Manufacturing's Data Security Problem

Even as security improves, the sharing of BOMs, CAD files and audit specs places vital IP at risk.

Intllectual Property

A bill of materials leaving an engineering team’s inbox looks identical to any other email attachment – until a competitor is building the same part six months later for a fraction of the development cost. That’s the exposure hiding behind manufacturing’s numbers in this year’s Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report. It's a sector whose security score looks comfortably above average, and whose actual data exchange discipline hasn’t caught up to what that score implies.

Manufacturing’s Data Security Maturity Score (DSMS) comes in at 43 out of 100, ahead of the survey-wide average of 39. DSMS is built from 11 binary security controls – classification, access enforcement, SIEM integration, and similar operational measures – scored as deployed or not, then converted to an index: DSMS = (number of controls deployed ÷ 11) × 100. 

A score of 43 means the sector has roughly 43 percent of those 11 controls actually in place, not just documented. AI Governance Maturity Score (AIGMS) works the same way over a separate list of 19 AI-specific governance capabilities: AIGMS = (number deployed ÷ 19) × 100. 

The report’s combined readiness measure, the Data Security and Compliance Readiness Index (DSCRI), multiplies the two together – DSCRI = DSMS × (AIGMS ÷ 100) – so a strong DSMS can’t compensate for a weak AIGMS. Manufacturing’s DSCRI lands at 18.4, only narrowly above the survey mean of 16.2. 

On paper, the DSMS reads as a sector doing the fundamentals right. It’s the wrong number to relax over, because the exposure that actually matters for manufacturing lives in a different place than the aggregate security score suggests.

Hiding the Real Exposure

Manufacturing’s DSMS ranked fourth among the ten sectors measured – ahead of healthcare, technology, and every sector below the survey mean. That’s a legitimate result, reflecting real investment in access control and monitoring across manufacturing IT environments. But general security maturity and AI governance maturity are measured separately in this year’s report precisely because they don’t move together.

An organization can carry solid security fundamentals and still have almost nothing in place to govern what its AI systems can access, process, or output – or, just as often, almost nothing in place to govern how sensitive design and supply chain data actually moves between the organization and everyone it exchanges data with: suppliers, contract manufacturers, engineering partners, and now AI tools layered on top of all of it.

Representation data in this year’s survey shows manufacturing underrepresented in the best-case “Resilient” quadrant – where both general security and AI governance are strong – at only 0.91 times the rate you’d expect given the sector’s share of respondents. Instead, the sector is mildly overrepresented in two mixed-risk profiles: “Fortified” (strong security, weak AI governance, at 1.09 times expected) and “Policy-Led” (AI governance frameworks in place without the technical controls to enforce them, at 1.19 times expected).

Read those numbers together and the pattern is specific: manufacturing isn’t concentrated in the worst-case profile, but it’s also not converging on the best one. 

A meaningful share of the sector has built solid security infrastructure without extending that discipline into AI-specific governance and the data exchange channels that AI systems increasingly touch, such as:

  • Who can query a model built on proprietary designs
  • What a supplier-facing AI tool can access
  • Whether an engineering assistant summarizing a bill of materials has any boundary around what else it can reach

Where the Real Exposure Sits

Manufacturing’s most valuable data rarely stays inside one system. CAD files, bills of materials, proprietary formulas, and quality specifications move constantly between engineering teams, contract manufacturers, and supply chain partners – largely through email and ad hoc file sharing. These are channels that this year’s Kiteworks data shows are governed inconsistently across every sector, manufacturing included.

That matters because manufacturing’s exposure isn’t primarily an internal-network problem. The Verizon 2026 Data Breach Investigations Report found that third-party and supply chain-related breaches jumped 60 percent year over year and now account for 48 percent of all breaches studied – and manufacturing, with its dense web of supplier and contract manufacturer relationships, sits squarely inside that exposure. 

The same report found ransomware driving the large majority of manufacturing malware-related breaches, frequently entering through exactly the kind of unmonitored file exchange and email channels that carry proprietary design data out to partners every day.

That exposure has a price tag attached to it. IBM’s Cost of a Data Breach Report 2026 puts the average industrial-sector breach at $5.5 million – not the highest cost of any industry IBM measured, but high enough that the third-party breaches driving nearly half of all incidents industry-wide land squarely in expensive territory once they hit a manufacturing organization.

Why IP Theft is a Manufacturing-Specific Version of the Problem

For most sectors, a data governance gap creates compliance risk. For manufacturing, it creates a more specific exposure: intellectual property theft. A CAD file, a formulation, or a bill of materials that leaves the organization through an ungoverned channel – an unencrypted email attachment, a personal file-sharing account, an AI tool with no restriction on what it can ingest – doesn’t just represent a security incident. 

It represents years of engineering investment that a competitor or a compromised supply chain partner can reproduce without paying for the development cost.

That risk compounds with every AI tool an engineering or supply chain team adopts without governance behind it. Sixty-five percent of organizations across this year’s survey discovered employees using unapproved AI tools with organizational data in the past 12 months. In manufacturing specifically, that shadow AI exposure often means a design engineer or supply chain planner feeding proprietary specifications into a consumer AI tool with no visibility at the enterprise level at all – the digital equivalent of mailing a competitor your blueprints.

The instinct inside manufacturing organizations that already have a reasonable general security posture is to assume AI governance and data exchange governance are extensions of what they’ve already built. They aren’t. 

Both require their own controls: purpose binding that restricts what an AI system or a supply chain partner can access, technical enforcement of approved-channel restrictions so sensitive design files can’t leave through email or unmanaged file sharing, and audit trails that can produce a complete access record on demand – not just general network logs.

None of that is covered by the controls that got manufacturing to a 43 on general security maturity. It’s a separate build, and treating it as an afterthought to an already-decent security program is how a sector with a real security foundation still ends up underrepresented in the one quadrant that actually matters: strong on both dimensions at once.

What Manufacturing Leaders Should Prioritize

Start with visibility into where CAD files, bills of materials, and other proprietary design data actually travel today – most manufacturing organizations have never mapped this end to end. Then build purpose binding and approved-channel enforcement specifically around that data: engineering and supply chain exchanges routed through governed channels, not personal email or consumer file-sharing tools, with an audit trail that can show exactly what left the organization, when, and to whom.

The sectors producing the fewest AI governance failures this year weren’t the ones with the biggest security budgets. They were the ones that treated AI governance and data exchange governance as a distinct discipline requiring its own controls, rather than assuming a strong DSMS would carry over automatically. 

Manufacturing has the security foundation to make that shift. The data says most manufacturing organizations haven’t made it yet – and with third-party breaches now accounting for nearly half of all incidents industry-wide, the sector with the deepest supplier network in this survey has the least room left to wait.

Frank Balonis is the Field CTO at Kiteworks.

More in Cybersecurity