Dragos, the industrial-control cybersecurity firm that tracks attacks on manufacturers, counted 1,140 ransomware incidents against industrial organizations in the second quarter of 2026, and 747 of them hit manufacturers. The number that should change how you spend your security budget is a different one: zero. Across the quarter, Dragos reports it observed no operator reach the control-system stage, so none of these attacks worked by reaching into a PLC or an HMI. Where a line went down, it traced back to the ordinary IT the plant floor quietly depends on, not to the control system. [1]
The project most owners assume protects production, hardening the control network, is not the project that would have kept these plants running. Where these attacks stopped production, they did not need the control network. They took the file server, the virtualization host, or the scheduling system, and the line went down on its own.
Run a plant in the 200-mile radius around High Point and not sure where your production actually depends on IT? Ask Preferred Data Corporation for an IT/OT dependency and segmentation review. We are local, on-site within 200 miles, and manufacturing-focused since 1987. Call (336) 886-3282.
Did the ransomware that stopped these plants ever touch the control system?
No. Across the entire quarter, Dragos reports it saw no ransomware operator reach the control-system stage or directly manipulate an ICS. [1] Production still stopped, because attackers encrypted the enterprise IT that plants run on, or because operators pulled lines down themselves as a precaution once virtualization and file servers went dark.
The numbers are worse the longer you look at them. Industrial ransomware incidents rose 12 percent quarter over quarter, from 1,020 in the first quarter of 2026 to 1,140 in the second. [1] Manufacturing absorbed 747 of those, roughly 65 percent of the total. [1] The second-largest top-level category was not a plant type at all: it was the engineering firms, system integrators, and equipment makers that support industrial operations, at 117 incidents. [1] That is well behind manufacturing's 747, but it is a substantial category in its own right, and it means the people who wire up your automation sit directly upstream of your production line as targets.
Key takeaway: The plant floor is rarely the front door. The front door is the same Windows domain, hypervisor, and file share your bookkeeper logs into every morning, and that is exactly why commodity ransomware crews can shut down a specialized manufacturer they know nothing about.
What actually goes down when your office network gets encrypted?
Almost everything the line needs to keep moving. A CNC controller can be perfectly healthy and still sit idle because the server that feeds it the job file is encrypted, the label printer lost its database, or the ERP that releases work orders is offline. Dragos found the United States absorbed 431 of the quarter's incidents, about 38 percent of the worldwide total, so this is not a distant problem for North Carolina shops. [2]
A vulnerability scan will never tell you this, but time on a shop floor will: the machine does not have to be the target to go dark. It just has to lose the box that feeds it work. When Preferred Data maps a plant in Winston-Salem or Burlington, we are not counting PLCs first. We answer one question for every production-critical process: if this specific server, share, or virtual host went dark for several days, does the line keep running? The answer is usually no, and the owner is usually surprised by which box it was.
| Plant manager assumes the line depends on | What actually stops the line |
|---|---|
| The PLCs and machine controllers | The file server that stores the job programs |
| The plant-floor network | The Active Directory domain and DNS |
| Machine vendor support | The VMware or Hyper-V host running a dozen VMs |
| A local operator panel | The ERP and scheduling system in the office |
| Nothing in the front office | Label, shipping, and quality databases |
The pattern is not unique to manufacturing. Within that 747-incident total Dragos counts construction-related work at 176 and food and beverage at 70, while transportation and logistics, a separate sector, took another 95. [2] Those are counts of ransomware incidents, not a tally of confirmed plant stoppages, but the through-line Dragos reports across the quarter holds: when these campaigns disrupt operations, they do it by way of IT, not by reaching a turbine or a mixer.
Want to know which systems your line depends on, and how long it survives without them, before an attacker finds out for you? Explore Preferred Data network and segmentation services or call (336) 886-3282.
Who is hitting NC manufacturers right now, and how fast?
The groups doing the most damage to industry in the quarter were Qilin with 140 victim claims, Akira with 129, and The Gentlemen with 125. [2] None of them build ICS-specific malware. They run high-volume, opportunistic campaigns against exposed remote access, unpatched edge devices, and stolen credentials, and manufacturing keeps landing in the net because manufacturers run flat networks and thin IT teams.
Mackay Sugar in June is the whole thing in one incident. The Gentlemen claimed responsibility on June 15 by listing the company on its leak site, and the mills stopped milling and cane haulage at two of three sites early in the crushing season. [1] Treat the details as unconfirmed: a leak-site post is the gang bragging, not a forensic report, and the full story is still being pieced together. The operational lesson does not depend on the details being settled. An IT-side event took a physical, seasonal, revenue-critical process offline at the worst possible week.
Key takeaway: You are not being targeted by an ICS specialist. You are being caught by a commodity crew that will take whatever network answers the door, and a flat plant network answers on the first ring.
Is air-gapping the plant floor the answer?
For most North Carolina manufacturers, no, and chasing it first is how shops waste a year. Be honest about the air gap: your machines report to the ERP, your maintenance team remotes in, and your vendors push firmware whether you like it or not. You are not going to isolate the plant floor, and spending a year trying is how a shop burns the budget before it fixes anything. The project that actually keeps the line running is narrower and cheaper, and it has two halves.
First, make the IT/OT boundary real instead of theoretical. That means a segmented network where a compromised office laptop cannot directly reach the plant-floor VLAN, where remote access into production runs through a controlled path with multifactor authentication, and where the machines that must talk to the ERP do so through defined, monitored rules rather than a flat switch. Second, make the IT the plant depends on genuinely recoverable: immutable backups of the ERP, the domain, the hypervisor, and the production databases, with restore tests you have actually run.
That second half is where most shops quietly fail. "We have backups" is not the same as "we restored our ERP to a spare host last quarter and timed it." Cyber-insurance carriers have caught on, and MFA on remote access, demonstrated network segmentation, and evidence that you have actually restored from backup are now routine questions at renewal rather than nice-to-haves.
What can you check yourself Monday morning?
Before you call anyone, five questions tell you most of what you need to know about your exposure. None of them require a consultant.
- Is there any remote access, RDP or otherwise, reachable from the open internet without MFA in front of it?
- When did you last actually restore your ERP or a core server from backup, start to finish, and time it? "We have backups" does not count.
- Is the plant floor on the same flat network as the front-office laptops, or is it segmented behind the firewall?
- If your main virtualization host died right now, do you know every production process that would stop with it?
- Does every vendor and maintenance path into your machines have a named owner, logging, and MFA?
If any of those made you uneasy, that is the finding. It also tells a provider exactly where to start, which is why the ones who move fastest ask these first.
What should a 20 to 250 person NC manufacturer do before the next quarter closes?
Work the dependency map, then segment, then prove recovery. A first wave of segmentation typically runs on the order of 60 to 90 days once scoped, and it rarely needs a plant shutdown, because the highest-value moves happen in the network and server layer, not on the machines. Your actual timeline depends on fleet size and how tangled the network is, which is exactly what the assessment establishes.
- Map production-critical IT dependencies. For every line and cell, list the servers, shares, databases, and hosts that must be up for it to run. This document turns "improve security" into a ranked project list.
- Segment the plant floor from the office. Put OT on its own VLAN behind the firewall, break the flat network, and force office-to-plant traffic through explicit rules.
- Control and monitor remote access. Every vendor and maintenance path gets MFA, logging, and a named owner. No standing open RDP.
- Make dependencies recoverable. Immutable, offline-capable backups of ERP, AD, the hypervisor, and production databases, with a scheduled restore test.
- Write the one-page runbook. Who declares an incident, who calls whom, and how the plant runs manually for a shift while IT recovers.
| Control | What it takes | What it buys when IT is hit |
|---|---|---|
| Dependency map | A scoped assessment, duration set during scoping | A ranked plan instead of guesswork |
| IT/OT segmentation | Firewall and switch work, staged | Far fewer paths for an office compromise to reach the plant |
| Immutable backup and restore test | An ongoing managed service | Recovery against a tested RTO, without paying for decryption |
| Monitored remote access | Configuration, not new hardware | The most common entry path is hardened, not left standing |
Preferred Data has supported North Carolina manufacturers since 1987, which is a long time to learn what a shop floor actually tolerates. Because we are on-site within 200 miles of High Point, segmentation and recovery work gets scheduled around your production windows, and a person can be on your floor rather than on a national ticket queue.
Ready to see where your line would stop if the office got encrypted? Request a manufacturing resilience assessment or call (336) 886-3282.
Questions NC plant managers are asking
If the attackers never touched a PLC, why did production stop?
Because modern manufacturing runs on IT that most people never think of as production equipment. Dragos found that in Q2 2026 disruption typically followed the encryption of enterprise IT or a precautionary shutdown of virtualization and related infrastructure, not any manipulation of the control system itself. [1] When the ERP, the file server, or the hypervisor goes down, the line has no work to run, and operators often stop it deliberately to protect quality and safety.
How much of this is aimed at big companies versus a shop my size?
The volume is driven by opportunistic groups, not targeted operators, which is worse for small shops, not better. Qilin, Akira, and The Gentlemen together claimed nearly 400 industrial victims in the quarter by hitting whatever network was exposed. [2] A 60-person fabricator with a flat network and no restore test is an easier payday than a hardened enterprise, and the crews do not need to know anything about your product to encrypt your servers.
We already have a firewall and antivirus. Is that enough?
Those help at the perimeter and the endpoint, but neither one keeps a compromised office network from reaching your plant VLAN, and neither one gets your ERP back if it is encrypted. The two controls that map directly to the Q2 2026 pattern are segmentation, which sharply limits how far an office compromise can travel toward production, and tested immutable backups, so recovery does not depend on a decryption key. Preferred Data treats those as the foundation, with managed IT and monitoring layered on top.
What does the segmentation project actually involve on the plant floor?
Usually less machine disruption than owners fear. Most of the work happens in the switch and firewall configuration and the server layer: defining the plant VLAN, writing the rules for what may cross the IT/OT boundary, and routing remote access through a controlled path. Machines rarely need to be touched or rebooted for the network changes, so the work can be staged around scheduled maintenance windows in your Charlotte, Raleigh, or High Point facility.
How do we prove recovery to our cyber-insurance carrier?
By running a documented restore test and keeping the evidence. Carriers increasingly want to see that you restored a core system to alternate hardware within a defined window, alongside demonstrated network segmentation and MFA on remote access. Preferred Data prepares that evidence to the carrier's specification, which is often what separates a manageable renewal from a declined one.
How fast can Preferred Data assess our operation?
A short on-site assessment plus remote analysis produces the dependency map and a ranked remediation plan, with a timeline scoped to your operation. For a mid-sized shop a first segmentation and backup wave typically runs on the order of 60 to 90 days once the work is scoped, not a fixed commitment. Post-incident engagements are prioritized ahead of routine work and scheduled as fast as the situation demands.
Related Resources
- Manufacturing IT and OT Services
- Network and Segmentation Services
- Cybersecurity Services for NC Businesses
- Backup and Data Protection
- Contact Preferred Data to request an IT/OT dependency and segmentation review
References
- Dragos. (2026, August 11). Dragos Industrial Ransomware Analysis: Q2 2026. https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026
- Help Net Security. (2026, August 11). Ransomware gangs don't need control system access to disrupt industrial production. https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/
- SecurityBrief. (2026, August 12). Industrial ransomware hits 1,140 incidents in Q2 2026. https://securitybrief.com.au/story/industrial-ransomware-hits-1-140-incidents-in-q2-2026