Four Winds Blog

Most of What Gets Sold to Manufacturers as Security Does Not Protect a Single Production Hour

Written by Dylan Borden | Aug 31, 2026, 11:45:00 AM

Ask a plant manager what keeps them up at night and you will not hear about data breaches. You will hear about the line stopping.

That is the correct instinct, and it is also the reason most security conversations with manufacturers go badly. The pitch arrives framed around data: what could be stolen, what could be exposed, what the regulatory exposure looks like. None of that is how a manufacturer measures risk. A manufacturer measures risk in hours of production.

So here is the version of this conversation that is actually useful. Forget threats for a minute. The only question worth asking about any security control is: if this failed, would the line stop, and if I bought it, would the line keep running?

Rank everything by that, and the list changes considerably.

What Actually Protects a Production Hour

Two things stand out about that list.

The top of it is cheap. Backup, network separation, email security, multi-factor authentication. None of these are premium products. Several are configuration decisions more than purchases. All four sit directly between a routine problem and a stopped line.

The bottom of it is expensive. Around-the-clock monitoring and enterprise compliance platforms are real products with real value at the right scale. At a plant with no after-hours response capability, monitoring produces an alert at 2 a.m. that nobody sees until 6. The alert did not protect a production hour. It documented the loss of several.

Most manufacturers we look at have bought from the bottom of that list and skipped items at the top. Not out of carelessness. It is what gets sold, because it is what carries margin.

The Three That Matter Most

A tested restore of the ERP specifically

Not backups in general. Everyone has backups. The question is whether anyone has restored from them, and how long it took.

Your ERP is the system that schedules production, tracks inventory, and tells the floor what to build. If it is unreachable, the line does not stop instantly, but it stops within a shift or two, and it stops in a way that is expensive to untangle afterward because nobody knows what was actually completed.

The exercise worth running this quarter: ask your provider to restore the ERP to a test environment and time it. Write down the date and the result. If the answer is "we have never done that," you have learned the most important thing in this article, and it cost you an email.

Separation between the office network and the plant floor

If a compromised laptop in accounting can reach production systems, the blast radius of a routine problem is your output rather than your paperwork.

This is largely a configuration and architecture question rather than a purchasing one, which is why it gets skipped. There is no product to demo. It is a network design decision that somebody has to actually make and document, and it is the single highest-leverage thing most manufacturing environments are missing.

Email security and multi-factor authentication

Almost every event that ends with production disrupted begins with a credential that was not supposed to be in someone else's hands.

That chain is not dramatic and it is not unusual. It is the ordinary sequence, and the useful thing about it is that the cheapest place to break it is step one.

Multi-factor authentication means a stolen password is not access. Email filtering and authentication means the credential is less likely to be taken at all. Both are inexpensive, both are boring, and both sit at the front of the chain where intervention costs the least.

The Thing Manufacturers Underestimate

Contractor and temporary access.

Manufacturing runs more short-term people through its systems than almost any industry we work in. Temps during a production ramp, contractors during an installation, integrators with remote access to a machine, vendors who needed a login once for a commissioning visit in 2023.

Every one of those is an access grant. Very few of them get removed, because nobody owns the list, and because removing access is nobody's deadline the way granting it was.

There is no product that fixes this. It is a documented list of who has access to what, reviewed quarterly, with removal treated as a task with a name attached rather than something that happens eventually. It costs nothing, and it closes a gap that grows every single month you do not look at it.

What Actually Changes Your Requirements

Right-sizing applies here the same as anywhere. We sort security into three tiers, and the tier you belong in is set by your obligations rather than your budget.

Secured is the floor: firewall, multi-factor authentication, endpoint protection, offsite backup, email security. Insured adds what carriers now require: training with completion records, password management, managed detection, advanced email protection. Compliant adds centralized logging, formal governance, and documentation, and it applies when somebody outside your company can compel you to produce evidence on their schedule.

For most manufacturers in this market, Insured is the right tier and Compliant is premature. The things that move a manufacturer up are concrete: a cyber policy with control requirements attached, a large customer adding security terms to a supply agreement, or an acquisition that doubles the footprint.

What should not move you up a tier is the calendar, or a renewal conversation where the provider needs a bigger number.

The full framework is in our security spending guide, Overpaid and Under-protected.

Can You See What You Are Paying For?

One bundled line on the invoice that says "security." A number that moves occasionally with no explanation, because nobody can see inside it.

That means you cannot tell whether you are paying for the tier you are actually in, whether two products are doing the same job because one was added years ago and never removed, or whether the license count still matches your headcount after a season of turnover.

We itemize every component with a monthly report behind it. Not generosity. A client who can see what they are buying makes better decisions.

If your provider cannot produce a line-item breakdown of your security spend within a day, that is the finding. You do not need to know anything about firewalls to know that is a problem.

Start With One Question

If you do nothing else after reading this: ask your provider when they last restored your ERP to a test environment, and what the result was.

Not "are we backed up." Anyone says yes to that. The date of the last actual restore, and how long it took, tells you more about your real exposure to lost production than any assessment you could buy.

Frequently Asked Questions

What security controls actually protect manufacturing uptime?

The four with the most direct effect on production continuity are offsite backup with a tested ERP restore, network separation between the office environment and the plant floor, email security and authentication, and multi-factor authentication. All four are inexpensive relative to their impact, and all four sit between a routine problem and a stopped line. Monitoring platforms and compliance software have value at larger scale but do not protect a production hour at a plant with no after-hours response capability.

How often should a manufacturer test an ERP restore?

At least annually, and ideally before any period of peak production. The test should restore to a working environment and be timed, with the date and result recorded. A backup that has never been restored from is an assumption rather than a control, and the difference typically surfaces at the worst possible moment.

Should the plant floor be on the same network as the office?

Generally no. If a compromised device in the office environment can reach production systems, the consequences of an ordinary incident expand from data to output. Separating the two is primarily an architecture and configuration decision rather than a purchase, which is why it is frequently overlooked, and it is often the highest-leverage improvement available in a manufacturing environment.

Do manufacturers need 24/7 security monitoring?

Usually not as the next investment. Around-the-clock monitoring produces alerts, and alerts create value only when someone is positioned to respond to them. A plant without after-hours response capability or a documented escalation path gets a notification rather than protection. Monitoring becomes proportionate once the fundamentals are in place and there is a plan for who acts on an alert overnight.

What is the most commonly missed security gap in manufacturing?

Contractor and temporary access that is never removed. Manufacturing grants more short-term system access than most industries, through temps, integrators, installers, and vendors, and removal is rarely anyone's assigned task. The fix requires no software: a documented list of who has access to what, reviewed quarterly, with removal owned by a named person.

Find Out Which Tier You Are Actually In

Ninety-second version: take the three-question self-check. No email required to see your result.

Longer version: send us your cyber policy or your most recent renewal application, whichever you have handy. We will tell you which of those controls you can actually prove today, which ones you cannot, and which tier your operation is genuinely at. Send your IT invoice along with it if you want us to check whether your spend matches your tier, though that part is optional.

No charge. No meeting required. Five business days.


Four Winds IT is a technology company serving 300+ businesses across Southwest Florida, headquartered right here in Sarasota. Call us at (941) 315-2380 and an engineer picks up.