Operational technology that cannot be patched, sites reached by satellite, and safety systems that must never be touched by an attacker. Sophos sized for resource operators in Canada and the United States. Sophos Silver Partner. Offices in Markham, Ontario and Dallas, Texas. Quotes in CAD and USD, shipping to Canada and the United States. What the breach data says about this sector. Every figure links to its source at the foot of the page. Verizon does not publish a mining snapshot; the manufacturing figure is the nearest industrial benchmark and the others are all-industry 2026 DBIR baselines. The same four stages appear in nearly every breach. Each stage below shows what it looks like in this sector and the control that breaks the chain. Attackers do not need to reach the PLCs. Encrypting the IT side, the historian and the fleet systems is enough to halt a shift. A flat network between the office and the process control system is the most common finding on a mine site. Low bandwidth and high latency rule out heavy agents and constant cloud round-trips. Detection has to be local and efficient. Drilling, blasting and maintenance contractors bring their own laptops and remote-support tools. Ventilation, gas monitoring and tailings sensors must be isolated and monitored, never scanned or patched casually. The rules and expectations that shape a security purchase in this sector, in both countries. Status is as of September 2026; check the linked source before relying on a date. Each product is tagged with the NIST Cybersecurity Framework 2.0 function it serves, so the list can go straight onto a questionnaire. Zones between corporate, OT and contractor networks; rackmount at the mill, desktop at remote camps; SD-WAN over satellite and LTE. Passive detection on the OT segment: new devices, unusual protocols, lateral movement, with no agent on the equipment. 24/7 analysts for sites with no security staff and shifts around the clock. Contractor and vendor access to one system at a time, logged and time-limited. Industrial-grade PoE switching and Wi-Fi for camps and workshops, managed centrally. IT systems and the historian backed up off site over the available link. A head office, a mill and a remote camp, about 300 staff and 80 contractors, would typically run: Licenses are sold in 1, 2 or 3-year terms or month to month through Nuformat. Hardware is bought outright or as Hardware as a Service. Every quote states the currency. Send us your site list, user count and any questionnaire you have been given. A Nuformat specialist maps the products to it and returns a quote within two to three business days. Available in Canada and the USA. Sophos Silver Partner. Yes. The Sophos NDR sensor watches the OT network passively and reports new devices, unusual protocols and lateral movement. The XGS firewall separates OT from IT so nothing reaches the equipment without a rule allowing it. Yes. The XGS firewall runs SD-WAN over satellite and LTE with failover, and Sophos agents are designed for intermittent connectivity. MDR telemetry is compact; Nuformat sizes the link budget with you. Put contractors on their own network zone with no route to OT, give them ZTNA access to the specific systems they need, and let MDR watch the traffic. No corporate agent has to go on their machines. Mining is not itself a designated sector. Mines that own power generation or rail assets, or that supply designated energy or transportation operators, should expect requirements to flow down through those relationships as regulations are phased in. Yes. Nuformat is a Sophos Silver Partner with offices in Ontario and Texas, quoting in CAD and USD, and ships to remote sites.Cybersecurity for mines, mills and remote resource sites.
The risk in numbers
How an attack unfolds here, and where Sophos stops it
What is at risk in mining
Ransomware that stops production
IT to OT crossover
Remote sites on satellite and LTE
Contractors and vendors on site
Safety and environmental systems
What you have to comply with
Where Rule or expectation What it asks for Both NIST Cybersecurity Framework 2.0 and CISA ICS guidance The reference frameworks lenders, insurers and joint-venture partners use to assess a mine's cyber program, including segmentation and monitoring of control systems. Source Canada Bill C-8, Critical Cyber Systems Protection Act Royal Assent June 16, 2026. Energy and transportation operators are designated sectors; mines that own power or rail assets, or supply designated operators, will see requirements flow down. Source Canada Provincial mine health and safety regulations Safety-critical control systems fall under provincial mining safety rules; cyber changes to them need the same change control as any other. Source Both Insurer and lender requirements Project finance and property insurance increasingly require OT segmentation, monitoring and an incident response plan. Source The Sophos stack for mining
Sophos XGS firewall
Sophos NDR
Sophos MDR Plus
Sophos ZTNA
Sophos switches and AP6
N-able Cove backup
A worked example: a mine with a head office and two sites
Where What runs there Head office XGS 3100 with Xstream, Sophos Endpoint, MDR Plus Mill XGS 2300 with Xstream, IT and OT zones, NDR sensor on the OT segment Remote camp XGS 128 with Xstream over satellite, 5G failover where available Contractors Sophos ZTNA, per system, time-limited IT systems and historian Cove backup with a tested restore Get this sized and quoted for your organization
Frequently asked questions
Can Sophos protect control systems without installing anything on them?
Does Sophos work over satellite links?
How do we handle contractor laptops on site?
Does Bill C-8 apply to a mine?
Do you serve operators in both countries?
Industries · Mining and resources · Canada and USA
In plain terms: A mine's IT network is the easy part. The hard part is the operational side: crushers, conveyors, ventilation, fleet management and process control, running on equipment that was installed for a 20-year life. The defense keeps IT and OT apart, watches the OT side without touching it, and works over a slow link.
31%
of breaches began with an exploited vulnerability (all industries)
Verizon 2026 Data Breach Investigations Report
48%
of breaches involved ransomware (all industries)
Verizon 2026 Data Breach Investigations Report
48%
of breaches involved a third party (all industries)
Verizon 2026 Data Breach Investigations Report
61%
of manufacturing breaches involved ransomware, the closest DBIR industrial benchmark
Verizon 2026 DBIR
1Entry
What happensContractor laptop or an exposed remote-support tool
What stops itXGS firewall with IPS; ZTNA for vendors; ITDR
2Foothold
What happensAn office PC or the historian server
What stops itSophos Endpoint on IT systems
3Spread
What happensToward the OT network
What stops itFirewall zones between IT and OT; NDR sensor on the OT segment sees any crossing
4Impact
What happensProduction halt, safety risk
What stops itMDR Plus responds 24/7; Cove restores IT systems; OT stays isolated
Protect
Detect
Respond
Protect
Protect
Recover

