AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Manufacturing & OT security

The plant rarely gets hacked. It gets switched off.

Manufacturing has been the most-attacked industry for five years running, and most of those attacks never touch a controller. They start in the office, cross a boundary that was supposed to be there, and stop the line by encrypting the servers that run it — or by forcing you to shut everything down to contain them. This page is about that path, what a stopped day costs you, and how to test it without stopping anything.

Reviewed 24 September 2026 · 14 sources cited

The short answer

Manufacturing cybersecurity is mostly about the boundary between the office network and the plant. Most attacks that stop production start in IT — a phished login or an unpatched VPN — and reach the servers, historians and engineering workstations that run the line. Report incidents to CERT-In within six hours; OT and SCADA attacks are on the list. Start by mapping every path from IT into OT, then test those paths, passively where the equipment is live.

Why manufacturing

Five years at the top of the target list.

IBM’s 2026 X-Force Threat Intelligence Index put manufacturing at 27.7% of the incidents it responded to in 2025 — the most-targeted industry for the fifth consecutive year. In Asia-Pacific the share was far higher: manufacturing accounted for 65% of the incidents X-Force handled in the region. In India, CERT-In’s ransomware report found the same thing from the other side: manufacturing was the sector most targeted by ransomware in 2024.

The reason is not that attackers understand ladder logic. It is that a manufacturer cannot tolerate downtime, so the pressure to pay — or to restore at any cost — is unusually high. Dragos tracked 119 ransomware groups hitting 3,300 industrial organisations in 2025, more than two-thirds of them manufacturers, and noted how often these incidents are logged as “IT only” because the machine that was encrypted was a Windows server running SCADA software or an engineering workstation.

The clearest recent example is Jaguar Land Rover, part of the Tata group. A cyberattack announced on 2 September 2025 shut production at its major plants and sent staff home; the company put the cost at £196 million in that quarter alone. The UK’s Cyber Monitoring Centre estimated the wider damage at £1.9 billion across more than 5,000 UK organisations — most of them suppliers who could not ship to a customer that could not build. Closer to home, Tata Technologies disclosed a ransomware attack to the National Stock Exchange in January 2025 and suspended some IT services while it recovered.

For an Indian supplier the question is therefore two-sided: what happens to your own line, and what your customers now require of you because of what happened to theirs. Both lead to the same place — the boundary between IT and OT, and whether you can prove it holds.

Evidence

What the incident data says about manufacturing

From IBM’s X-Force incident response work, Dragos’s industrial threat intelligence, CERT-In’s ransomware analysis and the Jaguar Land Rover disclosures. Each figure is linked in the sources.

27.7% Of incidents IBM X-Force responded to in 2025 were at manufacturers — the most-targeted industry for the fifth year [1]
65% Share of X-Force’s Asia-Pacific incidents that hit manufacturing [2]
3,300 Industrial organisations hit by ransomware in 2025, more than two-thirds of them manufacturers [3]
42 days Average ransomware dwell time in OT environments — against 5 days where OT visibility was comprehensive [3]
£196M Cost to Jaguar Land Rover of its September 2025 cyberattack, in a single quarter [5]
£1.9bn Modelled UK economic impact of the same incident, across more than 5,000 organisations [6]

CERT-In’s India Ransomware Report for 2024 names manufacturing as the most-targeted sector in India, ahead of finance and IT. IBM’s 2026 India study found offensive security testing to be the single largest factor reducing the cost of a breach.

The attack path

From an office inbox to a stopped line, in five steps

The composite path behind most manufacturing incidents. Each step is a place to test — and a place the attack can be stopped.

  1. 1

    A foothold in IT

    A phished login, reused credentials, or an internet-facing VPN or remote-access tool with a known, unpatched flaw. Vulnerability exploitation was the leading cause of the attacks IBM saw in 2025.

    External perimeter and phishing resilience

  2. 2

    Domain administrator

    Weak Active Directory permissions turn one account into control of every Windows machine on the network — including the ones on the plant floor that were joined to the office domain for convenience.

    Active Directory privilege paths

  3. 3

    Across the boundary

    A dual-homed server, a historian replicating into the office, a jump host with saved credentials or a vendor remote-access tool that bypasses the firewall. This is where “segmented” turns out to mean “mostly”.

    Firewall rules and routes between IT and OT, tested from the IT side

  4. 4

    The servers that run the line

    MES, SCADA servers, HMIs and engineering workstations — ordinary Windows machines that happen to hold production. Ransomware here stops the plant without touching a controller.

    Configuration and architecture review; active tests only on replicas, with written instruction

  5. 5

    Production stops

    Either the encrypted servers take the line down, or the company switches production off to stop the spread — which is what a responsible plant does, and why the cost lands either way.

The controllers usually survive untouched. What fails is the assumption that the office and the plant were separate. Finding the real paths between them — before an attacker does — is most of the work.

Your numbers

What would a stopped line cost you?

Put in your own figures — the defaults are placeholders, not benchmarks. Nothing you enter leaves this page.

Cost of this stoppage

—

Lost margin
—
Idle wages
—
Recovery
—
Per hour stopped
—

This is a floor, not a forecast: it leaves out ransom, regulatory exposure, lost customers and the cost to your own suppliers. Jaguar Land Rover’s single quarter came to £196 million.

Level by level

What we test actively, what passively, and what we leave alone

Organised by the Purdue reference model, the layering most plant networks are designed — or supposed to be designed — around. The line between active and passive is agreed in writing before anything runs.

LevelWhat lives thereHow we test itNot without your written instruction
Levels 4–5 · enterprise IT Email, ERP, the office network, Active Directory, cloud Active — full penetration testing, as for any corporate network —
Level 3.5 · the IT/OT DMZ Jump hosts, historian replicas, patch and antivirus relays, vendor remote access Active, from the IT side — can anything in IT reach past this layer? Testing from inside the DMZ towards the plant
Level 3 · site operations MES, historians, engineering workstations, domain controllers for the plant Mostly passive — configuration and account review; active tests in agreed windows or on replicas Any test that could restart a service during production
Level 2 · supervisory control SCADA servers, HMIs, alarm systems Passive — traffic capture, protocol inventory, configuration review Any active scan or exploit
Level 1 · basic control PLCs, RTUs, drives, safety instrumented systems Passive only — asset and firmware inventory from observed traffic, logic backup review Anything at all that sends traffic to a live controller
Level 0 · the process Sensors, actuators, motors, valves Architecture and physical review Not tested

Where active testing below Level 3 is genuinely needed, it is done on a spare controller or a test bench, with your automation engineers present. ISA/IEC 62443 is the standard family most OT security programmes are built against; SemperWise is not an IEC 62443 certification body.

Next step

Start with the boundary, not the controllers.

A 30-minute call with a practitioner who scopes around live production. No charge, and no obligation.

  • A first map of the likely paths from your office network into the plant
  • A written agreement on what is tested actively, passively, or not at all
  • A fixed price, with a retest of every fix included
  • Findings mapped to ISO 27001 and to what your customers audit — TISAX, NIS2 or CMMC
Book an OT-safe scoping call We reply within 24 business hours.

Through your customers

The rulebooks that reach a supplier, by date

Most of these do not bind an Indian manufacturer directly. They bind your customers — who then write them into your contracts and questionnaires.

  1. April 2022

    CERT-In Directions In force now

    Binds you directly. Listed incidents — including attacks on SCADA and operational technology — must be reported within six hours, and logs kept for 180 days in India.

  2. October 2024

    NIS2 applies across the EU In force now

    Manufacturers of electrical equipment, machinery, motor vehicles and other listed products are “important entities” in the EU, and must manage supply-chain security — which reaches their Indian suppliers through contracts and audits.

  3. Ongoing

    TISAX for automotive In force now

    The automotive industry’s shared assessment and exchange mechanism, run by the ENX Association: a third-party audit whose result an OEM can check instead of sending its own questionnaire. Increasingly a condition of doing business with European carmakers.

  4. 10 November 2025

    CMMC Phase 1 begins In force now

    US defence contracts started carrying Cybersecurity Maturity Model Certification requirements, flowed down from prime contractors to their suppliers — Level 1 self-assessment against 15 requirements, Level 2 against 110.

  5. 13 May 2027

    DPDP Act duties Coming

    Employee, dealer and customer personal data becomes subject to the Act’s security safeguards and 72-hour breach reporting.

SemperWise is not a TISAX audit provider, a CMMC third-party assessment organisation or an IEC 62443 certification body. We prepare you for those assessments, test what they will look at, and you appoint the accredited party directly.

In the room

Four people, four different reasons to care

An OT security programme fails when it is owned by one of these people and ignored by the other three.

Plant head

Worried about
An unplanned stop, a safety incident, and a customer’s line waiting on parts that were not shipped.
Has to show
That testing will not disturb production — and that recovery has actually been rehearsed.
What we hand them
A written test plan with production-safe windows, and a recovery exercise built around the servers that run the line.

Automation / OT engineering

Worried about
Anyone touching controllers they did not commission, and security rules that break vendor support.
Has to show
That the plant network works exactly as it did before.
What we hand them
Passive findings in their language — assets, firmware, flows — and changes proposed through their own change control.

CIO or IT head

Worried about
Being blamed for a plant stoppage that started on a machine IT never managed.
Has to show
Where the IT/OT boundary really is, and who owns each side of it.
What we hand them
A tested map of every path across the boundary, and the Active Directory paths that lead to them.

CFO and board

Worried about
An exposure nobody has priced, and a customer contract that now carries security clauses.
Has to show
That the risk is sized, owned and falling.
What we hand them
A stoppage cost built on your own numbers, a risk register the board can read, and evidence your customers will accept.

Where SemperWise fits

What we do for manufacturers and their suppliers

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

“Can the office network reach the plant?”

Service

External perimeter, Active Directory and IT/OT segmentation testing — active on the IT side, from the IT side, in agreed windows.

Network testing

“What is actually on the plant network?”

Service

A passive OT assessment: asset and firmware inventory from observed traffic, architecture and configuration review, and a prioritised list of boundary fixes. Nothing sent to a live controller.

“Our VPN and vendor remote access face the internet.”

SemperWise One™

Continuous discovery of internet-facing services, so a new remote-access portal or an exposed remote desktop is noticed the day it appears.

Attack surface management

“Our ERP, MES and supplier portals are web applications.”

Service

Authenticated testing of the applications that hold orders, drawings and supplier data.

Web application testing

“Our OEM wants TISAX, NIS2 or CMMC evidence.”

Service

Readiness against the customer’s rulebook, built on ISO 27001, so one programme answers several customers. You appoint the accredited assessor; we get you ready for them.

ISO 27001 as the base

“Every customer sends a different questionnaire.”

SemperWise One™

Answer once, with the control and the dated evidence behind every answer, and reuse it — answers retire themselves when the evidence expires.

Questionnaire automation

“One control set for ISO 27001, TISAX, NIS2 and CMMC.”

SemperWise One™

The unified control model maps each control once to every framework you hold, so evidence gathered for one audit counts for the others.

Unified control model

“We have no security lead for the plants.”

Service

A named senior practitioner a few days a month, with an incident response retainer for the day a line stops.

Virtual CISO

Questions

Manufacturing security — answered.

What buyers in this sector ask us before they commit to anything.

What is OT security, and how is it different from IT security?

Operational technology is the equipment and software that runs physical processes — controllers, drives, SCADA servers, HMIs and historians. IT security protects information; OT security protects a process that must keep running safely. That changes the priorities: availability and safety come before confidentiality, patching may wait years for a vendor-approved window, and testing has to be designed so it cannot disturb production. The attacks, though, are mostly the same ones seen in IT — which is why the IT/OT boundary is where an OT programme usually starts.

Can you test PLCs and SCADA without stopping production?

Yes, because most of the useful testing does not touch them. Live controllers and safety systems are passive-only for us unless you instruct otherwise in writing: we build an inventory from observed traffic, review configurations, logic backups and architecture, and test the network paths that reach the plant — from the IT side. Where active testing of a controller is genuinely needed, it happens on a spare unit or a test bench with your automation engineers present. See the level-by-level table on this page.

What is the Purdue model, and does it still matter?

The Purdue reference model describes a plant network in layers — from the physical process at Level 0 up through controllers, supervisory systems and site operations to enterprise IT at Levels 4 and 5 — with a buffer zone between IT and OT. Real plants rarely match it neatly, and cloud connections and remote vendor access cut across the layers. It still matters as a common language and as the frame for deciding how each zone may be tested, which is how we use it.

Does NIS2 apply to Indian manufacturers?

Not directly, unless you operate in the EU. NIS2 binds medium and large manufacturers of listed products in the EU — electrical equipment, machinery, motor vehicles, computers and electronics, medical devices and other transport equipment among them — and it requires them to manage the security of their supply chains. That is how it reaches an Indian supplier: through contract clauses, questionnaires and audit rights from European customers. The practical response is a documented, tested programme — usually built on ISO 27001 — that can answer those customers with evidence.

What is TISAX, and do Indian automotive suppliers need it?

TISAX is the automotive industry’s shared information security assessment, run by the ENX Association: a supplier is audited once by a third party and shares the result with the carmakers that ask for it, instead of answering each one separately. It is not a law, but for suppliers to European OEMs it is increasingly a condition of the contract. SemperWise is not a TISAX audit provider; we prepare suppliers for the assessment and test what it looks at, and the audit itself is carried out by an approved provider you appoint.

What does CMMC mean for Indian suppliers to US defence contractors?

Since 10 November 2025, new US Department of Defense contracts have started to carry Cybersecurity Maturity Model Certification requirements, which prime contractors flow down to their suppliers. Level 1 is an annual self-assessment against 15 basic safeguarding requirements for federal contract information; Level 2, for controlled unclassified information, covers 110 requirements and may need an assessment by a certified third-party assessment organisation. SemperWise is not one of those organisations; we help suppliers close the gaps and assemble the evidence first.

Does CERT-In’s six-hour reporting rule apply to a factory?

Yes. The April 2022 CERT-In Directions apply to every body corporate in India, and their list of reportable incidents explicitly includes attacks on critical infrastructure, SCADA and operational technology systems, alongside ransomware and unauthorised access. The report is due within six hours of noticing the incident, and ICT logs must be kept for 180 days in India — including logs from the plant network, where they often do not exist. CERT-In compliance covers the full set of duties.

Isn’t our plant safe because it is on a separate network?

Only if you have tested that it is. Separation erodes quietly: a historian that replicates to the office, an engineering laptop that moves between networks, a vendor’s remote-access tool installed for one job and never removed, a server joined to the office domain for convenience. Dragos notes how often OT incidents begin on exactly these Windows machines and get recorded as IT incidents. Testing the boundary from the IT side is the quickest way to learn whether the separation you designed is the separation you have.

How long does an OT security assessment take, and what does it cost?

It depends on the number of sites and zones and on how much can be observed passively, which is why we do not publish a price list. A typical first engagement covers the IT/OT boundary and a passive assessment of one plant, and runs for a few weeks including the report. We scope it in a 30-minute call at no charge, then send a written scope and a fixed price, with a retest of every fix included.

Sources

Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. IBM 2026 X-Force Threat Index: AI-driven attacks are escalating as basic security gaps leave enterprises exposed — IBM, February 2026
  2. IBM X-Force reports 44% surge in exploitation of public-facing applications — Industrial Cyber, February 2026
  3. Dragos 2026 OT report shows surge in threat groups and ransomware — Dragos, 17 February 2026
  4. India Ransomware Report 2024 — CERT-In, March 2025
  5. Jaguar Land Rover cyberattack cost the company over $220 million — BleepingComputer, November 2025
  6. Cyber Monitoring Centre statement on the Jaguar Land Rover cyber incident — Cyber Monitoring Centre, October 2025
  7. Tata Technologies reports ransomware attack to Indian stock exchange — The Record, January 2025
  8. India records its highest average cost of a data breach — Cost of a Data Breach Report 2026 — IBM, 3 August 2026
  9. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  10. ISA/IEC 62443 series of standards — International Society of Automation
  11. Directive (EU) 2022/2555 (NIS2), Annex II and Article 21 — EUR-Lex
  12. TISAX — ENX Association
  13. CMMC Phase 1 begins November 10 — Dorsey & Whitney, November 2025
  14. Digital Personal Data Protection Rules, 2025 — MeitY, 13 November 2025

All 17 industries we serve

Next step

Find the path into the plant before anyone else does.

A 30-minute call, no charge. We agree which zones are tested actively, which passively and which not at all, then send a written scope and a fixed price — with a retest of every fix included.