In a plant, ransomware is an availability problem before it is a data problem
An encrypted scheduling system or a domain controller that will not authenticate the early shift stops production as effectively as a machine failure.
Ask a manufacturing executive what a security incident would cost and the answer involves stolen designs. Ask what a week of stopped production would cost and the number is immediate and much larger.
Manufacturing security conversations default to intellectual property. The event that actually stops the business is a line that will not start on Monday, and it is both more likely and more expensive.
This paper argues that reframing the threat model around availability changes the priority order materially — segmentation and identity ahead of detection sophistication, recovery objectives expressed in shifts rather than days — and sets out what that reframing implies for a plant estate carrying equipment with decade-long lifecycles.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
An encrypted scheduling system or a domain controller that will not authenticate the early shift stops production as effectively as a machine failure.
Days is the unit IT uses. Shifts is the unit in which the cost accumulates, and stating it that way changes what leadership will fund.
It is the highest-value control available in a plant estate precisely because it does not require modifying certified equipment.
That gap is the single largest determinant of what an incident costs, and closing it is a consolidation problem rather than a detection one.
Not through negligence. Through the accumulated consequences of equipment lifecycles measured in decades.
Line controllers and human-machine interfaces running operating systems that cannot be patched without vendor certification. Flat networks where a compromised office endpoint can reach plant systems. Shared operator accounts, because individual logins slow a shift change. Remote access for equipment vendors granted years ago and never reviewed. Backup systems never tested against a full-plant restore.
Each of these was a reasonable local decision. Collectively they describe an estate where the most likely intrusion path runs from a phishing email to a production stoppage.
If the objective is confidentiality, the priority is data classification and exfiltration prevention. If the objective is availability, the priority order changes.
Segmentation comes first, because it limits how far an intrusion in the corporate estate can travel and it does not require touching equipment under vendor certification. Identity comes second, because multi-factor authentication and conditional access close the most common entry path. Detection tuning comes third, because an untuned console is functionally the same as no detection and this is a tuning problem rather than a licensing one.
Recovery moves from a technical afterthought to a first-order design constraint, and it is where the reframing has the largest practical effect. A recovery objective agreed with operations and expressed in shifts produces different investment decisions from one expressed in days by IT.
Automated response — isolating a device, disabling an account — is appropriate on standard user endpoints and rarely appropriate on plant-adjacent systems during a shift.
An automated isolation of the wrong host stops a line, and the incident will be remembered as an IT failure regardless of what the intrusion was doing. Agreeing the boundary in advance, in writing, with operations present, is the difference between a control that reduces risk and one that creates it.
This is a governance decision that looks like a configuration setting, which is why it is so often made by default.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five steps. The order is the argument.
Separate corporate from plant networks. Highest value, and it touches no certified equipment.
MFA and conditional access on every account including service and administrative ones.
Consolidate endpoint, identity, email and cloud signal into single incidents.
Agree automated response limits with operations, in writing, before an incident.
Full-scale recovery with plant management present, timed against the shift-based objective.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
We will map your coverage including plant-adjacent systems, test the segmentation independently, and facilitate a recovery rehearsal with operations present.
Deferral is a decision with a running cost. This paper quantifies where that cost accumulates and offers a framework for deciding whether to defer again.
Architectures that assume connectivity fail in exactly the places manufacturers need them most. This paper examines the design decision and the failure nobody plans for.
The parallel quarter is the whole method. Switching without one produces an accurate number nobody trusts.
Describe the situation in your own words.