For Manufacturers · Ransomware
Ransomware protection for manufacturers
A manufacturer hit by ransomware loses more than email. Orders stop, schedules vanish and the floor can go quiet. Here’s why plants are targeted, the five controls that do the most good, and what getting back to work looks like.
The target
Why manufacturers get hit
The FBI’s 2025 Internet Crime Report names critical manufacturing among the sectors the most-reported ransomware strains hit hardest.
-
Downtime is expensive
A stopped line costs so much that attackers expect a manufacturer to pay.
-
Old machine PCs
The computers that run equipment often can’t be updated without breaking the vendor’s software.
-
One flat network
Once an attacker is in the office, nothing stops them reaching the floor.
Prevention
The five controls that matter most
-
Control 1
Multi-factor authentication
A stolen password on its own stops being enough to sign in to email, remote access or an admin account.
The manufacturing wrinkle Shared floor logins need a plan too, not an exception.
-
Control 2
Endpoint detection
Software on each computer that spots ransomware behaviour and stops it before files are encrypted.
The manufacturing wrinkle Some machine PCs can’t run it, so the network has to watch them instead.
-
Control 3
Patching
Closes the known holes attackers scan for, on a regular schedule.
The manufacturing wrinkle What can’t be patched gets walled off, so an old machine PC isn’t an open door.
-
Control 4
Network separation
An infection in the office can’t spread to the machines, or the other way round.
The manufacturing wrinkle The machine network stays reachable only by the people and vendors who need it.
-
Control 5
Tested offline backups
A copy the attacker can’t reach or encrypt, with restores proven on a schedule.
The manufacturing wrinkle The ERP, the file shares and the machine PC images are all in the backup set.
Each of these is in CISA’s #StopRansomware Guide.
Recovery
If the floor stops
-
Isolate.
Cut infected computers off from the network so it stops spreading, without wiping the evidence.
-
Keep production running where it safely can.
If the machine network was kept separate and is clean, some lines may be able to keep working while the office is restored.
-
Restore the ERP and file shares from tested backups.
The systems that take orders, schedule work and hold drawings come back first, from a copy known to be clean.
-
Bring machine PCs back from known-good images.
Each one is rebuilt from a saved copy of how it looked when it worked, with the equipment vendor where the machine needs it.
How long recovery takes depends on the backups, which is why we test them. For the plan every business should write before it needs one, see a ransomware recovery plan you can write this week →
Proof
An industrial company whose IT we run
SIEMAG TECBERG makes equipment for the mining industry, and Aweeba runs all of its IT: Microsoft 365, every employee’s computer and its servers.
"With Aweeba, we finally have a tech partner who understands the stakes of operational downtime. Their support has been proactive, reliable, and tailored to the real-world needs of our facility. From device management to long-term planning, they've brought stability and forward momentum to our IT."— Randy Moore, Vice President Engineering, SIEMAG TECBERG
Where to start
Where to start
The choice is yours.
- Want to know which of the five controls you already have? Book my free IT risk review →
- A plant of 15 to 70 people who want all five run for them. Our Fully Managed IT Support Program →
- Want the network separation done properly on the floor? Shop-floor Wi-Fi that works →
What success looks like
A bad week, not a lost quarter.
Because the controls were in place first.
- The office and the floor can’t infect each other.
- The backups are out of reach and proven to restore.
- Everyone knows the first four steps if it happens.
Questions manufacturers ask about ransomware
Can you protect machine PCs we can’t update?
Yes. We segment them onto their own network and monitor them, and we work with the equipment vendor for anything inside the machine itself.
Does cyber insurance cover ransomware?
It depends on the policy. Most insurers also ask which controls you have before they’ll cover you. What cyber insurers require →
How long would recovery take?
We won’t promise a number of hours. How long recovery takes depends on the backups, which is why we test them.
Do you monitor nights and weekends?
Support hours are Monday–Friday, 8–5 Mountain; for Fully Managed clients, after-hours issues go through the same process, with the commitments written into your agreement.
Find the gaps before an attacker does.
Book a free IT risk review and we’ll check your plant against the five controls, backups first. Or start with a few questions about your tech.