back to list

Data Loss, an Industrial Disaster

Introduction: From Physical Catastrophes to Digital Crises

Industrial disasters have traditionally meant explosions, spills, or safety incidents on the plant floor. Today, however, mid-sized manufacturers and food & beverage companies face a new kind of threat that is just as crippling yet invisible: the loss or compromise of data.

How has the manufacturing sector been affected by ransomware attacks?

The median cost of a manufacturing ransomware attack is now around $500,000, and total recovery expenses are often higher. Manufacturing companies have recently become a hot spot for ransomware attacks. The manufacturing sector accounted for 65% of all industrial ransomware incidents in 2022 [1], by far the most targeted industry. Attackers know that manufacturers can’t tolerate long periods of downtime and are often on older on prem, vulnerable systems. Between 2018 and 2024 there were at least 858 known ransomware incidents against manufacturers, causing an estimated $17 billion in combined downtime and lost business [2].

The frequency and price tag of these attacks are climbing, 2023 saw nearly 200 ransomware strikes on manufacturing organizations alone. A single attack can be devastating. On average, each ransomware incident in manufacturing cost about $1.9 million per day in lost production and recovery expenses [3]. Some unlucky plants were offline for weeks, racking up tens of millions in losses. Even when companies do pay the ransom, it’s not a quick fix guarantee. In fact, the median ransom demanded from a manufacturing firm is now around $500,000, yet caving to hackers demands often leads to a costly journey of restoring systems and cleaning up corrupted data.

What makes manufacturing such a ripe target?

Many plants rely on a mix of older operational technology and newer IT systems, creating a broad attack surface. If a single engineer’s PC gets phished, attackers can leapfrog into plant controls or an ERP database and paralyze both production and enterprise operations.

On-Premise Systems: Ticking Time Bombs of Vulnerability

Many mid-market manufacturers still run on-premise ERP and plant software that are now aging and vulnerable. Legacy systems, from outdated Windows Server machines to older versions of ERP platforms, can have serious security flaws. Over time, vendors stop releasing patches for older software, and internal IT teams often hesitate to apply updates (for fear of breaking customizations or creating more issues) even when patches exist. This results in an accumulation of unpatched vulnerabilities that hackers know how to exploit.

Attackers actively scan for companies running legacy software or outdated Windows OS versions as easy entry points. For example, the infamous WannaCry malware spread rapidly by exploiting an old Windows vulnerability, and it was especially damaging to organizations that hadn’t upgraded from Windows 7 or XP. Running unpatched, or end-of-life software is the digital equivalent of running machinery without guards. Manufacturers must treat patching and modernization as essential maintenance. Ignoring those server update prompts could be as dangerous as ignoring a frayed wire on the shop floor. Often no patches and updates are available to systems that are off main stream support. Upgrading to newer OS versions can be an issue as well as the older business systems may not work on later versions of server operating systems.

How can a cloud based solutions help mitigate malware attacks?

One of the most effective steps in improving security is a secure cloud-based ERP platform. As someone who works with Microsoft Dynamics 365 Business Central (a cloud ERP tailored for mid-sized companies), I’ve seen how it fundamentally reduces the risks we’ve discussed. Here’s how modern cloud ERP solutions like Business Central act as a safeguard:

  • Automatic Backups & Rapid Recovery: In Business Central online, your data is automatically backed up continuously; with full backups daily, incremental backups as frequently as every 5 minutes, and point-in-time restore available for up to 28 days [4].
  • Geo-Redundancy and Uptime Resilience: Cloud ERP runs on globally distributed data centers. For example, Business Central data is hosted on Microsoft Azure, with automatic geo-redundant storage and replication to a secondary region. That means even if one Azure region has a major outage or disaster, your systems can fail over to another region with minimal data loss (usually just a few minutes of transactions at most).
  • Robust Access Control (Identity & Permissions): Cloud ERPs like Business Central enforce modern security for logins and user access. Business Central can integrate with Microsoft Entra ID (Azure Active Directory) for authentication, and govern users by role-based access control (RBAC), so each person only sees and does what their job role requires.
  • Continuous Monitoring and Audit Trails: A modern cloud ERP provides a detailed audit trail of user activities and changes. Every posting action is logged in Business Central, creating a timestamped record of who did what.
  • Data Encryption and Compliance: In a secure cloud ERP, your data is encrypted at rest and in-transit by default. Business Central uses technologies like Transparent Data Encryption to scramble the database contents on disk, so even if someone somehow obtained the raw files, they couldn’t read your information. Furthermore, Microsoft’s cloud meets rigorous compliance standards (GDPR, ISO 27001, etc.), meaning the system’s security controls and privacy measures are audited and up to international benchmarks. Essentially, a cloud ERP is designed with security as a core feature, not an afterthought.


Adopting cloud ERP doesn’t eliminate the need for cybersecurity hygiene, after all no system is 100% immune to attack or failure. You still need strong policies, and employee training (especially about phishing and AI data sharing). But it significantly reduces the likelihood that a single vulnerability or hardware glitch will lead to catastrophic data loss.

Are you treating your systems and their data as the critical asset they are?

For mid-sized manufacturers and F&B companies, it’s time to elevate data security and integrity.

CFOs and CIOs should look at their current operations and ask themselves: are we treating our data as the critical asset it is? This means making cybersecurity a part of operational risk management.

Finally, strongly consider leveraging modern technology platforms that are built with security in mind. Cloud-based ERP solutions such as Microsoft Dynamics 365 Business Central offer a blueprint for resilience with their combination of automated backups, access control, encryption, and audit capabilities.

Treating data integrity and cybersecurity as core priorities is about basic business survival and success. In manufacturing, we’ve long understood that safety doesn’t happen by accident. The same applies to safeguarding data. Acting now can ensure that the only “disasters” making headlines, are the ones that were avoided.

Reach out to us any time if you need help getting started on your journey to a more secure cloud solution.

References
  1. Cobalt: Cybersecurity Statistics 2024 —
    https://www.cobalt.io/blog/cybersecurity-statistics-2024
  2. Tripwire: The Growing Threat of Ransomware in the Manufacturing Sector —
    https://www.tripwire.com/state-of-security/growing-threat-ransomware-manufacturing-sector
  3. Tripwire: The Growing Threat of Ransomware in the Manufacturing Sector — downtime and recovery cost data —
    https://www.tripwire.com/state-of-security/growing-threat-ransomware-manufacturing-sector
  4. Microsoft Learn Q&A: Backup frequency for Microsoft Dynamics 365 Business Central —
    https://learn.microsoft.com/en-us/answers/questions/2079137/what-is-the-backup-frequency-for-microsoft-dynamic

Reach out to learn more about what we can do.

contact us