Manufacturing at a crossroads: why leaders need to elevate their approach to risk
- Coevolve
The changing risk landscape
Industry 4.0 has ushered in a new era of interconnection and promise for the manufacturing industry. Factories that were once isolated, standalone entities are now connected to the internet and to other stakeholders, vendors, and suppliers. New cloud, AI, and Internet of Things (IoT) technologies are being leveraged to unlock modern capabilities, synergies, and ultimately, profit.
However, with such new technology also comes new risk. The interconnection of data and proliferation of access has made traditional perimeter-based security thinking obsolete, while the increasing level of online visibility and automated control of operations has also made it possible for bad actors to pose an even greater threat.
Indeed, IBM has found that cyber attackers in 2026 are increasingly aiming at operational disruption today rather than data, with 45 percent of manufacturing cyberattacks – the largest proportion – focused on malware designed to create disruption, either as a goal or as leverage for financial extortion. Google’s 2026 M-Trends Report adds that these cyber attackers, often enabled further by AI themselves, are also going after backups, identity services, and virtualization layers to prolong and intensify that operational disruption.
The urgency to elevate the risk conversation
The risk from Industry 4.0 innovation today is existential, not just departmental. Manufacturers urgently need to elevate their risk conversation and move it from the server room into the boardroom. This will help leaders to address the conversation at a whole-of-business level that mobilizes the expertise and cooperation of company stakeholders.
The consequences of overlooking network and security risk are increasingly serious. At the operational level, increasing production or operational downtime may occur, with its accompanying financial and reputational losses. And with Industry 4.0 technology increasingly controlling physical devices, manufacturers now also run the risk of physical damage caused by disruptive cyber-attacks.
At the ecosystem level, manufacturers who do not gain a higher-order awareness of their risk levels and exposure may be affected by cyberattacks targeting their suppliers or other third parties. High-profile supply-chain attacks like the 2017 NotPetya and 2020 SolarWinds attacks have shown that a third-party breach today can be as damaging as a direct breach.
At the regulatory level, failure to mitigate these business-wide risks and remain compliant can lead to significant regulatory penalties.
Reframing risk as a strategic priority
To elevate the risk conversation at the executive level, manufacturing leaders must get into the right mindset by reframing risk as a strategic priority. Leaders must move away from the traditional perception of risk as a compliance checkbox or cost center, to a recognition that risk is a fundamental revenue and business continuity issue.
This will also require leaders to expand their ownership of risk from single plants or a single business, to also encompass the entire supply and demand ecosystem that they are now digitally connected to, any of whose failures could also become their disruption.
Reframing risk will also require shifting the discourse around cyber-attacks and disruptions. This means moving away from an understanding of risk as unexpected failure of competence if it happens, to an expected occurrence that the organization can recover from when it happens.
This reframing will bring new clarity and opportunities to solve cross-cutting network and digital security areas of friction, at a decision-making level high enough to drive consensus and effectively mitigate business-wide risk.
Bridging the IT/OT governance gap with better governance
A key source of friction that an elevated risk conversation can address is the information technology (IT) and operational technology (OT) governance gap.
As manufacturers adopt Industry 4.0 technologies, OT environments are becoming increasingly connected to enterprise IT, cloud platforms, and data-driven applications. While this creates opportunities for greater visibility, automation, and efficiency, it will also expose tensions between IT and OT teams over ownership, risk, processes, and operational priorities.
Addressing risk at an executive level allows manufacturing leaders to apply the decision-making authority needed to bring the IT and OT teams together. This will help to create a shared responsibility model, with clearly defined ownership that supports better collaboration.
Enabling a unified security posture across regions
Another such source of friction is the often-fragmented security postures that global manufacturers often manage.
The geographical spread of factories means complex operating constraints and compliance requirements. This has led to a patchwork of inconsistent site postures, whose most poorly protected sites become convenient entrance points for cyber-attackers into the broader network.
To mitigate this risk, manufacturers need to forge a framework of common control that establishes a globally unified security posture across all sites, while retaining the flexibility needed to ensure local and regional compliance and site compatibility. By elevating the risk conversation, manufacturing leaders can bring together the security, operational, geographical, and compliance expertise that this interdisciplinary approach requires.
Overcoming the integration challenge of legacy systems
Reframing risk as a strategic priority across the business will also allow manufacturing leaders to address a universal manufacturing security and resilience risk in Industry 4.0 transformation: legacy systems.
Industry 4.0 is not so much a tech acquisition problem as an integration problem. Many businesses struggle with legacy equipment and systems, particularly in crucial network connectivity, even as they try to layer new applications and technology on top of the older, inadequate infrastructure.
Our Global Business Connectivity Outlook Report 2025-2026 found that businesses recognize the drag that legacy systems impose on transformation. Our data found that 38 percent of leaders are upgrading systems to support their global connectivity journey, compared to 27 percent who are implementing new systems.
Yet many manufacturing operations remain built upon obsolete, unpatchable systems that can’t be paused, replaced, or upgraded to modern standards without major disruption. This creates increased operational and security risks.
Enabling an architectural solution to legacy system risks
Since many legacy systems can’t be upgraded to modern security standards, the ideal solution is to provide the security they lack externally at the network layer. This can be done by segmenting their network and containing legacy systems within separate segments, providing the requisite protection and minimizing lateral movement in the event a segment is breached.
However, constructing such a network-wide architecture requires that the right network-level security and connectivity solutions, operational preparations, and stakeholder buy-ins have been planned or secured in advance. By beginning the risk mitigation conversation in advance and elevated across the right decision-making levels and stakeholders, manufacturers will be able to accomplish this challenging transition. They can then position themselves to seize future opportunities without being held back by legacy infrastructure.
No better time than the present
To paraphrase a famous quote, “The best time to give risk a seat at the boardroom table was yesterday. The second-best time is today.”
Industry 4.0 is both disruptive and game-changing to manufacturers. Those who can robustly manage the operational and security risks raised by such innovation, and safeguard resilience while remaining compliant, can seize a competitive advantage in the global market. To fully unlock the potential of the AI-enabled smart factory of the future, repositioning risk as a strategic concern at the executive level is the way forward.
Table of contents
FAQs
Why is it important for manufacturers to consider resilience and business continuity in the evaluation of risk?
Manufacturers must be prepared for disruption and validate their preparations to avoid being caught unprepared when a breach happens. Some of the key resilience questions manufacturing leaders should be asking at the executive level are:
- Are we able to recover quickly from a disruption?
- How well are we able to keep operating while being disrupted?
- Can we ensure business continuity in the event of a digital disaster (not just a physical one)?
- Have we stress-tested and gamed out any digital disaster business continuity plans we made?
Why should manufacturers discuss governance as part of their risk conversation?
Lack of clear governance is a key source of risk for businesses because it leads to a lack of visibility and control, and ultimately, additional vulnerabilities in security. Manufacturers must ensure that responsibility over the entirety of their network and operational flow is clearly delegated, with no gray areas. They need to ensure their IT and OT teams have complete visibility over every asset, API, or process.
Responsibility boundaries are also potential gaps. Manufacturers should ensure they have the right people on board with the authority and accountability to act across boundaries. This will ensure coordinated and unified responses to any incident.
To mitigate supply chain risk, what are some key areas manufacturers should be looking at?
Today’s increasingly complex supply chain offers a host of hidden risks and threats posed by suppliers. To mitigate these risks, manufacturers need to understand who their vendors are, how they operate, and whether their level of security is satisfactory for current business requirements. Some key questions to ask are:
- Do we have similar levels of visibility into all our tier 1, 2, and 3 suppliers?
- Do any of these suppliers pose cyber risk to us through unsafe practices or inadequate security?
- Have we directly audited and validated the compliance of all suppliers to our standards and requirements?
- Are we overconcentrated in one location, vendor, platform, or item?