U.S. manufacturers face a multitude of cybersecurity challenges that threaten their operations, reduce productivity, and jeopardize their intellectual property and data. For the past two years, the manufacturing sector has been the most targeted industry for ransomware attacks,1 with manufacturers spending an average of US$1.82 million per attack in 2023, not including any ransom payments.2

These cybersecurity challenges and risks are exacerbated by the simple reality that manufacturing operations often rely on various intertwined systems not designed with cybersecurity in mind. Retrofitting those systems can be both costly and complex. But manufacturers with more modern systems do not escape the risks. Although the rapid integration of technology and connectivity in manufacturing operations has brought unprecedented levels of innovation and efficiency, it also exponentially expands the cyberattack surface area and creates new categories of vulnerabilities.

To navigate the spectrum of cybersecurity challenges, U.S. manufacturers must adopt a holistic approach to safeguarding their operations and data and moving toward a system that protects the company and helps drive profitability. In this paper jointly authored by Foley & Lardner and the Cybersecurity Manufacturing Innovation Institute (CyManII), we first outline five key cybersecurity challenges facing manufacturers, identify ways to manage those risks, and describe the legal and insurance considerations for manufacturers in addressing these issues. Next, we propose new approaches that have the potential to usher in a new era of smart, secure manufacturing that converts cybersecurity from a cost center to a value-driven profit center. In the final section, we describe the power of public-private partnerships in addressing cybersecurity challenges.

More about CyManII

Launched in 2020 by the U.S. Department of Energy, CyManII works across the manufacturing industry, research and academic institutions, and federal government agencies to develop technologies that enable the security and growth of the U.S. manufacturing sector. Foley & Lardner is currently a member of CyManII.

Additional information on cybersecurity risks faced by manufacturers available in Recommendations for Managing Cybersecurity Threats in the Manufacturing Sector, also co-authored by Foley & Lardner and CyManII.

Authors

Tantleff, Aaron K. Misakian, Alexander Howard Grimes
Aaron Tantleff
Partner, Foley & Lardner LLP
Alex Misakian
Associate, Foley & Lardner LLP
Howard Grimes
Chief Executive Officer, Cybersecurity Manufacturing Innovation Institute

1 “X-Force Threat Intelligence Index 2023,” IBM Security, February 2023.

2 “The State of Ransomware in Manufacturing and Production 2023,” Sophos, June 2023 (14-country survey of manufacturers with 100-5,000 employees).