What New OT Cybersecurity Data Reveals About Manufacturing’s Readiness Gap
Nearly half of industrial organizations were breached in the past year, and nine out of ten still believe they could contain the next one without much trouble. That single contradiction, drawn from new Rockwell Automation research on connected manufacturing environments, is the clearest signal yet that manufacturing’s cybersecurity confidence has outrun its actual readiness.
Rockwell’s report, “Operational Resilience in the Age of Connectivity,” published in August 2026, finds that 46 percent of industrial organizations experienced a cyber incident in the past year, yet 90 percent say they are confident they could contain one. That is not a small discrepancy. It is a structural pattern, and it shows up again in Kiteworks’ own 2026 Annual Survey Report, formally titled the Kiteworks Data Security and Compliance Risk 2026 Annual Survey Report, which surveyed 459 security, compliance, and technology professionals across ten industries, including a 16 percent manufacturing cohort. The Kiteworks data does not measure confidence directly, but it measures something more useful for a CISO or a compliance officer trying to explain risk to a board. It captures the actual controls an organization has deployed, scored against a security maturity index and an AI governance maturity index, then combined into a single readiness score.
Manufacturing sits in an unusual spot in that data. It is not the worst performer, and it is not the leader either. It occupies a middle ground that looks reassuring on a dashboard and looks considerably less reassuring once you separate the sector’s operational technology exposure from the audit evidence its security and compliance leaders would need to produce after an incident. This piece walks through what both reports say, where they corroborate each other, and what a manufacturing CISO or Chief Compliance Officer should take away from the combination.
This matters because the reader who must explain a breach to a regulator, an insurer, or a board audit committee does not get credit for confidence. They get credit for evidence, specifically who accessed what data, when, under what authorization, and whether the control that should have stopped it was deployed and tested. Kiteworks secure data exchange exists to make that evidence trail available at the moment data moves, not reconstructed after the fact. That is the lens this piece uses throughout.
Key Takeaways
1. Confidence and control deployment are not the same thing.
Rockwell finds 46 percent of industrial organizations were breached in the past year while 90 percent report confidence in their ability to contain an incident, a gap that mirrors the self-reported versus control-based maturity gap Kiteworks documents across all industries.
2. IT/OT integration points are now a named, ranked exposure.
Rockwell ranks the IT/OT boundary as one of the most vulnerable areas to cyber incidents, just behind enterprise IT networks, which raises the stakes for how manufacturers govern data moving across that boundary.
3. Manufacturing’s security maturity is above average, but its readiness index still falls well short of resilient.
Kiteworks measures a manufacturing Data Security Maturity Score of 43.0 against a survey mean of 39, yet the sector’s combined Data Security and Compliance Readiness Index of 18.4 confirms that security controls alone do not close the governance gap.
4. Framework alignment is necessary but not sufficient.
Rockwell recommends aligning OT security programs to NIST, NIS2, and IEC 62443. Kiteworks’ broader survey data shows that even organizations tracking the right frameworks often cannot produce the audit-ready evidence those frameworks require on short notice.
5. Third-party and supply chain exposure is the discipline manufacturers cannot skip.
Manufacturing runs on supplier networks, contract manufacturers, and machine builders with their own remote access into the plant floor, and Kiteworks’ survey found third-party and vendor-related incidents to be the single most commonly reported data security incident type across all respondents.
The Confidence Gap Behind Manufacturing’s OT Security Numbers
Start with the number that should stop a board conversation. Forty-six percent of industrial organizations in Rockwell’s research experienced a cyber incident in the past year. That is not a hypothetical exposure or a modeled risk scenario. It is a reported outcome, from organizations describing what already happened to them.
Set next to that reported outcome is a second number. Ninety percent of the same population say they are confident they could contain a cyber incident. Read those two figures together and the story is not that manufacturers are unaware of risk. Awareness is high. Rockwell’s own framing makes that point directly, stating plainly, “The issue is not awareness. Industrial organizations know cyber risk affects uptime, continuity, productivity, and growth.” The real issue is that confidence has become detached from the infrastructure that would justify it.
This is precisely the pattern Kiteworks’ 2026 Annual Survey Report documents at a much larger scale and with harder numbers behind it. Across the full 459-respondent sample, Kiteworks finds that self-reported maturity runs well ahead of what its control-based Data Security Maturity Score actually measures. When Kiteworks asked respondents basic operational questions, such as whether they could identify their own SIEM platform or name the audit framework their organization is assessed against, without consulting a colleague, 49 percent could not name their SIEM platform and 41 percent could not identify their audit framework. An organization cannot govern what its own security leadership cannot name, and it certainly cannot produce evidence of governance on demand.
The practical consequence for a manufacturing CISO or compliance officer is that “confidence” is not a defensible answer in an incident review, a cyber insurance renewal, or a regulatory inquiry. What is defensible is a specific, testable answer to a specific question, namely which controls are deployed, when they were last tested, and whether the organization can produce the audit trail proving it. Rockwell’s data says manufacturing is confident. Kiteworks’ data says confidence, industry-wide, correlates poorly with what an auditor would find.
You Trust Your Organization is Secure. But Can You Verify It?
IT/OT Integration Points Are Where the Exposure Actually Lives
Rockwell’s report makes a specific, useful claim about where manufacturing risk concentrates. IT/OT integration points are ranked as one of the most vulnerable areas to cyber incidents, just behind IT systems and enterprise networks themselves. That ranking matters more than it might first appear, because it identifies the boundary, not either side of it, as the highest-priority exposure.
Every additional connection between a plant-floor control system and the corporate network, a supplier portal, a remote maintenance vendor, or a cloud analytics platform is a new data exchange point that must be governed, logged, and defensible after the fact. As Rockwell puts it plainly, “Every connection creates another dependency. Every dependency creates another point of exposure.” That is not an argument against connectivity. Rockwell is equally clear that AI adoption and IT/OT convergence are accelerating and are not going to reverse. It is an argument for governing the data that crosses that boundary as deliberately as the systems on either side of it.
This is where network segmentation and a defensible zero trust architecture earn their place in Rockwell’s recommended capability model, under what the report calls Industrial Networking and Infrastructure. But segmentation alone answers only half the question a compliance officer needs answered. Segmentation limits where a threat can move. It does not, by itself, produce the record of who accessed what sensitive engineering data, specification file, or supplier document, and when, across that boundary. That record is what zero trust data exchange is built to provide, and it is the same discipline behind Kiteworks secure data exchange. Governance travels with the data itself, not just with the network segment it happens to sit in at a given moment.
What the Kiteworks 2026 Annual Survey Report Shows About Manufacturing
Manufacturing accounted for 16 percent of the 459 organizations Kiteworks surveyed for its 2026 Annual Survey Report, tied with Financial Services as the second-largest industry segment behind Technology. That sample size is large enough to draw a real sector picture, and the picture is more nuanced than either “manufacturing is behind” or “manufacturing has this handled.”
On the Data Security Maturity Score, which is built from eleven binary security controls including encryption, SIEM integration, and kill switch capability, manufacturing posts a mean index of 43.0, ahead of the survey-wide mean of 39 and just behind Financial Services (43.3) and Energy and Utilities (43.2). On its own, that would read as a reasonably strong result. The more revealing number is what happens when that security score is combined with the sector’s AI Governance Maturity Score into Kiteworks’ Data Security and Compliance Readiness Index, or DSCRI, which multiplies the two together specifically because governance failures cannot be offset by security spending alone. Manufacturing’s DSCRI comes in at 18.4, ahead of the survey mean of 16.2, but nowhere close to the 45-plus average Kiteworks measures among the roughly one in five organizations, across all sectors, that reach the top quadrant on both dimensions simultaneously.
Kiteworks’ representation analysis, which measures how often each industry’s organizations land in a given quadrant relative to their share of the overall sample, adds useful texture to that number. Manufacturing organizations are slightly underrepresented in the top-performing “Resilient” quadrant, appearing there at 0.91 times the rate their sample share would predict, while showing modest overrepresentation in the “Fortified” quadrant (1.09 times) and a more pronounced overrepresentation in the “Policy-Led” quadrant (1.19 times), meaning a disproportionate share of manufacturing respondents have governance frameworks and stated policy ahead of the technical controls that would enforce them. That is a specific, actionable finding. Manufacturing does not primarily have an awareness problem or a policy problem. It has an enforcement gap between what the policy says and what the infrastructure does when a sensitive file, a supplier drawing, or a proprietary process specification tries to leave the building through an unmanaged channel.
The Governance Gap Behind the Confidence Gap
Rockwell’s report includes one figure that deserves particular attention from a manufacturing security leader. Forty-five percent of industrial organizations plan to use AI and machine learning for cybersecurity purposes over the next 12 months. That is a meaningfully different claim from using AI broadly across the business, and it is worth being precise about the distinction, because Kiteworks’ Annual Survey Report measures a different and equally important question. The question is not whether organizations are using AI to help secure their operations, but how well they are governing the AI systems, including AI-assisted tools, that already touch sensitive data across the business.
Across the full Kiteworks survey population, the picture there is not encouraging. Sixty-four percent of organizations have deployed AI in production, and among those, 64 percent experienced an AI-specific security incident in the past 12 months. No AI containment control measured in the survey, including kill switches, purpose binding, or AI-specific DLP, is deployed by more than 35 percent of organizations. Half of all organizations cannot produce a complete AI data access audit trail within one business day, and among organizations that have deployed AI in production, 23 percent have never tested their AI kill switch capability at all.
For a manufacturing organization layering AI-assisted tools onto cybersecurity operations, as Rockwell’s 45 percent figure suggests is already underway, this is the exact governance gap that needs to close before that adoption scales. An AI tool with access to security telemetry, asset inventories, or vulnerability data is itself a system that touches sensitive operational information, and the same audit-trail and access-governance questions that apply to a plant-floor engineering file apply to it. Bolting AI onto a security stack without the underlying data governance to log and control what that AI can see does not close the confidence gap Rockwell identifies. It has the potential to widen it, by adding a new system that generates the appearance of capability without the evidence trail to back it up when a regulator or an insurer asks for it.
Rockwell’s Six Capability Areas for Building Resilient OT Operations
Rockwell organizes its recommendations into six capability areas, and it is worth walking through each one because several map directly onto data governance decisions rather than pure network engineering ones.
Strategic Advisory comes first in Rockwell’s model, and the report frames it as the foundation everything else depends on, stating, “Before organizations can effectively reduce risk, improve resilience, or meet compliance requirements, they need a clear view of their current cybersecurity posture.” Asset Inventory and Lifecycle Management follows, addressing the visibility gap that Rockwell identifies as one of the most common barriers to resilience, particularly across legacy systems, serially connected devices, and temporary connections that accumulate on a plant floor over years of operation.
Risk and Vulnerability Management is the third capability, and Rockwell ties it explicitly to demonstrating measurable compliance progress against IEC 62443, NIST CSF, and NIS2, a direct acknowledgment that vulnerability management and regulatory compliance are the same discipline viewed from two angles. Managed Detection and Response addresses the 24/7 monitoring gap that most manufacturers cannot cost-effectively staff on their own, and incident response and recovery closes the loop with the incident response plan discipline that determines how much damage, downtime, and cost an organization ultimately absorbs. Industrial Networking and Infrastructure rounds out the model with the segmentation and secure remote access work described above.
Read as a set, these six capabilities describe a security program. What they do not describe, on their own, is a compliance evidence program, and that distinction is where a Chief Compliance Officer’s priorities diverge slightly from a CISO’s. A well-segmented, well-monitored OT environment can still leave an organization unable to answer, within the timeframe a regulator or an assessor demands, exactly which sensitive files moved across the IT/OT boundary during an incident window, who authorized that movement, and whether the control that should have flagged it was actually enabled at the time. That evidence layer is the piece a secure data exchange approach adds on top of Rockwell’s six capabilities rather than in place of them.
Compliance Frameworks Manufacturers Must Align To
Rockwell’s report names three frameworks explicitly: NIST, NIS2, and IEC 62443. That is a meaningful list for a manufacturing audience specifically, because NIS2 in particular extends European critical-infrastructure cybersecurity obligations to a wide range of manufacturing subsectors that previously sat outside comparable regulatory scrutiny, and IEC 62443 is the closest thing the OT world has to a universally recognized control standard.
Kiteworks’ broader 2026 Annual Survey Report data puts useful weight behind why framework alignment, on its own, is not the finish line. Sixty-three percent of organizations across the full survey experienced at least one compliance consequence in the past 12 months, defined as an audit finding, a required remediation plan, a board escalation, a contractual penalty, or a formal regulatory investigation. Sixty-one percent rank AI-specific regulatory requirements among their top three compliance challenges, ahead of every other named framework, and only 33 percent of organizations across the survey have tamper-evident audit trail capability in place at all, the specific evidence type an investigator or auditor examines to confirm records were not altered after the fact.
None of these figures are manufacturing-specific; they describe the survey-wide population. But they describe the same underlying failure mode Rockwell’s OT-focused research points to from a different angle. Organizations increasingly track the right frameworks and understand the right obligations, and still cannot produce audit-quality evidence of compliance fast enough to matter when it counts. ISO 27001 compliance, NIST CSF alignment, and CMMC 2.0 compliance for the defense manufacturing subsegment all share this same gap between framework adoption and evidence production. Framework alignment tells a regulator what an organization intends to do. Evidence tells the regulator what it actually did.
Third-Party Risk Is the Discipline Manufacturing Cannot Skip
Manufacturing does not operate as a single organization with a clean perimeter. It operates as a network of suppliers, contract manufacturers, machine builders, logistics partners, and maintenance vendors, many of whom require some form of remote access into plant systems or exchange of proprietary specifications, bills of materials, and quality documentation on an ongoing basis.
Kiteworks’ 2026 Annual Survey Report gives this exposure a hard number, and it is a striking one. Across the full survey, a third-party or vendor-related data incident was the single most commonly reported data security incident type of all categories measured, ahead of PII breaches, ransomware, and insider threats. That finding lands with particular force in manufacturing, where supply chain risk management and vendor risk management are not abstract governance categories but daily operational realities tied to production continuity itself.
Rockwell’s report reinforces this from the OT side without naming it directly. Secure remote access appears explicitly among the outcomes its Industrial Networking and Infrastructure capability is meant to deliver, described as access “that supports operational flexibility, productivity and collaboration without creating unmanaged entry points.” An unmanaged entry point, in practice, is very often a third-party connection that was provisioned for a legitimate purpose and never fully governed afterward. Closing that gap requires the same evidence discipline discussed throughout this piece, namely knowing which vendor accessed which system or file, under what authorization, and being able to prove it after the fact through access controls and logging that survive contact with an actual audit.
What Manufacturing Security and Compliance Leaders Should Do Next
The combination of Rockwell’s OT-specific findings and Kiteworks’ broader 2026 Annual Survey Report data points toward a consistent set of priorities for manufacturing CISOs and compliance leaders, and none of them require abandoning the connectivity and AI investments already underway.
Treat the IT/OT boundary as a governed data exchange point, not merely a network segment. Segmentation limits blast radius, but it does not produce the access record a regulator, insurer, or board audit committee will ask for after an incident.
Close the gap between policy and enforcement that Kiteworks’ representation analysis surfaces in manufacturing specifically, where governance frameworks are disproportionately in place relative to the technical controls that enforce them. The same discipline needs to extend to the AI tools manufacturers are adopting for cybersecurity operations themselves. AI governance is measurably the weaker of the two maturity dimensions Kiteworks tracks across every industry, manufacturing included, and there is no reason to expect the sector’s AI-assisted security tools to be the exception.
Vendor-related incidents outrank every other category in Kiteworks’ survey, which is reason enough to treat third-party and supplier access as a first-class governance category with its own logging and evidence requirements, not an afterthought bolted onto the main IT/OT security program.
Manufacturing is not the industry with the worst numbers in either report. It is, in some respects, a sector doing more right than most. But “more right than most” is not the standard a regulator, an insurer, or a board applies after a breach. The standard is evidence, and the gap between manufacturing’s demonstrated security investment and its ability to produce audit-ready proof of that investment is exactly the gap both reports describe from different vantage points.
To learn more about closing the audit evidence gap between OT security investment and compliance-ready proof, schedule a custom demo today.
Frequently Asked Questions
Yes, and increasingly by design rather than by accident. Rockwell’s research explicitly ties its recommended OT capabilities to NIST CSF, NIS2 compliance, and IEC 62443, and NIS2 in particular has extended critical-infrastructure obligations to manufacturing subsectors that previously sat outside comparable regulatory scope. The practical question for a compliance leader is not whether the IT/OT boundary is in scope, but whether the organization can produce evidence of the controls the framework requires at that boundary specifically.
At minimum, a defensible audit trail showing which systems and sensitive files were accessed, by whom, under what authorization, and whether the relevant control was enabled and tested at the time of the incident. The Kiteworks Data Security and Compliance Risk 2026 Annual Survey Report found that only 33 percent of organizations across its full survey have tamper-evident audit trail capability in place, the specific evidence type auditors and investigators use to confirm records were not altered after the fact, which is the gap most likely to surface during a post-incident review or regulatory inquiry.
The Kiteworks Data Security and Compliance Risk 2026 Annual Survey Report measures these as two distinct dimensions for a reason. An organization can have solid general security infrastructure while its AI-specific governance, covering things like kill switches, purpose binding, and AI-specific DLP, lags well behind. Across the full survey, no AI containment control is deployed by more than 35 percent of organizations, and this gap is the reason Kiteworks combines both scores into its Data Security and Compliance Readiness Index rather than reporting general security maturity alone.
This is genuinely unsettled in most organizations, and that ambiguity is itself part of the risk. A CISO typically owns the security architecture on both sides of the boundary, while a Chief Compliance Officer or Head of GRC owns the evidence obligation once a framework like IEC 62443 or NIS2 is in scope. Manufacturers that treat this as strictly an IT/OT engineering question, rather than a shared security-and-compliance accountability, are the ones most likely to discover the gap only after an incident forces the question.
Zero trust data exchange governs sensitive data based on what it is and who is accessing it, rather than relying solely on which network segment it happens to be traveling through at a given moment. For a manufacturer, that means the same governance and logging discipline applies whether a sensitive specification file moves between two plant-floor systems, out to a supplier, or into an AI tool used for security operations, producing the single, consistent evidence trail an auditor or regulator will ask for regardless of which system originated the request.
Additional Resources
- Blog Post Zero Trust Architecture: Never Trust, Always Verify
- Video Microsoft GCC High: Disadvantages Driving Defense Contractors Toward Smarter Advantages
- Blog Post How to Secure Classified Data Once DSPM Flags It
- Blog Post Building Trust in Generative AI with a Zero Trust Approach
- Video The Definitive Guide to Secure Sensitive Data Storage for IT Leaders