but-critical-activity-7305210889379434496-AvVH

Control of that money is also divided. IT alone maintained the budget at 31% of organizations. Another 37% shared control between IT and OT, while 26% put control directly with OT teams.

That means a provider selling security into an industrial organization may no longer be dealing only with the CIO or IT department.

Plant leaders, engineering teams, security specialists, and operations executives can all have a financial interest in what gets purchased and who delivers it.

The technical requirements reinforce that separation.

CISA’s industrial cybersecurity guidance recommends network segmentation, firewalls between ICS and corporate IT networks, contained remote access, ICS-specific policies, joint IT/OT incident-response procedures, and cybersecurity requirements within industrial procurement.

Those are not simply additional layers of endpoint protection.

They require knowledge of what can be isolated, patched, monitored, or shut down without damaging production.

The MSP Renewal Now Has an OT Test

This does not mean manufacturers are uniformly dropping generalist MSPs.

The available data does not support that claim.

It does show why OT capability is becoming part of the renewal conversation.

CISA recommends maintaining a distance between IT and operational technology and accounting for third-party, MSP, and cloud connections when mapping network access.

Its guidance on network segmentation also says separating IT and OT networks can reduce the ability of attackers to move laterally after disrupting the business network.

That creates specific questions for the incumbent provider.

Can it identify industrial assets? Can it monitor the IT/OT boundary? Does its incident-response process compensate for production systems? Can it secure vendor access without disrupting plant operations? Does it understand when an IT containment action could create an OT problem?

https://www.linkedin.com/posts/sans-institute_ics-ot-icssecurityreport-activity-7421975445216219137-FoFc

If the answer is no, the manufacturer has alternatives.

It can buy a separate OT security service, add a specialist partner, expand the existing contract, or move to a provider capable of covering both spaces.

That is why comparing IT services pricing on headline monthly cost alone becomes less useful in an industrial environment. Buyers need to know which systems, response responsibilities, and security procedures are included in that price.

A low-cost IT contract can look completely unique once OT monitoring, network architecture, remote-access security, and industrial incident response are priced separately.

Downtime Changes What Security Is Worth

Manufacturing makes this distinction commercially valuable because cyber incidents can affect physical output.

Dragos found 747 manufacturing organizations were listed as ransomware victims in Q2 2026, spanning areas that included equipment, building materials, and food and beverage production.

Attackers do not always need direct control-system access to create that disruption. Dragos notes that attacks against enterprise systems supporting industrial operations can still impact production through lost access to ERP platforms, virtualization infrastructure, files, communications, and other dependencies.

The underlying architecture remains a weak point at many organizations.

In its 2026 field assessments, Dragos identified inadequate IT/OT segmentation in 81% of assessments. It also found compromised VPN or jump-host credentials in 73% of its historical incident-response cases.

That puts responsibility at the center of the purchasing decision.

Manufacturers require contracts that define who monitors the boundary between IT and OT, who responds when an attack crosses it, who oversees remote access, and who has authority when a security decision could stop production.

Generalist MSPs do not automatically lose that work.

But they increasingly have to prove they can handle it.

OT security is becoming more than an optional line item inside the IT bundle. For manufacturers who face growing ransomware exposure, it is becoming part of the renewal test.

FAQs

Ans: CISA recommends maintaining a distance between IT and operational technology and accounting for third-party, MSP, and cloud connections when mapping network access.

Ans: Manufacturers require contracts that define who monitors the boundary between IT and OT, and who has authority when a security decision could stop production.

Ans: A contract that covers the corporate network but leaves the IT/OT boundary ambiguous may still leave one of the organization’s most damaging attack paths without a clear owner.




Related Posts

×