/
Contención de ransomware

How Manufacturers Can Keep One Breach From Stopping the Plant

In July, a ransomware attack forced Coca-Cola’s Fairlife dairy business to halt U.S. production. Coca-Cola said product safety and quality weren’t affected. Production stopped anyway.

The ransomware group Anubis later claimed responsibility. It said it had stolen 1 terabyte of data and threatened to publish it unless a ransom was paid. Eleven days after Coca-Cola disclosed the attack, Fairlife had resumed most production at its four U.S. plants.

Attacks like this one are surging across manufacturing. Black Kite tracked 1,183 disclosed manufacturing ransomware incidents worldwide from January 1 through July 29, 2026. That’s nearly 40% more than in the same period in 2025, and more than in all of 2024.

Manufacturers are targets because downtime is leverage. Every hour a line sits idle puts orders, revenue, and customer commitments at risk.

“Stopping operations puts pressure on a business whose revenue depends on making and delivering products,” said Trevor Dearing, director of critical infrastructure solutions at Illumio.

Manufacturers can reduce that pressure by planning for a breach before it happens. The goal is to keep one compromised system from becoming a plant-wide shutdown.

As production advances, security falls behind

Downtime is one source of leverage. Stolen data is another. Designs, formulas, and production knowledge are valuable targets.

“Stealing intellectual property creates another opportunity for extortion or theft,” Dearing said.

At the same time, manufacturers are connecting more of their operations. Remote maintenance and data sharing improve efficiency. They also open new paths into the plant.

“Manufacturing is transforming faster than its security,” he said.

The gap runs between teams, too. IT security teams understand cyberthreats but may lack detailed knowledge of production. Plant teams know the equipment but may be less familiar with the risks new connections create.

“Neither team can solve this alone,” he said. “Together, they need to understand which systems production depends on and how a breach could spread between them.”

One workstation, plant-wide risk

Engineering workstations show how. Staff use them to configure and maintain equipment. Those same connections can give attackers a route into the rest of the plant.

“Someone could be sitting at an engineering workstation opening their personal email,” Dearing said. “A phishing attack could introduce ransomware onto that workstation.”

From there, attackers could move laterally to connected systems or disable services the plant needs. Protecting the equipment alone leaves a gap. Manufacturers also need to understand and protect the connections and services behind it.

Start with a map of how production runs

Dearing recommends working out how production runs first, then mapping the systems and connections that support it. A device list tells teams what they have. A map shows what depends on what.

The next step is a protocol audit, a review of how systems communicate. It should flag:

  • Remote desktop access where it doesn’t belong
  • Insecure protocols
  • Access beyond what a system needs to do its job

“You need a view of how everything is connected,” he said. “Then you need to understand what’s vulnerable, what it can reach, and where the risk lies.”

IT and plant teams need to review those findings together. Operators know which connections production requires. Security teams can see where that access creates risk.

Joint U.S. government guidance on adapting Zero Trust to operational technology (OT) backs this up. It calls for visibility, controlled access, and segmentation that account for safety and reliability.

Give every connection a purpose

Once teams understand what production needs, they can limit access to match. Manufacturing has an advantage here. Many systems do one narrow task and use a small set of protocols, which makes precise access rules easier to write.

“Give the workstation the connections it needs to do its job,” Dearing said. “Each connection should have a clear purpose.”

He recommends segmentation between IT and OT, and within the plant itself. Those boundaries cut the paths an attacker can use to spread.

The same principle applies to vendors. A supplier servicing one piece of equipment shouldn’t have access to unrelated systems. Its remote connection should pass through identity controls the manufacturer owns.

For equipment that can’t be patched easily, restrict what can reach it. The flaw remains, but fewer systems can touch it.

All of this depends on understanding the process first. Before enforcing new rules, teams need to confirm they won’t block traffic production needs.

Build the big red button before you need it

Access rules limit how far a breach can spread. Dearing also recommends a plan to isolate production when one gets close. He calls it a “big red button”: a prepared way to cut production off from a breach in the wider business. The plan should spell out what to disconnect, who authorizes it, and which services must stay up.

“The goal is to isolate production so it can keep going, even if other systems go down,” he said. “You need to build that plan before something goes wrong.”

A plan no one has run is only a guess.

“You’ve got to test it,” he said. “You need to know that the plan works.”

Some processes depend on shared login services, remote support, or outside data. Isolation could cut those off, so teams need to understand the consequences before an attack. A test should confirm which processes can continue, which must stop safely, and what to restore first.

The UK National Cyber Security Centre’s August alert makes the same point. It urges operators to plan for rapid isolation and practice restoring systems from trusted backups.

Dearing’s advice comes down to three things: know what production needs, control access to it, and prove that containment works. Fairlife needed 11 days to bring most of its production back. The time to learn what keeps a plant running is before it stops.

Artículos relacionados

Experimente Illumio Insights hoy

Vea cómo la observabilidad impulsada por IA le ayuda a detectar, comprender y contener amenazas más rápido.