Manufacturers are the most-targeted mid-market sector for ransomware, and every one of them is a supplier to someone. This guide treats those two facts as a single problem and lays out a 90-day plan that does not begin with a purchase.
Manufacturing accounts for more mid-market ransomware victims than the next two sectors combined. Between January 2023 and June 2026, manufacturers made up 2,521 of the 9,781 disclosed mid-market incidents that Black Kite catalogued in North America and Europe, and the sector's share rose from 20.7 percent in 2023 to a peak of 28 percent in 2025.1
The reasons are structural rather than technical. Manufacturers run long, opaque supplier chains, tolerate very little downtime, and increasingly serve customers who audit them. A mid-market manufacturer is therefore exposed in two directions at once: through the suppliers it depends on, and through the customers who depend on it. Most companies manage those directions with separate people, separate budgets, and separate spreadsheets, if they manage them at all.
This paper argues for treating them as one problem, owned by one person, with one short list of controls. It closes with a 90-day plan, a board reporting format, and an honest statement of what can wait.
Three characteristics make manufacturing the preferred target.
Low tolerance for outage. A distributor can reroute. A professional-services firm can work from laptops. A plant that cannot see its production schedule, ship orders, or invoice cannot substitute. Attackers price their demands against that pressure.
Long, layered supply chains. The typical manufacturer buys from hundreds of suppliers and sells to a smaller number of customers who are themselves larger and better defended. Every one of those relationships is a network connection, an EDI feed, a shared portal, or a remote-access agreement. Black Kite describes a typical vendor-risk team as two people responsible for more than 300 suppliers, with some software and services sitting outside any formal inventory.2
Operational technology that cannot be patched on a Tuesday. Production systems run on schedules set by output, not by vendor release notes. Where the boundary between the office network and the plant floor is soft, an email compromise becomes a production incident.
None of this is news to plant leadership. What is new is the speed. A related Black Kite study found that once an attacker gains initial access to a vendor environment, the handoff to a ransomware operator takes a median of 22 seconds, down from eight hours in 2022.3 The window between a supplier's compromise and your own has effectively closed.
As a customer of your suppliers. The question is not are our suppliers secure but which suppliers can stop us, and how would we know they were compromised. Most manufacturers can name their top ten suppliers by spend. Far fewer can name the ones whose failure stops shipping within a week, and those lists overlap less than people expect. The logistics provider, the label printer, the managed-service provider with remote access to every workstation, and the small software vendor whose module runs the shop floor are rarely top-ten by spend.
As a supplier to your customers. Larger customers now send security questionnaires as a condition of doing business, and the trend is regulatory as well as commercial. Rules such as the EU's NIS2 Directive and, in the United States, requirements including NYCRR 500 and HIPAA can oblige covered organizations to address risk in their supply chains.2 When your customer is covered, the obligation flows down to you whether or not you are.
The commercial consequence is rarely immediate. A weak questionnaire answer does not lose the account this quarter. It loses the account at renewal, to a competitor who answered well, and the reason is never stated.
The questionnaire your largest customer sends is the questionnaire you should send upstream.
Seen this way, the two directions are the same work. The controls that make you a defensible supplier are the controls you should require of your own suppliers.
The volume of published vulnerabilities is not a useful measure of risk. More than 48,000 CVEs — Common Vulnerabilities and Exposures, the catalog numbers assigned to publicly disclosed software flaws — were published in 2025; roughly 800, about 1.6 percent, were ever exploited in the wild.1 Black Kite's supply-chain analysis narrows that further to a much smaller set that is both discoverable from the outside and carries a high probability of exploitation.3
Of the 60 ransomware operators active against the mid-market in 2023, only 17 remained active by the first half of 2026, and roughly one in three groups active in any six-month period had never been seen before.1 A defense built around named adversaries will need rebuilding every year. A defense built around the four exposures above will not, because every operator in the dataset used some combination of them.
The plan below assumes no new tooling and no new headcount. It assumes one accountable owner, usually the controller or the operations leader rather than IT, because the decisions are commercial.
A board does not need a threat briefing. It needs five lines, updated quarterly:
Five numbers, one page, no adjectives. When a customer's procurement team or an insurance underwriter asks, the same page answers them.
The controls above are the ones cyber underwriters weight most heavily, and the ones most likely to appear as conditions or exclusions at renewal. A manufacturer that can show enforced email authentication, no exposed known exploited vulnerabilities, tested backups, and a dated plan for unsupported software is negotiating from a different position than one that cannot. Most commercial cyber policies renew on a calendar-year cycle, and underwriters typically begin their review 60 to 90 days ahead of the renewal date.8 A gap fixed in September is a gap the underwriter never sees. The same gap found in a December renewal review is a condition, an exclusion, or a higher premium, negotiated from a weaker position with less time to respond.
We would resist any proposal that begins with a platform purchase and ends with a dashboard. The companies in this dataset were not defeated by sophisticated, novel attacks. They fell to a known vulnerability, a spoofable domain, an unwatched supplier, or a remote-access tool with a shared password. Fixing those does not require a vendor. It requires an owner.
There are things that can wait. A formal third-party risk management program with tiering, scoring, and continuous monitoring is worth building at $200 million in revenue and usually premature at $40 million. A security operations center, in-house or outsourced, is a reasonable investment once the basics are in place and a poor one before. Segmenting the plant floor from the office network is valuable and often disruptive; it belongs in a planned window, not in a panic.
What cannot wait is the first thirty days. The arithmetic is simple: at $40 million in revenue, ten days of disrupted shipping is roughly $1.1 million of revenue deferred or lost before any recovery cost is counted. The first thirty days of the plan above cost a few weeks of one person's attention.
Our team has led technology and security functions inside manufacturers and distributors, and we have sat on the customer side of the questionnaire. We resell nothing, so the answer to what should we buy is often nothing yet. If your team wants a second opinion on the plan, the supplier list, or a customer's audit, start a conversation.
The Business Resiliency Scorecard benchmarks your continuity readiness against NIST CSF 2.0 in ten minutes — free, no signup.
No SDR layer. We sell expertise, not products.