Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Tagged with:
A modern manufacturing cyberattack does not go anywhere near the equipment that makes the product. It goes after the ordinary computers in the office, and the work stops on its own. Your business has the same weak point, even if you have never set foot on a factory floor.
See Where Your Business Stands →
A plain-English scan of the computers your business actually runs on. No card needed to see your results.
The problem: Owners picture an attack on a plant as somebody reaching into the production machinery. So they protect the floor, feel reasonably covered, and never look hard at the email server, the file share, and the time clock. Those are the things that actually get hit, and when they go down the floor stops anyway.
What it actually feels like: Not fear. Most owners I talk to are not frightened, they are annoyed at themselves. There is a short list of computers this whole company balances on, and they could not name it if I asked. Some quiet part of them has known that for a while.
The straight answer: You should not have to become a security expert to know whether your business opens on Monday. Nobody should. You need to know which handful of office computers your business would stall without, and whether anybody is watching them. Short list, short conversation.
Hey folks! I want to show you what a manufacturing cyberattack looked like this month. The shape of it has changed, and almost nobody has updated the picture in their head.
Foxconn confirmed a cyberattack hit some of its North American factories. The company did not name a site. But workers at the plant in Mount Pleasant, Wisconsin described their Friday, and that account is the part worth sitting with.
They showed up in the morning and there was no Wi-Fi. Computers would not come up. The time clock was dead, so people were filling out paper timesheets by hand. Nobody could pull a work order. By eleven o’clock the manager was sending people home.
Now notice what is missing from that story. Nothing happened to the production machinery. No robot got reprogrammed, nothing on the line was sabotaged. The equipment that makes the product was sitting there in perfect working order. The plant still could not run, because the ordinary computers in the office had gone dark and everything depends on them.
Coca-Cola had a version of the same thing in July, halting production at its fairlife dairy business. The office goes down and the physical work stops behind it.
Sources: Foxconn statement on the North America cyberattack, August 2026; worker accounts reported from the Mount Pleasant, Wisconsin site; Coca-Cola / fairlife production halt, July 2026.
Dragos, a firm that watches industrial security for a living, counted 1,140 ransomware attacks on industrial companies last quarter, up 12 percent in three months. Manufacturing absorbed 747 of them, two out of every three.
Ransomware, if the word is new to you, is software that locks up your files and holds them for money.
But the count is not the interesting part. The finding underneath it is. The attacks have moved off the production machinery and onto the ordinary office computers a plant leans on. Email. File servers. The time clock. Scheduling. Shipping paperwork.
The logic from the criminal’s side is depressingly sound. Breaking into production machinery is hard, because every plant is different and you have to understand the equipment to do damage. Breaking into an office network is easy, because every office in America runs the same handful of programs. Learn it once, use it on ten thousand companies. The result is identical: the work stops either way, and the company pays either way.
So a manufacturing cyberattack in 2026 is really just an office break-in with a factory standing behind it. The hosers are not clever engineers taking apart your production line. They are opportunists walking through the same unlocked door in the front office that they walked through at the accounting firm down the road.
Which is why I do not spend much time talking about the criminals. They are weather. Always out there, always will be, and nothing you decide tomorrow changes how many of them exist.
What actually decides how your week goes is far less dramatic: whether anybody is watching the handful of ordinary computers your company balances on. Not whether somebody was hired to. Whether anybody is actually looking, this month, at those machines. The real villain in every one of these stories has no face. Somebody set it up years ago, it worked, everybody got busy, and nobody has looked since.
If you do not own a plant, you may have read this far thinking it does not apply. It does. A dental practice cannot see patients without the scheduling system. A distributor cannot ship without the order system. You have a floor too. It just does not look like one.
Let me put a real number on this, because the abstract version never lands.
Walter Rowen runs Susquehanna Glass in Columbia, Pennsylvania. Family business, started by his grandfather in 1910. The hosers encrypted his servers and forty people went home.
He refused the ransom. They wanted a million dollars, he told them no, and he beat them. I want to be clear that he won.
The cleanup still ran him over one hundred thousand dollars.
That was the bill for winning. Not the ransom he did not pay. The rebuilding, the specialists, the days of not shipping, the forty people he was paying to stand around. Winning cost six figures.
Refusing to pay is now the norm, and that is good news. A record 86 percent of businesses refused the ransom last year. That tells you preparation works, because you can only say no if you can recover on your own.
The average loss was still $269,000. The honest figure is bad enough without anybody dressing it up.
The real risk of a manufacturing cyberattack was never that it ends your company overnight. It is the quieter version. Weeks of disruption absorbed out of working capital, an insurance claim picked apart on a technicality, and customers who never do tell you why they stopped calling.
If you cannot say today which computers your business would stall without, that is the whole problem, and about fifteen minutes fixes it. Book a call, on us. We scan your business and fix the single most important thing first. You will not pay a dime, and you decide what happens next.
One more thing about cost, because you have almost certainly had this quoted at you.
Sixty percent of small businesses close within six months of a cyberattack. You will find it in the ads, the sales decks, and half the conference talks I sit through.
It is not true. The National Cybersecurity Alliance, the group it gets pinned on, said plainly the number was never theirs and could not be sourced. They pulled it off their own website.
Somebody is selling you protection on the back of a figure withdrawn for being invented. Fair to ask what else in that pitch nobody checked. The honest numbers are bad enough without help.
My own father fell for a phishing email. That is a fake message built to trick you into handing over a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. The hosers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was off and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
I bring that up here because of what they went after. Not anything valuable in itself. Just his ordinary computer, the one he checked email on, because that was the road to everything else. The same instinct runs through every manufacturing cyberattack in the Dragos numbers. Go at the plain thing that everything else depends on. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware. That is not luck. It is knowing which plain things matter and watching them.
You are half right, and the half you are right about matters. Nobody is sitting in a room picking your company off a list. You are not a target in that sense, and anyone who tells you otherwise is selling through fear.
But that is exactly why this reaches you. These crews scan the whole internet for the same few common weaknesses and take whoever answers. Being small does not make you invisible to a scanner. It usually means fewer people watching the door. Susquehanna Glass is forty people in a Pennsylvania town, and it cost them six figures to win.
None of these is the whole job and I will not pretend otherwise. They are the three answers that turn any conversation about your security from a long one into a short one. That holds whether the conversation is with me or with whoever you already pay.
1. Write down the five office computers you cannot work without. Not every machine you own. The five. Email, the file server, whatever holds your orders or patient list, payroll, and whatever prints invoices. Ten minutes, and most owners have never done it. That short list is your actual floor, and you cannot protect what you have never named.
2. Ask what happens on the morning they are all dark. Not “do we have backups.” Ask how long until we are taking orders again, who makes that call, and who has done it before. If the answer is a name, good. If the answer is a shrug or a brand of software, you have found the gap. A backup nobody has ever restored is a theory, not a plan.
3. Turn on real two-step login for the accounts that manage things. Not just staff email. The administrator accounts, the ones that can change other accounts. Use an app like Duo rather than text-message codes, which can be stolen. It is the cheapest barrier against the most common way in, which is simply a password somebody already gave away.
Let me ask you a few plain things, and just answer them in your head. You know what your business is insured for. You know roughly what a day of downtime costs. If your best delivery truck died tomorrow you could tell me, within an hour, how long until you were moving product again. You have thought all of that through, because thinking it through is what running a company is.
Now hold that next to this. If somebody locked every computer in your office tonight, you probably could not tell me how long the rest of the business keeps running. And I would bet nobody else in your building could either.
Both are true about the same careful person, and they do not sit together comfortably. That gap is not carelessness. Nobody ever handed you the second checklist. You learned the truck, the insurance, the payroll and the lease because somebody walked you through each one. Nobody did that for the computers your whole operation quietly balances on.
So you can decide it is probably fine, which it probably is, and carry that unanswered question into the next manufacturing cyberattack that makes the news. Or you can spend a few minutes and find out, and be done wondering. One of those ends the question. The other reschedules it. Acting is not the nervous choice here. Acting is what lets you stop thinking about it.
You should not have to become a security expert to know whether your business would keep running on Monday. You should just be able to know. And you do not have to work it out alone.
Book a call, on us. We scan your business and fix the single most important thing first. You will not pay a dime, and you decide what happens next. If whoever handles your computers is already doing right by you, you will find that out too, and that is worth knowing.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join 10,000+ cybersecurity professionals