JCIT Blog

Ransomware Is Hammering Manufacturers: An OT Security Starting Point for Wasatch Front Shops

August 2026 6 min read

If you run a manufacturing operation along the Wasatch Front, you have probably noticed that "cybersecurity" used to feel like an office IT problem and now feels like a production problem. That shift is real, and the numbers back it up. Manufacturing has been the most-attacked industry in the world for four years running, and ransomware incidents against manufacturers jumped roughly 61% in 2025. Attackers are not picking on factories by accident. They have figured out that when a plant goes down, the pressure to pay adds up fast, because every hour of stopped production is money walking out the door.

The good news is that a smaller manufacturer does not need an enterprise security budget to make real progress. You need to understand how these attacks actually reach the shop floor, and then make a few proportional moves that close the doors attackers use most. Here is a plain-language starting point.

How a front-office breach shuts down the shop floor

Here is the part that catches a lot of owners off guard. The attacker almost never walks straight into your production equipment. They get into the boring stuff first: an email account, a billing PC, a shared file server in the front office. From there, they look for a path into the systems that actually run the plant.

In most shops, the office network and the production network are more connected than anyone realizes. Someone set up a convenient link years ago so a machine could pull a file, or so a supervisor could check output from their desk, and it never got locked back down. That convenient link is the bridge. Once ransomware crosses it, the same attack that would have just encrypted your invoices can now reach the systems controlling your equipment, and production stops.

So when you hear "IT security" and think it does not apply to your machines, that is the exact assumption attackers are counting on.

The legacy equipment problem, in plain terms

A lot of the gear that runs a manufacturing floor was built to run reliably for a very long time, not to defend itself against hackers. The PLCs (the small controllers that run individual machines) and SCADA systems (the software that monitors and coordinates the line) were often designed in an era when nobody imagined they would ever touch the internet. Many of them cannot run modern security software, cannot be patched easily, and were never meant to be exposed to an office network at all.

That is not a reason to panic, and it is definitely not a reason to rip out equipment that still does its job. It is a reason to treat that older gear like a bank vault: valuable, hard to upgrade, and something you build walls around rather than expecting it to defend itself.

Three proportional moves that actually matter

You do not need to boil the ocean. For a small or mid-sized manufacturer, three moves deliver most of the protection.

1. Segment your network. This is the single highest-value step. Separate the office network from the production network so that a compromised billing PC physically cannot reach the machines. Think of it as putting a locked door between the front office and the shop floor. If an attacker gets into email, segmentation is what stops that from turning into a plant shutdown. Done right, your equipment can still get the data it needs, but only through controlled, monitored paths.

2. Get your backups right, and test them. Ransomware is a bet that you cannot recover without paying. Good backups call that bluff. The key word is "tested." A backup you have never restored from is a hope, not a plan. You want copies that are kept separate from the systems they protect, so the ransomware cannot encrypt your backups along with everything else, and you want to have actually practiced bringing things back so you know how long it takes.

3. Train the people at the keyboards. Most attacks still start with a person clicking something. A short, practical training program that teaches your team to spot a fake invoice, a suspicious login prompt, or a too-good email attachment costs almost nothing and stops a large share of attacks before they begin. This matters just as much for the front office as the floor, because the front office is usually where the attacker lands first.

What IT/OT convergence means for your risk (and your insurance)

You will hear the phrase "IT/OT convergence," and it just means your business systems and your production systems are increasingly tied together. That connection brings real benefits, like better visibility into output and easier scheduling. It also means the two worlds now share risk. A weakness in one can become a problem in the other.

This is also showing up in insurance. Cyber insurers have gotten far more demanding about what they expect to see before they will cover a manufacturer, and increasingly before they will pay a claim. Network segmentation, multi-factor authentication, and reliable backups are moving from "nice to have" to "show us you have these or we are not writing the policy." Getting these controls in place protects your operation and protects your coverage at the same time.

A realistic path forward for a local shop

The mistake we see is manufacturers looking at enterprise security programs, deciding it is all too much, and doing nothing. That is the worst outcome. The right approach for a Wasatch Front shop is proportional: figure out where your office and production networks touch, put a proper barrier between them, get backups you have actually tested, and train your people. That covers most of the real-world risk without an enterprise-sized budget or a full-time security staff.

This is the kind of work we handle for manufacturers around Salt Lake City and the surrounding area. We start by mapping how your networks actually connect, because that map almost always reveals a surprise or two, and then we close the gaps in priority order. You keep the equipment that works. We just make sure a bad click in the front office can never again turn into a stopped line.

Not sure where your office and shop floor networks touch?

We map how your networks actually connect, then close the highest-risk gaps first. Start with a free, no-pressure assessment.

Get a Free IT Assessment