Skip to main content

Cyber resilience in connected manufacturing: How to protect OT and IT environments

Modern manufacturing has evolved from isolated, manually controlled environments into highly connected ecosystems of cloud platforms, remote-access systems, and increasingly autonomous machinery. These advancements have delivered real productivity gains — but they have also dramatically expanded the cyberattack surface. 

Leading with resilience: The modern manufacturer's imperative

Learn how Canadian manufacturers can manage risk and build long-term stability.

Why cyber risk is now a core operational discipline

Legacy PLCs, SCADA systems, HMIs, and industrial sensors were never designed with cybersecurity as a primary requirement. Yet today, these OT systems are interconnected with IT networks and third-party organizations through remote access pathways — creating exposure at every junction.

The consequences of cyber incidents in manufacturing extend far beyond data loss: production shutdowns, safety hazards, equipment damage, environmental harm, regulatory penalties, and significant revenue losses are all within scope. Cyber resilience must therefore be treated as a core operational discipline — not an IT department initiative.

IT vs. OT in manufacturing: An important distinction

Information technology (IT): Systems used for data management, asset tracking and maintenance, safety and risk monitoring, and financial reporting. IT systems handle information flows across the business.

Operational technology (OT): Systems and equipment used to manage and control physical operations — industrial control systems (ICS), PLCs, SCADA systems, HMIs, sensors, and automation tools. OT controls the physical world. As IT and OT systems converge, vulnerabilities in either domain can now compromise the other.

The four primary cyber threats facing manufacturers

selected option

Deliberate attacks aimed at a specific organization, facility, or production process. These often exploit known vulnerabilities of trusted access pathways.

Potential impacts: Extended downtime, safety risks, high recovery and extortion costs.

Indiscriminate attacks that scan for exposed, vulnerable systems at scale. Manufacturing organizations are frequently affected due to legacy systems and remote connectivity. 

Potential impacts: Sudden production outages caused by rapid malware propagation.

Access originating from vendors, system integrators, software providers, or equipment suppliers with access to manufacturing environments. 

Potential impacts: Widespread industry disruption, difficult containment, loss of supplier trust.

Incidents caused by human error, misuse of access, misconfiguration, or lack of awareness rather than malicious intent. 

Potential impacts: Equipment damage, unsafe operating conditions, operational downtime.

Build resilience. Protect what you've built.

Download Leading with resilience: The modern manufacturer's imperative — Marsh Canada's comprehensive guide to navigating the risk landscape facing Canadian manufacturers. Get ready to act today.

Recommended controls for manufacturing leaders

While not an exhaustive list, a few highly recommended cyber controls for Canadian manufacturers to prioritize include: 

Require two or more forms of authentication for remote access, privileged accounts, engineering workstations, cloud platforms, and backups. Especially critical where vendors and third parties access OT systems remotely.

Resilience outcome: Prevents credential theft or compromise from becoming a production-impacting incident.

Perform frequent, encrypted backups and test restoration capabilities regularly. Backups must cover not only IT systems but also critical OT configurations, PLC logic, HMIs, and historians.

Resilience outcome: Enables rapid restoration after cyber disruption or data loss, limiting operational downtime.

Deploy monitoring and response tools across engineering workstations, operator stations, and servers to detect and block threats early.

Resilience outcome: Improves early detection and containment of cyber threats before they reach production systems.

Establish response plans that clearly define roles, escalation paths, and decision authority. Make sure to cover OT scenarios such as ransomware, loss of control systems, and unsafe operating conditions. Plans must involve plant leadership, not just IT and OT teams.

Resilience outcome: Enables coordinated, rapid response to minimize operational and safety impacts.

Apply patches using a risk-based approach that prioritizes critical vulnerabilities while coordinating changes with production schedules. Where patching is not possible for legacy systems, compensating controls (like network isolation) should be implemented.

Resilience outcome: Reduces exposure to known exploits without disrupting operations.

Adopt third-party risk management frameworks, conduct regular assessments, and maintain ongoing oversight of vendors, integrators, software providers, and equipment suppliers.

Resilience outcome: Limits exposure from third-party and supplier-originated cyber incidents.

Measure the financial impact of cyber risk

To secure executive engagement and prioritize investment, security and risk leaders must express cyber risk in financial and operational terms. Three practical approaches include:

1. Risk assessments:

Identify critical assets, production dependencies, and potential downtime to estimate recovery costs and regulatory exposure.

2. Historical incident analysis:

Review internal and industry-wide incident data to understand frequency, recovery timelines, and actual costs.

3. Scenario modelling:

Evaluate specific scenarios — ransomware affecting production, attacks causing physical damage — using stochastic loss modelling for a dynamic risk.