Plant Floor Cybersecurity for Small Manufacturers
Generic small business security advice does not fit a plant. Here is what is different about protecting production, and the one control worth doing first.
By Cohesive Security
Security advice written for small businesses tends to assume your worst day is a lost spreadsheet. On a plant floor the worst day is a line that will not start, and the cost is not measured in support tickets. It is measured in scrap, missed shipments, and a customer who moves their schedule somewhere else.
That difference changes what is worth doing first. Manufacturers also carry a technical problem that offices do not: a significant share of the equipment running your business cannot be patched, updated, or protected the way a laptop can, and never will be. Here is how to think about it.
Key takeaways:
- Segmentation is the highest-value control on a plant floor. Production equipment in its own network lane means a compromised office PC cannot reach your machines.
- You cannot patch a controller the vendor stopped supporting. You can make sure it only talks to the handful of things it actually needs.
- Machine programs and controller configurations are business data. Most backup jobs cover the file server and quietly miss them.
- If you are anywhere in the defense supply chain, CMMC requirements now flow down through contracts, including to subcontractors.
Why an hour down costs more here
Attackers work out quickly which victims feel the most pressure to restore fast, and a stopped production line is near the top of that list. Every hour is people standing around being paid, orders not shipping, and in some processes material spoiling in place. Restart is rarely instant either: lines have to be brought up in sequence, and quality checks have to be redone.
That is why the arithmetic matters before an incident rather than during one. Our downtime cost calculator is a blunt tool but an honest one: put in your own labor and revenue numbers and it gives you a figure per hour. That figure is what justifies the spending decisions below, and it is usually larger than expected.
The machines nobody can patch
Every plant has them. An inspection system on an operating system that went out of support years ago. A CNC controller whose vendor will void support if anything is touched. A test rig running software that only exists as a disc in a drawer. A press with an interface built when nobody imagined it would be on a network at all.
You are not going to fix these, and you should stop planning as if you will. Replacement runs to six figures, and revalidating a machine after a change can cost more than the change.
What you can do is limit what they can reach and what can reach them. In plain terms, segmentation means putting production equipment in its own lane on the network, with a controlled crossing point, so that machine only talks to the specific systems it genuinely needs. The practical payoff is that a phishing email opened at the front desk cannot spread to the plant, because there is no path from one to the other.
NIST maintains a whole guide to securing this kind of equipment, SP 800-82 on operational technology security, and the recurring theme is exactly this: where you cannot harden the device, control its environment. For a small manufacturer this is usually a few days of network work rather than a capital project, and it removes an entire category of risk.
The connection you did not know was open
Machine builders and systems integrators often support equipment remotely, which is genuinely useful when something fails at 2 a.m. and the specialist is three states away.
The question worth asking is how that access works today. In a lot of plants the answer is a cellular modem or remote support tool the vendor installed, with credentials nobody on site controls, running whether or not anyone is using it. That is a door into your production network held by a third party whose own security you have never assessed.
You do not need to remove it. You need it to be deliberate: access that you switch on when it is needed and off afterwards, tied to a named person, logged, and going through your controlled crossing point rather than around it.
Invoice fraud, in both directions
Manufacturing gets hit from two sides on payment fraud. Purchasing receives a message from a supplier whose banking details have supposedly changed, and pays it. Or a customer receives a convincing message that appears to be from you, and their payment goes somewhere else, which becomes your problem regardless of where the fault sits.
The defense is procedural rather than technical: any change to payment details gets verified by voice on a number you already had, never one from the message requesting the change. It costs one phone call. We covered how this scam actually runs, including why it survives good technical defenses.
The questionnaire from your biggest customer
Larger customers and primes push security requirements down the supply chain, and increasingly answering them is part of keeping the work.
For defense work this is now formal. The acquisition rule implementing CMMC took effect on November 10, 2025, which means applicable solicitations carry a required CMMC level. The levels range from a self-assessment through to assessment by a certified third party, and the requirement flows down: subcontractors have to submit their own affirmations and self-assessment results, so being a second-tier supplier is not an exemption. The rollout is phased over three years from that effective date, and awards solely for commercially available off-the-shelf items are excluded. As the phases progress, contracts that accept a self-assessment today will require a third-party assessment.
Underneath CMMC sits NIST SP 800-171, the actual list of practices for protecting controlled unclassified information. If you handle any, that document is your specification, and the honest answer for most small manufacturers is that meeting it is a project measured in months rather than weeks. Worth starting before a contract depends on it.
If you are not in the defense chain, the same pressure arrives less formally through customer questionnaires and audit clauses. Same response: treat the questions as the specification.
Backing up the things that are not files
This is the gap we find most often, and it is specific to this sector.
Your backup covers the file server and the ERP, because that is what backup software is sold to do. It very likely does not cover the machine programs, the controller configurations, the recipes, the fixture offsets, and the settings that took someone years to tune. Those live on the equipment, or on a laptop in the maintenance office, or on a USB stick in a drawer.
Losing the ERP is expensive. Losing the programs that make your line produce good parts is worse, because there is no vendor who can send you a copy. Get them into the backup, and test that they come back, which is the step that catches most failures. We wrote about why backups fail quietly if you want the fuller version.
A first month, and then a longer plan
If you do nothing else this quarter: segment the plant network from the office network, get machine programs and controller configurations into a tested backup, and put multi-factor authentication on email and any remote access. Those three remove most of the realistic paths to a stopped line, and none is a capital project.
Longer term sits the work that does not finish: monitoring, patching what can be patched, the vendor access reviews, and the documentation your customers ask for. That is what we carry for the manufacturers we work with, alongside the security controls and backup and recovery behind them, including dealing with equipment vendors directly so your maintenance lead is not relaying messages between two companies.
If you want an honest read on what could actually stop your line, that is a free assessment: where the network is flat, what the vendors can reach, and what would not come back from backup. Or email hello@cohesivesecurity.com.