A Guide for Navigating Cyber Risks in Engineering and Manufacturing

The risks involved in Australia’s engineering and manufacturing sector can have real knock-on effects on the businesses involved and up and down the supply chain. According to Telstra, in collaboration with Omdia Research, 80% of manufacturing firms globally reported a rise in security incidents in 2024, yet only 45% felt equipped to manage these threats. What’s needed to better prepare your organisation?

This guide explores common challenges, compliance obligations, future trends, and practical strategies tailored to this critical sector in the Australian economy.

Current Outlook for Cyber Security in Manufacturing and Engineering

Several shifts are redefining how firms manage cyber risk. This blog covers each of these points in more depth.

  • Rising Baseline Expectations: Compliance standards are changing. Companies engaged in the Defence Industry Security Program (DISP) must now satisfy the Essential Eight Maturity Level Two across all eight mitigation strategies. The Security of Critical Infrastructure (SoCI) Act also puts requirements on companies judged critical, including risk management initiatives and required cyber event reporting.
  • Stricter Compliance and Legal Exposure: Updates to the Privacy Act, the Cyber Security Act 2024 mean companies must satisfy stricter breach reporting, risk management, and accountability criteria or face significant fines and potentially compensation claims from impacted persons.
  • Cyber Risk is a Governance Priority: Boards and executives are responsible for cyber security. Organisations should quantify cyber risk, ensure accurate reporting, and embed security across all levels of operations.
  • Escalating Threat Sophistication: Threat actors now deploy coordinated ransomware-as-a-service campaigns and exploit IT and OT (Operational Technology) integration gaps. Detection and response should match the pace and complexity of these threats.

What are common cyber threats to engineering and manufacturing?

  • Phishing and Email Compromise: Business Email Compromise (BEC) and Vendor Email Compromise (VEC) have increased significantly over the last 12 months. Usually by phishing, scammers obtain access to email accounts, bypassing multifactor authentication and then using their access to control financial operations, pose as suppliers, intercept invoice approvals, or reroute critical information including board-level decisions. These compromises can result in the theft of economically or personally sensitive data.
  • Ransomware: Ransomware remains a top cyber threat. These attacks encrypt systems or data, demanding payment for restoration. The rise of Ransomware-as-a-Service has made it easier for attackers to launch sophisticated campaigns. Increasingly, ransomware groups also threaten to leak or sell stolen data on dark web sites if ransoms aren’t paid.
  • IP Theft: IP (Intellectual Property) theft of proprietary designs, processes or trade secrets.
  • Insider Threats: Breaches caused by employees, contractors or others with internal access. Breaches can also originate via third-party vendors, underlining the importance of securing the industrial ecosystem.
  • IT/OT Vulnerabilities: Over 75% of OT attacks originate from IT environments. These are weaknesses created when OT is connected to IT systems without adequate security controls. As Industry 4.0 drives integration between IT/OT, the attack surface expands dramatically.
How Engineering and Manufacturing Firms Can Manage Cyber Risks

How Engineering and Manufacturing Firms Can Manage Cyber Risks

Implement the Essential Eight Maturity Model

A set of baseline security practices developed by the Australian Signals Directorate (ASD) and recommended for implementation in manufacturing and engineering firms. These foundational measures minimise the risks of cyber attacks by establishing a foundation for firms to build cyber resilience.

Align with Cybersecurity Frameworks

The NIST Cybersecurity Framework helps businesses manage risk in five categories: Identify, Protect, Detect, Respond and Recover. It is widely recognised alongside standards like ISO 27001 as a best-practice approach that complements the Essential Eight and provides a management system for businesses that promotes continuous improvement, raising and treating of risks and goes beyond a set of technical controls.

Train Staff and Build a Cyber Security Culture

Cyber awareness training should be regular, role-specific and scenario-based to prevent accidental breaches from staff or vendors. Training should be aligned and relevant to all roles, from board members and executives to engineers, frontline staff, administration, finance, and operations teams.

Build a Cyber Security Culture

Cyber security is a shared responsibility across the organisation, not just an IT issue. Leadership should model strong cyber hygiene, set clear expectations, and foster a culture where employees understand and feel empowered to report risks. Embedding cyber security into the broader risk management framework ensures it is regularly reviewed, tested, and improved as threats evolve.

Security Monitoring and Response

A Security Operations Centre (SOC) is critical for detecting and responding to incidents early so firms can contain damage and restore operations before threats escalate further.

Leverage Relevant Guidance

Standard approaches to cyber security often overlook the unique risks in engineering and manufacturing, such as legacy systems, regulatory complexity, and IT/OT convergence. That’s why specialist support is critical. A security-first approach allows your organisation to exercise cyber resilience with frameworks like NIST and the Essential Eight.

Director Responsibilities and Compliance with the Privacy Act

Director Responsibilities and Compliance with the Privacy Act

The Privacy Act and the new Cyber Security Act impose responsibilities on organisations to protect personal information and notify individuals and the Office of the Australian Information Commissioner (OAIC) in cases of significant breaches. Directors are encouraged to understand and drive cyber security as part of their corporate governance responsibilities.

The Cyber Security Act introduces mandatory reporting concerning ransomware, a Cyber Incident Review Board, and requirements for IoT devices. Proposed amendments to the Privacy Act include the removal of exemptions for small businesses, stipulating breach notifications within 72 hours, and allowing individuals to undertake civil litigation for violation of the Privacy Act.

The direction in which regulations are moving is quite evident: boards and executives need to become active participants in managing cyber risk, ensure plausible reporting, and implement structures such as the Essential Eight and NIST to improve organisational resilience.

Conclusion

Cyber security has become a necessary investment for Australian engineering and manufacturing firms. A layered cyber security approach that implements staff awareness, adherence to compliance frameworks, and technical defences can prevent exposure to myriad threats. With the right expertise and a commitment to resilience, engineering and manufacturing firms can protect their operations, reputation, and future growth.

Rodin Can Prepare Your Firm For Today’s Cyber Threats

At Rodin, we tailor solutions for engineering and manufacturing businesses to help you address evolving threats, meet compliance obligations, and protect critical assets. Our team understands your sector’s unique IT and OT challenges and works closely with you to design a secure, future-ready environment. 

Visit our website to get in touch and learn how we support the engineering and manufacturing sector.

Related Blogs

Lee Hodgson

Technology Strategist
Helping businesses and other organisations get the most from their IT systems and business technology, Lee is passionate about business technology and how processes can improve productivity, minimise risk, reduce costs and even provide a competitive edge. Lee and his team of professionals provide excellent technology consultancy, taking the time and effort to understand the processes and challenges within an organisation to make informed recommendations.
Lee Hodgson

Subscribe to Our Newsletter

Sign up to receive all the latest news updates straight into your inbox.