AccuSights
PartnersBlogAbout
Book my 30-minute demo

Manufacturing & Machine Shops · Cybersecurity, compliance and GRC, in plain English

Keep the spindles turning. Keep the drawings yours.

Manufacturing is the most-breached industry in the 2026 DBIR, and the reason is not exotic: office email and shop-floor controllers on the same network, remote-access software nobody patched, and backups that sit next to the files they are supposed to save. We separate the floor from the office, test the restore before you need it and watch the whole plant around the clock.

Shop-floor segmentation without replacing machinesCMMC path if a prime asksPublic pricing

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The night shift at a 40-person machine shop finds the quoting server locked

the second-generation owner of a job shop in Elk Grove Village

Dan’s father started the shop with two Bridgeports in 1987. Today it is 40 people, six CNC cells and a quoting system that knows every part they have ever cut. The shop runs a second shift because the customers in medical devices and food equipment want parts Thursday, not next week.

At 11:20 on a Tuesday night the lead machinist calls Dan at home. The quoting server is showing a ransom note. The shared drive with thirty years of drawings, fixtures and CMM programs is renaming itself file by file. The controllers on the floor still run, for now, because the same network carries the office and the machines.

The note asks for a sum that is roughly the shop’s profit for the year. It is the moment every owner imagines and never plans for. In the version that ends badly, the backups sit on the same network and are already encrypted, the customer files go up on a leak site and the medical-device customer suspends the supplier.

In Dan’s version, the protection agent isolated the quoting server at 11:04, sixteen minutes before the call, and the engineer on watch is already restoring drawings from the offline copy. First shift starts on time. Dan spends the morning deciding which customers to tell, not whether the company survives.

The shared drive with thirty years of drawings, fixtures and CMM programs is renaming itself file by file.

What changes the ending

  1. Offline, tested backups of drawings, programs and the quoting database, restored on a schedule (CIS Control 11, Data Recovery)
  2. The machine network separated from office email and browsing (CIS Control 12, Network Infrastructure Management)
  3. Patching the remote-access and ERP software attackers exploit first, with someone watching for the exploit (CIS Controls 7 and 13)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

If someone encrypts thirty years of our drawings, what do we actually do on day one?

Day one is isolation, then restoration from a backup the attacker could not reach, then a decision about customer notification, in that order. If the backup is offline and was tested last month, day one is a long day; if it sat on the same network, day one is a negotiation, which is why the assessment tests the restore before you ever need it.

Our machines run on old Windows and cannot be patched. Are we just exposed?

Controllers on Windows 7 or XP are normal on a shop floor, and they can be protected by putting them on their own network segment with no path to email or the internet. The assessment maps every controller and gives you a segmentation plan that does not require replacing a $400,000 machine.

A customer just sent us a 40-question security questionnaire. Do we need a certification?

Usually not yet; they want evidence that the basics run: MFA, backups, endpoint protection, a written response plan. We answer the questionnaire with you from the assessment evidence, and if a defense customer flows down NIST 800-171 we move you to the CMMC path from the same control set.

What you hold, and why someone wants it

Your data protection needs, by the data.

Drawings, CAD models and CNC programs

Thirty years of customer IP that a competitor overseas would pay for and a ransomware crew will auction. Offline backups, access limits and data classification protect them.

Quotes, pricing and customer contracts

Your margins and your customer list in one ERP table. Role-based access and monitoring protect them.

The shop-floor network and controllers

Unpatchable controllers on the same network as office email are the path ransomware takes to the floor. Segmentation and a watched network protect them.

Customer-furnished data, including CUI on defense work

Specifications and drawings your customer is contractually obligated to protect, so the breach becomes their problem and your lost contract. Enclaves and NIST 800-171 controls protect them.

Payroll, banking and supplier payment details

The wire to a supplier and the payroll file are the two targets of business email compromise. MFA, call-back verification and inbox monitoring protect them.

61%
of manufacturing breaches involved ransomware, and 61% involved a third party; malware was present in 75%
Source: Verizon 2026 Data Breach Investigations Report, Manufacturing snapshot
38%
of manufacturing breaches began with an exploited vulnerability, usually in remote-access or edge software nobody patched
Source: Verizon 2026 Data Breach Investigations Report, Manufacturing snapshot
96%
of ransomware victims where size was known were small and mid-size businesses; the median ransom paid was $139,875
Source: Verizon 2026 Data Breach Investigations Report

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

NIST CSF 2.0 and IEC 62443
NIST and IEC
Voluntary frameworks that customers, insurers and larger primes increasingly write into supplier agreements; we use them as the map, not the mandate.
DFARS 252.204-7012 and CMMC 2.0
US Department of War (DoD)
Only when you supply defense primes and handle CUI; Phase 1 self-assessment and SPRS posting apply now despite the Phase 2 pause.
State breach notification laws
State attorneys general
Employee and customer data stolen in a ransomware attack triggers notification in all 50 states.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Ransomware that reaches the shop floor through the office network and stops every spindle at once.
  • A spoofed customer or supplier email that diverts a progress payment or a payroll run.
  • Drawings and customer files walking out through remote-access software left unpatched, then posted on a leak site.

It happened to businesses like yours

A September 2025 cyberattack stopped Jaguar Land Rover’s UK production for about five weeks and hit more than 5,000 suppliers; the Cyber Monitoring Centre estimated a £1.9 billion cost, the most damaging cyber event in UK history.

September 2025 · BBC News

Attackers talked their way past Clorox’s outsourced IT help desk in August 2023, crippled production for months and cost the company an estimated $380 million; Clorox sued the help-desk provider in July 2025.

August 2023, lawsuit July 2025 · Cybersecurity Dive

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a manufacturing business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your employees’ inboxes, where the fake supplier invoice and the spoofed customer purchase order arrive.
  • Every laptop, engineering workstation and front-office PC, including the CAM seats.
  • The server, the ERP and the file share holding drawings, programs and quotes.
  • The shop-floor network, segmented so an infected office PC cannot reach a controller.
  • The cloud apps: email, ERP, file sharing, remote access and the customer portals.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Manufacturing

Built on the CIS Controls v8.1 IG1 and scoped from what a plant stands to lose: the floor, the drawings and the customer relationship. The output is a segmentation plan, a tested restore and a ranked list, written for an owner rather than an auditor.

  • Inventory of every controller, workstation, server and cloud app, including the machines nobody thought of as computers (CIS Controls 1 and 2)
  • Shop-floor network segmentation plan that protects unpatchable controllers without replacing them (CIS Control 12)
  • Backup and restore test for drawings, CNC programs, the ERP and the quoting database (CIS Control 11)
  • Remote-access, ERP and VPN patch status against the CISA Known Exploited Vulnerabilities list (CIS Control 7)
  • Account audit: shared logins on the floor, ex-employee access, MFA on email, ERP and remote access (CIS Controls 5 and 6)
  • Customer questionnaire answers, a NIST CSF 2.0 profile and, if you supply defense primes, a NIST 800-171 readout
Start with the 3-minute test

Packages

Built for manufacturing businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

CMMC Self-Assessment and SPRS Score Calculation

The simplest step a defense supplier can take this quarter: a guided self-assessment against all 110 controls, the DoD scoring methodology applied correctly (1, 3 and 5-point weights, from -203 to 110), the quick wins that move the score most, and a number you can post in SPRS and defend to a prime..

Fixed feescoped in 30 minutes
1 to 2 weeks
Details →

CMMC Level 2 Gap Readiness Package

A fixed-scope package for defense suppliers who need a defensible SPRS score, an SSP a C3PAO will accept and a remediation path that fits a small company.

From $6,000published price
3 to 5 weeks to the delivered gap assessment, SSP and POA&M
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Can ransomware really stop our CNC machines?
Yes, when the controllers share a network with office PCs and email, which is the default in most shops. Jaguar Land Rover lost about five weeks of production in 2025. Segmentation keeps an infected office PC from reaching a controller, and it can be done around the machines you already own.
Do small manufacturers need NIST compliance?
No law requires it unless you supply defense primes, but customers, insurers and larger buyers increasingly ask for a NIST CSF profile or a completed questionnaire. The assessment produces both from the same controls that protect the plant.
What does a manufacturing cybersecurity assessment cost?
A fixed fee scoped in a 30-minute call by sites, machines and systems. Published market rates for a plant assessment run from a few thousand dollars to well beyond $20,000; ours is kept simple so more of the budget goes to fixing what we find.

People also search: cybersecurity for machine shops near me · manufacturing cybersecurity in Chicago · for a 40-person job shop · IT security for a plastics plant in Elk Grove Village · OT security for a small manufacturer · cybersecurity for metal fabricators in the Midwest · NIST CSF for manufacturers · ransomware protection for CNC shops

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test