Industries · Manufacturing · Canada and USA

Cybersecurity for manufacturers and plant floors.

The DBIR's fastest-growing breach category, and the sector with the clearest new rules for defense suppliers. Sophos sized for plants in Canada and the United States.

In plain terms: Manufacturers are breached through unpatched systems more than anyone else, and the payload is ransomware that stops the line. Add CMMC in the US and CPCSC in Canada for anyone in a defense supply chain, and the plant floor now needs the same evidence as the office.

Sophos Silver Partner. Offices in Markham, Ontario and Dallas, Texas. Quotes in CAD and USD, shipping to Canada and the United States.

The risk in numbers

What the breach data says about this sector. Every figure links to its source at the foot of the page.

61%
of manufacturing breaches involved ransomware
Verizon 2026 DBIR
38%
began with an exploited vulnerability, ahead of phishing at 13%
Verizon 2026 DBIR
61%
involved a third party such as a supplier, integrator or MSP
Verizon 2026 DBIR
15%
of breaches were espionage-motivated, alongside 87% financial
Verizon 2026 DBIR

3,627 incidents and 2,713 confirmed breaches in manufacturing, Verizon 2026 DBIR manufacturing snapshot.

How an attack unfolds here, and where Sophos stops it

The same four stages appear in nearly every breach. Each stage below shows what it looks like in this sector and the control that breaks the chain.

1Entry
What happensUnpatched edge device or an integrator's remote tool
What stops itXGS firewall with IPS; Managed Risk finds the exposure; ZTNA for vendors
2Foothold
What happensAn engineering workstation or ERP server
What stops itSophos Endpoint stops exploits and ransomware behavior
3Spread
What happensToward MES, historians and the plant network
What stops itFirewall zones between IT and OT; NDR sensor on the plant segment
4Impact
What happensProduction halt, design theft
What stops itMDR Plus responds 24/7; Cove restores; SIEM keeps CMMC evidence

What is at risk in manufacturing

Exploited vulnerabilities

At 38%, manufacturing has the highest vulnerability-exploitation rate of any DBIR industry snapshot. Edge devices, remote access and old application servers are the targets.

Ransomware that stops the line

61% of manufacturing breaches involved ransomware. The ERP, MES and file servers are enough to halt production even when the PLCs are untouched.

Supplier and integrator access

Third parties were in 61% of manufacturing breaches. Machine builders and integrators keep remote-support tunnels open for years.

Espionage

15% of breaches were espionage-motivated, targeting designs, bids and process data.

Defense supply chain rules

CMMC in the US and CPCSC in Canada turn cybersecurity into a contract condition.

What you have to comply with

The rules and expectations that shape a security purchase in this sector, in both countries. Status is as of September 2026; check the linked source before relying on a date.

WhereRule or expectationWhat it asks for
United StatesCMMC 2.0 (32 CFR and 48 CFR)Phase 1 self-assessments for new DoD solicitations began November 2025. Level 2 is NIST SP 800-171. Third-party assessment timing (Phase 2) was placed under DoD review in July 2026; check the current status before bidding. Source
CanadaCanadian Program for Cyber Security Certification (CPCSC)Level 1 certification applies to select defense contracts from summer 2026, with Levels 2 and 3 to follow, harmonized with US requirements. Source
BothNIST SP 800-171 and CSF 2.0The control set behind CMMC Level 2 and the framework customers and insurers use to assess a plant. Source
BothCustomer and insurer questionnairesOEM customers require MFA, endpoint detection, segmentation and incident response from suppliers. Source

The Sophos stack for manufacturing

Each product is tagged with the NIST Cybersecurity Framework 2.0 function it serves, so the list can go straight onto a questionnaire.

Protect

Sophos XGS firewall

Zones between office, plant and vendor networks; IPS and TLS inspection; HA pair at the main plant.

See Sophos XGS firewall →
Detect

Sophos NDR

Passive detection on the plant network for PLCs, HMIs and CNC controllers that cannot run an agent.

See Sophos NDR →
Identify

Sophos Managed Risk

External attack surface and vulnerability prioritization, the answer to a 38% exploitation rate.

See Sophos Managed Risk →
Respond

Sophos MDR Plus

24/7 analysts with response authority across shifts.

See Sophos MDR Plus →
Protect

Sophos Endpoint

Engineering workstations, ERP and file servers, office PCs.

See Sophos Endpoint →
Protect

Sophos ZTNA

Integrator and machine-builder access to one system at a time, logged.

See Sophos ZTNA →
Detect

Sophos Next-Gen SIEM

The audit log retention CMMC and CPCSC assessors ask for.

See Sophos Next-Gen SIEM →
Recover

N-able Cove backup

ERP, MES and file server backups with immutable copies.

See N-able Cove backup →

A worked example: a manufacturer with two plants

A head office attached to the main plant, a second plant, about 220 staff and an on-premises ERP would typically run:

WhereWhat runs there
Main plant and ERPXGS 3300 HA pair with Xstream, Sophos Endpoint, MDR Plus, Next-Gen SIEM
Second plantXGS 2300 with Xstream, SD-WAN to the main plant
Plant floor at both sitesOT zone behind the firewall, NDR sensor on each
Integrators and vendorsSophos ZTNA, per system
ExposureManaged Risk scanning the external footprint; Cove backup with a tested restore

Licenses are sold in 1, 2 or 3-year terms or month to month through Nuformat. Hardware is bought outright or as Hardware as a Service. Every quote states the currency.

Get this sized and quoted for your organization

Send us your site list, user count and any questionnaire you have been given. A Nuformat specialist maps the products to it and returns a quote within two to three business days.

Available in Canada and the USA. Sophos Silver Partner.

Frequently asked questions

Why is manufacturing breached through vulnerabilities more than other sectors?

The Verizon 2026 DBIR manufacturing snapshot puts exploited vulnerabilities at 38% of breaches, ahead of phishing at 13%. Plants run long-lived systems and remote-access tools that are hard to patch, which is what attackers scan for. Sophos Managed Risk finds that exposure and the XGS firewall's IPS blocks known exploits while patches are scheduled.

Does Sophos make us CMMC Level 2 compliant?

No product does. Level 2 is the NIST SP 800-171 control set, and it is assessed against your whole environment and your documentation. Sophos provides the technical controls for many of the requirements, including endpoint protection, network segmentation, MFA-related identity monitoring, logging and incident response, and Nuformat maps them to the control numbers.

What is CPCSC?

The Canadian Program for Cyber Security Certification, Canada's counterpart to CMMC for defense suppliers. Level 1 applies to select contracts from summer 2026, with Levels 2 and 3 to follow, harmonized with US requirements.

How do we protect PLCs and CNC machines that cannot run security software?

Put them in their own zone behind the Sophos XGS firewall with only the traffic they need, watch the zone with a Sophos NDR sensor, and give integrators ZTNA access to specific machines rather than a VPN into the plant.

Do you serve plants in both countries?

Yes. Nuformat is a Sophos Silver Partner with offices in Ontario and Texas, quoting in CAD and USD.