Manufacturing
Your production line should never share a network with your email
Here is a pattern we see walking into Australian factories, and it should scare you more than it does:
The CNC machines, the PLCs, the weighbridge, the pick-and-pack system, all sitting on the same flat network as reception’s PC, the sales team’s laptops, and the free wifi in the lunchroom.
Everything can see everything. Which means the day someone in accounts opens the wrong attachment, the ransomware does not stop at the office. It walks straight onto the factory floor and turns your production line into very expensive furniture.
Why production systems are different
Your office IT and your operational technology (OT) live by different rules, and treating them the same is where the trouble starts.
Office systems get patched constantly. Windows updates monthly, browsers weekly. Annoying, but routine.
Production systems often cannot be patched at all. That machine controller might run software the vendor certified once, on an operating system from a decade ago, and any change voids the support agreement or risks the calibration. It is not lazy IT. It is how bespoke industrial systems work. The machine is the asset; the computer bolted to it is just its nervous system.
So you have a machine that must keep running, cannot be updated, and was never designed with hostile networks in mind. Put that on the same network as email and web browsing, the two front doors for nearly every attack, and you have built a bridge from the internet to your production line.
The fix is segregation, and it is not exotic
Network segregation means your OT lives in its own protected zone. The concept is old, the execution matters:
Separate the zones. Production systems on their own network segments, invisible to and unreachable from the general office network. If the office gets infected, the floor keeps running. That is the entire point.
Control the crossing points. Some data must cross, production output into your ERP, job data down to the floor. Those crossings go through controlled, monitored gateways that allow exactly what is needed and nothing else. Not “the ERP can see everything”, but “this system can send this data to this destination”.
Give vendors a door, not a key to the house. Machine vendors need remote access for support, and this is where many setups quietly fall apart: a TeamViewer install here, an old VPN account there, each one a permanent unguarded entrance. The right pattern is brokered, time-limited, logged access to the specific machine, switched on when support is happening and off when it is not. Your vendor still gets their access. You still get to sleep.
Watch the OT zone separately. You cannot run normal security agents on a 15-year-old machine controller, but you can watch its network behaviour. When a PLC that has talked to the same two systems for five years suddenly tries something new, someone should know within minutes.
”Our machine vendor handles that”
They handle the machine. Ask them directly who is responsible for the security of its network connection, and listen carefully to the answer, because it is usually some version of “not us”.
This is the gap DJC exists in. We support manufacturers across both worlds: the corporate IT that runs your business and the boundary that protects your production systems, coordinating with machine vendors instead of pointing fingers at them. Because we build software and integrations as well, we can also connect your floor data to your business systems properly, through the controlled gateways, rather than via somebody’s USB stick.
On the security side we are certified to SMB1001 Diamond, the top tier of Australia’s SMB cyber standard, along with ISO 27001 and ISO 9001. Worth checking on whoever currently looks after your factory network, because plenty of providers will advise you on a standard they have never been assessed against themselves.
What this costs you if you skip it
When ransomware reaches a production environment, you are not restoring laptops. You are re-certifying machinery, coordinating several vendors’ recovery procedures, and losing production the entire time. Recovery is measured in days, not hours, and every one of those days is output you never make up.
You already know what an hour of stopped line costs you better than any published benchmark does. Run that number against a few days and you have the business case.
Segregation, by contrast, is mostly design and discipline. It is some of the highest-return security spend a manufacturer can make.
Book Your Free Security Gap Check: 30 minutes with a DJC director. We will look at how your production and corporate networks currently relate, where the gaps are, and what fixing them actually costs. You keep the roadmap.