On May 13, 2025, Nucor, North America's largest steel producer, detected unauthorized third-party access to its IT systems. Within a day, the company had activated its incident response plan, taken affected systems offline, and temporarily halted production operations at multiple locations as a precaution. A later filing confirmed the attacker had exfiltrated limited data before being evicted. (Source: Nucor Corporation, Form 8-K filed May 14, 2025, and Form 8-K/A filed June 20, 2025)
Two weeks earlier, Masimo, a medical device manufacturer, identified unauthorized activity on its on-premises network. Certain manufacturing facilities were left operating below normal levels, and the company's ability to process, fulfill, and ship customer orders was temporarily impacted. Masimo found no indication that its cloud systems were affected. No threat group claimed responsibility. (Source: Masimo Corporation, Form 8-K filed May 6, 2025)
Neither attack reached an OT system. Both stopped production anyway. Attackers no longer need to touch the control layer to take a line down—and it keeps working because the accountability gap between IT security teams and operational leadership remains wide open.
If you’re a CISO at a mid-market manufacturer, that gap is yours to close. And your operations team—plant managers, shift supervisors, engineering leads—may be your underutilized asset in closing it.
Why This Is a CISO’s Problem, Not Just an IT Problem
For CISOs in manufacturing, cyber risk doesn’t stay in the network. It shows up as halted production, missed shipments, and real revenue impact. A compromised credential or an unpatched system in IT can now stop a line on the floor.
Frameworks like NIST CSF and IEC 62443 already recognize this shift. They call for integrated visibility across IT and OT, segmentation across Purdue levels, and coordinated response across teams. But in most environments, those controls are implemented on paper, not in practice.
Security programs are still built around IT visibility. The impact, however, plays out in OT.
That gap is where attacks succeed. CISOs are accountable for enterprise risk, but without operational context—machine behavior, production dependencies, safety constraints—that view is incomplete.
What Operations Teams See That Your Tools Cannot
Your SIEM won’t tell you that a PLC on line 4 is cycling 30% faster than usual, or that a vendor technician left a USB drive in a machine last Tuesday. The people who will notice those things are the ones running that floor. The question is whether they know what to do when they do.
Anomaly Detection at the Device Level
Unusual PLC polling rates, unexpected machine shutdowns, SCADA displays behaving erratically—these are early indicators of lateral movement or ransomware staging in OT environments. Operational staff who understand production baselines are a real-time detection layer. In the Nucor incident, the production halt was an operational decision, not a SOC alert.
Vendor Access as a Live Control Point
Vendor remote access is among the highest-risk and least-controlled access paths. Supply chain attacks amplified by third-party vendor access were a leading factor in 2025 manufacturing breaches. Operations managers who are briefed on your PAM policies can flag unscheduled vendor sessions and escalate immediately. That human checkpoint is often faster than any automated detection.
Safe-State Authority During an Incident
When ransomware hits OT systems, isolation decisions made purely by IT can create physical hazards: equipment running without safety interlocks, pressure systems left active, conveyors cycling unsafely. Your IR plan needs operational co-authorship. Who has authority to call a controlled shutdown? What is the safe state for each production line? That decision cannot wait for a chain of approvals. The authority and safe-state procedure need to be predefined with operations.
How to Build This: Four Concrete Steps
Run a Joint Tabletop Exercise
Most IR tabletop exercises run entirely within the security function. Change the format: simulate ransomware crossing from your ERP into the SCADA historian and bring the VP of Manufacturing and two plant supervisors into the room. The gaps that surface in decision authority, communication paths, and safe-state procedures cannot be found any other way. Schedule this before your next audit, not after your next incident.
Map Every Vendor Access Path Against Your Purdue Zones
Pull a full list of every vendor with remote access to your environment. For each: which Purdue zone can they reach, through what mechanism, and with what level of session logging? If any answer is “unsure,” that’s your starting point. Operations managers often know about vendor access that IT doesn’t—make that inventory a joint exercise.
Build a Security Scorecard Operations Leaders Can Act On
Numbers that resonate with a CISO often mean nothing to a plant manager. Translate your posture into operational metrics: unmanaged devices on the floor network, percentage of vendor sessions with active logging, accounts with access to both IT and OT systems. In a recent assessment of a mid-market manufacturer, we found 11 compromised credentials exposed on the dark web, 127 exposures on a single device, and a Microsoft 365 security score of 48 out of 100. Operational leadership had no clear view of these findings. Once these numbers landed in business context, budget and attention followed within weeks.
Define Escalation Paths That Work on the Floor
Your SOC has an escalation matrix. Does it include the plant manager’s mobile number? In OT incidents, security and operational leadership need to be notified simultaneously, not sequentially. Build a one-page incident notification protocol for each facility: what triggers a call, who receives it, and what they should do in the first 30 minutes. Test it. Update it quarterly.
The Accountability Structure That Makes It Stick
Shared responsibility without shared accountability is just a policy document. Three foundational elements are required for IT–OT collaboration to succeed:
The CISO and VP of operations have a standing monthly working session focused on active risks and open items, not a QBR slide deck.
Security KPIs include OT metrics: unmanaged OT assets, patch compliance rates for ICS components, vendor access audit frequency.
Operational leaders have a named security contact who speaks their language and picks up the phone—not a ticketing system.
CISOs who have closed the IT–OT gap describe the same inflection point: when plant leadership stopped seeing security as IT’s problem and started owning it as a production risk. That shift doesn’t happen through policy. It happens through shared scenarios, shared language, and consequences attached to both sides of the equation.
Where to Start
.png)
If you can’t answer these questions with confidence, that’s your starting point:
Which OT assets are currently unmanaged or unknown to your security team?
What is your mean time to detect anomalies at Purdue levels 0-2?
Does your IR plan include a manufacturing-specific safe-state annex, co-signed by operations?
How many vendor remote access sessions occurred last month, and what percentage of those sessions were logged?
Most manufacturers we speak to aren’t careless—they’re stretched. New plants, acquisitions, inherited infrastructure—and somewhere in that complexity, the unknown risk sits unnoticed.
That’s exactly what our Security Jumpstart is designed to uncover.
In three days, we identify hidden exposures across your environment and translate them into a clear, actionable plan. No disruption to production. No agents on every machine.
You get:
A 25+ page executive security report tailored to your environment
A 30/60/90-day action plan with specific next steps
Your top 10 vulnerabilities, prioritized
A 60-minute walkthrough with our team to unpack findings
Because the biggest risk in manufacturing isn’t what you know.
It’s what you haven’t uncovered yet.



