The manufacturing sector is at a 'breaking point' as the convergence of Information Technology (IT) and Operational Technology (OT) creates new, high-value targets for cybercriminals. According to the 2026 SonicWall Manufacturing Protect Brief, attackers are shifting from high-volume, indiscriminate attacks to more precise, surgical strikes. While overall intrusion attempts fell, the manufacturing industry experienced the highest detection rate for SCADA attacks of any tracked sector. Attackers are successfully exploiting the expanded attack surface, with old vulnerabilities like the 2021 Hikvision camera flaw and Log4j2 still proving effective. This trend highlights the critical danger of a stolen IT credential being used to pivot to the production floor, potentially causing operational shutdowns and physical damage.
Data from SonicWall's global sensor network in H1 2026 revealed a complex threat picture for manufacturing. While total intrusion prevention system (IPS) events declined by 56.2% year-over-year, the absolute volume was still massive at 474 million. This suggests a move away from 'spray and pray' tactics toward more focused attacks.
Key findings include:
CVE-2021-44228) was responsible for 13.8 million detection events on manufacturing networks alone.The core of the issue is the insecure convergence of IT and OT networks. Historically, OT networks were air-gapped and isolated. As they become connected to corporate IT networks for data analysis and remote management, they inherit risks from the IT side. A threat actor can use a common IT entry point, like a phishing email, to gain a foothold and then pivot to the OT network.
This lateral movement is often enabled by flat network architectures and weak access controls between the two domains. The exploitation of the Hikvision camera flaw is a prime example of an IoT device being used as an entry point. These cameras are often placed on the network without proper security considerations, providing a beachhead for attackers. This aligns with MITRE ATT&CK for ICS techniques like T0819 - Exploitation for Initial Access and T0886 - Remote Services to pivot from a compromised device.
Cyberattacks in the manufacturing sector have consequences that go beyond data theft. A successful attack on OT systems can lead to:
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
The following patterns could help identify threats in a converged IT/OT environment:
/PSIA/Custom/IO/inputs/jndi:ldap://plclogic.exe (example)
Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.