Corporate & Thought Leadership

Breaking Point: Why Manufacturing’s Cybersecurity Moment Is Already Here

by Jordan Riddles

The factory floor and the corporate network have been quietly merging for years. Attackers noticed before most security teams did.

Manufacturing has always been good at building things that last. Machinery runs for decades. Processes get refined over generations. Infrastructure gets layered on top of infrastructure until nobody quite remembers what’s underneath anymore. It’s a feature of the industry, not a bug.

Until it isn’t.

The same architectural patience that makes manufacturing efficient has created a security problem that has reached a breaking point. IT and operational technology (OT), the systems that control physical equipment, production lines and industrial processes, now share infrastructure across most manufacturing environments. 

What was once an isolated factory floor is now connected to corporate networks, remote access tools, vendor maintenance portals and Enterprise Resource Planning (ERP) systems. Every connection added for operational convenience is also a connection an attacker can walk through. And they aren’t just walking through, they’re sprinting. 

The Camera of Infinite Peril

SonicWall detected 43 million exploitation attempts against a single IP camera signature in the first half of 2026. Read that again slowly. A single IP camera signature. One type of device. The Hikvision command injection vulnerability, CVE-2021-36260, was disclosed five years ago. It’s still the largest Internet of Things (IoT) attack signature across any industry tracked. Not just in manufacturing. Any industry.

Manufacturing relies heavily on networked cameras for production monitoring, warehouse oversight and facility security. These devices run embedded operating systems, sit on networks alongside production systems and almost never receive patches on a predictable schedule. A five-year-old vulnerability on a device nobody’s patching, connected to a network nobody’s fully segmented. That’s not a future risk. That’s an open door.

And cameras are only one category. Manufacturing networks saw exploitation attempts across 262 unique IoT attack signatures in H1 2026. Every connected device category, including industrial sensors, building automation systems and HVAC controls, has its own vulnerability profile and its own entry point. Can you imagine a threat actor controlling your HVAC in the middle of summer? Making you think a faulty sensor is working properly? It’s a business nightmare waiting to happen. 

A Stolen Password Shouldn’t Be Able to Stop a Production Line

Here’s the architectural problem in plain terms: in most manufacturing environments today, a compromised business credential doesn’t just mean someone has access to email or a procurement application. It means they potentially have a path to the systems controlling physical processes.

Manufacturing has the highest supervisory control and data acquisition (SCADA) attack detection rate of any vertical SonicWall tracks. Across 539 devices and 18 unique attack signatures, networks are seeing active, targeted probes against industrial control systems. Not generic web attacks, but deliberate attempts to reach the OT layer. Ransomware groups have mapped this. Ten active families were targeting manufacturing networks in the first half of 2026, and the Zhen family alone generated 22.2 million hits concentrated on just two devices. That’s not a threat trend to monitor. That’s an active incident.

The reason manufacturing is at a breaking point isn’t that attackers have gotten dramatically more sophisticated. It’s that the attack surface has expanded faster than the security architecture protecting it. The factory floor is now part of the network. The security model hasn’t caught up.

The Breaking Point Is Also a Decision Point

The data in SonicWall’s 2026 Manufacturing Protect Brief doesn’t describe an inevitable outcome. It describes a choice. The convergence of IT and OT was largely driven by operational necessity. Remote monitoring, predictive maintenance and ERP integration all create real business value. None of that has to be undone. What has to change is the assumption that a valid credential equals valid access to everything behind it.

Application-level Zero Trust access, strict IT/OT network segmentation and treating any connection to operational systems as a privileged session are the architectural response to an architectural problem. The production floor doesn’t have to be reachable from a stolen laptop.

The brief lays out exactly where manufacturing networks are exposed and what to do about it. Read the full brief today

Share This Article

An Article By

Jordan Riddles

Content & Copywriting Specialist

Jordan Riddles is a Content & Copywriting Specialist at SonicWall, where he helps bring complex cybersecurity topics to life through clear, engaging content. Since joining the team in 2023, he’s written everything from blogs and email campaigns to case studies, threat briefs and threat reports—always with an eye toward making technical info accessible and interesting. Before SonicWall, Jordan worked as an editor and copywriter in the publishing world. He’s a proud graduate of Northeastern State University in Tahlequah, Oklahoma.

Related Articles

  • Most Targeted, Most Overdrawn: The Financial Sector’s Security Debt
    Read More
  • Code Red: Healthcare Can't Pull the Plug On Its Cybersecurity Problem
    Read More