60% of manufacturing enterprises worldwide expect to fully transition to digital technologies within the next two years — today, only 9% consider themselves fully digital. This is shown by the results of a joint study* by Kaspersky and VDC Research.
Why digitalization for manufacturing. Respondents named the following main goals of their digital transformation strategy:
• increasing production volumes or efficiency (24%);
• reducing operational or production costs (15%);
• opening new strategic opportunities (14%);
• improving cyber resilience (13%).
As a result of digitalization, production equipment, conveyors, and operations at an enterprise depend on the operation of industrial automation systems, production management, and technological data storage (MES, SCADA, Historian). Factories are turning into cyber-physical systems in which software failures can slow down conveyors or even stop production entirely.
The same integrated systems that increase enterprise efficiency, including production process management systems (MES), industrial internet of things (IIoT) sensors, automated material transport systems, and remote access for engineering personnel, directly affect whether production runs without interruption.
What cyber incidents lead to. As industrial environments transform into cyber-physical systems, information security (IS) risks cease to be exclusively an IT problem and can become a direct source of financial losses. In integrated environments, digital failures affect not only data — they can lead to unsafe operations, product defects, and production stoppages, reduce overall equipment effectiveness, create additional burden on personnel, and disrupt supply chains. This means that cybersecurity must be considered a key component of operational resilience.
Almost 60% of manufacturing companies estimate damage from cyber incidents at more than one million dollars per incident, with the average downtime lasting 15.3 hours. The most significant losses are often associated with production stoppages, failure to meet supply obligations, and penalties, rather than just incident analysis costs.
Mature IS management systems include ensuring the security of production infrastructures. Particular attention is paid to how quickly operations can be restored after an incident, how well the backup and recovery process is organized, how legacy systems are secured, and whether a fail-safe mode is configured that preserves key safety functions but reduces overall performance or disables secondary options. Such consistency ensures that cybersecurity contributes to production continuity and resilience, rather than merely complying with IT requirements.
Nevertheless, unresolved problems remain due to fragmented responsibility. In most cases (59%), IT departments are responsible for managing security policies at production facilities. They often do not take into account the real conditions at production sites. The need to manage multiple security tools (44%) and problems with installing patches for technological systems (38%) indicate that cybersecurity must be integrated into the daily work of production, engineering, and instrumentation and automation services. Only in this way can operational reliability be effectively improved and protection against constantly changing threats be ensured.
"As production environments become increasingly interconnected, the focus in cybersecurity is shifting from simply adding layers of protection to ensuring the availability, resilience, and integrity of production processes. The goal is to minimize the impact on production activities and accelerate recovery, not just prevent intrusions. Kaspersky offers a unified ecosystem that combines protection for IT, OT, and the internet of things, allowing the manufacturing sector to safely undergo digital transformation. This strategy helps maintain production continuity and reduce long-term cybersecurity costs," comments Andrey Strelkov, Head of Industrial Security Product Development at Kaspersky.
Kaspersky offers industrial enterprises a platform approach that combines specialized protection technologies as well as the experience and knowledge of experts. Its key component is the native XDR platform Kaspersky Industrial CyberSecurity (KICS). It provides comprehensive security for production infrastructure and offers capabilities such as incident response, centralized asset management, audit and risk assessment, and allows scaling protection in complex distributed environments.
