BLOG

Date
20-09-2026

OT Cybersecurity

Attackers Don’t Need to Hack Your PLC to Stop Your Plant

In June 2026, Mackay Sugar halted milling and cane haulage at two of its three Queensland mills after a ransomware incident. Limited manual crushing resumed two days later. Dragos assessed that the attack primarily affected enterprise IT, and found no evidence the actor reached industrial control systems or manipulated OT at all.

The mills still stopped. That is the pattern worth understanding, because most OT security investment is built around preventing an attacker from reaching a controller, and most production losses are now happening without anyone reaching one.

 

What the Q2 2026 Data Shows

Dragos recorded 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12 percent from 1,020 in the first quarter. North America accounted for 514 of them, up from 480.

 

Sector

Q2 2026 Incidents

Share

Manufacturing

747

65 percent of total

Construction

176

15 percent

Equipment manufacturing

114

10 percent

ICS-supporting organizations

117

Engineering firms, integrators, equipment makers

Food and beverage

70

6 percent

 

Two details matter more than the totals. Dragos notes that extortion is shifting away from file encryption toward data theft, which means an attacker no longer needs to encrypt anything to create leverage. And 117 incidents hit the engineering firms, system integrators and equipment manufacturers that operate inside other people’s plants.

 

Why Production Stops Without OT Being Touched

A modern plant does not run on its control system alone. It runs on a web of dependencies, most of which live on the enterprise side, and losing any of them can halt output while every PLC continues executing perfectly.

  • Production scheduling and ERP. No work orders, no batch records, no dispatch instructions. Operators can run the process and cannot legally or commercially release the product.
  • Manufacturing execution and quality systems. In regulated sectors, product that cannot be documented cannot ship. The line runs and the warehouse fills.
  • Virtualization and shared infrastructure. HMIs, historians and engineering workstations increasingly run as virtual machines. A compromised hypervisor takes out the visibility layer across multiple systems at once.
  • Identity services. Where OT authenticates against corporate Active Directory, a domain compromise locks operators out of their own consoles.
  • Logistics and shipping. Raw materials stop arriving and finished goods stop leaving, which fills tankage and forces a rate cut or shutdown within days.

 

The decision that actually causes the outage

In many of these incidents the plant is shut down deliberately rather than technically. Operations cannot confirm the integrity of what they are seeing, cannot document production, or cannot rule out that the intrusion has spread, so they stop as a precaution. Colonial Pipeline is the reference case: DOE records that Colonial proactively shut down its pipeline system in response to a ransomware attack on the enterprise side. Precautionary shutdown is the most common mechanism by which an IT event becomes an OT event.

 

The Question That Reframes the Problem

Most OT risk assessments ask what happens if an attacker reaches the control system. That question still matters. But it is incomplete, and the Q2 data suggests it is not where most of the loss is occurring.

The better question is: which enterprise systems does production actually depend on, and how long can the plant run without each of them. Very few operators can answer that, because nobody has mapped it. Asset inventories catalogue OT devices. They rarely capture the dependency on an ERP instance three network segments away.

This is different from asking how an attacker gets in. Our guide to securing the IT/OT boundary covers the intrusion pathways. This is about what breaks when systems you do not consider part of OT become unavailable, whether or not anyone crossed into your control network.

 

What to Do About It

  • Map production dependencies, not just assets. For each production line, list the enterprise systems it needs to operate and to release product. An OT risk assessment that includes dependency mapping produces this as an output.
  • Define the disconnected operating mode. Decide in advance what the plant does when ERP, MES or identity services are unavailable. If the answer is stop, say so and plan for it rather than discovering it under pressure.
  • Test restoration, not backup. OT backup and recovery means little until a restore has actually been performed. Virtualized HMI and historian estates need their own tested recovery path.
  • Separate OT identity from corporate. Where operators authenticate against corporate Active Directory, a domain compromise reaches the control room. Independent OT authentication removes that single point of failure.
  • Rehearse the shutdown decision. Since precautionary shutdown is the usual mechanism, the decision authority and criteria should be exercised. A tabletop exercise is where that gets tested cheaply.
  • Extend the question to your integrators. With 117 incidents hitting ICS-supporting organizations, a vendor outage can stall your maintenance and project work even when your own environment is untouched.

 

Why Choose Arista Cyber

Arista Cyber assesses industrial environments the way they actually fail, which increasingly means examining dependency rather than only intrusion.

We map what production genuinely relies on, including the enterprise systems most OT assessments leave out, then design the architecture and recovery capability that keeps the plant operable when those systems are gone. That covers IT/OT boundary and DMZ design, tested backup and recovery for virtualized OT estates, and incident response planning that puts the shutdown decision in writing before it is needed rather than during.

 

Next Steps

If you cannot currently say how long each production line would run without ERP, the answer is worth establishing before someone establishes it for you. Explore our OT cybersecurity services, read about the first 60 minutes of an OT incident, or contact the Arista Cyber team.

 

Common Questions

If ransomware never reaches OT, is it really an OT problem?

It is an operational problem, which is what OT security exists to prevent. The distinction matters for where you invest. Preventing intrusion into the control network is necessary and does not address dependency. A plant that cannot release product because its quality system is down has an availability failure regardless of which network the attacker was on.

How do we find our production dependencies?

Work backwards from the line rather than forwards from the network. For each production area, ask what has to be working for the plant to make and ship product: scheduling, batch records, quality release, materials, identity, shipping. Then map each of those to a system and a network location. Most of what emerges sits outside the OT boundary, which is why conventional asset inventory does not surface it.

Does segmentation help if the attack never enters OT?

Yes, for a different reason than usual. Segmentation limits spread, but it also makes it possible to keep operating with confidence during an enterprise incident, because you can demonstrate the control network was not reachable. Without that, operations often shuts down precautionarily because nobody can rule out spread. Network segmentation buys you the option to keep running.

 

How long can your plant run without ERP?

Arista Cyber maps production dependencies and builds the recovery capability that keeps output running when enterprise systems are gone.

Book a Free Consultation

BOOK YOUR CONSULTATION