SonicWall warns manufacturing cybersecurity risks are changing

DQChannels Bureau
DQChannels Bureau
SonicWall warns manufacturing cybersecurity risks are changing

Manufacturing cybersecurity risks are shifting even as the overall volume of attacks on factories falls. SonicWall’s 2026 Manufacturing Protect Brief found that intrusion prevention (IPS) activity against manufacturing dropped 56.2% year-on-year in the first half of 2026. Yet 474 million events were still recorded, suggesting that attackers are becoming more selective about where they strike.

The bigger concern is the expanding attack surface. As factories connect operational technology (OT) with IT systems for remote monitoring, predictive maintenance and vendor access, more pathways are opening into production environments.

Manufacturing attack surface expansion is changing the threat

The manufacturing attack surface is no longer limited to traditional factory systems. Networked security cameras, industrial sensors and smart building controls are now part of the connected environment.

Many of these devices were not designed with modern security in mind. Some run old software and may remain unpatched. When they share connected networks with critical production systems, old vulnerabilities can continue to create fresh risks.

The Hikvision IP Camera Command Injection vulnerability, CVE-2021-36260, is one example. Disclosed in 2021, it generated 43 million hits in the first half of 2026. It was also the largest IoT attack signature across any industry tracked by SonicWall.

IoT attacks were manufacturing’s second-largest attack category, generating 46.2 million hits. More than half of manufacturing networks detected exploitation attempts.

IT and OT convergence security risks are growing

The connection between corporate IT and factory operations creates another layer of concern. A stolen employee credential can potentially provide a route from office systems towards production environments.

SonicWall recorded the highest SCADA attack detection rate in manufacturing among all tracked verticals. The finding adds weight to the wider concern around IT and OT convergence security risks.

The issue is not only the number of attacks. It is where a compromised identity or device can take an attacker.

As remote monitoring, maintenance tools and vendor access become more connected to production systems, the impact of a single compromised credential can become much greater.

Ransomware families targeting manufacturers remain active

Ransomware also remains part of the threat picture. Ten ransomware families were active against manufacturing networks in the first half of 2026.

The Zhen family generated 22.2 million hits concentrated on just two devices. According to the brief, this pattern was consistent with an active, ongoing incident rather than a broad campaign.

That distinction matters. A lower overall attack count does not necessarily mean the risk is lower. A more focused attack against a small number of critical systems could still have serious consequences for a manufacturing operation.

Legacy flaws continue to create exposure

The data also shows how long-known vulnerabilities can remain relevant. Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.

The pattern is similar to the Hikvision camera findings. Old vulnerabilities can remain active threats when connected devices and systems are not adequately protected or updated.

For manufacturers, this makes visibility across the full technology environment important. Security teams need to understand not only what is connected but also how those systems can reach critical production assets.

Read More: 

BD Soft channel partner expansion reaches Rajasthan

Nutanix exolains how hybrid multi-cloud services will define channel growth

Cyble APAC threat landscape report flags rising ransomware

SK Group and NVIDIA Sign USD 500B+ Mega-Deal to Build 2-Gigawatt AI Factory in Korea

Latest Stories