Manufacturing Cybersecurity Under Threat
The manufacturing industry is facing a critical juncture in cybersecurity as revealed by SonicWall's latest report, the 2026 Manufacturing Protect Brief. This comprehensive research underscores the alarming vulnerabilities in factory environments, highlighting a shift in cyber threats that could jeopardize operational integrity.
Key Findings
The report indicates that, while the overall number of cyberattacks in manufacturing has witnessed a decline, the nature of these attacks is shifting towards more targeted and strategic efforts. In the first half of 2026, intrusion prevention events dropped by 56.2% year-over-year, making it the largest reduction among all tracked sectors. However, this drop should not be misinterpreted as a decrease in risk; the volume of attacks remains staggeringly high with 474 million incidents logged.
One notable statistic shows that the Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260), first disclosed in 2021, continues to dominate the attack landscape, amassing 43 million attempts in just six months.
The Growing Attack Surface
The expansion of Internet of Things (IoT) devices in manufacturing facilities has significantly increased exposure to threats. The interconnectedness of systems—from networked security cameras to industrial sensors—has created various entry points for cybercriminals. SonicWall's findings demonstrate that IoT attacks were the second-largest category in manufacturing, with over 46 million attempts logged.
Despite a reduction in the overall number of intrusion events, the landscape reveals a much higher selectivity among attackers, targeting specific vulnerabilities in manufacturing’s operational technology that were often ignored historically.
Ransomware Threats
The study also highlights a worrying trend regarding ransomware attacks, with ten distinct families noted as active against manufacturing systems. Focusing on the Zhen ransomware, the report recorded an astonishing 22.2 million hits on just a pair of devices, indicating concentrated and sustained attacks rather than widespread campaigns.
Old Vulnerabilities Persist
Legacy systems and outdated software remain major culprits in the cybersecurity landscape of manufacturing. Devices designed without modern security in mind tend to run on unpatched software and are frequently placed on networks that intersect with critical production systems. Consequently, vulnerabilities from previous years, such as the Hikvision camera flaw, continue to be significant threats today.
Michael Crean, SVP of Managed Services at SonicWall, emphasized the changing nature of manufacturing security: “The architecture supporting our defenses doesn't keep pace with the new threats we face. Every new connection made for convenience can turn into an entry point for attackers.”
The Path Forward
These challenges compel the manufacturing sector to adopt more sophisticated cybersecurity measures. SonicWall advocates for a Zero Trust approach, emphasizing continual verification of user identities and device security posture. This method limits potential damage by ensuring that even if credentials are compromised, attackers cannot easily access critical systems.
By eliminating broad VPN access in favor of application-level controls, manufacturers can significantly mitigate risks associated with stolen credentials. As organizations link their corporate offices to the production floors for improved efficiency, securing these transitions is imperative.
In conclusion, the manufacturing sector's cybersecurity must evolve. With increased connectivity and the rising threat of cybercrime, manufacturers need to re-evaluate their security postures and adapt to protect not only their data but also their operational capacity. For more information, visit
SonicWall.