
A press that stops mid-shift costs more per hour than most security budgets spend per month. That arithmetic is why manufacturing security decisions get made differently from office IT decisions, and why advice written for corporate networks tends to fall apart on a factory floor.
The equipment is older, the tolerance for downtime is lower, and the machines that matter most are frequently the ones that can accept the least protection. A workable programme starts from those constraints rather than treating them as problems to be solved first.
This guide covers what makes manufacturing different, what convergence between operational technology and information technology actually breaks, and the sequence a plant can follow to close the gap without stopping production.
Three constraints divide a plant floor from an office, and each one breaks a belief that standard security practice depends on.
Most industrial incidents do not begin on the plant floor. They begin on a laptop in an office, then travel.
Plant systems used to sit in isolation. Connecting them to business networks delivered real functional value, and it also removed the separation that was doing most of the security work.
Three distinct things break.
Shared credentials become shared risk. A vendor account used to service a machine, or an engineering login that works on both sides, turns a single compromise into access across two environments.
Normal looks suspicious here. Machines talk to each other in rigid, repetitive patterns that trip detection rules written for the messier rhythms of people using laptops. Add a plant that runs different volumes in different seasons, and any system tuned over a few weeks will misread the next quarter as an incident.
And the two teams have opposing goals. IT wants fixes applied quickly. Operations needs the line running. Left unresolved, that tension delivers indefinite deferral rather than a driven decision.
The principle is easy. No single control should be the only thing standing between an email attachment and a production controller.
This is where most plants run out of capacity. Running a security operation around the clock needs staff that mid-sized manufacturers do not have and cannot easily hire, which is why managed detection and response has become the practical route.
The question to ask a provider is what happens between detection and action, and how long that takes. The measure that holds meaning is mean time to respond, the interval between initial detection and the first action taken against an incident. Published figures vary widely because providers time different things.
One benchmark worth knowing: the service reports a six-minute mean time to respond, set against a 22-minute average across sample MDR providers and a 24-day median for organizations to find a breach, drawn from the Verizon 2025 Data Breach Investigations Report and public provider materials as of July 2025.
ESET frames its managed service around exactly this problem, naming an on-boarded security operations center, a mitigated cybersecurity skills gap, and optimized operational visibility as its stated outcomes. For a plant with a two-person IT team, that is the whole proposition.
The detection side draws on a global telemetry network of more than 100 million sensors across 11 research and development centers, built on more than 35 years of threat research, with access governed through a Zero Trust approach rather than assuming anything inside the perimeter is safe.
The service is offered in two tiers, one scoped for small and mid-sized organisations and one for enterprise-scale needs, so a single-site operation and a multi-plant group are not forced into the same contract.
It is also built to support cyber insurance and regulatory compliance requirements, which matters as insurers increasingly ask what monitoring is in place before writing a policy. The service was named a Market Leader in MDR in the KuppingerCole Leadership Compass 2026, and the company a Leader in the 2024 IDC MarketScape for Modern Endpoint Security.
Raicam Group, an automotive company founded in 1982, runs this system in production. The company uses the 24/7 managed detection and response service to keep track of its network security status without the risk of interruption from a lack of staff, and without obtaining or maintaining additional internal IT security resources.
That combination is a reasonable argument for a managed service in manufacturing. The alternative is not cheap; it is simply unstaffed.
Controls that have never been tried are assumptions. Three forms of validation are worth running.
Simulated attacks. Have someone try to reach plant systems from the business network the way an attacker would. This finds the ways that documentation says are closed, but reality says are open, and it is the fastest way to locate an undocumented connection.
Vulnerability management as a cycle rather than a report. Finding flaws is the easy part. The discipline is in scoring them against your environment, choosing which ones warrant production downtime, applying compensating controls to the rest, and re-checking.
If the same machines appear on the same list month after month and nothing changes in between, what you own is a reporting tool. The value sits in the decisions made about each finding, not in the finding itself.
Recovery rehearsals. Test the shutdown and restart process before an incident forces it. Most plants find during a real event that the recovery plan assumes systems and people that are not available at three in the morning.
In short: Untested defences are assumptions. Simulated attacks find open paths, a vulnerability cycle turns findings into decisions, and recovery rehearsals reveal the gaps in a plan before an incident does.
Five steps, in this order, because each one depends on the last.
Most plants try step four first, because it feels like the security purchase. Done before segmentation and inventory, it delivers alerts nobody can act on.
In short: Inventory, segment, fix access, monitor, then rehearse. The order matters because monitoring deployed before segmentation and inventory causes alerts without the context to act on them.
Manufacturing security is not mainly a technology problem. Segmentation, inventory and access control are well understood, and the tooling to observe both environments exists.
The constraint is operational. Plants cannot go offline while someone investigates, cannot patch equipment that must keep running, and mainly cannot staff a security operation around the clock. A workable programme is one that takes those limits and builds around them rather than thinking they can be removed.
What is the difference between IT and OT security?
IT security prioritises confidentiality and data integrity. OT security prioritises availability and physical safety, because the systems involved control machinery. When the two environments connect, a plant needs an approach that respects both sets of priorities rather than applying office assumptions to the factory floor.
How do you protect equipment that cannot be patched?
You work around it. Put the machine behind a boundary so nothing reaches it directly, track its normal operating pattern closely enough to notice when it changes, limit the handful of accounts allowed to touch it, and record the decision formally so the risk stays visible to whoever signs off on it.
Can a managed service cover operational technology, not just office systems?
Coverage varies considerably by provider, and it is worth asking specifically rather than accepting a general claim of industrial support. Ask which systems are monitored, how telemetry is collected from assets that cannot run an agent, and what response actions are permitted on the plant side.
Where should a manufacturer start?
With an inventory. Every subsequent control depends on knowing what is connected, and most plants discover equipment nobody had documented.
