Manufacturing has a security problem that office-based businesses do not: a meaningful share of the environment predates the idea that everything would be networked, cannot be patched on anyone's schedule, and stops making money the moment it stops running. That reality drives almost every decision worth making here.
Operational technology sharing a network with the office
The most common serious finding we encounter in Northeast Ohio manufacturing is flat networking — the machine controllers, the historian, the HMIs, and the front-office workstations all reachable from one another because that is how the plant was wired years ago and nothing has forced a change since.
The consequence is direct. A phishing email opened in accounts payable lands on a network segment with a direct path to production. Ransomware that would have been an annoying but survivable office incident becomes a stopped line.
Segmentation is the highest-value work available in most plants we assess, and it can usually be done incrementally, without the shutdown people fear. It does not require replacing equipment that still works — it requires putting a boundary around it and controlling what crosses.
Equipment that cannot be patched
Some controllers run software that has not been supported for a decade, and the vendor that wrote it may no longer exist. Telling a plant manager to patch it is not advice, it is a fantasy. The realistic approach is compensating controls: isolate the device, restrict what may talk to it, monitor that boundary closely, and document the risk decision properly so it is a considered position rather than an oversight.
That documentation matters more than it sounds. An unpatched device that has been assessed, isolated, monitored, and signed off is a managed risk. The identical device with none of that is a finding — from an auditor, an insurer, or a customer's third-party risk team.
Flow-down requirements from customers
Supplier security requirements now arrive from two directions. Defense-adjacent work brings NIST SP 800-171 and, where CUI is involved, CMMC — the same regime driving the market around Dayton. Commercial primes increasingly send their own questionnaires, control expectations, and audit rights as a condition of remaining on the approved supplier list.
For a supplier with a hundred employees, this feels disproportionate. It is also not optional, and the firms that manage it best build the control set once, document it well, and treat each subsequent questionnaire as a retrieval exercise rather than a project.
Intellectual property is the quiet risk
Ransomware is loud and gets the attention. The quieter loss in advanced materials, formulation, and precision manufacturing is theft of the thing that actually makes the business valuable — a process, a formulation, a tooling design, a set of tolerances developed over twenty years. That kind of intrusion is designed not to be noticed, which is exactly why continuous monitored detection matters more here than in a business whose worst case is an encrypted file server.
Recovery, priced in downtime
When a line stops, the cost accrues per hour with unusual clarity, which makes the recovery objective conversation refreshingly concrete. We set recovery targets per system rather than as one number, because the tolerance for a shared file server and the tolerance for the system that schedules production are rarely within an order of magnitude of each other.
What we deliver in Akron and Canton
Managed security, managed IT and co-managed support alongside a plant IT person, 24/7 SOC monitoring, BCDR sized to production tolerance, NIST 800-171 and CMMC compliance work, and security awareness training that accounts for a workforce which is largely not sitting at a desk.
Flat network, unpatchable controllers, or a customer questionnaire you can't answer yet?