When the factory floor becomes the front line

Posted on 22 Sep 2026 by The Manufacturer
Company: Ricoh

There is something to be said about a piece of industrial machinery that has been running without interruption for 25 years. It speaks to the quality of the engineering behind it. But that same longevity is now presenting manufacturers and essential service operators with a security problem they were never prepared to face.

Over seven years building Ricoh’s cybersecurity practice, I have seen some of manufacturing’s most persistent gaps. One has widened faster than most people could have predicted.

Many operational technology (OT) environments have sat untouched for years, sometimes decades. They are now starting to be exploited by threat actors, and quite often the people responsible for them are not IT professionals. They are machine room operators and facilities managers focused on keeping operations running. Cybersecurity was never part of their job description, and that imbalance sits at the heart of a growing problem.

The legacy problem no one planned for

Operational technology in today’s factories and facilities was built to a different standard, in a different era. Programmable logic controllers, industrial control systems and SCADA environments were engineered for reliability and availability – not for a world where connectivity would arrive long after the machines were already bolted down. Many still run on obsolete operating systems that are no longer supported, such as Windows XP, and cannot easily be patched. Others support round-the-clock production; pulling them offline, however briefly, impacts output and profitability.

The technology, in most cases, has done exactly what it was built to do. The problem lies in what has been layered around it since. Remote access, cloud connectivity, integration with enterprise IT systems, third-party supply chain connections have arrived gradually, often for legitimate operational reasons. But each new connection presents a potential route in for malicious actors.

Attackers understand this. An organisation breached through its outdated or unpatched operational systems may find that a data breach is the least of its worries. The larger threat is losing access to production altogether.

At Ricoh, our starting point is to understand the operational environment before recommending changes. That means identifying what is connected, how systems communicate and where risks sit. From there, passive monitoring can build visibility without disrupting production; secure remote access can replace unmanaged connections; and a digital twin can provide teams a separate environment in which to test changes and simulate attacks safely.

When IT problems become OT consequences

The Jaguar Land Rover experience illustrates how an attack on an IT network can cascade directly onto the factory floor. If an OT network is properly segregated, production facilities would have more resilience. But OT environments are often designed around the function they deliver – keeping production lines moving, treating water, running hospital wards – with IT connectivity integrated afterwards. When that connectivity becomes a route into the operational environment, the danger is that an incident which begins in IT does not necessarily stay there.

The organisations facing the most acute version of this challenge are not necessarily the largest or best funded. The bigger manufacturers around the world have resources to respond. I am more concerned about smaller manufacturers, food production facilities and water treatment plants – operations where the machinery is critical and IT security resource is limited. These are environments where the machinery does something more important than the technology connected to it, and that is exactly what makes them vulnerable.

Three priorities for securing connected operations

For organisations working through this, the response comes down to three priorities: knowing what is connected, protecting it within operational constraints, and testing whether defences actually hold.

The first is harder than it sounds. In complex industrial environments, teams may have only a partial view of which devices are on the network, how they communicate, or where the IT and OT boundary actually sits. Passive network scanning – monitoring traffic without interacting with live systems – can surface that picture without risking disruption to operations. Yet in many environments, there has never been a full assessment of what is connected. Without that baseline, it is impossible to know where an attacker might find a way in.

The second priority is building protection that fits the operational reality. In IT security, patching or wholesale replacement is standard practice. In OT security, it’s rarely a realistic option. The focus should instead shift to controlling the routes into and out of the OT environment: restricting unnecessary communication between systems, placing rigorous controls around third-party remote access, and monitoring how data moves between the production environment and the wider business.

Third-party access, in particular, merits a closer look. When specialist engineers need to work on machinery, the traditional approach has often been to send someone on site with a laptop or USB drive. That access requirement may be legitimate, but an external device can introduce malware or a virus into the OT network. Organisations may have limited visibility of what is being connected and whether that device has been compromised. The answer is not to ban access but to make it structured, controlled, authenticated, and logged.

The third priority is validation. Security configurations drift, new technology gets connected, and what looked secure six months ago may now carry attack surfaces that did not previously exist. Testing defences without touching live systems is how organisations can stay confident that their controls are holding. This is where digital twin technology comes into its own. A virtual replica of the OT environment lets teams simulate attacks and test configuration changes with no risk to production. When taking systems offline is not an option, simulation offers a safer way to test.

Shared responsibility is non-negotiable

None of this works if the ownership stays within one team. Historically there has been a clear divide: operational teams managed the machinery on the production floor, while IT teams managed the network. When something went wrong, it was a matter of pointing at each other. That model no longer holds.

There is more awareness now that these two worlds need to collaborate seamlessly, because what happens in one can affect the other. Security, IT and operational teams each hold part of the picture. The ones that bring those perspectives into the same room, before an incident forces the conversation, are the ones best placed to weather what comes next.


Steve Timothy

Steve Timothy is Cyber Security Specialist Director at Ricoh UK. With 30 years of experience in sales, business leadership, and cyber security, he joined Ricoh UK over 7 years ago with the goal to set up a dedicated cyber security practice. He built out the capability portfolio needed to support a strong offering to customers with a heavy focus on innovation.


For more articles like this, visit our Digital Transformation channel.