> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Manufacturing Cybersecurity Spending Is Up. So Is Ransomware
- URL: https://www.cybrsecmedia.com/manufacturing-cybersecurity-spending-is-up-so-is-ransomware/
- Published: 2026-09-22T12:29:55.000Z
- Updated: 2026-09-22T12:31:39.000Z
- Description: Manufacturers are investing in cybersecurity, yet ransomware attacks keep rising. New research exposes persistent vulnerabilities and stolen credentials.
- Author: George V. Hulme
- Tags: Ransomware, Manufacturing Cybersecurity, Cybersecurity Spending, Article

Ninety percent of industrial organizations say they are confident they can prevent, contain, or recover from a cyber incident. Meanwhile, a separate survey reveals manufacturers are experiencing the highest rate of ransomware attacks in four years.

Those two data points come from separate research efforts: one survey commissioned by Rockwell Automation consisting of 1,560 manufacturing and industrial operations decision-makers, and the other, conducted by Black Kite Research Group, is a four-year dataset of disclosed ransomware victims. The pair of reports reveals organizations are investing in cybersecurity, growing more confident, and manufacturers are still getting hit at record rates. Confidence in one’s program is not the same as effectively managing the external attack surface attackers exploit.

Rockwell Automation's "Operational Resilience in the Age of Connectivity" report, based on responses from 1,560 manufacturing decision-makers across 17 countries conducted by Sapio Research, found that 62% of organizations have already invested in cybersecurity platforms and that cybersecurity ranks as the second-highest ROI-generating technology investment reported by respondents. This investment signal aligns with the confidence number.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

Black Kite's Research Group 2026 Manufacturing & Distribution Ransomware Report, covering the first seven months of 2026, documented 1,183 disclosed ransomware incidents against manufacturers. That tally is higher than the full-year totals for either 2023 or 2024, and 40% above the same period in 2025\. Manufacturing has recorded uninterrupted ransomware growth for five consecutive years.

Black Kite's external scan of the 1,000 largest manufacturers shows where the gap lives. As of August 2026, 75% carry at least one critical vulnerability, 69% have employee or system credentials circulating in stealer log markets, and 54% carry at least one flaw from CISA's Known Exploited Vulnerabilities catalog. Credential exposure, at 69%, has not moved in two years despite the investment surge. No platform purchase removes credentials already circulating in stealer logs. No internal detection program drains that pool.

"Technology investments alone do not create operational resilience or confidence in an organization's security posture," said Rick Kaun, global director of cybersecurity services at Rockwell Automation. "True resilience is built when cybersecurity becomes an integral part of business strategy."

**Related:**

[Industrial Ransomware Held Steady in Q1 2026, That’s the ProblemThe normalization of ransomware in industrial systems, along with an operating culture that treats downtime as unacceptable, is an uncomfortable tension that’s not likely to go away soon.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-bde0238b-87c6-4771-8421-06f53d93d113.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/4ac64672-97f2-4b3b-80cd-4f676a452a4e-fb2e7f84-7793-45c2-a0b1-be2d560f2ff0.png)](https://www.cybrsecmedia.com/industrial-ransomware-held-steady-in-q1-2026-thats-the-problem/)

[Manufacturing: NIST Wants to Upgrade the Incident Response PlaybookNIST releases its first concrete OT recovery playbook and it looks nothing like an IT runbook. The document is formally aimed at manufacturing, but the problem it addresses is structural across every operational technology environment where stopping production has physical consequences.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-582361d7-0570-4ead-bc74-8fbafd63c242.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/5c4ad154-a668-4cf7-b4b4-d8b952e1870a-57e487bf-30a4-44c3-a7a0-f3c5338ce984.png)](https://www.cybrsecmedia.com/manufacturing-nist-wants-to-upgrade-the-incident-response-playbook/)

"But attackers don't operate blindly," said Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. "Their reconnaissance relies on externally visible signals from unpatched systems and exploitable services to leaked credentials and misconfigured defenses."

At disclosure, 74% of manufacturing ransomware victims in Black Kite's four-year dataset carried a Ransomware Susceptibility Index score in what Black Kite considers in the “critical” range, above 0.4\. That’s where the company's research finds manufacturers 36 or more times more likely to experience an attack than those scoring below 0.2\. Rockwell's survey identifies IT/OT integration points as the second-most-vulnerable zone in industrial environments. For instance, when Asahi Group Holdings was breached in late September 2025, attackers entered through a weak password on network equipment, an IT/OT convergence point that was visible to threat actors before the company realized it was exposed. Asahi's RSI stood at 0.778 at that time.

For security teams, the practical takeaway is the same. A program optimized for internal detection and platform ROI is unlikely to close all the externally exploitable points that threat actors target. “Organizations that proactively manage risk and prepare for disruption are better positioned to protect operations, sustain production and gain a competitive advantage," said Kaun. That first part of that advice should go without saying; however, organizations must decide it’s worth doing.