Manufacturers now absorb roughly half of all ransomware attacks worldwide. Most of what drives that number is fixable, if you know where to start.
It's 6 AM and the plant manager can't release a work order. Not because a machine is down, but because the ERP system that tells the machine what to build is encrypted, the file server holding CAD drawings is encrypted, and the ransom note on every screen in the front office says the attackers were inside for eleven days before anyone noticed. Production stops. Trucks sit at the dock with nothing to load. Customers start calling. Somewhere in the plant, a supervisor is trying to remember whether the backup that's supposed to fix this was ever actually tested.
This isn't a hypothetical scenario built to scare you into a sale. It's the median week for a manufacturer hit by ransomware in 2025, and it's happening more often, to smaller companies, than most mid-market leaders realize.
Manufacturing didn't used to be the top target. Now it is.
For years, conventional wisdom held that ransomware crews went after banks, hospitals, and Fortune 500 names with deep pockets. That's no longer where the numbers point. According to Check Point Research, manufacturing absorbed roughly half of all ransomware incidents recorded globally in 2025, with attacks against the sector surging 56% year-over-year to 1,466 confirmed cases, up from 937 the year before. Verizon's 2025 Data Breach Investigations Report tells the same story from a different angle: manufacturing logged 1,607 confirmed data breaches, nearly double the prior year's 849, and ransomware was involved in 47% of them.
Why manufacturing, specifically? Three structural realities make the sector unusually attractive to attackers. Legacy operational technology is everywhere: Check Point found that 80% of European manufacturers were still running critical OT infrastructure with known, unpatched vulnerabilities. Supply chains have become a second front door. Supply-chain-related attacks nearly doubled, from 154 to 297 incidents year-over-year, as attackers compromise a smaller vendor or managed service provider to reach a larger industrial target. And production creates leverage that a typical office environment doesn't have. A manufacturer facing a shut-down line has a much shorter fuse than a company that can simply route around a downed file share.
The numbers that matter
of all ransomware attacks worldwide in 2025 hit manufacturers
Check Point Research, 2025
of manufacturers hit by ransomware paid the ransom, a median of $1M
Sophos, State of Ransomware in Manufacturing 2025
average cost of a data breach in the industrial sector
IBM, Cost of a Data Breach 2025
Why manufacturers make an easy mark
The uncomfortable part of this story isn't the attackers. It's how avoidable a lot of these incidents turn out to be. Sophos surveyed 332 manufacturing organizations that were hit by ransomware in 2025 and asked them, after the fact, what let the attacker in. The top three answers weren't exotic zero-days or nation-state tradecraft. They were a lack of security expertise (cited by 42.5%), security gaps the organization didn't know it had (41.6%), and simply insufficient protection for what they had (41%). Put plainly, most manufacturers that get hit aren't outmatched by sophisticated adversaries. They're under-resourced against ordinary ones.
That tracks with what mid-market manufacturers typically look like from the inside. IT teams are lean and focused on keeping production running, not threat-hunting. Security tools, where they exist, often go unmonitored, with alerts piling up in a console nobody has time to watch. OT and IT networks that were designed decades apart now share the same flat network because someone needed a dashboard to talk to a PLC. And the pressure to get the line moving again makes paying a ransom feel like the fast option, even though Sophos's own data shows the median payment of $1 million bought back only partial certainty. Recovery still cost affected manufacturers an average of $1.3 million beyond the ransom itself, and payment is never a guarantee that stolen data won't surface anyway.
None of this is a reason for fatalism. It's the opposite. If the primary causes are expertise gaps, unknown exposure, and thin protection, all three are directly addressable, and none of them require a Fortune 500 budget to fix.
Reducing the risk: a practical framework
The #StopRansomware Guide published jointly by CISA, the FBI, NSA, and MS-ISAC lays out the core defensive playbook, and it holds up well for manufacturing environments specifically. Here's how it translates into a prioritized set of actions for a mid-market plant.
1. Put phishing-resistant MFA on everything that matters. Email, VPNs, remote access, and any account that touches critical systems. Passwords alone are not a control anymore. They're a formality attackers walk past.
2. Patch what's exposed to the internet first, and patch known-exploited vulnerabilities fastest. You don't need to patch everything overnight. You need a defensible, risk-based order, with internet-facing systems and anything on CISA's Known Exploited Vulnerabilities list at the front of the line.
3. Separate IT from OT. This is the single highest-leverage architectural change most manufacturers can make. A ransomware infection that starts in the front office should never have a clear path to the plant floor. Network segmentation and zero-trust principles contain the blast radius before it reaches production.
4. Lock down email. Filter external mail, disable Office macros by default, implement DMARC/SPF/DKIM, and block the attachment types that don't belong in your inbox. Email is still the most common way attackers get an initial foothold.
5. Deploy endpoint detection and response, and make sure someone is actually watching it. A tool that generates alerts nobody reads is functionally the same as no tool. This is precisely the gap Sophos's "lack of expertise" and "unknown gaps" findings point to.
6. Make your backups ransomware-resistant, and test them like your recovery depends on it. Because it does. Offline, immutable, or logically isolated backups that an attacker on your network can't reach or encrypt. Then actually restore from them on a schedule, before an emergency forces the first real test.
7. Enforce least privilege and eliminate exposed RDP. Remote access is one of the most reliable entry points into manufacturing environments. If RDP has to be exposed at all, it needs MFA and tight restriction, not a default port sitting open to the internet.
8. Train your people like it's part of the job, not a compliance video. Realistic phishing simulations and pretexting tests, with real feedback, consistently outperform annual training modules nobody remembers a week later.
9. Know who's plugged into your network. With supply-chain-related attacks nearly doubling in a single year, the vendors, integrators, and managed service providers with access to your environment are now part of your attack surface. Vet them accordingly.
10. Build and test your incident response plan before you need it. A ransomware playbook that only exists as a document nobody has rehearsed is a plan in theory only. Run a tabletop exercise. Find the gaps on a Tuesday afternoon, not during an actual outage.
If prevention fails, how you respond matters just as much
Manufacturers face a specific pressure that other industries often don't: every hour of downtime is a visible, quantifiable production loss, which makes the temptation to just pay and move on especially strong. It's worth being direct about the trade-offs. The FBI and CISA both highly discourage payment, in part because it funds the next attack and offers no guarantee that decryption will work cleanly or that stolen data won't be leaked regardless. Sophos's data backs this up in practice: the manufacturers who paid still absorbed substantial recovery costs on top of the ransom itself.
What consistently shortens the bad outcome is preparation that exists before the incident: a response team that already knows your environment, a plan with defined roles and communication paths, and backups that have actually been proven to work. Organizations with a tested incident response plan and team save real money and real time compared to those improvising in the moment. The gap between the two is usually measured in weeks of downtime, not hours.
Ransomware defense is a program, not a product.
The manufacturers that get hurt worst aren't the ones with no security spending. They're the ones with scattered investments and no one connecting the pieces.
Why Digital Elevation
Every item in the framework above maps to something we do for mid-market manufacturers every day.
We find the gaps before attackers do. Our Security Assessments go across network, cloud, and physical controls to surface the "unknown security gaps" that Sophos's research identifies as a top root cause, before they turn into an incident.
We keep the entry points closing. Vulnerability Management and External Vulnerability Scanning give you a continuously updated, prioritized view of what needs patching, with authenticated and non-authenticated testing of your internet-facing perimeter and an attestation letter for your auditors and insurance carrier.
We watch what your tools are already telling you. Our vSA (virtual Security Analyst) service puts a dedicated analyst on your alerts around the clock, triaging and responding in real time. That directly addresses the "lack of expertise" gap that leaves EDR consoles unread until it's too late.
We build and pressure-test your people. Our Social Engineering service runs realistic phishing simulations and pretexting tests so you know exactly where human defenses break, and our Tabletop Exercises put your executive and IT team through a simulated breach so the first time you run your plan isn't during a real one.
We give you security leadership without a security-executive salary. Our vCSO service provides fractional, board-ready leadership to own the strategy behind everything above (segmentation, backup posture, vendor risk, budget) instead of leaving it to whoever has the most spare time this quarter.
We're already running when the call comes. Our Incident Response retainer means the environment familiarization, custom response plan, and pre-established access happen months before you need them, so when something does happen, the response starts in minutes, not days.
An honest caveat
None of this is a single purchase that makes the risk go away. A manufacturer that buys EDR but never segments IT from OT, or that runs a tabletop exercise once and calls it done, hasn't meaningfully changed its exposure. Ransomware defense is a program, not a product. It requires the technical controls above, but also leadership attention, a realistic budget, and the discipline to actually test what you've built instead of assuming it works. The manufacturers that get hurt worst aren't usually the ones with no security spending at all. They're the ones with scattered investments and no one connecting the pieces. That coordination is the part most worth getting outside help with.
Where to start
You don't have to fix all ten items in the framework at once, and you shouldn't try. Start with a real picture of where you stand (most mid-market manufacturers are surprised by what a proper assessment turns up), then prioritize by what would actually stop production if it failed. Manufacturing didn't choose to become ransomware's top target. But mid-market plants do get to choose how ready they are for it.
Get a clear picture of where your plant stands. Start the conversation with Digital Elevation.
Sources
- Check Point Research, cited in Industrial Cyber, "Manufacturing absorbs 56% ransomware surge of global attacks in 2025, as RaaS, legacy OT, supply chains fuel spike" (2025): manufacturing's share of global ransomware attacks, year-over-year growth, legacy OT vulnerability rate, supply-chain attack growth. industrialcyber.co
- Verizon, 2025 Data Breach Investigations Report, Manufacturing Snapshot: confirmed breach counts, ransomware involvement rate, breach pattern distribution. verizon.com
- Sophos, "The State of Ransomware in Manufacturing and Production 2025": ransom payment rate, median ransom paid, recovery cost, root causes of successful attacks. sophos.com
- IBM Security, Cost of a Data Breach Report 2025: industrial sector average breach cost. ibm.com/reports/data-breach
- CISA, FBI, NSA, and MS-ISAC, #StopRansomware Guide: core prevention and hardening recommendations. cisa.gov/stopransomware/ransomware-guide
W. Scott Montgomery is Director of Security at Digital Elevation, a Springthrough company helping mid-market organizations understand their real security risk and do something about it.