ms-solutions-partner
Back

Ransomware Readiness in Manufacturing: Building an Operation That Recovers on Its Own Terms

Ransomware Readiness in Manufacturing: Building an Operation That Recovers on Its Own Terms

Stay connected with our Dynamics experts.

Sign up for updates, insights, and personalized support from Western Computer.

Manufacturing is the most attacked sector on the planet. Readiness is no longer an IT project. It is a production decision. 

Introduction

Every manufacturer knows how to bring a line back after it goes down. Ransomware is the same challenge with a different cause, and the plants that handle it well treat it exactly that way: as something you plan for, practice, and recover from on your own terms. The encouraging part is that most of what determines the outcome is within your control, and the steps that make the biggest difference are ones you can put in place now.

Why Attackers Keep Coming Back to the Plant Floor

Manufacturing was the most targeted sector for ransomware in 2025, with 1,466 incidents worldwide, up 56 percent from 937 the year before. It is not a coincidence, and it is not bad luck. Attackers have learned that a manufacturer with a line down is under more pressure to pay, and faster, than almost any other kind of business. Add valuable product designs, aging equipment that cannot be patched, and control systems that were never meant to touch the internet, and the plant floor becomes an easy, high-value place to strike.

The Real Cost Is the Line, Not the Ransom

The ransom number gets the headlines. The production loss is what actually shows up on your P&L. Manufacturers hit by ransomware lose an average of 11.6 days of production, and industry breach costs averaged $5.56 million in 2025. Those days do not come back. Orders slip, contracts carry penalties, and customers who waited start looking at your competitors. When you weigh the cost of readiness, the honest comparison is not readiness versus zero. It is readiness versus two weeks of stopped output plus recovery.

Attackers Go After Your Backups First

Here is the part that catches teams off guard. A backup you cannot restore from is not a backup. In manufacturing ransomware cases, 94 percent of victims had attackers try to compromise their backups, and 57 percent of those attempts succeeded. Once the recovery copy is encrypted or deleted, the only path left is the ransom. This is why the older 3-2-1 rule has grown into 3-2-1-1-0: three copies, on two media, one offsite, one immutable or air-gapped, and zero recovery errors that you have actually tested. Immutable storage matters because it cannot be altered even by someone holding your admin credentials. That single layer is often the difference between a bad week and a bad quarter.

IT and OT Do Not Fail Separately

In most plants, the admin laptop in the front office and the control system on the floor are one flat network apart. Attackers know it. When there is little separation between IT and OT, a phishing click at a desk can reach the systems that run production. Segmentation, tested isolation, and knowing exactly which systems have to come back first are not luxuries. They are the difference between recovering one cell and rebuilding the whole plant. When your business data lives in one connected, well-governed system instead of scattered across spreadsheets and disconnected islands, you also know precisely what to protect and what to restore, in what order.

A Legacy Platform Quietly Adds to the Risk

If you are running Dynamics GP, NAV, or AX today, this is where it gets specific. These platforms are winding down on a published schedule. Extended support for Dynamics AX 2012 R3 ended in January 2023, Dynamics NAV 2018 support ends in January 2028, and Dynamics GP support ends December 31, 2029, with security patches only through April 2031. When a platform stops getting security updates, the openings attackers rely on stop getting closed. Older ERP also tends to sit on older Windows Server and SQL versions that are past support too, so one aging system widens the attack surface around it. Years of custom code make the picture harder again, because a fast, clean restore is tough when the thing you are restoring is complex and lightly documented. None of this means you have to move tomorrow. It does mean a modern, cloud-based foundation like Dynamics 365 Business Central gives you patchable, protected, recoverable data by default, and takes a layer of risk off your plate that you are carrying right now. If a move off GP is already on your radar, we walk through the specifics in our guide to the Dynamics GP end-of-support timeline.

The Questions Insurers and Customers Now Ask

Readiness used to be an internal concern. It is not anymore. Cyber insurers now want proof of immutable backups, tested recovery, and network segmentation before they will write or renew a policy, and often before they will pay a claim. Your largest customers are asking the same questions in their vendor reviews, because your downtime becomes their supply gap. For an IT or security leader, that shifts the conversation with the board. The spend is no longer just risk reduction. It protects revenue you already have under contract and the audits you already have to pass. That reframe tends to move budget faster than any threat statistic.

Recovery Is a Plan You Rehearse, Not a Reaction

The manufacturers who recover in days rather than weeks are not the ones with the biggest security budget. They are the ones who decided ahead of time what a good recovery looks like: which lines restart first, how long the business can run on manual process, how fresh the restored data has to be, and who makes the call. A modern, cloud-based manufacturing ERP foundation makes that plan realistic, because protected and current data is the thing you are actually recovering to. The pattern we see is simple. The plants that practice the restore are the plants that trust it when it counts.

Where Western Computer Fits

For nearly 40 years and across more than 1,750 implementations, Western Computer has helped manufacturers put their operational data on a foundation they can protect and recover, not just run. We vet resilience the same way we vet everything else: against what actually holds up in production. Book a call with our team and we'll talk through your current setup and where the real gaps are.

Ryan Pollyniak

Ryan Pollyniak

Ryan is a seasoned consultant at Western Computer, helping organizations implement and optimize Microsoft Dynamics 365 and related cloud/ERP solutions. With years of hands-on experience in ERP, CRM, and business-intelligence systems, he brings deep technical knowledge and a pragmatic, customer-first approach to every project.

Unlock the Future of Smarter Selling

Book a consultation with a Dynamics 365 Sales expert to discover how AI and human connection can work hand-in-hand.

Rectangle 122