.jpg%3Fwidth%3D1200%26height%3D500&w=3840&q=75)
Manufacturing has always been good at building things that last. Machinery runs for decades. Processes get refined over generations. Infrastructure gets layered on top of infrastructure until nobody quite remembers what’s underneath anymore. It’s a feature of the industry, not a bug.
The same architectural patience that makes manufacturing efficient has created a security problem that has reached a breaking point. IT and operational technology (OT), the systems that control physical equipment, production lines and industrial processes, now share infrastructure across most manufacturing environments.
What was once an isolated factory floor is now connected to corporate networks, remote access tools, vendor maintenance portals and Enterprise Resource Planning (ERP) systems. Every connection added for operational convenience is also a connection an attacker can walk through. And they aren’t just walking through, they’re sprinting.
SonicWall detected 43 million exploitation attempts against a single IP camera signature in the first half of 2026. Read that again slowly. A single IP camera signature. One type of device. The Hikvision command injection vulnerability, CVE-2021-36260, was disclosed five years ago. It’s still the largest Internet of Things (IoT) attack signature across any industry tracked. Not just in manufacturing. Any industry.
Manufacturing relies heavily on networked cameras for production monitoring, warehouse oversight and facility security. These devices run embedded operating systems, sit on networks alongside production systems and almost never receive patches on a predictable schedule. A five-year-old vulnerability on a device nobody’s patching, connected to a network nobody’s fully segmented. That’s not a future risk. That’s an open door.
And cameras are only one category. Manufacturing networks saw exploitation attempts across 262 unique IoT attack signatures in H1 2026. Every connected device category, including industrial sensors, building automation systems and HVAC controls, has its own vulnerability profile and its own entry point. Can you imagine a threat actor controlling your HVAC in the middle of summer? Making you think a faulty sensor is working properly? It’s a business nightmare waiting to happen.
Here’s the architectural problem in plain terms: in most manufacturing environments today, a compromised business credential doesn’t just mean someone has access to email or a procurement application. It means they potentially have a path to the systems controlling physical processes.
Manufacturing has the highest supervisory control and data acquisition (SCADA) attack detection rate of any vertical SonicWall tracks. Across 539 devices and 18 unique attack signatures, networks are seeing active, targeted probes against industrial control systems. Not generic web attacks, but deliberate attempts to reach the OT layer. Ransomware groups have mapped this. Ten active families were targeting manufacturing networks in the first half of 2026, and the Zhen family alone generated 22.2 million hits concentrated on just two devices. That’s not a threat trend to monitor. That’s an active incident.
The reason manufacturing is at a breaking point isn’t that attackers have gotten dramatically more sophisticated. It’s that the attack surface has expanded faster than the security architecture protecting it. The factory floor is now part of the network. The security model hasn’t caught up.
The data in SonicWall’s 2026 Manufacturing Protect Brief doesn’t describe an inevitable outcome. It describes a choice. The convergence of IT and OT was largely driven by operational necessity. Remote monitoring, predictive maintenance and ERP integration all create real business value. None of that has to be undone. What has to change is the assumption that a valid credential equals valid access to everything behind it.
Application-level Zero Trust access, strict IT/OT network segmentation and treating any connection to operational systems as a privileged session are the architectural response to an architectural problem. The production floor doesn’t have to be reachable from a stolen laptop.
The brief lays out exactly where manufacturing networks are exposed and what to do about it. Read the full brief today
Share This Article

An Article By
An Article By
Jordan Riddles
Jordan Riddles