It’s 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on: no machine control, no scheduling, no way to see orders or tell customers why.
You have an incident response plan. Now you find out whether it was ever more than a document in a drawer, and if it can save your production.
Never tested? This is where that failure leads.
You’re a manufacturing firm, and because your industry has been the #1 ransomware target for the last five years, you know an attack is likely. You’re still caught unaware when one hits.
Day 1. The line is down and no one has formally declared an incident. IT starts pulling systems offline. Operations keeps asking when production resumes, and gets no answer. No one in the building will make, or believes they can make, the call to take control.
Day 2. You find the incident response plan buried in a folder within a folder. It names an owner who left the organization two years ago. It doesn’t help.
Day 3. Forensics from your cyber insurer arrive and tell you to touch nothing until they’ve scoped the breach. Your backups exist, but no one has restored from them under real pressure, and the first attempt fails. The attacker’s note sets a deadline and a number.
Week 2. You’re running what you can by hand, and shipments are slipping. The first customer asks whether to place next month’s order elsewhere. Legal is still deciding what has to be disclosed, and to whom.
Week 4. Some production is back. Some customers are not, because the ones who found a second supplier during the outage kept it. Your renewal quote lands higher than last year with new conditions attached. The team that carried the response for a month is spent, and the post-incident review keeps finding the same root cause: the plan named steps, but no one had ever run them together.
But what if you had an IR plan that has proven, tested capabilities?
We worked with a manufacturer that lived through the same attack, but their approach was different.
Weeks after being acquired by a larger parent, ransomware hit one of their facilities and halted the entire manufacturing process. Production of consumer goods stopped. Revenue fell by roughly $100,000 a day. The ransom demand was $3 million.
What they didn’t do was negotiate from weakness.
Day 1: They calmly opened up their incident response plan, and followed the tested steps.
From Day 1: The small IT team worked around the clock on two fronts at once: supporting the cyber insurer’s forensics team, and standing up a clean, segmented environment to run production from.
From Day 1: The executives ran communications to consumers, customers, regulators, and suppliers, working alongside legal counsel, ransom negotiators, and a PR team.
The strategy was to slow-play the attackers, buy time, and refuse to pay.
End of Week 1: They had rebuilt a secure, segmented environment and brought production back. They never paid the ransom.
Without the ability to recover into an isolated environment, the choice would have been to pay the $3 million or absorb fines and reputational damage that would have cost more.
Because the capability was there, they had a third option to keep production moving.
The attack was the same. The plans on paper may well have looked alike. The difference was capability, built before the incident rather than improvised during it.
Three things separated the week from the month:
1. A recovery environment they could switch to
Backups on their own don’t restore a business (because remediation is not the same as readiness). A clean, segmented environment, ready before it was needed, gave them somewhere to run production while the original systems stayed quarantined for forensics.
2. A cross-functional response, not an IT one
IT rebuilt. Executives owned customer and regulator communications. Legal owned disclosure. Negotiators bought time. Everyone understood their role before the incident, not during it.
3. Decision authority settled in advance
No one lost ninety minutes working out who could refuse the ransom or halt the line. The calls that cost the unprepared manufacturer days were already assigned.
None of that gets written into existence the night the line goes down. It’s either built ahead of time, or it isn’t there when you reach for it.
The distance between one week and four weeks isn’t luck, and it isn’t the size of your IT team. It comes down to what you built before the attack arrived.
Most manufacturers don’t know which timeline they’d get, because they’ve never run the plan against a real scenario. They’ve never considered the difference between an IR plan and a tested capability, or worked through what losing every system would cost them.
The Manufacturer’s Guide to Operational Resilience breaks down the full cost of an incident and includes a self-assessment scorecard you can run today.
Or, our free Resilience Readiness Workshop gives you an honest read on where you stand across the six operational dimensions that decide it, from governance through testing, in 60 minutes.
Risk is constant. Ready is a choice. The only way to know which version of the shutdown you’d face is to find out before the attacker does.
Book a time today and see what your response would be.
Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.
Because while risk is constant, ready is a choice.
You've been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers...
Read more
You passed the audit. The certificate went up on the wall. The consultant packed up, the engagement closed out,...
Read more
It's 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on:...
Read moreLet’s help Plan, Build and Run your cyber and AI programs to keep your business capable, compliant, and resilient. Because while risk is constant, ready is a choice.