Median Manufacturing Ransomware Victim: $42.9M, NC Plants

Black Kite: the median manufacturing ransomware victim books $42.9M in annual revenue. What that size finding means for NC plants. Call (336) 886-3282.

Cover Image for Median Manufacturing Ransomware Victim: $42.9M, NC Plants

The 60-second version: Black Kite's 2026 Manufacturing and Distribution Ransomware Report, released September 17, 2026, named 1,183 manufacturing organizations as ransomware victims in the first seven months of the year. The median one booked $42.9 million in annual revenue, and 70.2% fell in the $10 million to $100 million band. Here is the part nobody puts in the headline, and it is our argument rather than a finding in the report: how long you cannot ship is what you end up negotiating against. Can anyone in your building say what that number is? Asking your provider for it costs nothing.

Start there, because everything else in this report is a probability and that one is a price.

Why recovery time is the number worth measuring first

Black Kite's research chief Ferhat Dikbiyik puts the mechanism plainly in the release: "One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker's negotiating position."

Note what that does and does not say. Black Kite describes downtime as something that strengthens the attacker's hand in a negotiation, not as a pricing formula, and we are not aware of any dataset that publishes how ransoms are actually set. The argument we would make from it is this: every figure about how likely you are to be hit describes the odds, and none of them describes the bill. The gap between "the ERP is encrypted" and "we are shipping again" is what you are negotiating against, and it is the one variable on this page you control.

A backup being in place is not the same as being able to ship. When we take over an environment in the Piedmont Triad, the gaps we look for sit around the backup rather than in it:

  1. Nobody has ever timed a full ERP restore against a real shipping cutoff. A backup that verifies green says the file is readable. It does not say the business is running on Wednesday.
  2. The manual fallback has never been written down. Can the floor run a shift off printed travelers and a whiteboard while IT rebuilds? In the shops we have seen ride out an outage well, somebody had already answered that, sometimes because a hurricane rather than a hacker had forced the question.
  3. The keys and the contracts sit with one person. ERP license keys, the MES vendor's support contract, the domain registrar login. When that person has left and the vendor will only speak to a name that is no longer on the account, the recovery stalls on paperwork rather than on technology, and no security product on the market prevents it.

The third one is the least technical item on the list, and in our experience it is the one that quietly stretches a recovery out. Price it for your own environment before you assume it is cheap: moving a contract off a departed employee can mean vendor escalation, paperwork or paid support.

If you would rather have the hours measured than estimated, that is a conversation worth having before you need it. Preferred Data Corporation has worked with North Carolina manufacturers from High Point since 1987. Call (336) 886-3282.

Are we big enough for anyone to bother with us?

Check your revenue rather than your headcount, because revenue is the only thing this report measures. Black Kite recorded 1,183 manufacturing victims through July 29, 2026, up 39.7% on the same stretch of 2025. Within that group, 70.2% of 2026 victims reported annual revenue between $10 million and $100 million, and the median came in at $42.9 million. Separately, Black Kite's 2026 Ransomware Report counted 7,551 publicly disclosed victims across all industries and put manufacturing first for a fourth consecutive year at 22% of disclosures.

Black Kite reports revenue, not headcount, so do the translation yourself instead of trusting an average: pull last year's number and see which band it lands in. If it sits between $10 million and $100 million, you are inside the band that took seven of every ten named manufacturing victims this year. You are not under the line. You are the line.

One caveat on sourcing, because it matters for how much weight to put on this. Black Kite published the report, and the trade coverage relays Black Kite's own release rather than checking it independently. With that said, SecurityWeek's September 17 write-up carries the broader mid-market figure: 73% of ransomware attacks across North America and Europe from 2023 through the first half of 2026 hit mid-market companies. Black Kite's own framing is that these firms "are the supplier layer from which larger enterprises assemble their products."

Two honest limits on the 1,183, and they pull in opposite directions. It counts organizations named on leak sites and in breach notifications, so some entries are attacker claims rather than confirmed victims and can be false, duplicated or misclassified. It also misses everyone who restored quietly with no notification duty. Treat it as an incomplete observed count with error in both directions rather than as a floor or a total. Black Kite also scores victims on its own Ransomware Susceptibility Index and reports that most of them rated poorly on it, which is a vendor's proprietary model rather than an industry standard and carries less weight than the countable revenue data beside it.

Key takeaway: The question is no longer whether you are large enough to be worth attacking. You do not have to be singled out by name to be found.

Does the drop in the US share mean the risk moved to Europe?

No, and anyone presenting it that way is reading a ratio as a risk.

The US share of global manufacturing victims fell from 52.3% to 34.8%, which is the most quotable line in the coverage and the least useful. The US count went from 443 to 412. It barely moved. The share fell because the denominator exploded: European victims rose 85.4% and German victims alone rose more than 83%, per Distribution Strategy Group's September 17 summary, while SecurityWeek's regional breakdown puts the rest of the world at 402 incidents, close to double.

If somebody uses that share figure to argue for deferring the work, ask them for the count.

There is a second reading that cuts the other way, and it is the one that should concern any Triad plant that exports. That 85.4% is a measure of disruption among European manufacturers generally, not of your customer list, so nobody can tell you from this data whether your buyers are in it. What it does say is that observed disruption among European manufacturers rose sharply this year. If you sell into that market, an invoice sitting inside somebody else's frozen systems is your cash-flow problem as much as theirs, which is worth knowing before it happens rather than after.

What can you actually do on Monday, for nothing?

Four items, ordered so the ones you can answer without spending come first. The fourth needs a budget conversation.

  1. Inventory the keys and the contracts. ERP, MES, domain registrar, firewall support, the backup vendor. Name a current employee on each account. This is a short list of phone calls, done by you, with a legal pad.
  2. Write the two-shift manual plan. One page. How orders get picked, how shipments get documented, who signs off, with no network. Hand it to a supervisor who was not in the room when it was written and see if it survives.
  3. Ask for the number in writing. Send your provider one sentence: "How many hours from encrypted ERP to shipping again, and on what date did we last prove that number?" A good answer is a figure and a date. A bad answer is "we have backups." No answer by Friday is itself the answer.
  4. Then time a real restore. This is the one that is not free. Restoring the ERP to separate hardware needs somewhere to restore it to and somebody's time, and depending on your setup it may have to run outside production hours. Ask what it costs and how long it takes before you commit, then set that against what a day of not shipping costs you at your own volumes and margin. That comparison is the one that decides it, and it is yours to run: nobody else knows both of your numbers.

One more, and it is a quick check somebody else has to run for you: confirm that one backup copy is genuinely out of reach, immutable or offline, and cannot be deleted using the same domain administrator credentials that run the network. If it can, you have one copy rather than two.

Copy this into an email, as-is, with no phone number in it:

To our IT provider: (1) How many hours from encrypted ERP to shipping again, and when did we last prove it? (2) Can our backups be deleted with domain admin credentials? (3) Which of our software contracts are in the name of someone who no longer works here? Please reply by Friday.

However the reply comes back, grade it before you act on it:

What you askedAn answer that means somethingAn answer that means nothing
Hours from encrypted ERP to shippingA number and the date it was last proved"We have backups" or "it depends"
Can domain admin delete the backups"No, that copy is immutable until <date>""They are backed up nightly"
Whose name is on the software contractsNames current employees, per vendor"That has always been handled"

Two of those three questions your provider should be glad you asked. The third one is yours to fix regardless of who answers it.

Want a second opinion on the reply before you act on it? Send it over. Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265, (336) 886-3282, on-site within 200 miles.

What does this look like against North Carolina's own numbers?

It lands on a sector that has been shrinking here for three years. The North Carolina Department of Commerce reported in June 2026 that the state's manufacturing sector closed 2025 with 3,600 fewer jobs than the year before, a third consecutive year of net losses, with close to zero net growth projected between 2024 and 2034.

That is state-level context and not a comparison: those figures say nothing about other states, and a shrinking payroll does not by itself tell you how much slack any individual plant has. What it does mean is that if you are planning a manual-operations fallback, plan it against the crew you have now rather than the one you had five years ago.

For the controls underneath all of this, CISA's #StopRansomware Guide is the free, vendor-neutral baseline, and its response checklist is a reasonable skeleton for the call list you will want on paper.

So: Monday morning, put one name and one date against the timed restore. Not a project and not a quarter. A name and a date, while the choice is still yours to schedule.

If you want the questions above looked over before you send them, or the reply read afterwards, that costs you nothing. Preferred Data Corporation, High Point, NC, (336) 886-3282.

Objections, answered

We have never been hit in 30 years. Does that mean anything?

No data we can cite measures that directly. What is on the record is narrower. Black Kite reports that just under half of 2026 incidents (49.7%) were attributed to groups that did not appear in its data at all in 2023 or 2024. That is a statement about incident volume, not about how many groups are out there, and it does not follow that most of today's operators are new. What it does say is that a large share of this year's attacks came from somewhere your past record cannot speak to.

Does the timed restore take my plant down?

It should not, and if anyone proposes doing it on production you should push back. A proper test restores to separate hardware or an isolated environment while the live system keeps running. What it costs you is a technician's time and somewhere to put it, which is why it is worth asking for the price before agreeing to the test.

Is this a manufacturing problem or does it hit distributors too?

Both. SecurityWeek records 95 distribution incidents in the first half of 2026, against 196 across all of 2025, a year whose total was inflated by a single Clop campaign. Distributors also inherit the risk above them: a frozen supplier puts your shelves on their recovery clock, and how fast that bites depends on your own cover and whether a second source exists.

Should we buy cyber insurance or spend the money on controls?

Neither replaces the other. Read your own application and renewal questionnaire before you decide which to fund first, because what a carrier asks for varies by carrier and by policy, and the answers you would have to give are the fastest way to find out which gaps cost you money.

Does paying get us running faster?

Sometimes, and it is a business and legal decision rather than a technical one. What is consistent is that a tested restore weakens the attacker's position before the conversation starts, which is the argument for measuring your hours now rather than during the call.

Everything is in Microsoft 365. Are we covered?

Not for this. Cloud email and files change where the data lives, not whether someone with your credentials can encrypt or steal it. Whether your ERP and plant-floor systems are inside that same Microsoft estate is a question to answer rather than assume, and some are: a shop on Dynamics 365 Business Central is in a different position from one on an on-premise ERP, and both need the inventory before the recovery plan means anything.

Who should own this in a 70-person shop?

One named operations person, not the IT provider alone. Items one, two and three are decisions about how the plant runs, and an outside provider cannot make them for you.