What 1,625 Cybersecurity Findings Revealed About Manufacturing Risk
Published: September 9, 2026
We recently analyzed 1,625 cybersecurity findings across 21 manufacturing environments. The findings included familiar issues: weak passwords, missing patches, unencrypted drives, unnecessary administrative access, exposed services, and remote access tools that warranted a closer look.
But the most revealing part was not the list itself. It was how often we could see how the problems got there.
Those choices can be understandable. The problem is that reasonable decisions can create unreasonable risk when they accumulate. The patch that could not happen this week still has not happened six months later. The vendor access created for one service call is still enabled. The employee who needed elevated access for one project still has it.
Across all 1,625 findings, that pattern was more important than any single vulnerability.
Manufacturing Creates a Different Kind of Security Challenge
Cybersecurity best practices can sound simple until they reach the plant floor. Patch your systems. Require MFA. Remove unnecessary administrative access. Replace unsupported technology. Lock down remote access. Segment critical systems.
All of that is good advice. But a manufacturing company is not just an office with laptops. Its IT environment is tied to production equipment, specialized applications, vendor dependencies, legacy systems, multiple facilities, and machinery that may remain in service for decades.
We found 246 patch-related issues across the manufacturers we assessed, and every environment had some degree of patch exposure. Some systems simply needed updates. Others were complicated by production constraints, vendor support limitations, or legacy equipment.
In those situations, the issue is not always that an exception exists. Manufacturing will always have exceptions. The bigger issue is when no one is actively managing the exception. If a patch must wait, someone should know who owns the risk, what protects the system in the meantime, and whether there is a long-term plan.
Many Findings Were Not Exotic
More than half of all findings—54%, were identity-related. That included 877 credential-related issues, 201 passwords configured to never expire, and 78 credentials exposed on the dark web.
We also found 132 encryption-related vulnerabilities, including 85 unencrypted hard drives; 118 firewall and network vulnerabilities; and 60 internet-exposed RDP ports. Some manufacturers had accumulated three, four, or five separate remote access tools across their environments.
These are not futuristic cybersecurity problems. Security conversations often focus on the newest threat, but there is often a gap between how cybersecurity is discussed and how risk appears inside an environment.
An organization may deploy a new security platform while an old administrator account still has privileges it does not need. A remote access tool installed years ago may still be running. Everyone may agree with MFA matters, while certain accounts or applications remain outside the policy.
Identity findings were the clearest example. Identity now touches email, cloud applications, administrative systems, remote access, and sometimes production-connected resources. If a legitimate credential is compromised, an attacker may not need to break through much of anything. They may simply log in.
Risk Looks Different When Findings Connect
This is where the research shifted our thinking the most. Imagine a manufacturer who has an older production system that cannot currently be patched. Now imagine a vendor reaches that system remotely using an account with a password that has not changed in years, through outdated remote access software, on a network with more connectivity than it needs.
Each issue can appear on a separate line in a report, each with its own severity rating. But that is not how the risk exists. The real risk is in the relationship between them.
A stolen password matters more when it provides access through an exposed remote service. An unpatched system becomes more dangerous when an attacker has an easy way to reach it. Excessive privileges matter more when the same identity can move between systems. Weak segmentation can turn a contained issue into a much larger incident.
For manufacturers deciding where to invest limited time and budget, that context matters. One company might have 100 relatively isolated issues. Another might have 20 weaknesses that align into a practical attack path. The second environment may deserve more immediate attention even though its report is shorter.
Remote Access Shows How Risk Accumulates
Manufacturers often have legitimate reasons to allow remote access. Equipment manufacturers troubleshoot machines. Integrators support specialized applications. Internal IT teams manage multiple facilities. Outside IT providers need infrastructure access.
That is how manufacturers end up with three, four, or five remote access tools in the same environment. The issue is not that remote access should disappear. The real question is whether anyone has a complete picture of those pathways: which tools exist, who can use them, what authentication protects them, and what systems they can reach.
That is how manufacturers end up with three, four, or five remote access tools in the same environment. The issue is not that remote access should disappear. The real question is whether anyone has a complete picture of those pathways: which tools exist, who can use them, what authentication protects them, and what systems they can reach.
The same logic applies to the 60 internet-exposed RDP ports we found. RDP itself is not obscure technology. The concern is that direct exposure gives attackers another place to knock—and the consequences depend on everything behind that door.
The Stronger Environments Still Had Findings
One of the most useful parts of studying 21 environments was seeing the difference between manufacturers with lower and higher levels of security maturity. The stronger environments still had findings. That matters because finding issues is not proof that an organization is failing. If you look closely enough at almost any environment, you will find something.
What differed was consistency. Higher-maturity manufacturers generally had better asset and vulnerability visibility, more consistent access controls, stronger governance around administrative privileges and remote access, more developed recovery planning and better awareness of where exceptions existed and why.
That distinction matters because manufacturers are not going to eliminate every legacy system, vendor dependency, or operational constraint. A better question is whether those decisions are being made deliberately.
That distinction matters because manufacturers are not going to eliminate every legacy system, vendor dependency, or operational constraint. A better question is whether those decisions are being made deliberately.
If a production system cannot be patched for six months, that may be a reasonable business decision. But someone should know the decision has been made, understand the potential impact, and decide whether additional controls are needed in the meantime. The same goes for an old account, an unencrypted drive, or a vendor connection.
Not every finding needs to become an emergency project. Some should be fixed immediately. Some can wait. Some may remain in place for years because the operational cost of removing them is greater than the cyber risk they introduce. The important part is knowing which is which.
What We Took Away From the Research
When we started this research, we expected the most useful outcome to be a clearer picture of the vulnerabilities manufacturers are dealing with. We got that. Identity stood out immediately. Patching was nearly universal. Encryption, external exposure, remote access, and cloud security all produced meaningful findings.
But looking across the environments also made it harder to separate cybersecurity from the day-to-day decisions that created them. Most security gaps begin with someone trying to keep production running, repair a machine, finish a project, support an employee, or avoid replacing equipment that still does its job.
Then the environment changes around that decision. People leave. Vendors change. Software ages. New tools are added. Companies acquire locations. Cloud applications become more important. What was once a temporary workaround becoming infrastructure.
That is why manufacturers should periodically do more than ask whether their security tools are working. They should examine the environment as it exists today and compare it against the assumptions that shaped it.
Why does this account still have administrator access? Why is this port still open? Who still uses this remote access application? Why cannot this system be patched? What would happen if this credential were compromised? Is this exception still necessary—or have we simply stopped noticing it?
Those questions may not be as exciting as discussing the latest cyberattack, and they do not always require buying something new. But after reviewing 1,625 findings across 21 manufacturing environments, we are convinced they are some of the most valuable questions a manufacturer can ask.
Because the risk that deserves attention is not always the thing you do not know about. Sometimes it is the thing you have known about for so long that it stopped feeling like a risk.
See the Full Research Behind the Findings
Accent Consulting analyzed 1,625 cybersecurity findings across 21 manufacturing environments to understand where cyber risk shows up in manufacturing—and what organizations can do to address it more effectively.
Want to see the full data, key patterns, and practical takeaways?
Reach Out To Us
Recent Posts
-
Recognized Among America’s Most Reliable Companies – 2026March 11, 2026/0 Comments -
Top Managed Service Providers: 7 Signs of ExcellenceSeptember 8, 2026/ -
What Are the Best IT Support Options for Small Businesses?September 8, 2026/ -
-
Top 11 Manufacturing Technology Trends Shaping the FutureAugust 26, 2026/ -
The Latest Tech Trends to Watch this YearAugust 26, 2026/ -
AI Agents and the Future of Work: What You Need to KnowAugust 25, 2026/ -
Best Practices for Managing Sensitive Data SecurelyAugust 25, 2026/
