SURVEY: Manufacturers Get Tough on Cybersecurity

More companies are taking a disciplined approach to dealing with the growing threat of cyber attacks, a new MLC survey finds.

The message has been received.
After years of mounting warnings about the risks of being hacked or worse and now faced with a sharply rising number of cyber attacks in the industry, manufacturers have taken concrete steps to fortify their defenses and protect themselves against what is widely assumed will be an even larger threat in the years ahead.
More manufacturers than ever before have put in place formal cybersecurity plans in their companies to deal with threats and attacks. They are significantly increasing their levels of confidence that they have the internal expertise in place to deal with cybersecurity issues. And a majority of companies now have dedicated cybersecurity budgets, including provisions for cyber insurance, and are providing cyber awareness and technical training to their employees.
These are some of the most important findings of the Manufacturing Leadership Councilโs new survey on cybersecurity. More than 160 companies expressed their views on cybersecurity strategy in their organizations, whether they have been attacked and what the nature of those attacks were, what measures they have adopted to defend themselves, and how the growing problem of cybersecurity may be affecting their adoption of Manufacturing 4.0 and their transition to the digital model of manufacturing.
Formal Planning Takes Off
A sea change in how seriously manufacturers consider the cyber threat has occurred at the strategy level. Just four years ago, according to MLCโs 2018 cyber survey, barely one-third of manufacturers had devised and adopted formal cybersecurity plans that encompassed their plant floors. Today, the new MLC survey shows that nearly 62% have put such plans in place (Chart 1).
The more serious attitude is directly related to the perceived consequences of cyber attacks. When asked how important cybersecurity is as a business issue, 83% of survey respondents said it is of high importance, compared with 66% saying so in 2018. Moreover, 64% said this year that business disruption is the most significant cybersecurity-related risk to their companies, compared with 58% in 2018. Interestingly, very few fear equipment or product damage from cyber attacks and only 18% this year are worried about the theft of proprietary information (Charts 2,3).
Bolstered by the greater focus on formal planning and now regular awareness and technical training for employees on cybersecurity, a growing number of manufacturers feel confident that they have the internal expertise to deal with manufacturing-related cyber issues. This year, nearly 40% of survey respondents said they had a high level of confidence about their internal expertise, compared with 25% saying so in 2018. Another 46% assessed their confidence levels as moderate this year (Chart 4).

Mobile devices, e-mail servers, and laptop computers were cited by respondents as having the highest level of cyber vulnerability โ not plant floor equipment or plant floor control systems. Looked at from a business function or activity perspective, a similar dynamic โ vulnerabilities caused by external connections โ was revealed in the survey data. Social media networks, partner and distribution networks, and supply chain networks were the most cited points of vulnerability โ not plant floor networks, design and innovation networks, or field service operations. In addition, respondents said their best protected systems are their ERP and MES systems.
What these findings suggest is that, as manufacturers go about forging so-called business ecosystems of partners, suppliers, and customers that are increasingly digitally connected, they will have to extend existing cyber strategies and tactics or even create new ones to protect these networks in the future. This is perhaps the next frontier in cybersecurity.

Survey development was led by David R. Brousell, with input from the MLC editorial team and the MLCโs Board of Governors.