Key Takeaways
- The report details sharply lower IPS volumes but more targeted manufacturing attacks as OT and IT networks merge
- Legacy IoT exposures such as Hikvision CVE-2021-36260 continue to drive tens of millions of factory-floor intrusion attempts
- Zero Trust guidance from NIST and growing OT security investments suggest manufacturers are rethinking long-standing network architectures
Manufacturing cybersecurity is moving into uncomfortable territory. SonicWall's new 2026 Manufacturing Protect Brief lands at a moment when factory networks are changing faster than security teams can adjust. The headline number in the report, a 56.2% year-over-year decline in intrusion prevention events for the sector in the first half of 2026, might initially sound like progress. The firm's data shows a drop to 474 million IPS detections. Yet the report makes it clear the decline reflects attacker behavior, not reduced exposure. Fewer, more selective strikes are now hitting a broader and increasingly interconnected attack surface.
What stands out is how rapidly that surface has expanded. These findings reinforce what many analysts have warned for years: production lines, cameras, sensors and industrial control equipment are no longer isolated. They feed data into ERP platforms, analytics systems and remote maintenance tools. The convergence brings efficiency. It also introduces direct pathways for threat actors to reach physical equipment. The shift was already visible in earlier industry research, including the 2024 Cyber Threat Report, which highlighted 6.06 billion global malware attacks in 2023 and rising intrusion attempts across highly connected industries.
Then there is the IoT piece. IoT malware surged 107% in the first half of 2024 according to the 2024 Mid-Year Cyber Threat Report. That growth tracks almost perfectly with what manufacturers are seeing on the ground today. The latest brief details 46.2 million IoT attack hits on manufacturing networks in the first half of 2026, with more than half of these networks observing exploitation attempts.
One specific vulnerability tells the story. The Hikvision IP Camera Command Injection issue, CVE-2021-36260, was disclosed five years ago. Yet researchers identified 43 million attempts against it on manufacturing networks in just six months. Why does such an old flaw refuse to die? Because many cameras, sensors and building systems still run outdated firmware, often placed directly on corporate networks for convenience. That design choice may streamline operations, but it also gives attackers a predictable path into environments that control physical equipment.
Another angle worth noting is the surge in targeted ransomware activity. The Zhen ransomware family generated 22.2 million hits in the period, concentrated on only two devices. That pattern looks like an active incident rather than a widespread probe. It hints at attackers spending more time inside smaller numbers of environments rather than spraying every open port they can find. Apache Log4j2, disclosed more than four years ago, still produced 13.8 million detection events. Old software continues to haunt systems that were never patched or were forgotten in the sprawl of distributed plant operations.
Researchers are not the only ones paying attention to this shift. NIST’s industrial control system guidance, including the NIST SP 800-82 Rev. 2, has long recommended segmentation and Zero Trust style access within OT environments. It feels increasingly relevant. ENISA has been tracking similar patterns. Its Threat Landscape for Industrial Control Systems reported that about 35% of observed incidents involve compromised remote access pathways such as VPNs linking plants and corporate offices. Those numbers align with the narrative presented in the report: attackers are exploiting the seams between previously separate domains.
The report’s commentary also draws attention to architecture more than tooling. SonicWall's managed services SVP frames it plainly. The executive argues that a stolen credential should not allow an attacker to reach production systems, but today it often does. Many manufacturers expanded connectivity for remote monitoring, predictive maintenance and vendor troubleshooting without updating how identity and access are handled. That is not unusual. Industries with long equipment lifecycles tend to bolt on connectivity rather than redesign it. The result is a flat or semi-flat shared environment where plant systems are only a few hops away from email servers or HR applications.
Solving these architectural gaps tends to require organizational will more than advanced technology. Zero Trust frameworks are not new. NIST has discussed them for years. Many security analysts, including groups at Deloitte and IDC, have noted that practical implementations often start with something simple such as limiting who can reach specific applications rather than trying to rebuild an entire network. The provider pitches its Cloud Secure Edge offering as one implementation path. It aims to assign application-level access instead of extending full network access through a VPN. That approach, in theory, reduces the blast radius of compromised credentials.
A few manufacturers have already moved in this direction. Some have even begun aligning their security programs with IEC 62443, which has gained traction as a reference point for securing industrial control environments. And if you look at broader industry commentary, groups like McKinsey have highlighted how digital factory investments often outpace cybersecurity spending, creating timing gaps that adversaries exploit. This is not a surprise. Manufacturing digitalization efforts tend to focus first on productivity, then on governance.
There is another question worth asking: will the declining IPS volume lull some teams into a false sense of safety? Possibly. But the sharper picture painted by the data suggests the opposite is needed. Attackers appear more patient, more deliberate and more familiar with specific OT weaknesses. Legacy systems, especially those that were never designed to sit on the same network as cloud platforms or remote vendor logins, remain a persistent liability.
As manufacturing networks become heavily integrated with IT infrastructure, security teams are recognizing that visibility, segmentation and contextual access controls are mandatory components of modern operations. The next phase of this evolution will likely involve a mix of upgraded architectures, clearer identity boundaries and more direct alignment to recognized frameworks. The latest findings signal that this shift is already underway, even if uneven across the sector.
⬇️