Manufacturers are heavily targeted because downtime is extraordinarily costly (ideal for ransomware extortion) and factories increasingly connect legacy, unpatchable OT to corporate IT. The central risk — and the focus of a test — is IT/OT convergence: can an attacker who phishes into the office network reach the plant? A test spans corporate IT, ERP/MES, the IT/OT boundary and segmentation, and (carefully) the OT/SCADA environment. OT testing is passive-first and read-only, with active testing agreed and ideally run against a test rig or maintenance window — the plant team involved throughout. Drivers include OT controls like NCA OTCC, the PDPL, supply-chain contracts, insurers, and the raw cost of downtime. Full detail below.
// 01 Why manufacturing is a prime target
Manufacturing has climbed to the top of most-attacked-sector rankings for one blunt reason: downtime is unbearable. A halted production line loses money every minute, so attackers know a ransomware hit creates enormous pressure to pay fast — it's extortion with a countdown. Alongside ransomware, factories are targeted for intellectual property (product designs, processes, formulations) and are increasingly exposed by connectivity: Industry 4.0 links once-isolated machinery to networks and the internet. Much of that machinery runs legacy control systems never designed to be networked or patched, so it carries old, well-documented vulnerabilities in an environment where an outage isn't just costly — it can be a safety event. That combination makes factories both valuable and fragile.
// 02 IT/OT convergence — the core risk
The defining security problem of modern manufacturing is IT/OT convergence: the merging of corporate IT (email, ERP, business systems) with operational technology (the SCADA systems, PLCs and controllers that run the plant). Historically the two were separate — an “air gap.” Today they touch, deliberately or accidentally, and that creates a path from the exposed office network into the fragile production environment. The classic kill chain is: phish an employee → land on the IT network → pivot across a weak boundary → reach OT and hold production hostage. So the heart of a manufacturing test is the boundary: is the segmentation between IT and OT real and effective, or can a foothold in the office reach the factory floor? Where do the two environments unexpectedly connect?
// 03 What to test
Corporate IT
The external and internal network, email, identity and Active Directory — the usual entry point.
IT/OT boundary
The segmentation, firewalls and data flows between corporate IT and the OT network.
// 04 Testing live production safely
“Can you pentest my factory without stopping it?” is the first question, and the answer shapes the whole engagement. Corporate IT can be tested normally. The OT side is approached conservatively, because industrial equipment can be brittle and an outage carries production and safety consequences. A competent OT engagement is weighted toward passive and read-only techniques — architecture and configuration review, network traffic inspection, and IT/OT boundary testing — with any active testing agreed in advance and, where possible, run against a test environment or a planned maintenance window. The plant and controls-engineering team stay involved throughout. The goal is a clear picture of exposure without becoming the very incident you're trying to prevent — the same discipline we bring to oil, gas and energy OT.
// 05 Regulatory & commercial drivers
Several forces push manufacturers to test. Handlers of operational technology and critical systems may fall under national OT and critical-infrastructure controls — such as the NCA OTCC in Saudi Arabia — and broader national cybersecurity frameworks. Those processing personal data answer to the regional PDPLs. Manufacturers in regulated supply chains (defence, energy, pharmaceuticals, food) inherit customer and sector-specific requirements. And even absent a single mandating regulator, insurers increasingly require evidence of testing, enterprise customers demand it, and the sheer cost of downtime makes a proactive test cheap by comparison. Map your specific obligations with the requirements finder; engagements follow our methodology, reported to the frameworks you answer to.
// 06 Frequently asked questions
Why is manufacturing a target?
Downtime is extraordinarily costly, making factories ideal ransomware targets, and they increasingly connect legacy OT to corporate IT and the internet. Attackers halt production to extort payment, steal IP and designs, and exploit IT/OT convergence to reach the plant. Much industrial equipment was never designed to be networked or patched, presenting old vulnerabilities where an outage means financial and safety impact.
What is IT/OT convergence and why does it matter?
It's the merging of corporate IT with the OT that runs the plant (SCADA, PLCs, control systems). It creates a path from the exposed IT network into the fragile OT environment. A test focuses on this boundary — whether a compromise of the office network can reach production, whether IT/OT segmentation is real and effective, and where the two unexpectedly touch.
Is it safe to test a live factory?
OT must be tested carefully because industrial systems can be fragile and outages have safety and production consequences. A competent engagement is weighted to passive and read-only techniques — architecture review, configuration analysis, traffic inspection, boundary testing — with active testing agreed in advance and ideally against a test environment or maintenance window. IT is tested normally; OT conservatively, with the plant team involved.
What regulations apply in the GCC?
Handlers of OT and critical systems may fall under national OT controls like the NCA OTCC and broader cybersecurity frameworks. Personal-data processors are subject to the regional PDPLs, and manufacturers in regulated supply chains face customer and sector requirements. Even absent a single regulator, insurers, enterprise customers and downtime cost drive testing.
// 07 Related reading
- OT / ICS / SCADA penetration testing — the operational-technology service in depth.
- Pentesting for oil, gas & energy and SAP security assessment.
- Internal vs external testing and the requirements finder.