Ninety percent of industrial organizations say they are confident they can prevent, contain, or recover from a cyber incident. Meanwhile, a separate survey reveals manufacturers are experiencing the highest rate of ransomware attacks in four years.
Those two data points come from separate research efforts: one survey commissioned by Rockwell Automation consisting of 1,560 manufacturing and industrial operations decision-makers, and the other, conducted by Black Kite Research Group, is a four-year dataset of disclosed ransomware victims. The pair of reports reveals organizations are investing in cybersecurity, growing more confident, and manufacturers are still getting hit at record rates. Confidence in one’s program is not the same as effectively managing the external attack surface attackers exploit.
Rockwell Automation's "Operational Resilience in the Age of Connectivity" report, based on responses from 1,560 manufacturing decision-makers across 17 countries conducted by Sapio Research, found that 62% of organizations have already invested in cybersecurity platforms and that cybersecurity ranks as the second-highest ROI-generating technology investment reported by respondents. This investment signal aligns with the confidence number.
Black Kite's Research Group 2026 Manufacturing & Distribution Ransomware Report, covering the first seven months of 2026, documented 1,183 disclosed ransomware incidents against manufacturers. That tally is higher than the full-year totals for either 2023 or 2024, and 40% above the same period in 2025. Manufacturing has recorded uninterrupted ransomware growth for five consecutive years.
Black Kite's external scan of the 1,000 largest manufacturers shows where the gap lives. As of August 2026, 75% carry at least one critical vulnerability, 69% have employee or system credentials circulating in stealer log markets, and 54% carry at least one flaw from CISA's Known Exploited Vulnerabilities catalog. Credential exposure, at 69%, has not moved in two years despite the investment surge. No platform purchase removes credentials already circulating in stealer logs. No internal detection program drains that pool.
"Technology investments alone do not create operational resilience or confidence in an organization's security posture," said Rick Kaun, global director of cybersecurity services at Rockwell Automation. "True resilience is built when cybersecurity becomes an integral part of business strategy."
Related:


"But attackers don't operate blindly," said Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. "Their reconnaissance relies on externally visible signals from unpatched systems and exploitable services to leaked credentials and misconfigured defenses."
At disclosure, 74% of manufacturing ransomware victims in Black Kite's four-year dataset carried a Ransomware Susceptibility Index score in what Black Kite considers in the “critical” range, above 0.4. That’s where the company's research finds manufacturers 36 or more times more likely to experience an attack than those scoring below 0.2. Rockwell's survey identifies IT/OT integration points as the second-most-vulnerable zone in industrial environments. For instance, when Asahi Group Holdings was breached in late September 2025, attackers entered through a weak password on network equipment, an IT/OT convergence point that was visible to threat actors before the company realized it was exposed. Asahi's RSI stood at 0.778 at that time.
For security teams, the practical takeaway is the same. A program optimized for internal detection and platform ROI is unlikely to close all the externally exploitable points that threat actors target. “Organizations that proactively manage risk and prepare for disruption are better positioned to protect operations, sustain production and gain a competitive advantage," said Kaun. That first part of that advice should go without saying; however, organizations must decide it’s worth doing.

