On this page
Share
Link copied
Summarise this article with AI Short on time? Open this page in your assistant of choice and it will read the article and summarise it for you.

The Engineering Network published figures this week that are worth reading twice. 1.84 million ransomware attempts on UK industrial facilities in five months. Shop floor intrusions already running 28% ahead of the total for all of 2025. And almost all of it, 1.79 million attempts, concentrated on just two monitoring sensors.

That last number is the one that matters. It tells you this is no longer scattergun. Attackers have worked out which plants lose the most money when a line stops, and they are pointing their effort at those specific targets. A manufacturer running four machines at 90% utilisation with a fortnight of committed orders is not a random victim. It is a business with a very clear number attached to every hour of downtime, and the people running ransomware campaigns understand that number as well as you do.

So the question stops being “are we a target” and becomes something more practical. Where does your production data actually live, and what happens to it on the worst day?

The systems being targeted are the ones keeping production running

Ransomware crews are not chasing your marketing site. They are going for the systems that stop the shop floor: the server in the corner of the office, the on-prem MES box that has not been patched since it went in, the domain controller, and the backup drive that sits on the same network as the thing it is supposed to protect.

That last one does most of the damage. If your recovery point is reachable from the same network as the machine that got infected, it is not really a recovery point. It is another file the attacker encrypts on the way through. Plenty of manufacturers only discover this at the moment they need the backup, which is the worst possible time to find out.

On-prem is the easy target, and it is not the IT team’s fault

A flat factory network means one infected laptop can reach the file server, the domain controller and the backup drive in a single afternoon. Patching means downtime, and downtime means missed delivery dates, so patching gets pushed to the next quiet window that never quite arrives. Remote access was set up quickly during a shutdown and never tightened afterwards. Logins are shared because it was faster than setting up individual accounts.

None of that is a criticism of the people running it. In most UK SMEs the person responsible for IT security is also responsible for the network, the phones, the CAD licences and whichever machine has stopped talking to the network this morning. Security depends on a team that is already stretched thin keeping production going. Given the choice between patching a server and getting a line running again, everyone picks the line. That is the right call in the moment and it is exactly how the gap opens up.

Properly secured cloud changes the maths

Cloud is not magic. A badly configured cloud tenancy is just as exposed as a badly configured server room, and anyone who tells you otherwise is selling something. What changes is how the responsibility splits, and that split genuinely helps a manufacturer of 10 to 200 people.

Infrastructure gets patched continuously by a team whose only job is patching infrastructure, rather than at the next scheduled downtime window. Data is versioned and backed up away from the production environment, so an attacker who reaches your shop floor system cannot delete the recovery point in the same move. Access runs on identity and permissions rather than on whoever happens to be plugged into the same switch, which means removing an ex-employee’s access is one action instead of a hunt through shared credentials.

None of those are exotic security measures. They are the basics. The difference is that in a cloud platform they are somebody’s full-time job instead of an item on a list that never gets to the top.

What this looks like in DynamxMFG

That is the model DynamxMFG is built on. Your work orders, your BOMs, your tracking data, your traveller sheets sit in a platform that is patched and monitored by a dedicated team, not bolted onto a server that is also running your CAD licences and your email. Every user connects through managed authentication rather than a shared login taped to a monitor, so you know who did what and you can revoke access in seconds.

We applied the same thinking to Dynamx AI Assist. It answers questions about your production data without that data leaving the platform. No export, no spreadsheet copy sitting in someone’s downloads folder waiting to be found.

Deployment matters here too. A 90-day go-live means you are not spending 18 months half-migrated, running the old unpatched box alongside the new system and doubling your exposure while you wait.

The parts that are still on you

Cloud hosting does not remove your obligations. Multi-factor authentication still matters. Sensible user permissions still matter, particularly the habit of giving people access to what they need rather than everything by default. A real incident response plan, one that somebody has actually read, still matters. So does knowing which of your suppliers and customers you would need to call, and how, if your systems went dark on a Tuesday morning.

What changes is who carries the weight of getting the underlying infrastructure right. Instead of one stretched IT team defending a factory network alone, you have that team plus a platform provider whose entire business depends on keeping the system patched, backed up and monitored.

1.79 million of those attempts were aimed at two sensors on purpose. The manufacturers worth attacking are the ones running production on infrastructure nobody has had time to secure. That is a fixable problem, not a fact of life.

Book a 15-minute demo to see how DynamxMFG runs production without leaving it exposed.

Related reading

Written by Tom Drury

Part of the Total Control Pro team, helping UK SME manufacturers get real-time control of their shop floor.

See it running on your own shop floor data

A 30 minute call, a live look at DynamxMFG, then we configure it on your data and show it back to you.