OT Cybersecurity Is a Line-Uptime Problem Now

For packaging and processing plants, plant-floor security has moved out of the IT column. Recovery costs run four to six times higher than IT, connected lines have expanded the attack surface, and attackers don't need to reach the machine to stop production

The best intentions of IT don't always transfer seamlessly to the plant floor.
The best intentions of IT don't always transfer seamlessly to the plant floor.
Sean Riley

OT cybersecurity has grown into a production risk, a business-continuity risk, and in some cases, a safety risk. That was the central takeaway from Ashley Wolfe of Wolfe Evolution during her OT SCADA Con presentation on OT cybersecurity and ICS pentesting: the consequences of a cyber incident in operations do not remain confined to the IT department for long. In manufacturing environments, they quickly become problems measured in lost throughput, halted lines, delayed shipments, and third-party recovery costs — and they consume leadership attention along the way.

The message should resonate strongly with packaging and processing professionals. Modern plants depend on increasingly connected environments. Equipment that was once isolated now often communicates with plant networks, enterprise systems, cloud dashboards, OEM support platforms, and remote vendor-access tools. Those connections create efficiency, visibility, and service advantages. They also create exposure.

The presentation made the business case in stark terms. According to Wolfe, 70% of critical infrastructure sectors have reported OT-targeted incidents in the last three years, with an average attacker dwell time of 200 days before detection. OT incidents carry recovery costs four to six times higher than IT incidents. The reason is straightforward: when office IT systems go down, the business is disrupted. When OT systems go down, production can stop altogether.

Why IT playbooks don't fit OT

That distinction matters deeply in packaging and processing. A traditional IT mindset often prioritizes confidentiality first. On the plant floor, availability usually comes first. A server reboot may be an inconvenience in the front office. A reboot, scan, or patch at the wrong moment in a live controls environment can disrupt a line, overwhelm a PLC, or interfere with operations. The presentation captured that tension clearly: many standard IT security practices do not translate neatly into OT environments.

For manufacturers, that does not mean OT systems should be left untouched. It means plant cybersecurity needs to be designed around production realities.

When the attack doesn't touch the machine

One of the most useful examples in the session was Colonial Pipeline. The presentation noted that the attackers did not directly compromise OT systems, yet the company still shut down operations because it lost visibility into its supporting business systems. The lesson for packaging and processing manufacturers is hard to ignore. A cyberattack does not need to manipulate machines directly to stop production. If an incident affects the systems that monitor, support, bill, schedule, or validate operations, a company may decide it cannot run safely or with confidence.

That scenario is increasingly relevant as packaging lines become smarter and more connected. OEM remote-service links, cloud-based analytics, line-integration platforms, and plant-to-enterprise data flows all expand the operational attack surface. In many facilities, these capabilities were added over time for good business reasons, but not always with a full security review.

Start with visibility, not spend

The presentation's strongest practical point was that manufacturers do not have to start with a seven-figure cybersecurity program. They can start with visibility.

The recommended first steps were deliberately basic: capture network traffic long enough to identify devices and their periodic communications, build an OT asset inventory, document IP addresses and priority levels, identify where OT connects to external systems, audit remote access, and determine the true cost of one hour of unplanned downtime. For packaging and processing plants, that is the operational foundation of OT security.

In other words, before asking leadership for a budget, manufacturers should be ready to answer a few simple questions. What exactly is connected on the line? Which systems touch IT, the cloud, or third-party vendors? Who has remote access into the environment? Which assets are most critical to production? And what is the hourly cost if a filler, wrapper, palletizer, batching system, or process line goes down?

Those answers are what turn OT cybersecurity from a technical warning into a management issue leaders can act on. The presentation emphasized that leadership teams rarely respond to vague risk language alone. They respond to quantified business impact: downtime, recovery expense, liability, and exposure.

A line-uptime strategy, not an IT upgrade

For OEMs, the takeaway is clear. OT cybersecurity in packaging and processing should not be framed as an abstract IT upgrade. It should be framed as a line-uptime strategy. In highly automated manufacturing, cyber resilience is now part of operational resilience.

The organizations that make progress will likely be the ones that start with the simplest move of all: beginning the conversation, mapping the environment, and treating cybersecurity as part of the cost of keeping production running.