IT Brief US - Technology news for CIOs & IT decision-makers
United States
Manufacturers face new cyber risks from connected factories

Manufacturers face new cyber risks from connected factories

Thu, 23rd Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

SonicWall has published a report on cyber threats facing manufacturers, warning that connected factory systems are creating new entry points for attackers.

Intrusion prevention events targeting manufacturing fell 56.2% year on year in the first half of 2026, the sharpest decline among the sectors SonicWall tracks. Even so, the sector still recorded 474 million such events, showing that activity remains substantial despite the lower overall volume.

According to the report, this points to a shift in attacker behaviour rather than a reduction in risk. As operational technology becomes more closely linked to corporate IT systems, attackers are concentrating on selected routes into factory environments instead of relying on broader, less precise campaigns.

The report draws on data from SonicWall's network of more than one million security sensors. It identified internet-connected devices, industrial control systems and older software flaws as recurring sources of exposure across manufacturing networks.

One of the most prominent examples was the Hikvision IP Camera Command Injection vulnerability, CVE-2021-36260. SonicWall recorded 43 million hits linked to the flaw in the first half of the year, making it the largest single internet of things attack signature seen across any industry the company tracks.

Internet of things attacks were the second-largest attack category in manufacturing by volume, with 46.2 million hits. More than half of the manufacturing networks monitored detected attempts to exploit these weaknesses.

Manufacturing also posted the highest SCADA attack detection rate of any industry in SonicWall's tracking. SCADA systems monitor and control industrial processes and are often central to plant operations.

Ransomware activity also remained present. Ten ransomware families were active against manufacturing networks in the first half of the year, with the Zhen family alone generating 22.2 million hits concentrated on two devices.

Another persistent issue involved Apache Log4j2, a software component whose vulnerabilities have been widely exploited in recent years. SonicWall recorded 13.8 million detection events related to Log4j2 on manufacturing networks, suggesting that older weaknesses remain exposed long after disclosure.

Network overlap

The findings highlight the growing overlap between office systems and factory operations. Manufacturers have increasingly connected production environments to corporate networks to support remote monitoring, maintenance and supplier access, but those links can also allow intruders to move from business systems into operational systems.

Michael Crean, senior vice president of managed services at SonicWall, said the shift in factory connectivity has changed the sector's security profile.

"Manufacturing's attack surface looks nothing like it did even five years ago, and the security model hasn't caught up. Every connection added for operational convenience, remote monitoring, predictive maintenance, vendor access to production systems, is also a connection an attacker can walk through. A stolen credential shouldn't be able to reach the production floor, but in most manufacturing environments today, it can," Crean said.

Many connected devices on factory sites were not designed with current cyber threats in mind, SonicWall argued. Cameras, industrial sensors and building control systems often run older software, are patched infrequently and sit on networks close to production systems.

That can leave long-known flaws exposed. In practice, a vulnerability disclosed years ago can remain useful to attackers if the affected hardware stays in place and lacks effective network separation or update management.

Access controls

For many manufacturers, the central issue is how access is structured across linked environments, according to SonicWall. The report described how a stolen employee password obtained through phishing can provide a route from office networks into systems that manage machinery or support production operations.

Crean said the problem lies in network design rather than a lack of awareness in the sector.

"Manufacturing doesn't have a sophistication problem, it has an architecture problem. The factory floor is now part of the corporate network. Until we start continuously verifying every user and restricting their access to only the specific apps they need, one stolen password will continue to be enough to shut down a plant," he said.

The report pointed to tighter identity checks and more limited application-level access as the main ways to reduce the impact of compromised credentials. It said manufacturers that still rely on broad virtual private network access for vendors, maintenance teams and remote monitoring functions may face greater risk if user accounts are stolen or misused.

SonicWall's findings underline how cyber risk in manufacturing is shifting from sheer attack volume to the exposure created by connected operational systems, older devices and weak segmentation between office and plant networks.