Manufacturing companies are facing increasingly targeted cyberattacks as factory floors become more connected with corporate IT systems, according to SonicWall’s 2026 Manufacturing Protect Brief.
Based on data collected from more than one million global security sensors, the report found that while intrusion prevention system (IPS) events in the manufacturing sector fell 56.2% year-on-year during the first half of 2026, the industry continues to face significant cyber risks. SonicWall recorded 474 million IPS events, indicating that attackers are becoming more selective rather than less active.
The report identified 43 million attacks targeting a known Hikvision IP camera vulnerability (CVE-2021-36260), making it the largest IoT attack signature across all industries tracked by SonicWall. Manufacturing also recorded the highest SCADA attack detection rate among all sectors, while IoT attacks accounted for 46.2 million detection events. In addition, the Apache Log4j2 vulnerability continued to generate 13.8 million detections, years after it was first disclosed.
Michael Crean, Senior Vice President, Managed Services, SonicWall, said, “Manufacturing’s attack surface looks nothing like it did even five years ago. Every connection added for remote monitoring, predictive maintenance or vendor access also creates a potential entry point for attackers. In many manufacturing environments, a single stolen credential can still provide access to production systems.”
Crean added that the industry’s challenge is largely architectural rather than technological. “The factory floor is now part of the corporate network. Until organisations continuously verify users and limit access to only the applications they require, one compromised password can still disrupt an entire plant.”
SonicWall said adopting Zero Trust security with application-level access controls can help manufacturers reduce risks by preventing compromised credentials from providing unrestricted access to critical production systems.

