
In European cybercrime threat statistics, the manufacturing industry plays a comparatively minor role. However, the numbers are shifting, as evidenced by the ENISA Threat Landscape Report: Based on the proportion of reported incidents per sector, the industry has moved up from seventh to fourth place within a year. This marks the first time the manufacturing industry has ranked among the five most affected sectors in the EU.
One of the main reasons for this increase is growing connectivity: Production systems are now frequently connected to IT networks and external systems, creating additional entry points for attackers. The more closely IT and OT converge technically, the larger the attack surface becomes for cybercriminals. The ENISA report confirms that, in addition to mobile devices, operational technology (OT) systems in particular are an attractive target for cyberattacks.
The consequences of an attack can be severe. Operational disruption is among the most common immediate effects. Added to this are financial losses, damage to reputation, and data leakage or loss. (Source: ZEW, Leibniz Center for European Economic Research). For manufacturing companies, even the failure of individual systems can have a significant impact on supply chains and production processes.
Network Segmentation Slows Down Cyberattacks
Network segmentation is an important measure for limiting the impact of cyberattacks. It involves dividing networks into many small segments. The principle is similar to the bulkheads on a ship, which, in the event of a breach, prevent the entire ship from flooding and sinking. Applied to IT and OT infrastructure, this means that if malware enters a corporate network—for example, via an infected email or a compromised USB drive—network segmentation prevents it from spreading unchecked throughout the entire network.
The starting point for successful network segmentation is a thorough analysis to define the protection requirements of the various areas. The network segments can be designed to be as small as needed; even a single, particularly critical sector can constitute a single segment.
The individual segments are then separated from one another via security gateways. The Endian 4i gateways are specifically designed for use in industrial environments and can withstand harsh conditions. The gateways are equipped with several cybersecurity features. These include an intrusion detection and prevention system that uses deep packet inspection technology to detect and automatically block even complex threats.
Secure Remote Access as an Additional Layer of Protection
However, segmentation does not solve the problem as long as access to the individual segments remains insecure. All remote access should be regulated and subject to strict policies.
Endian Switchboard therefore offers centralized rights and permissions management based on the principle of least privilege. Each user is granted access only to the areas relevant to them and can perform only those actions necessary to fulfill their tasks. For particularly critical areas, it is possible to request authorization for remote access in advance. This is also an advantage from a safety perspective, as it allows the respective production facility to decide when remote maintenance can be performed without risk.
The connection between the end device used for remote access and the OT component is encrypted, ensuring that data cannot be intercepted or manipulated.
For additional security, remote maintenance sessions can be recorded via the Endian Switchboard. This feature is also gaining importance due to increasing regulatory pressure, as NIS2 and the Cyber Resilience Act require transparency and documentation. By recording remote access sessions, companies already have important proof of compliance without having to implement an additional product.
Conclusion
The threat landscape in the manufacturing industry will continue to grow as connectivity increases. This makes the question of how companies should structure their networks to ensure that a single incident remains manageable all the more relevant. Microsegmentation, combined with secure access and end-to-end logging, is a fundamental requirement for resilient production environments.
Frequently Asked Questions
Why are cyberattacks on the manufacturing industry increasing?
Production systems today are widely connected to IT networks and external systems, creating additional entry points for attackers. The closer IT and OT converge, the larger the attack surface becomes. According to the ENISA Threat Landscape Report, manufacturing has risen from seventh to fourth place among the most affected EU sectors within a single year.
What exactly does network segmentation achieve?
Network segmentation divides a network into many smaller segments, similar to the watertight compartments on a ship. If malware enters a corporate network, for example through an infected email or a compromised USB drive, segmentation prevents it from spreading unchecked across the entire network.
How should a company approach implementing network segmentation?
The starting point is a thorough analysis to define the protection requirements of each area. Segments can be designed to be as small as needed, in extreme cases a single critical sensor can form its own segment. The segments are then separated from one another using security gateways.
What role do the Endian 4i Gateways play?
The Endian 4i Gateways are designed specifically for use in industrial environments and built to withstand harsh conditions. Among other features, they include an Intrusion Detection & Prevention System that uses deep packet inspection to detect and automatically stop even complex threats.
How does Endian Switchboard secure remote access to segmented areas?
Endian Switchboard implements centralized rights and permission management based on the least-privilege principle. Each user is granted access only to the areas relevant to their role, connections are encrypted, and prior authorization can be required for particularly critical areas. Sessions can also be recorded, which additionally serves as compliance evidence for NIS2 and the Cyber Resilience Act.

Cyberattacks on the manufacturing industry
ENISA Threat Landscape 2025
In 2025, manufacturing moved from seventh to fourth place among the most affected NIS2 sectors. The figures show where the attacks come from, and why separated networks and controlled access now make the difference.
Source: ENISA Threat Landscape Report
of cybercriminal incidents in manufacturing involved ransomware
of attacks on the manufacturing industry came from cybercrime
of hacktivist attacks in manufacturing were DDoS attacks and attempts to disrupt OT


