Manufacturing Cybersecurity: 60% Breached Despite Training, And An MSP Question Underwriters Should Not Skip

Estimated reading time: 6 minutes

A new survey from Integris, a managed service provider, finds that 84% of U.S. manufacturers run cybersecurity awareness training, yet 60% reported a significant email-based breach in the past year. Another 49% reported a mobile device breach. The gap shines a light on manufacturing cybersecurity.

The 2026 Integris manufacturing technology and cybersecurity report surveyed 411 U.S. manufacturing executives and 600 consumers. All executive respondents work at companies that outsource some or all IT to an MSP, so the findings describe firms with existing outside technology support rather than the wider market. The report arrives as the sector invests in cloud, AI, and smart factory technology, with the attack surface expanding alongside the investment.

Factory robotic arm beside a warning shield icon with the headline 60% Breached, 84% Trained, illustrating manufacturing cybersecurity and cyber insurance risk, on cyberinsurancenews.org.

Reading The Breach Figures

The breach numbers are self-reported, with no fixed threshold for what qualified. “This was a self-reported measure of meaningful security incidents among the executives surveyed,” said Jason Griffin, VP of Cybersecurity Services at Integris.

Griffin argues the MSP-only sample still tells a useful story. “Outsourcing alone does not remove complexity,” he said. “Manufacturers still need strong internal ownership, clear accountability and partners that understand operational technology, cloud infrastructure and the unique risks of a factory environment.”

The results align with Integris surveys in other sectors run on the same method. Its law firm survey found a 63% email breach rate, and its banking report found 51%.

Training Alone Is Not Closing The Gap

Beyond training, 56% of manufacturers deploy secure email gateways. Another 51% use AI-powered anti-phishing tools. Breaches persist regardless.

Griffin’s view is that the individual pieces need to function as a system. “Training works best as part of a layered security program,” he said. “Manufacturers need strong identity protection, endpoint security, continuous monitoring and simple reporting processes alongside regular training. They should also test employees with realistic scenarios and measure whether people recognize, report and respond to threats correctly. The goal is to turn awareness into consistent action.”

See also  NEW - Cyber Insurance Podcast: A High-Vis Jacket Can Beat Your Firewall

For underwriters, that last point is the operative one. The existence of a training program is easy to attest. Measured response to realistic tests is the better signal.

Jason Griffin, VP of Cybersecurity Services, Integris

MSP Reliance And Aggregation Risk

The figure with the most direct insurance relevance sits in the cloud data. Eighty-eight percent of surveyed manufacturers rely on managed IT services to run their cloud operations.

MSP concentration is an established aggregation exposure. One compromised provider can affect many insureds at once, as the Kaseya incident demonstrated. A manufacturing book concentrated on a few shared MSPs carries correlated risk that individual applications will not surface.

Griffin is direct about the limits of outsourcing. “An MSP can provide expertise and scale, but the manufacturer still has to remain actively involved in its security strategy,” he said.

The report also documents a size divide. Industrial IoT adoption runs from 34% at firms with 50 to 99 employees to 75% at the largest surveyed firms. Smaller manufacturers lag in both modernization and defense. Many are also evaluating CMMC compliance for defense supply chain work. Both factors bear on appetite and expected loss at the small end of the market.

Consumer Findings And Their Limits

The consumer survey finds broad concern about manufacturing cybersecurity. The report states the figure as 85% in its analysis sections and 83% in its key findings.

On behavior, 25% of consumers say they have stopped buying from a manufacturer over security concerns. Sixty percent say a future breach would push them to stop. Integris did not indicate whether respondents identified a specific manufacturer or incident. Stated intentions in consumer surveys typically overstate later behavior, and the gap between the two figures is consistent with that pattern.

See also  Cyber Supply Chain Risks Gain Prominence: Report

The direction of the finding is still useful. “Consumers increasingly see cybersecurity as part of product quality and brand credibility,” Griffin said. “Manufacturers that explain how they protect customer data and respond openly when something goes wrong can strengthen loyalty and distinguish themselves from competitors.”

Kyle Wewe, chief revenue officer at Integris, framed the same point commercially. “The firms that will compete in this environment are the ones that treat cybersecurity as a brand issue, not just an IT function,” he said.

Where Cyber Insurance Fits

The survey did not measure insurance uptake, coverage adequacy, or claims experience. Griffin placed coverage within a broader resilience strategy instead.

“Coverage can support financial recovery, while a strong security foundation helps prevent incidents from becoming larger operational and reputational problems,” he said. He noted the point applies most to smaller manufacturers. “The right technology and insurance partners can help them prioritize improvements, document their security posture and prepare for incidents in a more structured way.”

For brokers, the report supports the case for pairing coverage with documented controls in a segment under growing compliance pressure. For underwriters, it suggests two questions. Which MSP runs the insured’s environment. And how much of the existing book shares it.

FAQ – Manufacturing Cybersecurity

What did the 2026 Integris manufacturing report find?

It surveyed 411 U.S. manufacturing executives and 600 consumers. Sixty percent of executives reported a significant email-based breach in the past year. Another 49% reported a mobile device breach.

What counted as a significant breach?

Respondents defined it themselves. Integris confirms it was a self-reported measure with no set threshold for loss, downtime, or confirmed compromise.


Why does the MSP reliance figure matter for cyber insurance?

Eighty-eight percent of surveyed manufacturers rely on managed IT services for cloud operations. Shared providers create aggregation risk. One compromised MSP can hit many insureds at once.

Do consumers really stop buying after manufacturer breaches?

Twenty-five percent say they already have. Sixty percent say they would. The survey did not verify specific incidents, so treat the behavioral claims as directional.

Did the survey measure cyber insurance uptake?

No. It captured no data on coverage, adequacy, or claims. Integris frames insurance as one part of a broader resilience strategy

Leave a Comment

×