The plant rarely gets hacked. It gets switched off.
Manufacturing has been the most-attacked industry for five years running, and most of those attacks never touch a controller. They start in the office, cross a boundary that was supposed to be there, and stop the line by encrypting the servers that run it — or by forcing you to shut everything down to contain them. This page is about that path, what a stopped day costs you, and how to test it without stopping anything.
Manufacturing cybersecurity is mostly about the boundary between the office network and the plant. Most attacks that stop production start in IT — a phished login or an unpatched VPN — and reach the servers, historians and engineering workstations that run the line. Report incidents to CERT-In within six hours; OT and SCADA attacks are on the list. Start by mapping every path from IT into OT, then test those paths, passively where the equipment is live.
Why manufacturing
Five years at the top of the target list.
IBM’s 2026 X-Force Threat Intelligence Index put manufacturing at 27.7% of the incidents it responded to in 2025 — the most-targeted industry for the fifth consecutive year. In Asia-Pacific the share was far higher: manufacturing accounted for 65% of the incidents X-Force handled in the region. In India, CERT-In’s ransomware report found the same thing from the other side: manufacturing was the sector most targeted by ransomware in 2024.
The reason is not that attackers understand ladder logic. It is that a manufacturer cannot tolerate downtime, so the pressure to pay — or to restore at any cost — is unusually high. Dragos tracked 119 ransomware groups hitting 3,300 industrial organisations in 2025, more than two-thirds of them manufacturers, and noted how often these incidents are logged as “IT only” because the machine that was encrypted was a Windows server running SCADA software or an engineering workstation.
The clearest recent example is Jaguar Land Rover, part of the Tata group. A cyberattack announced on 2 September 2025 shut production at its major plants and sent staff home; the company put the cost at £196 million in that quarter alone. The UK’s Cyber Monitoring Centre estimated the wider damage at £1.9 billion across more than 5,000 UK organisations — most of them suppliers who could not ship to a customer that could not build. Closer to home, Tata Technologies disclosed a ransomware attack to the National Stock Exchange in January 2025 and suspended some IT services while it recovered.
For an Indian supplier the question is therefore two-sided: what happens to your own line, and what your customers now require of you because of what happened to theirs. Both lead to the same place — the boundary between IT and OT, and whether you can prove it holds.
Evidence
What the incident data says about manufacturing
From IBM’s X-Force incident response work, Dragos’s industrial threat intelligence, CERT-In’s ransomware analysis and the Jaguar Land Rover disclosures. Each figure is linked in the sources.
27.7%Of incidents IBM X-Force responded to in 2025 were at manufacturers — the most-targeted industry for the fifth year [1]
65%Share of X-Force’s Asia-Pacific incidents that hit manufacturing [2]
3,300Industrial organisations hit by ransomware in 2025, more than two-thirds of them manufacturers [3]
42 daysAverage ransomware dwell time in OT environments — against 5 days where OT visibility was comprehensive [3]
£196MCost to Jaguar Land Rover of its September 2025 cyberattack, in a single quarter [5]
£1.9bnModelled UK economic impact of the same incident, across more than 5,000 organisations [6]
CERT-In’s India Ransomware Report for 2024 names manufacturing as the most-targeted sector in India, ahead of finance and IT. IBM’s 2026 India study found offensive security testing to be the single largest factor reducing the cost of a breach.
The attack path
From an office inbox to a stopped line, in five steps
The composite path behind most manufacturing incidents. Each step is a place to test — and a place the attack can be stopped.
1
A foothold in IT
A phished login, reused credentials, or an internet-facing VPN or remote-access tool with a known, unpatched flaw. Vulnerability exploitation was the leading cause of the attacks IBM saw in 2025.
External perimeter and phishing resilience
2
Domain administrator
Weak Active Directory permissions turn one account into control of every Windows machine on the network — including the ones on the plant floor that were joined to the office domain for convenience.
Active Directory privilege paths
3
Across the boundary
A dual-homed server, a historian replicating into the office, a jump host with saved credentials or a vendor remote-access tool that bypasses the firewall. This is where “segmented” turns out to mean “mostly”.
Firewall rules and routes between IT and OT, tested from the IT side
4
The servers that run the line
MES, SCADA servers, HMIs and engineering workstations — ordinary Windows machines that happen to hold production. Ransomware here stops the plant without touching a controller.
Configuration and architecture review; active tests only on replicas, with written instruction
5
Production stops
Either the encrypted servers take the line down, or the company switches production off to stop the spread — which is what a responsible plant does, and why the cost lands either way.
The controllers usually survive untouched. What fails is the assumption that the office and the plant were separate. Finding the real paths between them — before an attacker does — is most of the work.
Your numbers
What would a stopped line cost you?
Put in your own figures — the defaults are placeholders, not benchmarks. Nothing you enter leaves this page.
Cost of this stoppage
—
Lost margin
—
Idle wages
—
Recovery
—
Per hour stopped
—
This is a floor, not a forecast: it leaves out ransom, regulatory exposure, lost customers and the cost to your own suppliers. Jaguar Land Rover’s single quarter came to £196 million.
Level by level
What we test actively, what passively, and what we leave alone
Organised by the Purdue reference model, the layering most plant networks are designed — or supposed to be designed — around. The line between active and passive is agreed in writing before anything runs.
Level
What lives there
How we test it
Not without your written instruction
Levels 4–5 · enterprise IT
Email, ERP, the office network, Active Directory, cloud
Active — full penetration testing, as for any corporate network
—
Level 3.5 · the IT/OT DMZ
Jump hosts, historian replicas, patch and antivirus relays, vendor remote access
Active, from the IT side — can anything in IT reach past this layer?
Testing from inside the DMZ towards the plant
Level 3 · site operations
MES, historians, engineering workstations, domain controllers for the plant
Mostly passive — configuration and account review; active tests in agreed windows or on replicas
Any test that could restart a service during production
Passive only — asset and firmware inventory from observed traffic, logic backup review
Anything at all that sends traffic to a live controller
Level 0 · the process
Sensors, actuators, motors, valves
Architecture and physical review
Not tested
Where active testing below Level 3 is genuinely needed, it is done on a spare controller or a test bench, with your automation engineers present. ISA/IEC 62443 is the standard family most OT security programmes are built against; SemperWise is not an IEC 62443 certification body.
Next step
Start with the boundary, not the controllers.
A 30-minute call with a practitioner who scopes around live production. No charge, and no obligation.
A first map of the likely paths from your office network into the plant
A written agreement on what is tested actively, passively, or not at all
A fixed price, with a retest of every fix included
Findings mapped to ISO 27001 and to what your customers audit — TISAX, NIS2 or CMMC
Most of these do not bind an Indian manufacturer directly. They bind your customers — who then write them into your contracts and questionnaires.
April 2022
CERT-In Directions In force now
Binds you directly. Listed incidents — including attacks on SCADA and operational technology — must be reported within six hours, and logs kept for 180 days in India.
October 2024
NIS2 applies across the EU In force now
Manufacturers of electrical equipment, machinery, motor vehicles and other listed products are “important entities” in the EU, and must manage supply-chain security — which reaches their Indian suppliers through contracts and audits.
Ongoing
TISAX for automotive In force now
The automotive industry’s shared assessment and exchange mechanism, run by the ENX Association: a third-party audit whose result an OEM can check instead of sending its own questionnaire. Increasingly a condition of doing business with European carmakers.
10 November 2025
CMMC Phase 1 begins In force now
US defence contracts started carrying Cybersecurity Maturity Model Certification requirements, flowed down from prime contractors to their suppliers — Level 1 self-assessment against 15 requirements, Level 2 against 110.
13 May 2027
DPDP Act duties Coming
Employee, dealer and customer personal data becomes subject to the Act’s security safeguards and 72-hour breach reporting.
SemperWise is not a TISAX audit provider, a CMMC third-party assessment organisation or an IEC 62443 certification body. We prepare you for those assessments, test what they will look at, and you appoint the accredited party directly.
In the room
Four people, four different reasons to care
An OT security programme fails when it is owned by one of these people and ignored by the other three.
Plant head
Worried about
An unplanned stop, a safety incident, and a customer’s line waiting on parts that were not shipped.
Has to show
That testing will not disturb production — and that recovery has actually been rehearsed.
What we hand them
A written test plan with production-safe windows, and a recovery exercise built around the servers that run the line.
Automation / OT engineering
Worried about
Anyone touching controllers they did not commission, and security rules that break vendor support.
Has to show
That the plant network works exactly as it did before.
What we hand them
Passive findings in their language — assets, firmware, flows — and changes proposed through their own change control.
CIO or IT head
Worried about
Being blamed for a plant stoppage that started on a machine IT never managed.
Has to show
Where the IT/OT boundary really is, and who owns each side of it.
What we hand them
A tested map of every path across the boundary, and the Active Directory paths that lead to them.
CFO and board
Worried about
An exposure nobody has priced, and a customer contract that now carries security clauses.
Has to show
That the risk is sized, owned and falling.
What we hand them
A stoppage cost built on your own numbers, a risk register the board can read, and evidence your customers will accept.
Where SemperWise fits
What we do for manufacturers and their suppliers
Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.
“Can the office network reach the plant?”
Service
External perimeter, Active Directory and IT/OT segmentation testing — active on the IT side, from the IT side, in agreed windows.
A passive OT assessment: asset and firmware inventory from observed traffic, architecture and configuration review, and a prioritised list of boundary fixes. Nothing sent to a live controller.
“Our VPN and vendor remote access face the internet.”
SemperWise One™
Continuous discovery of internet-facing services, so a new remote-access portal or an exposed remote desktop is noticed the day it appears.
Readiness against the customer’s rulebook, built on ISO 27001, so one programme answers several customers. You appoint the accredited assessor; we get you ready for them.
What buyers in this sector ask us before they commit to anything.
What is OT security, and how is it different from IT security?
Operational technology is the equipment and software that runs physical processes — controllers, drives, SCADA servers, HMIs and historians. IT security protects information; OT security protects a process that must keep running safely. That changes the priorities: availability and safety come before confidentiality, patching may wait years for a vendor-approved window, and testing has to be designed so it cannot disturb production. The attacks, though, are mostly the same ones seen in IT — which is why the IT/OT boundary is where an OT programme usually starts.
Can you test PLCs and SCADA without stopping production?
Yes, because most of the useful testing does not touch them. Live controllers and safety systems are passive-only for us unless you instruct otherwise in writing: we build an inventory from observed traffic, review configurations, logic backups and architecture, and test the network paths that reach the plant — from the IT side. Where active testing of a controller is genuinely needed, it happens on a spare unit or a test bench with your automation engineers present. See the level-by-level table on this page.
What is the Purdue model, and does it still matter?
The Purdue reference model describes a plant network in layers — from the physical process at Level 0 up through controllers, supervisory systems and site operations to enterprise IT at Levels 4 and 5 — with a buffer zone between IT and OT. Real plants rarely match it neatly, and cloud connections and remote vendor access cut across the layers. It still matters as a common language and as the frame for deciding how each zone may be tested, which is how we use it.
Does NIS2 apply to Indian manufacturers?
Not directly, unless you operate in the EU. NIS2 binds medium and large manufacturers of listed products in the EU — electrical equipment, machinery, motor vehicles, computers and electronics, medical devices and other transport equipment among them — and it requires them to manage the security of their supply chains. That is how it reaches an Indian supplier: through contract clauses, questionnaires and audit rights from European customers. The practical response is a documented, tested programme — usually built on ISO 27001 — that can answer those customers with evidence.
What is TISAX, and do Indian automotive suppliers need it?
TISAX is the automotive industry’s shared information security assessment, run by the ENX Association: a supplier is audited once by a third party and shares the result with the carmakers that ask for it, instead of answering each one separately. It is not a law, but for suppliers to European OEMs it is increasingly a condition of the contract. SemperWise is not a TISAX audit provider; we prepare suppliers for the assessment and test what it looks at, and the audit itself is carried out by an approved provider you appoint.
What does CMMC mean for Indian suppliers to US defence contractors?
Since 10 November 2025, new US Department of Defense contracts have started to carry Cybersecurity Maturity Model Certification requirements, which prime contractors flow down to their suppliers. Level 1 is an annual self-assessment against 15 basic safeguarding requirements for federal contract information; Level 2, for controlled unclassified information, covers 110 requirements and may need an assessment by a certified third-party assessment organisation. SemperWise is not one of those organisations; we help suppliers close the gaps and assemble the evidence first.
Does CERT-In’s six-hour reporting rule apply to a factory?
Yes. The April 2022 CERT-In Directions apply to every body corporate in India, and their list of reportable incidents explicitly includes attacks on critical infrastructure, SCADA and operational technology systems, alongside ransomware and unauthorised access. The report is due within six hours of noticing the incident, and ICT logs must be kept for 180 days in India — including logs from the plant network, where they often do not exist. CERT-In compliance covers the full set of duties.
Isn’t our plant safe because it is on a separate network?
Only if you have tested that it is. Separation erodes quietly: a historian that replicates to the office, an engineering laptop that moves between networks, a vendor’s remote-access tool installed for one job and never removed, a server joined to the office domain for convenience. Dragos notes how often OT incidents begin on exactly these Windows machines and get recorded as IT incidents. Testing the boundary from the IT side is the quickest way to learn whether the separation you designed is the separation you have.
How long does an OT security assessment take, and what does it cost?
It depends on the number of sites and zones and on how much can be observed passively, which is why we do not publish a price list. A typical first engagement covers the IT/OT boundary and a passive assessment of one plant, and runs for a few weeks including the report. We scope it in a 30-minute call at no charge, then send a written scope and a fixed price, with a retest of every fix included.
Sources
Checked by our research desk on 24 September 2026. Regulations and
figures move; where a number here matters to a decision, follow it to the source.
Find the path into the plant before anyone else does.
A 30-minute call, no charge. We agree which zones are tested actively, which passively and which not at all, then send a written scope and a fixed price — with a retest of every fix included.