Manufacturing under fire: what the latest Clusit data tells us
Italian manufacturing absorbed 18.4% of all known cyber incidents in the country during the first half of 2026, making it the single most targeted sector in the national economy. More striking still, 91% of those attacks were classified as high or critical impact. The figures, presented by Clusit at the Security Summit, point to an uncomfortable conclusion for anyone running a factory floor: NIS2 compliance alone will not make your business resilient. Industrial cyber security requires something more than a checklist.
For European SMBs, and particularly for the thousands of small and mid-sized Italian manufacturers that form the backbone of the country’s export economy, this matters enormously. These are companies with sophisticated production lines, tight margins, and IT teams that are often two or three people. They are now facing the same threat actors that target multinationals, but without the same defensive budget.
The gap between regulatory compliance and operational resilience is where most of the damage happens. A company can tick every box in its NIS2 documentation and still lose three weeks of production to a ransomware incident that started with a compromised remote maintenance account.
Why manufacturing became the preferred target
Attackers follow money and leverage. Manufacturing offers both in abundance. A production line that stops costs money by the hour, which creates enormous pressure to pay a ransom quickly rather than rebuild from backups over several days.
There is also a structural weakness that attackers understand well. Industrial environments run on operational technology (OT) that was designed for reliability and longevity, not for security. A PLC installed in 2011 may still be running perfectly and will likely run for another decade, but it was never built to resist an attacker with network access.
Then there is the supply chain angle. Small component suppliers are frequently the entry point into much larger customers, which makes them disproportionately attractive targets. An attacker who compromises a 40-person machining shop may be using it as a stepping stone toward an automotive group three tiers up.
The 91% high-impact figure reflects this reality. When an attack lands in a manufacturing environment, it rarely stays contained to a single workstation. It spreads into the systems that keep machines running.
NIS2 sets the floor, not the ceiling
The NIS2 Directive is a genuine step forward. It extends cyber security obligations to far more organisations than the original NIS, brings manufacturing explicitly into scope for many product categories, and introduces real accountability for management bodies. In Italy, transposition through Legislative Decree 138/2024 has already put thousands of companies into ACN registration obligations, with the main technical implementation deadlines running through October 2026.
But the directive is written as a risk management framework, not as a technical blueprint. It tells you that you must have incident handling procedures, business continuity measures, supply chain security policies, and appropriate cryptography. It does not tell you how to segment a network where a robotic cell shares a flat VLAN with the office printer.
This is the core of the Clusit warning. Compliance produces documents, and documents do not stop lateral movement. A company can pass a compliance review in spring and be offline in autumn because the gap between “we have a policy” and “the policy is implemented on every subnet” was never closed.
What NIS2 actually requires of Italian SMBs
If your company has more than 50 employees or more than 10 million euro in turnover and operates in a listed sector, you are probably in scope as either an essential or important entity. Manufacturing of machinery, electrical equipment, motor vehicles, medical devices, computers, and chemicals all appear in the annexes.
The obligations that most affect day-to-day operations are incident notification (an early warning within 24 hours, a full notification within 72), management accountability (directors can be held personally responsible), and supply chain security assessment of your own suppliers. Penalties for essential entities can reach 10 million euro or 2% of global turnover.
Our team works with manufacturers on exactly this transition, and you can read more about our approach to NIS2 compliance and what the directive means in practice for a mid-sized industrial business.
How to secure an industrial OT network: practical steps
Resilience is built through architecture and habit, not paperwork. The following measures deliver the most protection per euro spent for a typical SMB manufacturer, and none of them require a security operations centre of your own.
Start with visibility
You cannot protect what you cannot see. Most industrial companies discover, when they finally run a proper asset inventory, that their OT network contains 20 to 40% more connected devices than anyone believed. Old engineering laptops, forgotten test rigs, vendor gateways installed years ago and never removed.
Passive network monitoring tools designed for industrial protocols can map this without disrupting production. They listen rather than scan, which matters when an aggressive scan can knock an older PLC offline. Getting a complete, accurate asset list is genuinely the first step, and everything else depends on it.
Segment the network properly
Flat networks are the single biggest contributor to high-impact incidents in manufacturing. If your ERP server, your office laptops, and your production cells all sit in the same broadcast domain, one phishing click can reach the shop floor in minutes.
The reference model here is Purdue-style segmentation, or its modern equivalents: a clear boundary between enterprise IT and industrial OT, with a demilitarised zone in between where data historians and remote access jump hosts live. Traffic crossing that boundary should be explicitly allowed, logged, and limited to specific protocols and destinations.
For an SMB, this does not mean buying a six-figure industrial firewall platform. It often means correctly configuring VLANs and access control lists on hardware you already own, then adding one properly sized firewall at the IT/OT boundary.
Control remote access from vendors
Machine builders and maintenance contractors need remote access, and this is where a very large share of industrial intrusions begin. Permanent VPN tunnels with shared credentials, cellular modems fitted directly to machines, and always-on TeamViewer installations are all common and all dangerous.
Replace these with brokered access: a single controlled gateway, individual named accounts, multi-factor authentication, sessions enabled on request rather than permanently, and full session recording. Your machine supplier will adapt. Most of them already support this model for larger clients.
Test your recovery, not just your backups
Backups that have never been restored are hypotheses, not safeguards. For OT specifically, you need more than data backups: you need current PLC programs, HMI configurations, drive parameters, and engineering workstation images stored offline.
Run a restore test at least twice a year, and time it. If bringing a production cell back from a clean state takes eleven hours and your recovery time objective claims four, you have found a problem worth fixing before an attacker finds it for you.
Train the people who touch the machines
Awareness training designed for office workers rarely lands with maintenance technicians and line supervisors. Build short, concrete sessions around the scenarios they actually face: a USB stick left by a contractor, a phone call from someone claiming to be from the machine vendor, an unexpected request to disable a safety interlock.
Building a realistic programme for a European SMB
The companies that handle incidents well are not the ones with the largest budgets. They are the ones that decided in advance who does what.
A workable twelve-month plan for a mid-sized manufacturer looks something like this. In the first quarter, complete the asset inventory and confirm your NIS2 scope and ACN registration. In the second, design and begin implementing network segmentation, starting with the IT/OT boundary. In the third, rebuild vendor remote access and run your first full restore test. In the fourth, run a tabletop exercise with the management team and refine the incident notification workflow so the 24-hour deadline is achievable at three in the morning on a Sunday.
Ongoing operational support matters as much as project work. Having a reliable help desk service that understands both the office environment and the production floor closes the gap between an anomaly being noticed and being investigated, and that gap is often measured in days.
The broader point from Clusit deserves repeating. Regulation raises the baseline across the European market, which is valuable, but it is a floor. Resilience is an operational property of your business: how quickly you detect, how well you contain, how fast you restore. Those are engineering questions, not legal ones.
If you want to understand where your own environment stands, a structured assessment against both NIS2 requirements and real operational risk is the right starting point. Our cybersecurity services are built around that combination, because passing an audit and surviving an attack are two different achievements, and only one of them keeps your machines turning.