Manufacturing

Could an Email Reach Your Machines?

Ransomware rarely starts on the plant floor. It starts in an inbox and travels. The question is whether anything stops it on the way.

September 2026  ·  6 minute read  ·  All articles

Here is a question you can put to your team in about ten seconds: if someone in the front office opened the wrong attachment this morning, could it reach the machines on the floor?

Ask it exactly that way. Not “are we secure,” which invites a reassuring answer, but a specific question about a specific path. In most of the shops we walk into around the South Hills, the honest response is a pause, and then some version of “probably, but I am not sure.”

That pause is the whole article. Ransomware almost never begins where the damage ends up.

Why Manufacturers Keep Getting Picked

There is a tendency to assume attackers go after banks and hospitals and skip the machine shop in Bethel Park. The opposite is closer to the truth, and the reason is not technical.

Manufacturers are targeted because the pressure to pay is unusually high. A law firm with encrypted files loses access to documents. A manufacturer with encrypted systems loses production, and production has customers attached to it, with delivery dates and contracts and penalties. When every hour of negotiation costs real output, the calculation tilts toward paying, and attackers know it.

The second reason is the equipment itself. Plenty of well run shops are operating machines that have been earning their keep for fifteen years, controlled by a PC running an operating system nobody has patched since the vendor stopped supporting it. That machine is not a security failure. It is a capital asset doing its job. But it is also the softest thing on your network, and it usually sits on the same flat network as everything else.

How It Actually Gets In

The entry points are less exotic than most people expect. Across the incidents we see and the ones our peers report, the same handful come up again and again.

None of that requires a sophisticated adversary. It requires an ordinary one and an opening.

The Flat Network Problem

Now back to the opening question, because this is where it gets answered.

In a lot of small and mid sized plants, the network grew the way the business grew. A switch here when the office expanded, a drop there when a new cell went in, a wireless access point so the tablets on the floor could reach the ERP system. Nobody sat down and designed it. It accumulated.

The result is a network where the front office computer, the shared server, the ERP system, and the machine controllers can all reach each other. That is convenient. It is also the reason a single opened attachment becomes a shutdown rather than an annoyance.

Segmentation is the difference between losing a workstation and losing a week of production.

Separating the production network from the office network is not glamorous work and it does not photograph well, but it is the single highest value change most manufacturers can make. Done properly, the office side can still reach what it legitimately needs, and the machines on the floor become unreachable from a compromised laptop three departments away.

What Your Backups Have to Survive

Almost every manufacturer we meet has backups. Far fewer have backups that would survive the specific event they are meant to protect against.

Modern ransomware looks for backups first. It has to, because a company that can restore does not pay. So the attacker sits quietly for days or weeks, finds the backup server, encrypts or deletes what is there, and only then triggers the encryption you actually notice.

A backup that protects you against ransomware has to meet a harder standard than a backup that protects you against a failed drive:

The question to ask is not “do we have backups.” It is “when did we last restore something from them, and how long did it take.”

The Ten Second Version

Take the question at the top of this article to your next production meeting:

If someone in the front office opened the wrong attachment this morning, could it reach the machines on the floor?

If the answer is yes, or if nobody in the room can say for certain, you have not found a crisis. You have found a project, and it is a more tractable one than most people expect. Segmentation, multifactor authentication on remote access, and backups that have actually been restored will close the majority of the realistic risk. None of it requires replacing equipment that is still making money.

Where We Fit

We work with manufacturers across the South Hills and Greater Pittsburgh on exactly this, and we tend to start by mapping what can reach what, because you cannot segment a network nobody has documented.

Being local matters here more than in most industries. When something on the floor needs hands on it, we are minutes away from Bethel Park, Whitehall, and South Park rather than an hour out on the Parkway. And in a ransomware event, the response happens in hours, not in a ticket queue.

If the question at the top gave you pause, that is worth a conversation.

Have Questions About Your Own Setup?

Thirty minutes, no pressure and no pitch. We will talk through your business, your technology, and whether we are the right fit.

Schedule a Free Consultation