THALES BLOG

Establishing an IAM Blueprint for Securing Manufacturing Environments

Published: July 26, 2022

Last Updated: August 25, 2026

Danna Bethlehem Danna Bethlehem | Director, Product Marketing More About This Author >

The manufacturing sector is crucial to the economic prosperity of all countries. Products made by these manufacturing industries are essential to many other critical infrastructure sectors. An attack on or disruption of certain elements of the manufacturing industry could disrupt essential functions across multiple sectors, affecting both the national economy and security.

Here's a quick rundown of manufacturing security threats and a blueprint for establishing strong identity and access management (IAM) to mitigate these threats as a manufacturer.

Must-Know Manufacturing Security Threats

Manufacturing environments are facing not only internal challenges with digital transformation but also external challenges with targeted cyber threats. That’s because as industrial networks become increasingly connected to cloud environments and enterprise systems, the attack surface expands, leaving critical infrastructure and production lines vulnerable to sophisticated adversaries.

Attackers are increasingly disrupting operations

The 2026 IBM X-Force Threat Intelligence Index found that manufacturing was the most targeted industry for digital attacks for the fifth consecutive year, accounting for 27.7% of all incidents observed, with data theft the most common outcome.

While exploitation of public-facing applications has overtaken credential abuse as the leading initial access vector, credentials remain implicated in roughly a third of intrusions and are the dominant mechanism by which attackers escalate and cause damage. In North America, credential harvesting drove 43% of observed impacts, according to the same IBM report.

Attacks are moving from IT to OT

Modern manufacturing operations rely heavily on interconnected software supply chains, remote vendor access, and unified information technology (IT) and operational technology (OT) architecture to drive efficiency. This unification is a double-edged sword: While it often unlocks solid operational gains, it also creates new opportunities for adversaries to pivot from enterprise networks directly into production systems.

It’s no longer necessary to physically breach facilities to cause operational downtime. Attackers can simply compromise vulnerable third-party software, managed service providers, or privileged user credentials within enterprise environments and then move laterally across IT networks into OT assets.

The scale of this vulnerability is evidenced in the IBM report, which indicates large supply chain and third-party compromises have “nearly quadrupled since 2020” as adversaries focus their efforts on where software is built and deployed.

To add digital insult to equipment injury, the 2026 Verizon Data Breach Investigations Report reveals that breaches involving third parties reached 48% — a 60% year-over-year increase — with ransomware driving 61% of all manufacturing malware breaches.

“Ransomware is still, in large part, the driving force behind both the growth in breaches and the prominence of system intrusion incidents.”


– 2026 Data Breach Investigations Report: Manufacturing Snapshot

That’s because when adversaries gain an initial foothold in corporate IT systems, hijacked credentials allow them to cross the IT-OT boundary, compromise supervisory control systems, and disrupt physical assembly lines.

Strong access controls are paramount

A cornerstone to protecting this hybrid environment is building strong access controls with appropriate multifactor authentication methods. The increased reliance on and importance of secure credentials is reflected the fact that 52% of organizations regard IAM as their most pressing security discipline, according to the 2026 Thales Data Threat Report.

To build security resilience without impeding operations, your security team needs a structured framework tailored to the unique realities of both connected shop floors and enterprise IT. The success of digitalization of the manufacturing sector depends on establishing trust relationships between internal employees, remote employees and partners, devices, and services. To establish these trust relationships, in place Identity and Access Management (IAM) systems will need several features and requirements as shown in the table below.

IAM Blueprint for Securing Manufacturing Environments

FeatureExplanation
Flexibility and elasticity to support deployment in a variety of scenarios and support a varying level of authentication journeysIAM acts as the bridge that creates a trusted connection between the IT domain and the OT environment, enabling the authenticated and authorized access of all personnel regardless of their role or position.
Support a variety of protocols and systems

 

RADIUS or application gateway for legacy, on-premises applications, and systems
  • SAML, OpenID Connect, or OAuth for web and cloud based apps
  • RESTful APIs, System for Cross-Domain Identity Management (SCIM) for non-standard legacy applications
  • Agents for non-standard applications
  • Compliance with standing acts and regulations for enhancing the cybersecurity posture of critical infrastructureThe 2021 White House Executive Order provides a framework of actions on modernizing cybersecurity with the adoption of zero trust and the deployment of multi-factor authentication and encryption.
    The OMB strategy for zero trust mandates all industries to provide phishing resistant multi-factor authentication methods, such as FIDO2 and PKI-based authentication to reduce the potential of advanced attackers breaking authentication through social engineering campaigns. This Zero Trust policy enforcement is aligned with OMB M-22-09 and CISA guidelines.

     

    How to reduce the risk of breach

    Thales’s SafeNet Trusted Access comes with powerful authentication capabilities to support a broad range of use cases within a manufacturing environment:

    • Secure access leveraging access management, adaptive and multi-factor authentication for both OT and IT worlds
    • Clientless authentication suited to shared workstations and mobile-free environments (Pattern-based, FIDO)
    • Authentication for knowledge workers and privileged users, depending on their user circumstances
    • Meet the guidelines for MFA that is resistant to Man-in-the-Middle attacks (FIDO2 and PKI certificate-based authentication)

    Use this infographic to learn more on how to reduce cyber risk using Multi-Factor Authentication, or you can download our FREE whitepaper on reducing the risk of breach from identity compromise.