
We've all seen the stats, and I continue to share them in confirming the overarching narratives:
- Manufacturing is the most targeted sector for cyberattacks.
- Ransomware attacks in the industrial sector continue to escalate.
- AI is making it easier for hackers to scale attacks on the ever-expanding threat landscape created by greater connectivity in manufacturing enterprises.
- The legacy equipment employed in industrial OT environments leaves them more vulnerable to attacks.
- Patching, credentialling and asset visibility challenges contribute to all of these problems.
This leaves many manufacturers, especially those with limited security resources, to wonder where they should start in building a stronger cybersecurity foundation. Patricia Egger, head of security at Proton Drive and co-founder of Women in Cyber Switzerland, offers the following focal points to help ensure organizations are working in the right direction, and can have confidence that future endeavors are built on viable, enduring strategies.
- Get the foundations right. Reducing reliance on passwords and moving toward passkeys and cryptographic authentication removes a key attack vector. Pairing this with secure devices, continuous monitoring, awareness training and basic cyber hygiene, and you treat identity, devices and employees as equally important parts of the strategy.
- Provide sanctioned and secure AI tools. New AI tools are appearing every day, so it becomes hard to keep track of what's out there and what employees are using. In a business without a dedicated security function, nobody is even trying to keep track, and that's where the exposure builds up quietly. Providing a sanctioned AI tool that meets employee’s needs and is convenient, will limit shadow AI use. Configure it according to company policies and set up additional security controls. Also, work to reduce the amount of tools, applications and systems the organization uses.
- Set clear norms to prevent accidental oversharing. Often an AI assistant will be granted access to email, files or calendars without an employee registering it. Its access then outlives the task it was installed for and puts company data at risk. Employees can also slip into a vicious cycle of feeding AI agents incremental amounts of information until they're sharing data they wouldn’t have shared on day one. Leaders need to interrupt this drift with clear, concrete norms about what goes into which tool, and with sanctioned tools that are secure by default, so employees don't need a security mindset just to do their jobs safely.
- Build verification habits into the culture. The vast majority of attacks involve some level of social engineering that no technology can fully fix, so build verification habits into the culture. Especially as AI is making impersonation cheaper and more convincing. Employees should feel empowered to hang up and call back through a known channel to check if a call is legitimate. Organizations should ensure all employees know their most important asset to protect, as well as the level of risk associated with their accounts and systems to help prevent social engineering attacks.
- Keep permissions to a minimum. Phishing attacks remain the most prevalent type of breach or attack, but the phishing threat has industrialized. Passwords were conceived in an era when phishing was largely manual. That era is over, and the answer isn't stronger passwords, it's fewer passwords and in-depth defense, with authentication built on cryptographic proof rather than human memory.
- Big breaches are almost never one dramatic failure. They're many small things that seemed entirely unimportant in isolation - that together let an attacker gather intelligence or hop from one system to another. One might be nothing. A hundred nothings can become something. The simplest way to secure a manufacturing business is to start by deciding what’s actually important, because if everything's important, nothing is.
- Don't aim to achieve perfection as it isn't conducive to actual change. Start small, and in a year the progress compounds.






















