Heights Consulting Group

Manufacturing and Industrial

Manufacturers need security leadership that treats the plant floor and the business systems as one program: protecting production continuity, managing operational technology that cannot be patched on an IT schedule, and answering the security requirements customers now flow down through the supply chain.

Obligations

What applies in this sector

Descriptions are of the published requirements, not claims about outcomes.

How we establish which obligations apply
Regimes that commonly apply to Manufacturing and Industrial organizations, NIST Cybersecurity Framework, ISO/IEC 27001, CMMC and NIST SP 800-171, all resolving into one governed security program.

Regimes in play

  • NIST CSF Voluntary framework
  • ISO 27001 Certifiable standard
  • CMMC Contractual requirement

One control base

Mapped once, evidenced once, and maintained between assessments.

The environment

What shapes security decisions here

In manufacturing the cost of a security failure is measured in stopped lines. Ransomware that would be a bad week for an office business can halt production, idle a workforce and breach delivery commitments within hours, which is why manufacturing is consistently among the most-attacked sectors.

The environment itself resists standard security practice. Operational technology such as controllers, HMIs and industrial networks runs for decades, is certified against change, and often cannot be patched or scanned the way corporate IT can. Security has to be designed around those constraints, not asserted over them.

At the same time, customers have made security a condition of doing business. OEMs and primes flow requirements down through purchasing agreements and questionnaires, and a manufacturer in a defense supply chain inherits federal obligations on top. The plant that cannot demonstrate its security posture is becoming harder to keep in a supply chain.

Exposure

Risks that behave differently in this sector

Not a general threat list. These are the exposures that need a different response here than they would elsewhere.

  • Downtime as the primary loss

    The dominant cyber loss scenario is production interruption. Attackers know it, which is why manufacturers are disproportionately targeted by ransomware: victims with an hourly cost of downtime settle quickly.

  • OT that cannot follow IT rules

    Plant systems run unsupported operating systems under vendor certification, cannot tolerate agent software or active scanning, and are reachable from business networks more often than anyone intended.

  • IT/OT convergence without ownership

    The network boundary between business systems and the plant floor has eroded through remote access, data collection and vendor connections, and responsibility for that seam frequently belongs to nobody.

  • Supply chain exposure in both directions

    Upstream, a supplier compromise can stop your line. Downstream, your own incident becomes a customer notification and a contract problem, because their questionnaires committed you to controls.

Requirements

Regulatory and contractual pressure

General descriptions of published requirements. Which of them apply to a particular organization is the first question an engagement answers.

IEC 62443
The international standard family for industrial automation and control system security: zones and conduits, security levels and lifecycle requirements for operators, integrators and product suppliers.
NIST SP 800-82
Federal guidance on securing operational technology, widely used as the reference for assessing and segmenting industrial environments.
Customer flow-down requirements
Security obligations imposed through purchasing agreements, supplier codes and questionnaires by OEMs and large customers, functioning as contractual requirements with audit rights.
NIST SP 800-171 and CMMC
For manufacturers in defense supply chains: safeguarding requirements for controlled unclassified information, with certification requirements arriving through prime contractors.
State breach notification laws
Employee and customer personal data held by manufacturers carries the same notification duties as in any other sector, a fact often overlooked until an incident.

How we establish which obligations apply

What we hear

What leadership raises with us

  • Nobody can say with confidence what is connected to the plant network, or what could reach it from the internet.
  • A ransomware event elsewhere in the industry made the board ask how long our lines would be down, and there is no defensible answer.
  • A key customer's supplier security requirements arrived, and compliance is being asserted rather than known.
  • Remote access for equipment vendors was set up during a crisis and never reviewed.
  • The person who understands the plant systems and the person who understands security are not the same person, and they rarely talk.

What prompts an engagement

  • An OEM or prime customer has made security evidence a condition of remaining a supplier.
  • A ransomware incident, at the company or at a peer, made production downtime a board question.
  • A plant modernization, new ERP or industrial data project is connecting systems that were never designed to be connected.
  • Cyber insurance renewal is asking specifically about operational technology and segmentation.
  • The company is entering a defense supply chain and CMMC obligations are arriving with the contract.

Alignment

Frameworks that apply here

NIST Cybersecurity Framework
Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
ISO/IEC 27001
Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
CMMC and NIST SP 800-171
Defense contractors and their supply chain, where flow-down clauses make this an eligibility issue rather than a compliance preference.

FAQ

Questions from manufacturing and Industrial leaders

General questions about the vCISO role are answered on the vCISO page.

How do you secure plant equipment that cannot be patched or take an agent?

By controlling what can reach it instead of changing the equipment itself. In practice that means segmenting the industrial network into zones with controlled conduits between them, restricting and monitoring remote access paths, and putting detection at the boundaries the equipment cannot defend itself at.

IEC 62443 exists precisely because industrial systems cannot follow IT security practice. The leadership work is deciding which zones matter most to production, sequencing the work accordingly, and documenting the compensating controls so the residual risk is a governed decision rather than an unexamined fact.

What does a customer supplier-security requirement actually commit us to?

Read as a contract, because it usually is one: the questionnaire answers and the supplier code language typically become representations with audit rights attached, and a breach of them can jeopardize the relationship independent of any actual incident.

The durable approach is to maintain one accurate account of your controls mapped to the frameworks customers reference, so each new flow-down is answered from evidence rather than negotiated from scratch under commercial pressure.

Who should own cybersecurity when we have a plant manager, an IT lead and no CISO?

Accountability has to sit above both, because the hardest decisions are trade-offs between them: taking a line down to contain an incident, delaying a project until segmentation is in place, spending on the plant network instead of visible IT. Those are business decisions about production risk.

That is the gap fractional security leadership fills in a manufacturer: one accountable owner for the whole program, who can speak to the plant floor, the IT team, the customer's auditors and the board in their own terms.