Ransomware Hit Manufacturing Harder Than Any Other Industry in 2025. Here Is What Billings Plants Need.

Ransomware Hit Manufacturing Harder Than Any Other Industry in 2025.
A hospital can run on paper charts for a week. A retailer can process cash. A professional services firm can tell everyone to work from home. A manufacturer can’t do any of those things. When the production network locks, production stops. The CNC machines become inert metal. The assembly line stops moving. The shipping dock goes quiet. And every hour the plant is down costs, on average, $260,000. The ransomware groups understood this before most manufacturers did. That’s why manufacturing overtook healthcare and financial services as the most targeted industry in 2025.
The mechanism isn’t complicated. Somewhere in the plant there’s an unsecured remote access connection. A VPN the equipment vendor set up for maintenance three years ago and never removed. An RDP session the plant manager uses to check the production dashboard from home. A wireless access point someone connected to the production network so the floor supervisor could check email. Any one of these is a door. If it isn’t protected by multi-factor authentication, a stolen or guessed password opens it. The attacker walks through, encrypts everything connected to that network, and names a price. For Billings manufacturing IT services providers, this is the most common call they get: a plant that was producing on Friday and is a brick on Monday.
The compounding cost of a production line ransomware attack
Each layer triggers the next. The total cost of a manufacturing ransomware incident is never just the ransom.
Sources: Coveware and Sophos incident response data, 2025. National Association of Manufacturers operational cost estimates. Figures represent averages across reported manufacturing ransomware incidents. Individual incident costs vary based on plant size, duration, and insurance coverage.
Coveware and Sophos tracked the numbers through 2025. Average ransom demand for a manufacturing company: $447,000. Average production downtime: twenty-one days. Average total incident cost, including the ransom, operational losses, recovery, and reputational damage: over $2 million. The National Association of Manufacturers pegs a single production line outage at $260,000 per hour when all operational and reputational consequences are counted. A mid-sized plant down for a week is looking at an eight-figure loss before the ransom conversation even starts.
The targeting is rational. Manufacturers have zero tolerance for downtime, and the ransomware groups price accordingly. They know the plant can’t move production to another facility because the tooling, the fixtures, the raw materials, the work-in-progress, and the people who know how to run the machines are all in one building. They know the cyber insurance policy probably requires specific security controls to be in place, controls that the plant might not have documented. They know the supply chain pressure will mount with every day the plant isn’t shipping. The ransom isn’t priced to what the data is worth. It’s priced to what the downtime costs.
For a Billings manufacturer, the supply chain math makes it worse. Raw materials travel farther to reach Montana. Lead times are longer. When a production line goes down, the raw materials in transit have to be stored somewhere. The finished goods that were promised to customers don’t ship. The customers, running their own just-in-time operations, can’t wait three weeks. They invoke force majeure. They cancel purchase orders. They qualify an alternative supplier. Some of those customers won’t come back after the plant recovers. The insurance claim covers a portion of the direct costs. It covers none of the lost customers.
How ransomware moves from the internet to the production floor
The average manufacturing ransomware attack unfolds over 11 days between initial access and detonation. Each step is a place where detection could have stopped it.
Initial access: unsecured remote connection
The attacker finds an internet-facing VPN, RDP port, or remote maintenance account. It was set up for a vendor or a manager and never removed. No MFA. A password bought from a broker or guessed with automated tools is all it takes. The attacker is inside the network. Nobody notices.
Lateral movement and reconnaissance
The attacker maps the network. They identify the manufacturing execution system, the ERP server, the engineering file share, the backup target. They harvest additional credentials from memory and configuration files. They move from the initial foothold machine to more valuable systems. They are quiet. They are patient. The average dwell time before detonation is 11 days, per Sophos data. Every day they are inside is a day detection could have stopped them.
Credential harvesting and backup targeting
The attacker identifies and locates backup systems. They delete or encrypt backup files, shadow copies, and recovery partitions. They exfiltrate sensitive data: engineering drawings, ERP records, customer contracts. This data becomes a secondary extortion lever. Pay the ransom for decryption, or pay again to prevent the data from being published. The attacker now controls both the production systems and the recovery path.
Detonation: production line goes dark
The ransomware encrypts everything connected to the production network. Manufacturing execution system. CNC config files. PLC programs. ERP database. Engineering drawings. The screen displays a ransom note. Production stops. The plant that was manufacturing parts on Friday is a collection of inert machines on Monday. Average time to full recovery: 21 days.
Attack sequence based on Dragos ICS threat intelligence, Sophos incident response data, and CISA ICS-CERT advisory patterns, 2024 to 2025. Individual attack timelines vary. The 11-day average dwell time is per Sophos 2025 State of Ransomware report.
Why manufacturing networks are uniquely vulnerable
The production network and the office network are supposed to be separate. In practice they haven’t been separate for years. Production data has to flow to the ERP so inventory updates and invoices generate. The equipment vendor needs remote access for diagnostics and updates. Someone bridged the two networks because the production manager needed to access the scheduling system from the shop floor. Every one of these connections is documented in theory and unmonitored in practice.
The machines on the production network run operating systems that can’t be patched on a normal IT schedule. A CNC machine running Windows XP or an unpatched build of Windows 7 isn’t an outlier. It’s standard, because the control software was certified for a specific OS version a decade ago and recertification means taking the machine offline for days and paying the vendor to requalify it. The PLC running a packaging line has never been patched because the vendor warned that changing the OS could affect timing parameters measured in milliseconds. Standard endpoint security software can’t be installed on these systems because it interferes with the deterministic timing that industrial processes require. These machines are defended by the air gap that no longer exists.
The organizational structure makes it harder to fix. The IT team reports to the CFO or CIO. The OT team, the engineers and technicians maintaining production equipment, reports to the VP of Manufacturing or the plant manager. They use different vendors, different budgets, and different definitions of what “secure” means. When IT deploys a patch that affects a production system, OT sees an interruption caused by IT. When OT connects a new machine to the network without telling IT, IT sees an unmanaged device. The gap between them is the most reliable entry point an attacker has. Two teams, each assuming the other is responsible for the bridge between their worlds.
What changes when security controls are in place before the attack
The same controls that prevent an attack are the ones that determine whether the plant recovers in a weekend or stays down for three weeks.
Recovering from a manufacturing ransomware attack and preventing one are the same work. The only variable is whether it’s done before the attacker arrives or after. Network segmentation between IT and OT, enforced by a managed firewall with documented rules, tested to confirm the air gap actually exists this time. Multi-factor authentication on every remote access connection, including every vendor VPN account, every RDP session, every remote maintenance portal. No exceptions. No “the vendor said it was fine.”
Automated daily backup of production data, engineering drawings, ERP records, CNC config files, and PLC programs. Stored offsite. Encrypted. Test-restored every quarter with a documented log proving the files actually restore. Endpoint detection and response on every computer connected to the production network, configured to flag attacker activity during the average eleven-day window between initial access and ransomware detonation.
A documented incident response plan, tested every year, that answers the questions the plant will face in the first hour. Who decides whether to pay? Who tells customers their shipments are delayed? Who handles the insurance carrier? Who’s allowed to talk to the press? An organization that answers these questions for the first time during an active attack will answer them badly. An organization that’s answered them in advance and tested the answers has a chance.
For a Billings manufacturer, these five controls cost less than a single hour of a production line outage. They are not IT line items competing with maintenance budgets and material costs. They’re the business continuity investment that determines whether the plant produces on Monday or sits idle while the FBI, the insurer, and the negotiation firm figure out what happens next.
Get a plant security assessment before the next attack finds your unsecured VPN
Entre provides IT and OT security services for manufacturers across Billings and Montana. Network segmentation, automated backup, MFA deployment, endpoint detection, and incident response planning built for the production floor.


















