In 2025, nearly 3,300 industrial organizations worldwide were hit by ransomware — the attack in which a program scrambles the company's files and demands payment to unlock them — according to the annual industrial security report from Dragos, published in 2026. This isn't a number about "organizations in general": it's plants, mines, power stations, distributors — businesses that depend on equipment running, not just a computer being on.

South America shows up in that picture as one of the most targeted regions in the world among computers that control industrial equipment: 20.4% of them had a malicious object blocked in the fourth quarter of 2025, according to Kaspersky — 2.4 times the rate in Northern Europe, the lowest in the report. Much of it arrived through the corporate email inbox, not some exotic machine failure.

For whoever runs a plant, why this matters isn't abstract. It isn't "the network went down." It's the production order that won't release, the inventory the system won't update, the invoice that won't print, the equipment waiting on a command that never arrives. Sixty people on shift, the line stopped, and an order with a shipping date already booked.

What breaks when the system goes down

On a factory floor, IT stopped being just "the office computer" a long time ago. It's IT that releases the production order so the floor can start running, that tracks raw material and finished goods, that issues the outbound invoice, and that, on many modern lines, exchanges information directly with the equipment — speed, product recipe, part count. When that system locks up, the plant doesn't lose email. It loses permission to work.

The broader picture has also gotten tenser: according to the X-Force Threat Intelligence Index 2026, from IBM, exploitation of internet-facing applications grew 44% year over year, across all organizations measured, and the number of active ransomware groups rose 49% in the same period. That isn't a number specific to industry — but it's the backdrop against which the manufacturing-specific figures below show up.

The problem rarely arrives like a movie hack, someone tampering with a machine in real time. It arrives as the administrative system — the same one that releases orders, tracks inventory, talks to the equipment — going down or getting locked. Dragos, which tracks industrial environments worldwide, was actively monitoring 26 attack groups focused specifically on this kind of environment in 2025. And in the same report, only 30% of industrial networks have enough visibility to spot a threat before it affects operations. In practice: most plants only find out something is wrong once the line has already stopped.

The most common way in isn't sophisticated. Kaspersky measured that, in the second quarter of 2025, Latin America led every region in the world in attacks that arrive through fake pages and malicious code hidden in a link — 9.18% of industrial computers hit, the highest rate in the report. A fake email, a clicked link, an opened file: the same mistake that already brings down an office also brings down, with the wrong network layout, the system that talks to the entire plant.

That changes the question an owner needs to ask. It isn't "can my machine be hacked" — it's "if the system that releases production locks up tomorrow morning, how long is the shift stopped before someone notices, understands what happened, and brings everything back up correctly."

Why the usual approach doesn't fix it

Why the usual approach doesn't fix it

The usual approach, at most mid-sized manufacturers, is one network for everything: the executive's computer, the accounting system, the workstation that talks to the machine — all together, with no separation. Nobody watches how that network behaves before something goes wrong; IT gets called once the line has already stopped. And the computer running a machine bought twelve years ago, which can't simply be "updated" because the manufacturer doesn't even exist anymore, stays plugged in exactly as it always was.

That design has a direct consequence: a problem that starts on one department's computer — accounting, the front desk, a visitor's laptop — doesn't stay contained there. It spreads to wherever production depends on a system to run. And because nobody monitors the plant network separately from the office network, the first sign that something is wrong is usually the line itself stopping.

What has to be in place

An IT setup ready for a manufacturing plant is defined by concrete mechanisms, not a promise of security.

A separate network for whatever talks to the machine. The computer controlling production equipment shouldn't sit on the same network as an executive's laptop or the accounting inbox — that way, a problem starting on one of those never reaches the line.

An agreed-upon way to keep production running while the system comes back. Before it's needed, the plant decides: does the shift continue with printed orders and manual logging until the system returns, or does the line stop safely? Without that agreement, the call gets made in a panic, mid-shift.

A specific plan for the computer nobody can update. Every plant has a machine running on an old system, because the equipment manufacturer no longer supports anything newer. Isolating that computer from the rest of the network and watching what goes in and out of it is the answer — replacing it isn't always possible.

Controlled remote access for the machine manufacturer's technician. When the equipment vendor needs to log in remotely to calibrate or repair something, access is opened for that specific visit and closed afterward — not a door left open all year for convenience.

An alert before the shift starts, not after the line stops. Someone watching how the plant network behaves catches the out-of-pattern signal overnight, before the first shift clocks in — not by hearing from an operator that the system won't release an order.

This is how Skills IT works: the plant network kept separate from the administrative network, vendor remote access under control, and monitoring built to warn before the shift starts, not after the line stops.

What the plant gains when IT stops being the weak link

The most direct gain is the obvious one: fewer hours of line downtime from a problem that was already known and avoidable — and less risk of a contractual penalty for a late shipment the customer bills later. But the bigger gain shows up in the full-year budget, not in a single incident. A fixed, predictable IT cost, negotiated before any project starts, is easier to defend to leadership than an emergency bill that arrives after the line has already stopped.

There's also an effect on the team. When the system that releases the production order is unstable, the shift supervisor unintentionally becomes an improvised IT technician — trying to restart, reboot, guess what locked up. Every minute spent on that is a minute away from the job that's actually theirs: running the line.

Finally, decisions made with information. A plant that knows, in real time, the state of its inventory and production makes better calls on accepting a rush order, reassigning a shift, or renegotiating a deadline with a customer. An unstable system takes that exact information off the table right when it's needed most.

A roadmap to get started

Before signing off on any project, it's worth bringing these questions to the next meeting with leadership and whoever handles IT today:

  1. Is the plant network separate from the office network? If an infected laptop in accounting can "talk" to the computer controlling a machine, the answer is no.
  2. Is there an agreed-upon plan to keep production going if the system goes down mid-shift? If the answer only exists in one person's head, it isn't a plan — it's luck.
  3. Can anyone list, off the top of their head, which machines run on a system that no longer gets updates? If nobody knows, you can't protect what isn't mapped.
  4. Is the equipment vendor's remote access open all year, or only during service visits? A permanent access point is a door nobody remembers exists anymore.
  5. Who would notice a problem in the production system first: the monitoring, or the shift operator? If the answer is the operator, the alert is arriving too late.