NextFin News - Manufacturers are entering a new phase of cyber risk: attackers are using artificial intelligence to compress intrusion timelines, probe old industrial vulnerabilities at scale, and turn the factory floor into a more expensive target to defend. SonicWall said manufacturing recorded a 56.2% year-over-year decline in intrusion-prevention volume in the first half of 2026, but still logged 474 million events, while Sophos said attackers are operationalizing AI for attacks and targeting ungoverned AI identities. The result is not just more noise. It is a structural widening of the attack surface that will push manufacturers toward more spending on Zero Trust, identity controls, and industrial-network segmentation.
That pressure matters because manufacturing has long lived on the fault line between information technology and operational technology. The business case for connecting plants to corporate systems has always been clear: remote monitoring, predictive maintenance, vendor access, and faster response times. The security cost of that connection is now clearer too. SonicWall said the Hikvision IP camera command-injection flaw CVE-2021-36260 generated 43 million hits in manufacturing networks in the first half of 2026, the single largest IoT signature across any industry it tracks, while IoT attacks in manufacturing generated 46.2 million hits and SCADA attack detection rates were the highest of any tracked vertical.
The new threat is not merely volume. It is precision. Attackers no longer need to blanket a network with generic scans if AI systems can help them identify the most valuable credentials, the most exposed devices, and the narrowest path from a corporate account to production systems. SonicWall said manufacturing’s attack surface has changed over the last five years as connected cameras, sensors, remote maintenance tools, and legacy software have multiplied access points. Its chief security argument is blunt: one stolen password can still be enough to reach the production floor in too many factories.
That is why the spending implication is likely to exceed a one-off software refresh. Manufacturers are being forced to buy for containment, not convenience. The immediate line items are application-level access controls, identity verification, device posture checks, network segmentation, and the replacement of broad VPN-style access with more granular policy enforcement. The longer-term bill is bigger because industrial environments are not like office networks. They are built around uptime, long equipment life, and patching cycles that are measured in years, not weeks. Every additional connected device expands the number of systems that must be monitored, authenticated, and isolated.
There is also a second-order effect that makes the spending case stronger. If AI makes attacks faster and more adaptive, then defenders cannot rely on static controls that were designed for slower threat cycles. Security teams will have to treat AI agents, vendor identities, and machine-to-machine access as first-class risk objects. Sophos said its AI Security 2026 report found attackers are moving beyond experimentation and operationalizing AI, while AI identities have become a new attack surface. That shifts cybersecurity from a perimeter problem to an identity-and-governance problem, which usually means more recurring spending and more consulting, not less.
In that sense, the market’s first instinct — that this is another incremental cyber upgrade cycle — is too small. The better read is that AI is changing the economics of offense and defense at the same time. Offensive tools are becoming cheaper to deploy and faster to adapt. Defensive tools must become more intelligent, more continuous, and more tightly integrated into plant operations. The asymmetry tends to favor the attacker in the short run, which is why manufacturers are likely to keep increasing security budgets even if broader capex remains restrained.
Why The New Threat Is Structural, Not Just Cyclical
The central question is whether this is a temporary wave of AI-assisted attacks or a lasting regime change. The evidence points to structural change. A cyclical spike would imply a burst of activity that fades once a few bad actors are disrupted, once patching catches up, or once a single exploit family is contained. That is not what the current data show. The threat is spread across old camera flaws, legacy Log4j-related detections, ransomware families, cloud-connected credentials, and AI-enabled attack workflows. The common denominator is not one exploit. It is the convergence of IT and OT, and the permanence of that convergence.
SonicWall’s figures are especially telling because they show both a decline in raw prevention volume and a rise in concentrated, high-value targeting. A 56.2% drop in IPS volume sounds like relief until it is paired with 474 million events and with 43 million camera attacks still hitting a single vulnerability. That combination suggests attackers are becoming more selective, not less dangerous. In other words, fewer broad attacks can coexist with greater operational risk if the remaining hits are aimed at critical assets. That is a structural change in attack economics, not a simple ebb and flow.
The manufacturing sector has seen cyber surges before, but the older cycles were easier to explain. Ransomware waves tended to follow periods of weak patching, remote-work expansion, or a well-publicized exploit family. Those episodes had a rhythm: attack volume rose, vendors published guidance, enterprises patched, and the pressure eased. The current cycle is different because the organization of work itself has changed. Factories now rely on connected cameras, predictive-maintenance sensors, remote support channels, and digital production workflows that must remain available even while they are being defended. That creates a persistent security premium.
The mechanism is straightforward. AI lowers the cost of finding weak access paths and raises the speed at which those paths can be exploited. At the same time, the factory environment raises the cost of shutting them off. A corporate IT team can reset credentials, isolate a laptop, or force a software update. A plant operator cannot casually stop a production line without creating downtime, scrap, missed deliveries, and possibly safety risks. That mismatch gives attackers more leverage and forces defenders to pay for layered controls rather than one-time fixes.
The market should therefore think in ratios, not headlines. If AI shortens an attacker’s discovery window while manufacturing equipment remains tied to long-refresh industrial systems, the gap between offense and defense widens. That gap is the spending engine. The more factories automate, the more they must insure, monitor, segment, and verify. The more they connect vendors and remote technicians, the more identity governance matters. The more AI agents are used internally, the more those agents themselves need to be authenticated, constrained, and logged.
This is why the comparable history matters. Old-fashioned malware could be blunted by patching and endpoint hygiene alone. AI-assisted attacks do not require the same crude scale; they can test credentials, adapt social engineering, and target the most consequential accounts. That means the old rule — spend only when you see more incidents — no longer works. Spending now has to rise before the breach, not after it.
"Manufacturing’s attack surface looks nothing like it did even five years ago, and the security model hasn’t caught up," said Michael Crean, SonicWall SVP of Managed Services.
That is the core structural argument in one line. The production floor is now part of the corporate network, and the network is now part of the production floor. Once those domains merge, security becomes a continuous operating expense, not a discrete project.
What The Market Is Already Pricing, And What It Is Not
The obvious counter-thesis is that cyber budgets have already been rising for years, so this story may be priced in. That objection is serious. Security vendors have spent years talking up AI-driven threats, and manufacturers already buy firewalls, endpoint tools, remote-access systems, and incident-response services. If the sector has been spending more for a decade, why would this wave force materially more spending now?
The answer is that the next dollar is being spent on a different problem. Earlier spending mostly protected perimeters. The new spending must protect identities, devices, and operational workflows. That difference matters because it changes who gets paid. Traditional point products may still benefit, but the bigger winner is likely to be vendors that can unify identity, network segmentation, and industrial visibility. Consultants, managed-security providers, and OT-security specialists also gain because factories rarely re-architect these systems on their own.
The market is also likely underpricing the second-order effect on procurement. When attacks become faster and more automated, the buying process itself changes. Security teams have to run tighter approvals, more frequent audits, and more continuous monitoring. That lengthens implementation cycles but deepens contract values. In practice, the spending path can look less like a one-time surge and more like a steady re-baselining of the security budget. That is especially true in manufacturing, where the cost of a breach includes downtime, safety exposure, quality failures, and supply-chain disruption, not just IT cleanup.
There is a useful analogy here. Industrial cybersecurity is becoming a kind of insurance premium on automation. The more a factory depends on connected systems, the more it must pay to make those systems trustworthy. AI does not change that premium in a linear way; it raises the rate because it makes the threat more adaptive. If the attacker can move faster, the defender must buy not just more tools, but more intelligence embedded into the tools.
Still, the counter-case cannot be dismissed. It is possible that some of the headline-driven fear is front-loading purchases that would have happened anyway, and that manufacturers will delay broader capex if margins weaken. A recessionary industrial cycle could temporarily mask the spending benefit for cyber vendors even as the threat rises. That is the strongest near-term bearish view on the spending story: security urgency may not fully offset budget caution elsewhere.
The falsifying signal is specific. If manufacturing cyber spending does not rise in the next two reporting seasons despite continued disclosures of AI-assisted attacks, while OT incident counts and identity-compromise events remain elevated, then the thesis that AI is forcing a new spending cycle would be overstated. In that case, the threat would be real, but the budget response would be slower and more cyclical than structural.
For now, the balance of evidence leans the other way. SonicWall’s data point to persistent exposure, not a temporary spike. Sophos’s warning points to a new class of attacker behavior, not just more of the old kind. Grant Thornton’s manufacturing survey indicates that even as manufacturers adopt AI, the operational payoff remains difficult to prove, which suggests managers are still experimenting while security risk rises underneath them. That combination is exactly the kind of environment that tends to produce delayed but durable spending.
Who Benefits, Who Is Exposed, And What Happens Next
In the short term, the beneficiaries are the vendors selling identity controls, Zero Trust access, industrial monitoring, segmentation, and managed response. Cyber insurers may also see more demand for tighter controls, though pricing and underwriting pressure will remain a separate battle. In the medium term, industrial software and automation firms that can prove secure integration may gain share because customers will increasingly want fewer disconnected tools and fewer unmanaged pathways into plants. In the long term, the exposed names are manufacturers with large legacy footprints, thin IT teams, extensive vendor access, and high dependence on connected OT systems.
The timeline matters. Over the next quarter or two, the impact is likely to show up in budget reallocation and vendor spending discussions, not in a single dramatic line item. Over the next year, it should appear in the broader adoption of identity-centric security controls and industrial segmentation projects. Over a longer horizon, it could reshape factory design itself, pushing new plants toward zero-trust architectures and older plants toward expensive retrofits. That is the most important implication: the security bill is not only about stopping attacks. It is about redesigning how factories connect.
The base case is that cyber spending in manufacturing keeps rising faster than general software spending as AI-assisted attacks become harder to ignore and as the cost of a successful intrusion remains tied to downtime and physical operations. The upside case is that a few high-profile incidents accelerate board-level budgets and pull forward multi-year modernization projects. The downside case is that margin pressure or an industrial slowdown delays spending even while threat severity rises, leaving plants more exposed for longer.
The next signals to watch are straightforward: whether manufacturers disclose larger security budgets, whether OT and identity-security projects move from pilot to rollout, whether insurers tighten underwriting on connected production environments, and whether AI-enabled attack reporting continues to climb. The single most important falsifier would be a clear deceleration in manufacturing security spending even as AI-linked incidents and credential-based intrusions keep rising.
AI is not just giving attackers another tool. It is changing the economics of what it costs to defend a factory. That is why the spending response is likely to be durable, and why the real story is not the attack itself but the new price of keeping the plant running.
Explore more exclusive insights at nextfin.ai.
