Human error, IT/OT confusion, burnout and weak training continue to expose manufacturers to preventable cyber incidents.

By Chris Brown
Manufacturing firms are more likely than those in any other industry worldwide to experience cyberattacks. In 2025, attacks on manufacturers accounted for 27.7% of all international incidents. Therefore, there is a greater focus than ever within the industry on prioritizing protection against evolving threats.
However, cyber incidents do not always occur simply because attackers use highly sophisticated tools and techniques. In many cases, manufacturing cyberattacks occur because of internal human error—mistakes or oversights that can easily be avoided.
Human error is a key driver in manufacturing cybersecurity incidents, largely due to operational complexities created by IT/OT convergence. Personnel are also under increasing pressure to maintain uptime, potentially leading to burnout and simple security mistakes and oversights. A third trigger is inadequate training and failing to provide employees with the specialized knowledge required to recognize and respond to cybersecurity incidents.
All three triggers vary in scale and effect from firm to firm, but each creates gaps in proactive security that real-world attackers are actively seeking. Managed threat detection and response is one way to close these gaps, lifting the effort off stretched internal teams, to ensure routine monitoring, threat investigations, and event containment all happen continuously.
The blending of IT and OT in manufacturing environments offers firms a variety of efficiency and visibility benefits. However, this complex convergence of disparate systems and operations leads to a broader attack surface and potentially causes confusion for employees, resulting in human errors.
OT systems prioritize uptime, while IT systems frequently prioritize security and confidentiality. An employee working in OT may be so focused on maintaining uptime that they overlook the security requirements meant to keep data protected, or make simple errors along the way.
For example, they may use unauthorized workarounds to hit targets, or ignore time-consuming security protocols to ensure OT targets are met.
However, security issues across IT/OT blending cannot be blamed entirely on employees taking shortcuts.
Research claims that while the majority of manufacturers have seen security incidents “increase” in 2024, less than half are sufficiently prepared to secure their converged IT/OT environments effectively.
“According to Telstra and Omdia, IT/OT integration among manufacturers in the US, Latin America and Europe is on course to increase from 50% to 70%. Asia and Oceania is starting from a lower base of 40%, rising to 60%.
And while 86% of the 500 manufacturers surveyed said IT/OT integration is important for business outcomes, Omdia and Telstra claim that only 19% of them can be considered ‘advanced’ when it comes to securing their IT/OT environments.”
Burnout runs high across US industries, and manufacturing is no exception. In one survey, over 70% of manufacturing staff said they had considered leaving their roles because of burnout within a single year. Heavy workloads account for 43% of burnout triggers across the board.
“Cybersecurity fatigue” sets in when stressed or overloaded employees overlook or intentionally miss security protocols in an effort to meet OT demands.
Such mistakes, made when overwhelmed, can include falling for phishing and social engineering tricks, bypassing rudimentary controls, and reusing the same passwords to access multiple systems.
Ways to reduce this cause of human error may include:
While cyberattacks continue to grow more sophisticated and threatening to IT/OT convergence, research shows there are still significant gaps in cybersecurity awareness and understanding in manufacturing.
Alqudhaibi et al (2024) suggest that these gaps are exacerbated by, for example, low funding and poor training standards.
Manufacturing firms under pressure to meet OT uptime and related targets may apply generic security training across their workforces to save time and reduce pressure.
However, generic, check-box security training leads to poor knowledge retention and is not conducive to behavioral change.
In short, manufacturing staff are making errors because their training is failing them.
Alqudhaibi et al recommend implementing awareness campaigns across entire workforces, improving equipment procedures, and maintaining ongoing training programs to support knowledge retention.
The exact training needs for one workforce will differ from the next, meaning there is a growing demand for customized, continuous programs to boost awareness and knowledge.
Continuous training is also important to help combat the increasing sophistication of threats facing OT environments, which are particularly sought after by attackers because of their critical operations.
Yes, it is a leading cause of cyberattacks across industries. According to Verizon’s 2026 Data Breach Investigations Report, a “human element” was discovered in 62% of all breaches they investigated for 2025.
Manufacturers can reduce human errors by running microlearning modules to reduce training fatigue, simulate threat scenarios, and build an open, communicative cybersecurity culture. Automating security enforcement, too, reduces workforce stress and potentially human error.
Human error continues to be a leading cause of cybersecurity weakness in manufacturing and across industries. However, the convergence of IT/OT, workload fatigue, and poor-quality training are all key triggers for security errors specifically within the sphere.
A holistic approach to IT/OT planning, embedding stronger security controls by default, and rethinking more engaging training strategies can all help to reduce error prevalence.
Doing the work to reduce human error looks different for every organization. Manufacturers must prioritize cybersecurity with adequate resources now, to avoid escalating costs and damage later.

About the Author:
Chris Brown is a senior cybersecurity and product marketing leader with over 15 years of experience across cybersecurity, information systems auditing, product management, and marketing. As a Senior Product Marketing Manager at VikingCloud, Chris helps businesses understand how to navigate complex security challenges through solutions that support secure, uninterrupted operations and align with risk management frameworks.
Prior to joining VikingCloud, Chris led product management initiatives for over a decade, building software and services that enable clients to confidently navigate risk and compliance obligations. Now in marketing, he leverages that same understanding to connect customers with the tools and services they need to secure their systems and make informed decisions.
Chris holds a BSBA from the University of Colorado at Boulder, with dual emphases in Accounting and Operations & Information Management. He also maintains several industry certifications, including CISSP, CISA, CRISC, and PCIP.
As manufacturers offer more customization than ever before, managing product complexity has become a critical challenge. Tune in with Dan Joe Barry, Vice President of Product Marketing at Configit, who explores how companies are tackling the growing number of product configurations across engineering, sales, manufacturing, and service. He explains how Configuration Lifecycle Management (CLM) helps organizations maintain a single source of truth for configuration data. The result: fewer errors, faster quoting, and the ability to deliver customized products at scale.