Protect production and the intellectual property behind it.
In manufacturing, a cyber incident can stop production lines and expose designs that took years to develop. We help manufacturers keep corporate IT and production systems apart, meet NIS2, Cyber Resilience Act, and defence supply chain requirements, and introduce AI into engineering and operations under clear rules.
Situations we help with
Across aerospace and defence; industrial and engineering manufacturing; automotive and transport equipment; and electronics and connected products.
- Production systems and corporate IT share network paths, and a ransomware incident in an office system could reach the factory floor.
- A defence customer has set a Cyber Risk Profile under Def Stan 05-138, and your controls or evidence do not yet meet it.
- Your connected products will fall under the Cyber Resilience Act, and nobody owns vulnerability handling or reporting.
- Designs and engineering data are shared with partners and suppliers without consistent controls on who can access what.
- Engineers want to use AI with design or production data, and there is no agreed rule on which services may see it.
The challenges
Production systems meet corporate IT
Factory control systems, machines, and quality systems connect to corporate networks and the cloud for planning and analytics, and each connection can carry risk onto the production floor. Changes need planning around production schedules and safety.
Intellectual property at risk
Designs, engineering data, and manufacturing processes are valuable to competitors and attackers, and they can move between sites, partners, and suppliers.
Defence and customer requirements
Aerospace and defence suppliers face contractual cyber requirements from their customers, including the Ministry of Defence's Cyber Security Model, and those requirements flow down to their own suppliers.
Products with digital elements
Manufacturers of connected products take on obligations for their products' security over the support period, including vulnerability handling and reporting under the Cyber Resilience Act.
ENISA's 2025 threat landscape lists manufacturing among the five most targeted sectors in the EU, alongside public administration, transport, digital infrastructure and services, and finance.
AI in aerospace and manufacturing
Predictive maintenance and quality
- The value
- Less unplanned downtime and fewer defects.
- What needs governing
- Models that need data from production systems, opening new connections onto the factory floor.
Engineering and design assistance
- The value
- Faster design iterations and documentation.
- What needs governing
- Designs and export-controlled data sent to services the organisation has not approved.
Supply chain and production planning
- The value
- Better scheduling and inventory decisions.
- What needs governing
- Plans built on poor data, and no clear owner when an automated recommendation is wrong.
AI Factory Design sets which AI services may use engineering and production data, and how their outputs are approved, so AI can scale without exposing intellectual property or production systems. It is part of our AI Governance and Transformation practice.
Regulation that may apply
NIS2 (EU)
- Applies to
- Manufacture of electronic and electrical products, machinery, motor vehicles, other transport equipment, and medical devices is among the other critical sectors, where entities meet the size thresholds in each Member State's law.
- What it asks
- The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
- Timing
- Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.
Cyber Resilience Act (EU)
- Applies to
- Manufacturers of products with digital elements made available on the EU market.
- What it asks
- Security requirements across design, production, and the support period, vulnerability handling, and reporting of actively exploited vulnerabilities and severe incidents.
- Timing
- Reporting obligations apply from 11 September 2026 and the main requirements from 11 December 2027.
Def Stan 05-138 (UK defence)
- Applies to
- Suppliers on Ministry of Defence contracts that include DEFCON 658, and their own supply chains.
- What it asks
- Controls set by the contract's Cyber Risk Profile, from Cyber Essentials at the lowest level to the full control set at the highest, evidenced through the Supplier Assurance Questionnaire.
- Timing
- Issue 4 and Cyber Security Model version 4 have applied to contracts containing DEFCON 658 since 3 December 2025.
Recommended engagements
Zero Trust Transformation
Separates production systems from corporate IT and controls partner access to engineering data.
View engagementAI Factory Design
Sets which AI services may see design and production data, with approval where outputs affect products.
View engagementNIS2 Readiness Diagnostic
Establishes which manufacturing entities NIS2 applies to in each Member State before programme spending starts.
View engagementCloud Landing Zone Design
Gives engineering, planning, and analytics workloads a governed cloud foundation across sites.
View engagementCase studies
Confidence in someone else's delivery: independent assurance for a FTSE 100-listed manufacturer's Azure migration
Meggitt
Evidence before commitment: an independent security assessment for a regulated aerospace manufacturer
Meggitt
Shrinking the blast radius: segmentation and access governance in a high-consequence environment
Meggitt
