Manufacturers Say They’re Ready, Their Own Data Says Otherwise

There's a serious disconnect between attack frequency and confidence in containing future hacks.

Robotic hand pointing at red warning triangle symbol with binary code background representing cybersecurity threat detection

Rockwell Automation surveyed industrial security leaders this year and found something that should worry every board overseeing a manufacturing operation. Forty-six percent of respondents say their organization experienced a cyber incident in the past twelve months. Additionally, 90 percent say they are confident they could contain the next one. Those two numbers cannot both be comfortable truths, and almost nobody covering that survey noticed the contradiction.

The disconnect is not a manufacturing problem. It is a measurement problem, and manufacturing just happens to be the sector where Rockwell went looking first.

A separate, much larger study points at the same gap from a different direction. Kiteworks’ Data Security and Compliance Risk 2026 Annual Survey Report surveyed 459 security and compliance professionals across ten industries and found that self-reported confidence consistently outpaces what the underlying controls can demonstrate. Forty-nine percent of respondents could not name their own organization’s SIEM platform without checking with a colleague first. Forty-one percent could not identify the audit framework their own company is assessed against.

That is not a knowledge problem confined to a handful of security teams. It is systemic, and it plays out differently depending on which sector a company sits in.

Manufacturing specifically is not the worst performer in that data set. It posts a Data Security Maturity Score of 43.0 against a cross-industry mean of 39, a genuinely solid number on its own. Combine that score with the sector’s AI governance maturity into the same report’s compliance readiness index, though, and manufacturing drops to 18.4, well short of the 45-plus average among organizations that reach top-tier maturity on both dimensions. 

The sector is disproportionately represented in what the report calls a Policy-Led posture, meaning manufacturers have written the governance policy before they built the control that enforces it. That gap is not academic. Sixty-three percent of organizations in the same survey experienced a compliance consequence in the past year despite tracking the frameworks they were supposed to track, and only thirty-three percent have tamper evident audit trail capability in place at all, which happens to be the exact evidence type an investigator or an examiner asks for first.

Put the two studies side by side and a pattern emerges that either one alone could plausibly be dismissed as noise. Confidence is not tracking readiness. It is tracking something else entirely, namely how recently the organization last had to prove what it believed under real scrutiny rather than in a self-assessment.

The instinctive response is to buy more. Sixty-two percent of Rockwell’s respondents already invested in cybersecurity platforms, asset inventory tools, and intrusion detection systems. Forty-five percent plan to add artificial intelligence and machine learning to their security stack within the next year. None of that spending closed the confidence gap, because the gap was never a tooling problem to begin with.

The second instinct fails for a different reason. Chasing framework alignment proves intent, and intent is not the same thing as evidence.

Rockwell’s report recommends aligning to NIST, NIS2, and IEC 62443, which is sound advice for demonstrating that an organization tracks the right obligations. It says nothing about whether that organization can produce, on demand, a verifiable record of who accessed a specific piece of sensitive data, under what authorization, at the moment a regulator asks, and examiners have learned to ask for that evidence directly rather than accept alignment as a substitute. 

This gap matters most at the boundary that Rockwell’s own data flags as one of the most vulnerable points in the environment - where IT systems meet operational technology. Every new connection between a plant floor and a supplier portal, a remote maintenance vendor, or a cloud analytics platform is a fresh place for confidence to detach from a control that can be tested.

Security leaders must stop treating the IT and OT boundary as a network segmentation problem and start treating it as a data governance problem. Segmentation limits how far an incident travels. It produces nothing for the auditor asking who touched a specific file six months after the fact, under whose authorization, and whether that access was ever revoked.

Close the tamper evident audit trail gap specifically, not generally. A third of an entire industry lacking this capability is not a rounding error. It is the single evidence type most likely to decide whether an incident review stays internal or becomes a regulatory finding, and it is the one gap on this list that a purchase order alone will not fix.

Stop treating vendor and third party access to the plant floor as a footnote in the security program. Manufacturing runs on supplier networks, contract manufacturers, and machine builders who each hold their own remote access credentials, and every one of those relationships needs its own governed, logged access path rather than a shared line item buried inside the broader IT and OT program. The evidence that a regulator or an insurer will eventually ask for must exist before the incident, not get assembled after it.

None of this is optional once a regulator’s clock starts running. A Chief Compliance Officer facing a supervisory inquiry does not get months to reconstruct what happened. Enforcement timelines are measured in days and weeks, and an audit trail that must be manually assembled from five different systems after the fact is functionally the same as no audit trail at all, because it cannot be produced fast enough to matter. 

The organizations that come through an incident review cleanly are not the ones with the most security spending. They are the ones that can hand an investigator a single, verifiable record the moment it is requested, rather than promising to compile one.

Forty-six percent of manufacturers already found out what happens when confidence outruns evidence. The other fifty-four percent are simply early.  

Frank Balonis is the Chief Information Security Officer and SVP of Operations at Kiteworks.

More in Cybersecurity