Podcast: How AI is altering the landscape of manufacturing cybersecurity

In this episode of Great Question, Scott Achelpohl of Smart Industry and Dennis Scimeca of IndustryWeek revisit news of several recent cyber breaches in manufacturing and examine the phenomenon of threat groups using AI to power their attacks.

What you'll learn:

  • AI is accelerating cyberattacks, shortening the window manufacturers have to detect vulnerabilities and deploy defenses.
  • Widely deployed PLCs are attractive targets, making OT cybersecurity critical for factories and infrastructure operators.
  • Patching is essential, but large manufacturers face complex barriers from legacy systems, software versions, and operational requirements.
Listen on Apple buttonListen on Spotify buttonListen on iHeartRadio buttonListen on Podbean button

In this episode of Great Question: A Manufacturing Podcast, Smart Industry Head of Content Scott Achelpohl and IndustryWeek's technology editor, Dennis Scimeca, discuss the evolving cybersecurity challenges facing manufacturers.

They examine recent attacks targeting PTC product lifecycle management software and Siemens S7 PLCs, highlighting the complexities of patching vulnerabilities across industrial environments.

See also: Hackers exploit PLMs in recent cyberattacks at Shell, GE, Philips 

The conversation also explores how AI is accelerating cyberattacks and shortening the time available for organizations to respond with patches for their systems or other countermeasures. 

Cyberattacks against manufacturing operations are hardly new, but AI is rapidly changing how quickly attackers can identify targets, find vulnerabilities, and exploit them.

At the same time, manufacturers are taking advantage of connectivity between IT and OT systems, adopting cloud-based tools, and enabling remote access to plant-floor assets. That connectivity exposes systems that do not have up-to-date cyber defenses to possible attack. 


Below is a partial excerpt from the podcast:

Dennis Scimeca: Hello, and welcome to our next episode of the Great Question Podcast. I'm Dennis Scimeca, Senior Editor for Technology at IndustryWeek, and I'm joined by my friend and colleague Scott Achelpohl, Smart Industry's Head of Content.

Scott Achelpohl: Heya, Dennis. Nice to be on the program.

DS: Thanks for joining us. So today we're talking cybersecurity, Scott. It's one of the least sexy topics we've covered at IndustryWeek, but also one of the most important. Scott's joining us today because cybersecurity is a much hotter topic over at Smart Industry, where they can get into some of the technical aspects of the hacks that we cover.

Now, IndustryWeek, of course, covered Verizon's annual Data Breach Investigations Report when it was released in late May. You can also look up additional coverage of that on Smart Industry.

I recommend looking up these stories for a condensed 50,000-foot view of the cybersecurity situation as a whole, not only in manufacturing, but in terms of major events or attempts to break into a system with no tangible results and major breaches—roughly defined as successful attempts to break into systems that likely include data theft—2026 has been fairly quiet.

That was until last week, when it rains, it pours, and we had two stories to report on, both at IndustryWeek and Smart Industry.

See also: Black Kite: Ransomware increasing across all metrics in 2026

First, the CLOP—C-L-O-P—ransomware gang claimed responsibility for 43 cyber attacks against targets including GE, Philips, and Shell. The attacks were targeted specifically at two product life cycle management or PLM tools developed by PTC, Windchill, and Flex PLM. The number of victims gives you an idea as to how widely these systems are deployed. Now this story turned into a conversation about patching.

Whenever you hear cybersecurity experts describe optimal cybersecurity hygiene, they always talk about the importance of patching. And in this case, PTC began releasing patches for this known vulnerability in mid-June.

So how do companies the size of GE, Phillips, and Shell, that ostensibly have large IT departments with people keeping an eye out for these patch releases, not have their systems patched two months later?

Well, we spoke to some experts, and it turns out that's an incredibly simplistic way to look at the problem. And we can't assume that GE Philips and Shell weren't on the ball here. In fact, the larger the company, the more difficult to apply patches org-wide.

There can be different versions of the software running across the org, and every version might not have a patch released at the same time. If the technology is old, especially an end-of-life system, it might not be easily updatable.

There might be operational or regulatory issues that slow things down. And for all anyone knows, the ransomware gang may have been inside these PTC environments long before anyone realized the security issue existed, in which case the security battle was over before it began.

See also: Workshop confronts manufacturing execs with the big stakes that ride on proper cybersecurity protocols

So, the short version is that cybersecurity experts can talk all they want about the importance of patching, but it isn't that simple. And we can't assume that just because a company fell victim to a known vulnerability, even with plenty of advance notice, that means said company isn't monitoring for patch releases and applying them as soon as possible.

The second story we covered a few days after the first, and concerned five S7 series PLC models manufactured by Siemens. Five different US federal agencies, the NSA, FBI, Department of Energy, Cybersecurity and Infrastructure Agency, and even the EPA issued a joint warning about the vulnerability, which suggests how widely these S7 series models are deployed across many different sectors.

And what makes this particularly interesting isn't that a breach took place, but rather the tools threat actors are using to try to crack the security. Smart Industry covered this really heavily, so Scott is really the better choice to get into the nitty gritty here. So Scott, what can you tell us about these tools that hackers are developing? What's the big deal?

SA: AI is the big deal. Over at Smart Industry, we've done a lot of coverage about how AI is being used as an accelerator, basically. Think of if you're throwing gas on a fire, that's essentially what AI is for cyber attackers. AI is incredibly useful, is proving to be useful in a positive way for manufacturers, but this is a way that it's occurring in a negative way.

Now, in this particular attack on the Siemens gear, and it affected a total of five Siemens PLCs, programmable logic controllers, the attackers used what was reported as Python scripts that use the Snap 7 DLL and the Python Snap 7 libraries to infiltrate Siemens S7 PLC devices. The five are the 200, the 300, the 400, the 1200 and the 1500.

And obviously the reason why we cover these is because these are incredibly common plant OT devices. You can find them in a wide range of kinds of factories. You also particularly find them in critical infrastructure, water, water treatment, electric plants, places like that.

And that's why it raised such a large, this story to such a large profile. And the fact that these PLCs are were targets and they're so common, and the fact that this was, in the time we've covered this, maybe the most prominent example of AI-enabled cyber attacks.

We've had two or three collaborators talk with us recently about how AI was accelerating cyber attacks, and this was a prime example of how it was happening. I mean, Siemens is a victim of their own success here, that their plant OT is so popular that it serves as such a large target and it dovetailed a little bit with some coverage that we had back in the fall about other Siemens gear an industrial device called the RuggedCom ROXOS II which apparently is quite popular. That particular piece of gear was identified with vulnerabilities by a security engineer whom we worked with, and it was fixed with patching. There was actually no cyber incursion involved in that.

But related to this story, we talked to a cyber CISO, a cybersecurity specialist at a company called Kiteworks that we talk to quite often. And he pointed out something very interesting, particularly about the Siemens attack was that the fact that yes, AI is supercharging cyber attacks and what makes that so dangerous is that number one, Frank said, organizations had better know who and what can reach their systems.

See also: Implementing a true approach to PLM, the cornerstone of manufacturing

In other words, they’d better know what their own vulnerabilities are and get them patched quickly. Sometimes patching alone can't even close the gap if you don't know where your vulnerabilities are.

And he said that, described it exactly as I mentioned, that AI is an accelerant here and it's really shortening the time in between scripts can be written to run these cyber attacks and the actual cyber attacks themselves. So it's really shortening the amount of time that people in IDT departments who are structuring their cyber defenses can erect those defenses and get them up in time before these attacks actually occur.

So that was basically a rundown. I wrote a blog a little bit about some of our other coverage and I encourage those of you who are listening to go read the blog and give us your thoughts.

DS: Do you ever in your stories come across AI-based security tools? Do the good guys get to use AI or is it mostly the hackers right now? Do you know?

SA: So far it’s the hackers. The defenders are still trying to write defenses, essentially. And because the AI defenses are so murky right now, or that the attacks are so murky right now, and it's just territory that's still being plowed, quite honestly, with AI cyber attacks.

See also: Ransomware attacks set new records in 2025, hitting manufacturing the hardest

Security that will be based on AI, that's to come. I'm sure we'll be doing a lot of reporting on the AI tools that manufacturers in our case will use to defend themselves against these attacks.

DS: I would say that's about it. So we're going to go ahead and wrap this one up. I'm Dennis Scimeca, Senior Editor for Technology at IndustryWeek, and I was joined by friend and colleague Scott Achelpohl, Smart Industry’s Head of Content. Thank you for joining us on Great Question.

About the Author

Sarah Mattalian

Staff Writer

Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.

Sign up for our eNewsletters
Get the latest news and updates