Manufacturing led every industry sector IBM tracked for the fifth year straight in 2026, and ransomware showed up in 61% of manufacturing breaches, the highest share Verizon has recorded for any sector. The reason lives on the shop floor, not in the finance department.
Ask a manufacturer in Rockland or Bergen County why a ransomware crew would bother with a 40-person machine shop instead of a Fortune 500 target, and the honest answer is that attackers don’t see much difference anymore. Automated tooling doesn’t care about company size. Never has. It cares about what’s reachable, and on a factory floor, what’s reachable usually includes production equipment nobody ever expected to need a firewall.

The Numbers Behind the Target
IBM’s X-Force Threat Intelligence Index 2026 puts manufacturing at the top of its target list. Fifth year running. The firm’s researchers logged 27.7% of all incidents in the sector, up from 26% the year before, with finance and insurance close behind at 27%. That’s overall attack volume, not a ransomware-only number. Still, it tells you something. Attackers keep circling back to the same industry, year after year, regardless of how much gets written about it.
Ransomware is where manufacturing separates itself further. Verizon’s 2026 Data Breach Investigations Report found ransomware involved in 61% of manufacturing breaches, well above the 48% rate reported across all industries in the same study. Dragos, which tracks industrial and OT-specific attacks exclusively, counted 119 active ransomware groups hitting 3,300 industrial organizations in 2025, up from 80 groups the year before, with manufacturing absorbing more than two-thirds of all the victims. None of this happens apart from ordinary IT risk. A lot of what a strong cybersecurity program handles for any small business, patching, MFA, monitored backups, still applies here. Manufacturing just adds a second network on top of it.
Why Flat IT-OT Networks Are the Real Problem
IT-OT segmentation means separating the office network, email, file shares, ordinary computers, from the operational technology network that runs production equipment, using firewalls, a demilitarized buffer zone, and strict rules about which traffic can cross between the two. NIST calls this the zones-and-conduits model.
Here’s the part that surprises most plant managers. Ransomware doesn’t need to touch a programmable logic controller or a robotic arm to stop production. Dragos has documented attackers compromising the virtualization layer hosting SCADA and HMI systems using nothing more exotic than valid, stolen credentials, killing an operator’s visibility into the process without the malware ever speaking an industrial protocol. Once that visibility goes dark, the plant stops, and it stops without a single machine actually failing.
Dragos’ OT security assessments found something else worth sitting with. Nearly half of manufacturing environments still run a shared or flat domain between IT and OT, more than three times the rate found in oil and gas or electric utility environments that get audited more aggressively. Average dwell time for OT ransomware runs 42 days before anyone catches it, and in a quarter of cases the result is a full site shutdown. Forty-two days is a long time for an attacker to map a network nobody ever segmented in the first place.
Office IT refreshes hardware every three to five years without much drama. Industrial equipment runs 15 to 25 years on a shop floor, and pulling a PLC offline mid-shift to install a patch can cost more in downtime than the vulnerability was ever likely to cost in damage. NIST’s Guide to Operational Technology Security, published in 2023, doesn’t pretend patching solves this. It recommends compensating controls instead. Segmentation. Allowlisting. Passive monitoring that watches traffic without ever touching the device directly.
IT-Only Ransomware vs. Manufacturing’s IT+OT Blast Radius
Put the two scenarios side by side and the gap gets concrete fast.
| Impact Area | Office-Only Ransomware Hit | Manufacturing IT+OT Hit |
|---|---|---|
| What stops running | Email, shared drives, billing software | Same, plus the production line itself |
| Typical recovery path | Restore from backup, rebuild endpoints | Restore IT first, then re-validate and safely restart OT systems |
| Physical safety review needed | No | Yes, engineers confirm equipment states before power-on |
| Revenue at direct risk | Delayed invoicing, admin slowdown | Missed production runs, contractual delivery penalties |
| Who signs off on restart | IT alone | IT and plant engineering together |
Same ransomware family in a lot of these cases. Same initial phishing email, even. Completely different bill at the end.

Two Real Incidents, Different Decades
On July 16, 2026, Coca-Cola disclosed that its Fairlife dairy subsidiary had suffered a ransomware attack serious enough to suspend all U.S. production. Canadian plants kept running. No pause there. The Anubis ransomware gang claimed responsibility, saying it had encrypted Fairlife’s Nutanix infrastructure and stolen roughly a terabyte of data. Coca-Cola refused to pay, reported the incident to law enforcement, and had most of its four U.S. facilities back to production within days, though Anubis published the stolen data once its deadline passed on July 27.
The older, more heavily documented example is JBS Foods. REvil ransomware hit the company’s systems on May 30, 2021, and shut down beef, pork, and poultry plants across the U.S., Canada, and Australia, including facilities in Utah, Texas, Wisconsin, Nebraska, and Pennsylvania. Roughly 7,000 Australian employees were stood down. The company scrambled to respond. Most operations resumed within three to four days, but JBS ultimately paid an $11 million ransom in Bitcoin, at the time the largest confirmed ransom payment tied to an attack on a food-production company.
Neither company is small. Neither runs on the kind of budget a 40-person NY manufacturer has access to. The mechanism attackers used against both, though, doesn’t care about company size any more than the ransomware-as-a-service kits selling on criminal forums do. The equipment mix that made Fairlife’s dairy lines and JBS’s meat plants attractive targets, physical production tied directly to a network, exists just as completely in a much smaller shop.
What Segmentation Actually Looks Like on a Shop Floor
None of this requires ripping out a plant’s existing equipment. Just real boundaries around it.
- The Purdue reference model layers the network from corporate IT at the top down to the physical process floor at the bottom, with a firewall boundary at every layer change. A 30-person shop can apply the same logic at a much smaller scale than a multinational plant.
- An industrial DMZ sits between the two zones. Nothing routes directly between the office network and the OT network. No exceptions. Everything crosses through a monitored buffer first.
- VLANs isolate control-zone traffic from general office traffic, even when both run over the same physical switches.
- Legacy PLCs and HMIs that can’t be patched get wrapped in compensating controls instead. Network isolation. Allowlisting. Passive monitoring that watches for anomalies without ever touching the device.
- Remote access into OT gets MFA and least-privilege by default. No shared logins into a SCADA workstation, ever.
- Monitoring has to actually watch the OT side, not just email and endpoints. When something flags on a segmented network under my team’s watch, response starts within 15 minutes, not the next morning.

What Plant Managers Actually Want to Know
Does segmenting IT and OT networks actually stop ransomware, or just slow it down?
What actually makes a manufacturing ransomware attack different from one that hits a regular office?
Can old PLCs and HMIs even be patched to fix something like this?
What does the Purdue Model actually mean for a small manufacturer that isn’t running a Fortune 500 plant?
Should a 30-person manufacturer really worry about the same ransomware groups that hit Coca-Cola’s Fairlife plants?
Manufacturing’s exposure isn’t going away because a plant is small or based in Rockland County instead of inside a Fortune 500 supply chain. It’s the equipment mix that draws the attention. Not the size of the company running it. VJNetworks builds managed IT services for manufacturers running exactly this blend of legacy production equipment and office IT. The detection principles are the same ones covered in why small businesses have become ransomware targets. Manufacturing just adds a second network to defend. For what happens after an attack actually lands, the first 24 hours of a ransomware incident walks through the response in more depth.
Further reading: the Dragos 2026 OT Cybersecurity Year in Review covers the full industrial threat landscape in more depth.
A free assessment maps exactly where your IT and OT networks touch today, and where a segmentation gap could let one bad email reach the production line. No obligation, no sales pitch.
