infinIT » Blog » The Manufacturing IT Dilemma: Securing Legacy Systems Without Stopping Production

The Manufacturing IT Dilemma: Securing Legacy Systems Without Stopping Production

Manufacturing workers using a tablet to manage industrial IT systems and production equipment in their facility.

Why Can’t Some Equipment Be Easily Updated?

Walk the floor of almost any Cleveland or Warren manufacturer and you’ll find at least one machine that’s older than half the people running it. The CNC controller still runs an operating system Microsoft stopped supporting years ago. The PLC on the packaging line was installed before smartphones existed. Nobody wants to mess with it because it works. They know touching it risks a shutdown they can’t afford.

That’s the real dilemma behind manufacturing IT support in the Cleveland and Warren area. Plant managers are told to secure their systems, but the equipment that keeps production running often can’t be patched, updated, or replaced without significant cost or downtime. Security advice that assumes you can just update software doesn’t hold up on a factory floor where a four-hour outage means missed shipments and angry customers.

Thankfully, securing legacy equipment doesn’t require ripping it out or forcing an upgrade you’re not ready for. It requires a different approach that’s built around visibility and containment rather than patching. That’s exactly what this post walks through.

How Do You Secure Legacy Machines That Can’t Be Patched?

Unpatchable equipment can be secured by controlling what can reach it and watching closely for anything unusual. This is the alternative to trying to modernize the machine itself. Three practices do most of the work in this process: 

  • network segmentation
  • continuous monitoring
  • and compensating controls that reduce risk without touching the equipment

Segmentation means putting legacy machines on their own isolated section of the network, separate from office computers, email, and general internet access. If a laptop in the front office gets infected, the infection still has nowhere to travel if the production network is walled off behind it.

Monitoring means having a system that watches network traffic around those machines and flags anything abnormal (like an unexpected connection attempt or unusual data movement). Someone can respond before a small problem becomes a shutdown. Compensating controls fill the gap that a missing software patch leaves behind. These might include strict access rules, dedicated firewalls, and multi-factor authentication for anyone who connects remotely.

None of this requires replacing equipment that still runs your production line. It requires wrapping that equipment in protections you control. This is exactly the approach our team takes when we design cybersecurity services for manufacturers who can’t simply swap out working machinery.

Why Is Manufacturing Now the Most Targeted Industry?

Manufacturing used to sit in the middle of the pack for cyberattacks. That’s no longer true. Plant managers should understand why before assuming their operation is too small or too unremarkable to be a target.

Research from cybersecurity firm Halcyon found that ransomware attacks against manufacturers jumped 61% year over year in 2025. That makes manufacturing the single most targeted sector worldwide. Attackers have learned that a manufacturer under pressure to keep the line running will often pay quickly rather than absorb the cost of extended downtime.

That pressure translates directly into losses. Research covered by Infosecurity Magazine found ransomware has cost manufacturers roughly $17 billion in downtime since 2018. The average incident knocked a plant offline for 11.6 days. For a Trumbull County shop running on tight margins and tighter delivery windows, that’s the kind of disruption that damages customer relationships for years afterward.

Why Are Smaller Plants Hit Hardest?

It’s tempting to assume attackers go after large, well-known manufacturers. The opposite is often true. Halcyon’s research found that smaller manufacturers are hit hardest of all. They generate enough ransom value to be worth targeting while typically lacking a dedicated security team to catch an intrusion early.

That same research offers a useful counterpoint. Companies with visibility into their operational technology (meaning they can see what’s connected to their production network and how it’s behaving) contained incidents in about five days on average. That’s compared to 42 days industry-wide. Visibility, not size or budget, is what separates a quick recovery from a two-week shutdown.

There’s a financial dimension to this too. Much of the cost of an OT breach comes from indirect impacts (like halted production, supply chain disruption, and reputational damage), rather than the direct cost of remediation. Having an incident response plan in place ahead of time is one of the highest-value steps a manufacturer can take to limit that exposure.

What’s the Difference Between IT Security and OT Security?

IT security protects the systems your office runs on, like email, file servers, laptops, and business applications. OT, or operational technology, refers to the machines that physically run your production line. Think PLCs, CNC controllers, sensors, and the industrial network that connects them. OT security protects that side of the business, and it requires a different mindset than typical office security.

The biggest difference is what success looks like. IT security teams usually prioritize protecting data and can tolerate a brief system restart or a delayed software update. OT environments prioritize uptime and physical safety above nearly everything else. This is because an unplanned stop does more than just interrupt an email server. It stops production, and in some cases it can create a safety hazard on the floor.

That’s also why the standard advice to “just patch everything” doesn’t translate to a factory floor. A patch that’s routine on an office laptop might void a machine’s warranty. It may also require a certified technician to reinstall the machine’s control software from scratch. Effective OT security works around that reality with segmentation and monitoring (rather than fighting it). This is a large part of why infrastructure management for manufacturers looks noticeably different from infrastructure management for a typical office.

Is CMMC Compliance Still Required in 2026?

In practical terms, CMMC compliance is still required. The picture has shifted this year though, and it’s worth understanding exactly what changed. In July 2026, the Department of War, formerly the Department of Defense, suspended the Phase 2 requirements of the Cybersecurity Maturity Model Certification program, according to reporting from Federal News Network. Phase 2 was the expanded set of third-party assessment requirements originally scheduled to take full effect by November 10, 2026. The department launched a formal review aimed at simplifying the framework.

That pause applies specifically to Phase 2. Phase 1 self-assessment requirements remain active. That means manufacturers in the defense supply chain still need to document and attest to their cybersecurity practices now.

The safest posture for a Northeast Ohio manufacturer working with or supplying defense-adjacent customers is to stay ready. The compliance obligation hasn’t disappeared, and the framework is expected to return in some revised form once the review concludes. Manufacturers who keep making steady progress on segmentation, monitoring, and documentation during this pause will be in a far better position than those who treat it as a reason to stop.

How Do You Get Visibility Without Shutting Down the Line?

Every recommendation above depends on knowing what’s on your network. You can’t segment, monitor, or protect a machine you haven’t identified. Guidance from the Cybersecurity and Infrastructure Security Agency frames a systematic OT asset inventory as the foundational first step for securing a legacy environment. This is precisely because operators can’t protect equipment they haven’t cataloged.

An asset inventory is passive by design. It doesn’t touch your machines, require downtime, or risk interrupting production. It simply maps what’s connected, what it’s running, and how it communicates. That gives you the picture needed to prioritize the next steps without guessing.

That starting point is where we typically begin with manufacturing clients across Cleveland and Warren. There’s a clear inventory first, then segmentation and monitoring built around what that inventory reveals. If your plant doesn’t have dedicated IT staff to run that process internally, managed security gives you that visibility without adding headcount, and our team works alongside Cleveland-area manufacturers as a local, responsive partner. 

Learn more about our IT support for manufacturers and how we approach environments where the production line can never simply be turned off to fix a problem.

TL;DR: How to Secure Legacy Equipment on the Plant Floor

Manufacturing is now the most targeted industry for ransomware, and the machines keeping production running usually can’t be patched the way office systems can.

Protecting What You Can’t Patch:

  • Network segmentation keeps legacy machines isolated from office systems, so an infected laptop has nowhere to spread
  • Continuous monitoring and compensating controls, like dedicated firewalls and multi-factor authentication, catch problems early without touching the equipment itself

Visibility Determines How Fast You Recover:

  • Companies with visibility into their production network contain incidents in about five days, compared to 42 days industry-wide
  • CMMC Phase 1 self-assessment requirements remain active in 2026 even though Phase 2 was paused, so staying documented and ready still matters

Do you represent a manufacturing facility in Northeast Ohio? Contact infinIT to discuss IT security strategies that can protect your operations without disrupting production.

Scroll to Top

Free Resource

IT Partner Readiness Guide