OT Cybersecurity for Manufacturers: 2026 Guide

Manufacturing has been the most-attacked sector globally for multiple consecutive years, based on tracking by IBM X-Force. Ransomware demands against manufacturers averaged $1.16 million in 2025, more than double the previous year (Industrial Cyber). Per Dragos data compiled by DeepStrike, 25% of incidents caused full OT-site shutdowns. Unplanned downtime on an automated assembly line costs $2.4 million per hour (CyberUpdates365). Grand View Research values the OT security market at $30.9 billion in 2026, growing at 15.7% CAGR. Yet spending alone does not solve the core problem: most manufacturers still treat operational technology networks with the same playbook they use for IT.

IT vs. OT Cybersecurity: Why the Difference Matters

The gap between IT and OT security reflects fundamentally different operating priorities and constraints that determine which protections work and which ones create new risks.

Dimension IT Security OT Security
Top priority Confidentiality Availability and safety
Patch frequency Regular update cycles Infrequent; requires planned downtime
System lifespan 3-5 years 15-25+ years
Breach impact Data loss, financial damage Physical damage, safety hazards, production downtime

Source: Compiled from Protiviti, BizTech Magazine, and IEC 62443 guidance

IT teams follow regular update cycles. OT teams patch infrequently, because taking a PLC offline can halt an entire production line. IT endpoints run standard antivirus and EDR agents. Many OT devices cannot support any endpoint agent at all. Protiviti reports that many OT environments still rely on aging operating systems and hardware that predate modern cybersecurity design. When organizations merge these two worlds without accounting for the differences, they expose those control systems to internet-facing attack surfaces they were never designed to withstand.

For a deeper look at how ICS/OT cybersecurity trends are reshaping risk management, including AI-powered data exfiltration, board-level governance shifts, and the rise of SBOMs in industrial supply chains.

IEC 62443 in 2026: New Standards for IIoT and Cloud

IEC 62443 is the primary international standard for industrial automation and control system (IACS) cybersecurity. In January 2025, ISA published the updated IEC 62443-2-1, establishing organization-wide cybersecurity management requirements. According to Abhisam’s 2026 standards analysis, the updates go further.

IEC 62443-1-6 (2026) addresses IIoT device security for the first time, covering smart sensors, actuators, and devices connecting to cloud and edge platforms (Abhisam). IEC 62443-6-2 introduces a security evaluation methodology for supplier conformity, and IEC 62443-1-5 defines security profiles for different industry applications. Abhisam reports the standard framework has expanded from four categories to six.

The broader IEC 62443 framework defines four Security Levels (SL1 through SL4), uses a zone-and-conduit architecture for network segmentation, and includes product development lifecycle requirements for vendors (ISA/IEC 62443 overview).

Securing Converged IT/OT Networks: A 5-Step Framework

CISA and U.S. government partners published a zero trust adoption guide for OT environments, and the Cloud Security Alliance published an analysis of zero trust for manufacturing OT. Together, this guidance translates to five practical steps for manufacturers.

  1. Build a complete asset inventory. Identify every OT device, every connection, and every data flow. Protiviti reports that manufacturing cybersecurity programs are less mature compared to sectors like energy or finance, and recommends inventorying all assets, especially legacy devices.
  2. Segment networks into zones and conduits. Follow the IEC 62443 zone-and-conduit model or the Purdue Model to create boundaries between IT, DMZ, and OT layers. USB drives and contractor laptops account for approximately 27% of OT incidents, per industry data. Segmentation limits how far those entry points can reach.
  3. Enforce identity and access management. Apply least-privilege access across all systems. Require multi-factor authentication wherever the OT environment supports it. The Cloud Security Alliance recommends TPM-backed certificates, secure boot, and mutual TLS for devices that support modern authentication, while using behavioral and indirect controls for legacy equipment that cannot.
  4. Deploy continuous monitoring with behavioral analytics. Legacy OT systems that cannot run agents need passive network monitoring and anomaly detection. Per Dragos data compiled by DeepStrike, 88% of OT networks currently struggle with detection and response.
  5. Develop OT-specific incident response playbooks. IT incident response procedures do not account for the physical consequences of shutting down industrial control systems. OT response plans must address safety, process continuity, and physical equipment constraints that IT playbooks ignore.

NIS2 Compliance: What Manufacturers Must Do Now

The EU’s NIS2 Directive classifies manufacturers as “important entities” subject to mandatory cybersecurity requirements (Secomea). Legiscope reports that penalties for important entities reach up to EUR 7 million or 1.4% of global annual revenue, whichever is higher. Germany transposed NIS2 into national law on December 6, 2025, with immediate effect and no transition period (Reed Smith). NIS2 Article 20 makes management bodies accountable for cybersecurity risk management, elevating OT security to a board-level issue.

Key deadlines manufacturers should track:

  • Registration: Most EU member states required registration in 2025 (Secomea). Germany’s BSI registration deadline is March 6, 2026 (Reed Smith).
  • Incident reporting: 24-hour early warning, 72-hour full incident notification, one-month final report required (Legiscope)

According to Legiscope, approximately two-thirds of EU member states had completed NIS2 transposition into national law by March 2026. Secomea’s country-by-country tracker lists 16 EU and EEA countries that have adopted national NIS2 laws, including Belgium, Croatia, and Hungary, while others remain in draft stages. For manufacturers operating across borders, compliance requires mapping operations against each member state’s specific implementation.

The convergence of NIS2, IEC 62443 updates, and rising attack frequency means that OT cybersecurity is now a regulatory and financial imperative, not a discretionary investment.


FAQ

1. What is the difference between IT and OT cybersecurity?

IT cybersecurity prioritizes confidentiality of data, with regular patching cycles and standard endpoint protection on systems with 3-5 year lifespans. OT cybersecurity prioritizes availability and physical safety, protecting equipment that runs for 15-25+ years and often cannot accept software agents or regular patches without risking production shutdowns. A breach in IT typically means data loss; a breach in OT can cause physical damage, safety hazards, or production downtime (Protiviti, BizTech Magazine).

2. How do manufacturers secure converged IT and OT networks?

Start with a complete asset inventory covering every OT device and connection. Segment networks using the IEC 62443 zone-and-conduit model to isolate IT, DMZ, and OT layers. Enforce least-privilege access with multi-factor authentication. Deploy passive behavioral monitoring on legacy systems that cannot run endpoint agents. Develop OT-specific incident response playbooks, since IT procedures do not account for the physical consequences of shutting down industrial processes (CISA, Cloud Security Alliance).

3. What is IEC 62443 and why does it matter for manufacturers?

IEC 62443 is the international standard for industrial automation cybersecurity, managed by ISA and IEC. It provides a risk-based framework with four Security Levels, a zone-and-conduit network architecture, and product development lifecycle requirements. The 2026 updates add IIoT device security (IEC 62443-1-6), supplier evaluation methodology (IEC 62443-6-2), and industry-specific security profiles (IEC 62443-1-5), expanding the framework from four categories to six (Abhisam).

4. How should manufacturers start with OT cybersecurity?

Follow the five-step framework based on CISA and Cloud Security Alliance guidance: (1) build a complete asset inventory, (2) segment networks into zones and conduits per IEC 62443 or the Purdue Model, (3) enforce identity and access management with least-privilege policies, (4) deploy continuous monitoring with behavioral analytics for legacy systems, and (5) develop OT-specific incident response playbooks. Protiviti reports that manufacturing cybersecurity programs are less mature compared to sectors like energy or finance, so starting with asset visibility is a recommended first step.

5. How do manufacturers achieve regulatory compliance for connected OT devices?

Under NIS2, manufacturers must register with national authorities, implement risk management measures aligned with IEC 62443, and report incidents within 24 hours (early warning) and 72 hours (incident notification), with a final report due within one month, per Legiscope. Penalties for important entities reach EUR 7 million or 1.4% of global revenue. NIS2 Article 20 holds management bodies accountable for cybersecurity risk management. IEC 62443-1-6 (2026) now specifically covers IIoT device security for sensors and actuators connecting to cloud and edge platforms (Abhisam), addressing security requirements for connected devices in industrial environments.

6. How can manufacturers secure operational technology networks against ransomware?

According to Industrial Cyber, manufacturing-specific ransomware attacks rose 56% in 2025, reaching 1,466 documented incidents. Per Dragos data compiled by DeepStrike, 75% of cases disrupted operations, with 25% causing full site shutdowns. Key defenses include network segmentation to contain lateral movement, behavioral monitoring for systems that cannot run endpoint protection, and supply chain vetting, since 61% of manufacturing breaches involved third parties per the Verizon 2026 DBIR (via DeepStrike). The 88% of OT networks that lack effective detection and response (Dragos via DeepStrike) should prioritize passive network monitoring as an immediate step.

Related from IIoT World

Sources

AI tools were used to help research and organize the content. Reviewed and edited by the IIoT World editorial team.