JJC SystemsBook a Consultation
Microsoft Defender · Manufacturing

Operational continuity as a security objective

Ask a manufacturing executive what a security incident would cost and the answer involves stolen designs. Ask what a week of stopped production would cost and the number is immediate and much larger.

PublishedApril 26, 2026
Length14 pages · 15 min read
SectorManufacturing
PlatformMicrosoft Defender
Service areaManaged IT & Security
Abstract

Operational continuity as a security objective

Summary

Manufacturing security conversations default to intellectual property. The event that actually stops the business is a line that will not start on Monday, and it is both more likely and more expensive.

This paper argues that reframing the threat model around availability changes the priority order materially — segmentation and identity ahead of detection sophistication, recovery objectives expressed in shifts rather than days — and sets out what that reframing implies for a plant estate carrying equipment with decade-long lifecycles.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

In a plant, ransomware is an availability problem before it is a data problem

An encrypted scheduling system or a domain controller that will not authenticate the early shift stops production as effectively as a machine failure.

02

Recovery objectives should be expressed in shifts

Days is the unit IT uses. Shifts is the unit in which the cost accumulates, and stating it that way changes what leadership will fund.

03

Segmentation limits blast radius without touching equipment that cannot be touched

It is the highest-value control available in a plant estate precisely because it does not require modifying certified equipment.

04

Correlation shortens the gap between compromise and discovery

That gap is the single largest determinant of what an incident costs, and closing it is a consolidation problem rather than a detection one.

Analysis

The argument in full

Where plant estates are structurally exposed

Not through negligence. Through the accumulated consequences of equipment lifecycles measured in decades.

Line controllers and human-machine interfaces running operating systems that cannot be patched without vendor certification. Flat networks where a compromised office endpoint can reach plant systems. Shared operator accounts, because individual logins slow a shift change. Remote access for equipment vendors granted years ago and never reviewed. Backup systems never tested against a full-plant restore.

Each of these was a reasonable local decision. Collectively they describe an estate where the most likely intrusion path runs from a phishing email to a production stoppage.

  • Controllers and HMIs on operating systems that cannot be patched without vendor approval
  • Flat networks permitting lateral movement from corporate to plant systems
  • Shared operator accounts at the line, driven by shift-change practicality
  • Standing vendor remote access, granted for a commissioning that finished years ago
  • Backup systems that have never been restored at full plant scale

What the reframing changes

If the objective is confidentiality, the priority is data classification and exfiltration prevention. If the objective is availability, the priority order changes.

Segmentation comes first, because it limits how far an intrusion in the corporate estate can travel and it does not require touching equipment under vendor certification. Identity comes second, because multi-factor authentication and conditional access close the most common entry path. Detection tuning comes third, because an untuned console is functionally the same as no detection and this is a tuning problem rather than a licensing one.

Recovery moves from a technical afterthought to a first-order design constraint, and it is where the reframing has the largest practical effect. A recovery objective agreed with operations and expressed in shifts produces different investment decisions from one expressed in days by IT.

The automation boundary

Automated response — isolating a device, disabling an account — is appropriate on standard user endpoints and rarely appropriate on plant-adjacent systems during a shift.

An automated isolation of the wrong host stops a line, and the incident will be remembered as an IT failure regardless of what the intrusion was doing. Agreeing the boundary in advance, in writing, with operations present, is the difference between a control that reduces risk and one that creates it.

This is a governance decision that looks like a configuration setting, which is why it is so often made by default.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

The availability-led priority order

Five steps. The order is the argument.

1

Segment

Separate corporate from plant networks. Highest value, and it touches no certified equipment.

2

Identify

MFA and conditional access on every account including service and administrative ones.

3

Correlate

Consolidate endpoint, identity, email and cloud signal into single incidents.

4

Bound

Agree automated response limits with operations, in writing, before an incident.

5

Rehearse

Full-scale recovery with plant management present, timed against the shift-based objective.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the operations director

For the CIO

For the CISO

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Microsoft Defender for Endpoint documentation
02
Microsoft Defender XDR incident correlation
03
Configure device groups and automation
04
Manage exclusions for Microsoft Defender
05
Azure Site Recovery and backup guidance

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We will map your coverage including plant-adjacent systems, test the segmentation independently, and facilitate a recovery rehearsal with operations present.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

azure
manufacturing15 pages

The edge-to-cloud architecture decision

Architectures that assume connectivity fail in exactly the places manufacturers need them most. This paper examines the design decision and the failure nobody plans for.

April 12, 2026 · 15 pages · 16 min readRead
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.