IT-OT convergence: When ransomware hits the factory floor

What these kinds of cyberattacks on food and beverage makers mean for all manufacturers.

What you’ll learn:

  • Although ransomware attacks can target anyone, food and beverage companies can be particularly vulnerable and hard-hit by coordinated strikes.
  • OT networks are essentially set up to be attacked, with one end of the plant accessible to the other end.
  • There has never been more urgency, with the average manufacturer bracing for 1,585 attempted attacks per week.

What do ransomware attacks on manufacturers look like?

Picture production lines going absolutely dark for days or weeks at a time. Store shelves, normally stocked with products, sitting empty due to serious and prolonged supply chain disruptions. These challenges impact everyone, from frontline workers to the president of the board.

See also: For sweeter AI adoption, Hershey and KDP utilize Augmentir's connected worker platform

Ransomware infects computers, locks them down, and encrypts files or systems until a ransom is paid. Malware can expand quickly in manufacturing environments, taking over computers one by one across the entire network. Every piece of equipment, from the mixer to the labeling machine, likely are talking to each other in this networked, IoT environment.

Although ransomware attacks can target anyone, food and beverage companies can be particularly vulnerable and hard-hit by coordinated strikes.

Why food and beverage makers are targeted

Among manufacturers, food and beverage are highly visible consumer products. There are massive reputational stakes on the line, with any loss of consumer confidence potentially damaging the company’s standing in a crowded marketplace. A halt to the production line has immediate ripple effects on everything from packaging and overtime to meeting product demand for consumers.

A manufacturing plant’s performance is predicated on the use of IT and reliability of their OT networks. As connectivity, automation, data-driven and even AI-enabled systems have become the standard, manufacturers have adapted their OT systems and processes to try to keep up, often developing patchworked networks over time.

See also: U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

Vendor integrations, remote access, unpatched third-party exposures, and shadow IT are more susceptible to ransomware that can cause significant disruption.

OT networks are essentially set up to be attacked, with one end of the plant accessible to the other end. And there are so many open targets, with over 42,700 food and beverage processing sites in the U.S. alone.

All of these factors combine to make food and beverage relatively low-hanging fruit for ransomware attackers.

Years of attacks against manufacturers

Arizona Beverages, one of the largest beverage suppliers in the country, suffered a significant ransomware attack in March 2019 that led to weeks-long disruptions. The ransomware infection was exacerbated by the use of outdated operating systems that were unpatched and no longer supported. The company reportedly spent hundreds of thousands of dollars to recover from the incident and rebuild their entire network.

OT networks are essentially set up to be attacked, with one end of the plant accessible to the other end. And there are so many open targets, with over 42,700 food and beverage processing sites in the U.S. alone.

Last summer, a targeted attack on United Natural Foods Inc. proved to be even more high profile and expensive. UNFI, the leading wholesale distributor of health and specialty food in North America, lost $400 million in sales due to the incident. As part of the fallout, UNFI had to reduce their quarterly earnings for the fourth fiscal quarter of 2025.

In these and other strikes, a worrying pattern has emerged. Attackers can readily expand from initial intrusion to wider attacks in OT that make up more of the company’s operations and cause more pervasive disruptions.

While the importance of bolstering security for OT environments has always been clear, there has never been more urgency, with the average manufacturer bracing for 1,585 attempted attacks per week.

Securing OT is fundamentally different than protecting IT

We all use IT every day, logging on to a computer, joining Wi-Fi, accessing websites, and downloading apps. We’re authenticating to gain access to perform all these tasks. Updates and patches are routine in IT.

Podcast: How AI is altering the landscape of manufacturing cybersecurity

Conversely, OT is highly specialized hardware running on technical protocols that may be supported by older, legacy software. OT prioritizes system availability and physical safety to keep production running. OT’s proprietary protocols lack basic security features like user passwords and data encryption.

Static-by-design networks are another factor working against OT’s relative security posture. Every OT device has a fixed job and is built for stability and predictability. They are difficult to update and not easily patched. Testing a security patch update is typically cost-prohibitive, as it often involves shutting down an assembly line or an entire plant.

Interconnected machines and fragile systems combine to form single-point-of-failure production lines. With continuous assembly lines, a single faulty controller can bring an entire factory to a halt. Restarting a server or running a heavy antivirus scan, which are standard IT security tactics, may overload OT networks and stop production.

Testing an OT security patch update is typically cost-prohibitive, as it often involves shutting down an assembly line or an entire plant.

During a cyberattack, ransomware moves from Windows computer to Windows computer, or Windows to Linux. The programmable logic controller isn’t spreading malware. Robotic arms and conveyor belts aren’t being ransomed.

Rather, it’s the Windows 7 or Ubuntu computer that controls them that is vulnerable and infected. The multipurpose endpoints increasingly deployed as part of OT environments are the targets of ransomware attackers.

All these factors, as well as OT’s acute focus on availability and zero downtime, contribute to manufacturing systems that are uniquely vulnerable to outside attacks.

Modern manufacturers’ OT playbook

So, what can be done to limit exposure to these attacks? Measures like real-time production network visibility, authentication parity between IT and OT, and isolation response time may help level the OT playing field against attackers.

These processes can make a critical difference by blocking hidden threats, preventing unauthorized lateral movement, and containing active cyberattacks before they damage equipment.

See also: Why IT-OT assessments help weigh risk, map modernization

Beyond these practices, manufacturers can learn from IT and apply concepts to OT by moving from simply finding vulnerabilities to taking action to fix the issue. There are also lessons to adapt from critical infrastructure, with the CI Fortify model a prime example of how isolation and recovery can mitigate cyber threats.

According to the international set of standards ISA/IEC 62443, companies need to secure systems in zones for containment and reliability in defending against attacks. If there is an incident, CI Fortify can help contain the threat and quarantine machines, then safely and swiftly recover.

Another way to fortify manufacturers is bringing identity to OT. Identity allows teams to determine which systems can and cannot connect or work together. When every machine on the network is identified, isolating devices and controlling access reduces both the risk and blast radius of these attacks.

And when enabled by identity, isolation is not static or fixed and can even respond by quarantining possible threats. With manufacturing quickly moving to a dynamic world and cyber threats escalating every day, identity is going to offer the best way to keep up and stay as safe as possible.

See also: Hackers exploit PLMs in recent cyberattacks at Shell, GE, Philips

A successful playbook is knowing every machine in the factory. Every machine has identity and access that’s controlled. We can then segment, isolate, and even quarantine as needed safely.

Another way to fortify manufacturers is bringing identity to OT. Identity allows teams to determine which systems can and cannot connect or work together.

We can measure success as the reduction in incidents, the time to identify a potential threat and quarantine it, and the time to recover.

Security ramifications beyond the plant floor

As much as these cyber challenges present immediate impacts to assembly lines and the factory floor, OT security has also become a tangible board-level concern and policywide issue.

Whether it’s a significant PR hit, production stoppage, supply chain disruption, or systemwide malware infection, these attacks are highly visible and can be very costly. And in food and beverage, any change in production or incident could create safety issues.

One approach worth considering is treating these threats to OT with the same level of importance and urgency as food-quality issues or contamination events that can have lasting impacts far beyond the factory floor. Cyber safety might just be as important as the safety of the products being produced.

Ultimately, manufacturing leaders are facing increasing pressure to not only adapt to these new threats but ensure they get OT right.

About the Author

Kevin Bocek

Kevin Bocek

Kevin Bocek is chief product officer at Corsha, vendor of a cybersecurity platform. He drives product strategy to continue building out the Corsha Platform and the industrial identity security category.

Before joining Corsha, Kevin led innovation for CyberArk's cutting-edge machine identity security for workload identity, kubernetes and AI. He brings almost 30 years of experience in cybersecurity with industry leaders, which also include CyberArk, Venafi, RSA Security, PGP Corp., and Xcert.

He has authored several books and is sometimes sought after for comment by media such as The Wall Street Journal, BBC, Reuters, and Handelsblatt.

Sign up for our eNewsletters
Get the latest news and updates