MANUFACTURING CYBER RISK STORY #3

The Encryption Gap: Why Sensitive Data Is More Exposed Than Leaders Realize

Data exposure grows when sensitive information moves across unencrypted devices, removable media, cloud systems and networks without consistent protection.

Why manufacturing data exposure often starts quietly.

Most manufacturing leaders think about cybersecurity in terms of disruption: ransomware, downtime, halted production, and the visible shock of an incident. But some of the most serious losses are quieter. A laptop disappears. A cloud repository is shared too broadly. A device is retired without proper safeguards. Data moves across an open wireless network in plain text. None of these events may look dramatic in the moment, but each creates the same outcome: sensitive information becomes readable to the wrong person.

That is the real story behind the manufacturing encryption gap. Accent Consulting’s findings show that 8% of identified manufacturing cyber risk was encryption-related, including 132 encryption-related vulnerabilities and 85 unprotected hard drives holding sensitive data. The same data also points to personally identifiable information stored in cloud environments without encryption and open Wi-Fi transmitting data in plain text. For manufacturers, this is not just a technical hygiene issue. It is a business exposure issue because engineering files, process documentation, pricing, customer data, employee records and operational information all help define the value of the business.

21

Manufacturers
Assessed

8%

Of Issues Are Patch
Related Issues

132

Encryption-Related Vulnerabilities

85

Unencrypted
Hard Drives

WHY IT MATTERS

Why encryption matters in manufacturing.

Without encryption, a lost laptop is not just a missing asset. It may be a readable archive of engineering drawings, process documentation, customer records, financial files or employee information. A compromised cloud account is not just an access problem. It may be direct access to sensitive content with no meaningful barrier left in place. A weak wireless network is not just an infrastructure issue. It may expose internal communications and credentials while data is moving. In each case, the problem is not only that data is exposed, but that it may still be immediately usable.

For manufacturers, that risk is especially serious because the information being exposed is often tied directly to operational value and competitive advantage. It may include engineering designs, production processes, pricing information and customer records. In many cases, that data supports the day-to-day decisions that keep operations moving. If it is exposed, the damage can extend beyond confidentiality and into productivity, trust and business continuity. The loss is not always immediate or obvious, but it can affect the organization’s position over time. That is what makes data protection such an important part of manufacturing cybersecurity.

KEY FINDINGS

What the encryption findings reveal.

The findings point to a broader pattern than any one metric alone can capture. Sensitive data is still being left readable across many of the ordinary systems and environments manufacturers use every day to operate the business. Rather than being isolated to a single device type or storage location, encryption gaps are appearing across laptops, hard drives, cloud repositories and wireless networks — often in places closely tied to production, administration and collaboration. That makes the issue more than a technical control gap; it becomes a business risk tied directly to the information manufacturers depend on most.

What matters most is the consistency of that exposure. When encryption is missing, engineering files, customer information, financial records and other sensitive data may remain usable to anyone who gains access, whether through loss, theft, compromise or interception. Taken together, these findings show that encryption risk is not confined to one corner of the environment. It follows data wherever it is stored, shared or transmitted, which is why strengthening encryption across endpoints, repositories and data in motion is such an important part of reducing long-term cyber risk.

BUSINESS IMPACT

Business impact of stronger data protection.

Strong cybersecurity does more than reduce the chance of attacking. It reduces the impact of ordinary failure.

  • make stolen devices less valuable,
  • reduce reportable exposure from lost hardware,
  • protect customer and employee data,
  • make intellectual property harder to steal,
  • improve legal and regulatory defensibility,
  • and lower the operational fallout when credentials or systems are compromised.

The source material also points to broader business consequences when encryption is missing, including regulatory exposure, legal liability, insurance complications and M&A diligence concern. Missing encryption may raise questions about how consistently sensitive data is being protected across the organization. It can also make it harder to demonstrate reasonable safeguards to regulators, insurers or potential buyers. That is why encryption should be viewed as both a security control and a business protection measure.

RISK LOCATIONS

Where the encryption gap shows up.

Encryption gaps tend to appear in the everyday systems manufacturers rely on most: endpoint devices, shared cloud repositories and networks that move data between people, plants and systems.

Accent Consulting’s findings point to three common exposure points:

  • Unencrypted hard drives: 85 unprotected drives contained engineering files, customer data and financial records.
  • Cloud storage without encryption: personally identifiable information, including employee and customer records, was stored in cloud environments without enough protection.
  • Plaintext data on open Wi-Fi: information transmitted over open wireless networks was visible to anyone on the network.

Each issue creates the same business problem: sensitive manufacturing information becomes readable outside its intended controls. That makes encryption a practical safeguard against lost devices, overly broad cloud access, compromised credentials and intercepted traffic.

COMMON QUESTIONS

What You Can Do Next

How do we prevent data exposure in manufacturing environments?

Across the benchmark, a clear pattern emerges: manufacturers are not all carrying cyber risk the same way. The same issue categories appear across many environments, but the gap between average and stronger performers is significant. What separates them is not usually size or complexity. It is how early foundational risks are identified, prioritized and addressed.

According to the encryption findings, 8% of identified issues were related to missing or weak encryption controls, including exposed endpoints, cloud storage, and network traffic. That is significant because it shows data protection is not just about access — it is about whether sensitive information remains unreadable when controls fail. Without encryption, exposure events can quickly become data loss events.

Some of the most serious data exposures start with something simple — a lost laptop or improperly retired device. With 85 unencrypted hard drives identified, full-disk encryption ensures that sensitive data remains unreadable, turning routine device loss into a manageable risk instead of a data breach.

Cloud storage makes collaboration easier, but it also introduces quieter forms of exposure. Findings revealed PII stored without encryption and accessible with valid credentials, showing that cloud risk is not just about access — it is about whether the data itself remains protected when controls fail.

Data is often most vulnerable while it is moving. The findings identified open Wi-Fi networks transmitting data in plain text, meaning sensitive information could be visible to anyone on the network. Without encryption in transit, even protected systems can expose data during everyday communication.

LEADERSHIP NEXT STEPS

Take control of your data protection strategy.

Identify sensitive data, validate encryption coverage and close the gaps that leave information exposed.