Ransomware attacks have been keeping IT executives around the world awake for years. But their encroachment into the world of operational technology (OT) and industrial control systems (ICS) has given this threat a whole new, much more threatening dimension. Here, what’s at stake is no longer just data in spreadsheets or customer databases. What’s at stake is physical production stoppage, supply chain paralysis and financial losses running into the millions per day.
In a manufacturing environment, ransomware stops being an IT problem and becomes an operational disaster. It’s this tangible, immediate business pressure that makes the industrial sector one of the most frequently attacked and, unfortunately, one of the most frequently paid ransom today. Cybercriminals are well aware of this and are increasingly boldly targeting the heart of factories, knowing that every minute of downtime works to their advantage.
But giving in to the pressure and paying the ransom is a short-sighted and extremely risky strategy. True resilience to this threat lies elsewhere - in conscious preparation, building a multi-layered defense and, most importantly, having a rehearsed plan for responding when the worst does happen, however. The purpose of this article is to provide you with the knowledge to build that plan.
Shortcuts
- What is ransomware and how does it cripple physical production processes?
- Why does the manufacturing sector pay ransom more often than other industries?
- What industries are the most common targets of attacks today?
- How quickly can ransomware spread in an unsecured OT network?
- How to build a step-by-step ransomware response plan (IRP)?
- What should a policy for dealing with a ransomware attack at a manufacturing facility include?
- How do you effectively isolate an infected OT network segment without stopping the entire plant?
- The first 24 hours after the ransomware attack: Action Checklist
- Whether and when it pays to pay ransom - what do the data and experts say?
- What tools and techniques realistically speed up recovery from an attack?
- How should machine operators be trained to become the first line of defense?
- What are they and where to look for decryptors under the “No More Ransom” initiative?
- What elements of a “Cyber” insurance policy cover losses after a ransomware attack?
What is ransomware and how does it cripple physical production processes?
Ransomware is a type of malware that aims to encrypt data on an infected system and then demand a ransom ( ransom) in exchange for the decryption key. In an office (IT) environment, this attack blocks access to files, emails and business systems. In a production (OT) environment, its effect is much more destructive.
Attackers are not targeting PLCs themselves, but the Windows and Linux operating systems on which key supervisory components run. When ransomware encrypts a SCADA server drive, operators lose the ability to monitor and control the entire process. When HMI stations are encrypted, operators on the shop floor lose the “eyes and hands” to operate machines.
As a result, while the machines themselves may still be operational, the entire “digital nervous system” of the factory is paralyzed. Production has to stop immediately for security reasons, because no one is in control. Ransomware in OT doesn’t block data - it blocks the physical ability of the company to operate.
📚 Read the complete guide: Ransomware: Ransomware - czym jest, jak się chronić, co robić po ataku
Why does the manufacturing sector pay ransom more often than other industries?
The answer is brutally simple: because of the math. In many other sectors, the effects of a ransomware attack, while severe, are often spread out over time. In the manufacturing sector, the losses are immediate, tangible and extremely easy to quantify. Each hour of downtime of a key production line has a specific, calculable value in the thousands or millions of zlotys of lost revenue.
When management is faced with a choice: “pay a 500K ransom with an uncertain chance of recovering data within 24 hours” versus “spend potentially two weeks rebuilding systems from scratch, losing 20 million zlotys in the process,” the business decision, while morally questionable, seems obvious. Pressure from customers waiting for deliveries and the threat of contractual penalties only compounds the dilemma.
Cybercriminals understand this perfectly. They conduct a reconnaissance, estimate the daily turnover of the attacked company and adjust the ransom amount so that it is severe, but still seen as the “lesser evil” compared to the cost of downtime. It’s a cynical but extremely effective business calculation.
What industries are the most common targets of attacks today?
While no industry is completely secure, some industries are more vulnerable to ransomware attacks than others. At the top of the list are those industries where production continuity is absolutely critical and tolerance for downtime is close to zero.
The highest risk group includes the automotive industry, which operates on a just-in-time model, where even a few hours’ downtime at one sub-supplier can bring a large corporation’s entire assembly line to a halt. Equally vulnerable is the food and pharmaceutical industry, where downtime can lead to the spoilage of entire batches of raw materials or products.
Companies in the machinery and component manufacturing and chemical industries are also increasingly becoming targets. Attackers realize that in these industries, OT systems are often older, less secure, and cyber security knowledge is at a lower level, making them easier targets.
How quickly can ransomware spread in an unsecured OT network?
The speed at which modern ransomware spreads across a flat, unsegmented network is frightening. Many attacks are fully automated. Once the malware gets into one computer on the network (the so-called “patient zero”), it immediately begins scanning its entire environment for other vulnerable machines.
Taking advantage of built-in mechanisms in operating systems and known vulnerabilities, it can infect dozens within minutes and hundreds or thousands of computers on the same network within hours. It requires no additional interaction on the part of the attacker. It’s a digital fire that spreads at the speed of the wind.
In OT environments, where networks are often flat and systems are not regularly updated, this process is even faster and more destructive. This is why the lack of network segmentation is one of the biggest risk factors. In a well-segmented network, the fire is confined to one “room.” In a flat network - the whole building burns.
How to build a step-by-step ransomware response plan (IRP)?
An effective Incident Response Plan (IRP) for a ransomware attack is not an improvisation, but a well thought out and rehearsed process. It must consist of several key steps:
-
Identification: confirm as soon as possible that there is a ransomware attack and determine its scale - which systems have been infected.
-
Containment: Immediately isolate infected machines and network segments to stop further spread of encryption.
-
Analysis: Securing a sample of malware and logs to identify the type of ransomware and attack vector.
-
Communication: Activate internal and external crisis communication plan - inform management, employees and, if necessary, law enforcement agencies and NASK CSIRT (as required by NIS2).
-
Elimination and Restoration: remove malware and start the procedure of restoring systems from clean, uninfected backups.
-
Conclusions: Once the crisis is over, a detailed analysis of the incident to strengthen defenses for the future.
What should a policy for dealing with a ransomware attack at a manufacturing facility include?
In addition to a technical plan, every company should have a formal, board-approved policy for dealing with a ransomware attack. Such a document eliminates decision-making chaos in a moment of crisis.
The policy should clearly define the decision-making chain: who is responsible for declaring a state of emergency and who makes the key business decisions, including the most important one - regarding possible ransom payments. As a general rule, the policy should clearly state that the company does not pay ransoms so as not to fund criminal activity and become a target for future attacks.
The document should also clarify communication procedures - who is authorized to contact law enforcement and the media. It must also contain clear guidelines for employees, such as “If you suspect an attack, immediately disconnect the computer from the network and inform the IT department. Do not attempt to reboot the machine yourself.”
How do you effectively isolate an infected OT network segment without stopping the entire factory?
The key to effective containment is speed and precision. “Pulling the plug” on an entire plant is an effective but extremely costly solution. That’s why it’s so important to segment the network beforehand, allowing for surgical precision in action.
If your network is divided into logical zones (e.g., a separate zone for each production line), when an infection is detected on Line A, you can immediately block all communications to and from that one segment on the firewall. This allows you to stop the spread of ransomware while keeping the other, uninfected production lines running.
Having ready-made, tested isolation procedures for each segment is a key component of playbooks in an IRP plan. The response team needs to know in advance which segments can be isolated safely and quickly, and which require a more complex, controlled shutdown procedure.
The first 24 hours after the ransomware attack: Action Checklist
| Phase | Key Action | Target |
|---|---|---|
| Hour 0-1 | Identification and Isolation: Confirm the attack, isolate infected machines and segments. | Stopping further encryption and proliferation. |
| Hour 1-3 | Escalation and Communication: Activate the Response Team (CSIRT), notify management. | Launch a formal crisis management structure. |
| Hour 3-8 | Analysis and Evaluation: Identify the type of ransomware, assess the extent of damage, verify the status of backups. | Understand the situation and evaluate the available playback options. |
| Hour 8-24 | Decision and Reporting: Deciding on a recovery strategy. Reporting the incident to the NASK CSIRT (NIS2 requirement). | Create an action plan and meet legal obligations. |
Whether and when it pays to pay ransom - what do the data and experts say?
The official position of all government agencies and cyber-security experts is clear: don’t pay the ransom. Paying finances criminal activity, encourages further attacks and offers no guarantee of data recovery. Many companies that paid never received a working decryption key or the key they received was only able to decrypt part of the data.
However, as mentioned earlier, in the real business world, this decision is not so simple. Sometimes, when the stakes are huge and the company has no working backups, management may consider this option as a last resort. However, one should be aware of all the risks.
By paying, you become a “verified paying customer” and will almost certainly end up on target lists for other criminal groups. Moreover, the negotiation and payment process itself (usually in cryptocurrencies) is complicated and risky. If a company is considering this option, it is absolutely crucial to engage professional third-party negotiators and experts who have experience in such situations.
What tools and techniques realistically speed up recovery from an attack?
The most effective “tool” for data recovery is not a key from a hacker, but a well-designed and tested backup (backup) system. This is the absolute foundation of ransomware resistance. It is crucial that these copies are kept isolated from the main network (so-called “air-gapped backup” or “immutable backup”), so that ransomware is not able to encrypt them either.
Having up-to-date, uninfected backups of key systems (SCADA servers, HMIs, PLC projects) allows you to completely ignore ransomware requests and proceed with the restoration procedure. This process, while still time-consuming, is the only guarantee of restoring a fully clean and trusted environment.
In addition to backups, it is crucial to have ready-made “gold images” of operating systems for key workstations. This allows you to restore a clean operating system very quickly, to which you can then restore the application and data itself.
How should machine operators be trained to become the first line of defense?
Machine operators and personnel on the shop floor are often targets of phishing and social engineering attacks. Regular, engaging and, most importantly, tailored to their realities, security awareness training is a key investment in prevention.
These trainings must focus on the threats they may realistically encounter. They should be taught how to recognize suspicious emails impersonating equipment suppliers, how dangerous it is to use unauthorized USB drives, and why private devices should not be connected to the company’s network.
Most important, however, is to build a culture in which every employee feels empowered and obligated to report any suspicions without fear of consequences. An operator who notices strange behavior on an HMI panel and immediately reports it to the IT department can be a hero for allowing an attack to be detected at a very early stage.
What are they and where to look for decryptors under the “No More Ransom” initiative?
In some cases, even if you don’t have a backup, there is a chance to recover data without paying the ransom. This happens when law enforcement manages to take over the criminal group’s servers and recover the decryption keys, or when a vulnerability is discovered in the code of the ransomware itself that allows it to be cracked.
These keys and decryption tools are often made available to the public and for free as part of the international “No More Ransom” initiative, supported by Europol, among others. The project’s website (www.nomoreransom.org) is the first place to visit once you have identified the type of ransomware that has attacked you.
However, it is important to note that this is only available for certain, older or “broken” ransomware families. Relying on this capability would be extremely unwise. The only sure strategy remains to have your own independent backups.
What elements of a “Cyber” insurance policy cover losses after a ransomware attack?
More and more industrial companies are choosing to purchase dedicated cyber insurance policies. Good insurance can be a powerful support in a crisis situation, but it is crucial to understand exactly what it actually covers.
A standard “Cyber” policy typically covers several categories of costs. First, incident response costs, i.e. expenses for computer forensics experts, lawyers and PR specialists. Second, the cost of restoring data and systems. Third, and extremely important in manufacturing, losses resulting from business interruption.
However, you should read the General Terms and Conditions of Insurance (GIC) very carefully, paying attention to exclusions, limits and deductibles (excesses). Increasingly, it is also a condition for full indemnification that the company prove that it has followed appropriate minimum security standards, such as having backups or implementing MFA.
How does nFlo help create a defense and response plan to ransomware attacks in an OT environment? At nFlo, we understand that ransomware resilience is not a single tool, but a comprehensive program that combines prevention, detection, response and recovery. Our approach is holistic - we help at every stage of building this resilience. We start with an audit and risk analysis that identifies the biggest gaps in your defenses. Then, we help design and implement a multi-layered prevention architecture based on segmentation, system hardening and secure remote access. A key component of our offering is to help you create and test a dedicated Incident Response Plan (IRP) and Disaster Recovery Plan (DRP). Our team of experts can also provide immediate support in the event of a real attack (Incident Response Retainer), guiding you through the chaos of the crisis and helping you restore production as quickly and safely as possible.
The IT-to-OT path is testable, not hypothetical
Almost every industrial ransomware case follows the same route: the intrusion starts in the office network and reaches production through something that was never meant to be a bridge — an engineering workstation with two network cards, a supplier’s remote support tunnel, a shared file server holding recipe files. Whether that route exists in a given plant is not a matter of opinion; it can be walked deliberately, under controlled conditions, before an attacker does it.
That controlled walk is the point of OT ransomware resilience testing — run without stopping production and reported as a list of reachable paths.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Backup — Backup, also known as a backup copy or safety copy, is the process of creating…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
Learn More
Explore related articles in our knowledge base:
- Defense in Depth - how to build multilayer protection against cyberattacks
- How to Build an Effective SOC Team: Key Roles, Competencies, and Processes
- What is Information Security and How to Build an Effective Information Security Management System (ISMS)?
- Cyber insurance for industry: What does your policy really cover and how to avoid costly surprises?
- Cyber Secure Local Government is coming to an end. How to ensure the sustainability of the project and build the long-term resilience of the local government?
Explore Our Services
Need cybersecurity support? Check out:
- Incident Response - rapid response to security incidents
- SOC as a Service - 24/7 security monitoring
- Backup & Disaster Recovery - data protection and business continuity
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
