Industries

Manufacturing & trades

The machine can't be patched. That was never the plan.

Most IT providers look at a controller running an operating system that went out of support before the iPhone existed and tell you to upgrade it. You can't, the vendor's gone, and revalidating the cell costs more than the machine is worth. So we do the thing that actually works instead: we stop the office network from being able to reach it.

Where the plant meets the office

In a lot of factories, the CNC and the payroll PC are on the same flat network.

Not because anyone decided that. Because a machine needed a data drop in 2013, there was a spare port in the office switch, and it worked. Fifteen machines later, that is the network.

What we find on the floor Why it can't just be patched What we do instead
CNC controller on Windows XP or 7 embedded The control software is tied to that OS version and the machine builder no longer ships updates Put it on its own VLAN with no internet path and a strict allow-list of who may talk to it
PLC or line controller with a flat, unauthenticated protocol Industrial protocols were designed for a private wire, not a routed network. There is often no password to set Segment the cell, control what can reach it, and log what does
SCADA or HMI PC nobody will touch Any change risks revalidation, and the person who commissioned it left in 2019 Image it so it can be rebuilt in an afternoon, then isolate it and leave it alone
Vendor remote support left permanently open The machine builder needs access, and the original install was "whatever gets it working today" Brokered access that is off by default, turned on for a named person for a named window, and recorded
A shared account with the password on a laminated card Three shifts, gloves, and a touchscreen. Individual logins genuinely slow the line down Accept it on the floor, contain the blast radius, and make sure that account can't reach finance

Say this back to any provider bidding for your work: the answer to legacy machinery is segmentation, not patching. If they respond by quoting you a replacement for the machine, they've never worked in a factory. Patch what you can patch. Isolate what you can't. That's the whole strategy, and it's achievable in weeks rather than capital cycles.

The scenario that costs you

Ransomware rarely starts on the plant floor. It just ends up there.

It starts in the office. Someone in accounts opens the wrong attachment, or a password that was reused turns up in a breach dump. From there it spreads to whatever it can reach.

On a flat network, what it can reach includes the machine controllers. Not because they were targeted — they're just addressable. And a controller that gets encrypted, or simply knocked over by a scan it wasn't built to survive, stops the line.

Segmentation is what makes the difference between a bad week in the office and a stopped plant. It's the single highest-value piece of work we do for manufacturers, and it doesn't require you to touch a single machine.

ERP

When the ERP stops, despatch stops. When despatch stops, invoicing stops.

Manufacturers are usually clear-eyed about this in a way other industries aren't. You know which system is load-bearing. It's the one where an outage at 9am means trucks sitting in the yard at 11.

Systems we see

Pronto, MYOB Advanced (Acumatica), SAP Business One, Odoo and Cin7 come up most often in Australian mid-market manufacturing, usually alongside a warehouse or MES add-on and a pile of Excel that nobody admits to.

Where it actually breaks

Rarely the application. It's the database server that ran out of disk, the integration that silently stopped posting overnight, the SQL maintenance plan that was never set up, or a reporting query that brings the whole thing to its knees at month end.

Upgrades and cloud moves

Plenty of these are in flight right now. We work alongside your ERP partner rather than pretending to be them: identity, network, data migration, cutover planning and the rollback you hope you don't need.

Availability, in dollars

You can put a number on an hour of downtime. Most businesses can't.

That makes this conversation much better than the one we usually have. It also means vague promises are useless to you, so here's what the words mean.

RTO — how long until you're running again

Recovery time objective. Not "we monitor 24/7". The actual answer to: the ERP server has died, it is 6am, what time are we taking orders again. If nobody has tested the restore, the honest answer is that nobody knows.

RPO — how much work you lose

Recovery point objective. If backups run nightly at 10pm and the server fails at 4pm, you've lost a day of despatch dockets, receipts and production data. Somebody has to re-key all of it from paper, if paper exists.

The bit that makes it real

We work out your cost per hour with you — lost production, idle labour, late delivery penalties, the freight you have to expedite to catch up. Then we price recovery options against it. Sometimes the answer is that a four-hour RTO isn't worth paying for. That's a fine answer, as long as it's a decision rather than an accident.

Questions worth asking your current provider

  1. When did you last restore our ERP database, as opposed to checking that the backup job said "success"?
  2. How long did that restore take, start to finish, and who timed it?
  3. If the site burned down tonight, where does the data live and how do we get to it?
  4. Which of our backups are stored somewhere ransomware can't reach from our network?
  5. What's our documented RTO and RPO for the ERP, and who signed off on those numbers?

If the answers are uncomfortable, that's worth knowing now rather than at 6am. We're happy for you to ask us the same five questions.

Regulation, honestly

You are probably not regulated. Your customer is, and that's how it reaches you.

A lot of IT marketing implies manufacturers are covered by the Security of Critical Infrastructure Act. For most of you that is simply not true, and you should be suspicious of anyone selling on it.

The SOCI Act applies to defined critical infrastructure sectors. Here they are:

ElectricityGasLiquid fuelPortsFreightBankingInsuranceSuperannuationFinancial market infrastructureBroadcastingTelecommunicationsDomain name systemsData storage and processingFood and grocery

General manufacturing isn't on that list. A sixty-person injection moulder in the western suburbs is out of scope, full stop. The one genuine exception worth flagging: if you make food or groceries and supply a major grocery chain at scale, the critical food and grocery asset provisions may catch you, and that's worth checking properly rather than guessing.

For everyone else the effect is real but indirect. Your customer is regulated. Regulated entities have to manage risk in their supply chain. So the obligation arrives as a vendor security questionnaire with a thirty-day deadline, sent by a procurement team who will not accept "we use a good IT company" as an answer.

Field and trades staff

Half your people aren't in the building, and coverage is patchy.

Installers, service techs, delivery crews. They need job details, schedules, photos, sign-offs and timesheets from a phone or tablet, often in a basement, a shed or a paddock with one bar.

  • Offline capability that's tested where it matters. Any app can look fine on the office Wi-Fi. What counts is whether a job can be completed with no signal and synced later without duplicating it.
  • Devices enrolled and replaceable. A phone that goes in a puddle on Tuesday should be replaced Wednesday with everything already on it.
  • Personal phones handled properly. Work data separated from the rest of the device, so a wipe doesn't take someone's photos with it.
  • One set of credentials. Field staff should not be keeping four logins in a notes app. That's how passwords end up written on the inside of a toolbox lid.

When manufacturers usually ring

"The line stopped and IT couldn't tell us why."

Or worse: something got from the office network onto the plant network and nobody could say how far it went.

"Our biggest customer sent a security audit and we have thirty days."

Usually the first time anyone has asked the business to prove anything in writing.

"The ERP is moving and we don't trust our current provider to do it."

A fair instinct. An ERP cutover is the one project where being cautious costs less than being optimistic.

Start with a look at the network.

A free IT review for a manufacturer usually begins with one question: what can the office network reach on the plant floor. We'll map it, tell you what we found, and put it in writing whether or not you use us.