Aerospace and manufacturing

Protect production and the intellectual property behind it.

In manufacturing, a cyber incident can stop production lines and expose designs that took years to develop. We help manufacturers keep corporate IT and production systems apart, meet NIS2, Cyber Resilience Act, and defence supply chain requirements, and introduce AI into engineering and operations under clear rules.

Situations we help with

Across aerospace and defence; industrial and engineering manufacturing; automotive and transport equipment; and electronics and connected products.

  • Production systems and corporate IT share network paths, and a ransomware incident in an office system could reach the factory floor.
  • A defence customer has set a Cyber Risk Profile under Def Stan 05-138, and your controls or evidence do not yet meet it.
  • Your connected products will fall under the Cyber Resilience Act, and nobody owns vulnerability handling or reporting.
  • Designs and engineering data are shared with partners and suppliers without consistent controls on who can access what.
  • Engineers want to use AI with design or production data, and there is no agreed rule on which services may see it.

The challenges

Production systems meet corporate IT

Factory control systems, machines, and quality systems connect to corporate networks and the cloud for planning and analytics, and each connection can carry risk onto the production floor. Changes need planning around production schedules and safety.

Intellectual property at risk

Designs, engineering data, and manufacturing processes are valuable to competitors and attackers, and they can move between sites, partners, and suppliers.

Defence and customer requirements

Aerospace and defence suppliers face contractual cyber requirements from their customers, including the Ministry of Defence's Cyber Security Model, and those requirements flow down to their own suppliers.

Products with digital elements

Manufacturers of connected products take on obligations for their products' security over the support period, including vulnerability handling and reporting under the Cyber Resilience Act.

ENISA's 2025 threat landscape lists manufacturing among the five most targeted sectors in the EU, alongside public administration, transport, digital infrastructure and services, and finance.

Source: ENISA Threat Landscape 2025, October 2025

AI in aerospace and manufacturing

Predictive maintenance and quality

The value
Less unplanned downtime and fewer defects.
What needs governing
Models that need data from production systems, opening new connections onto the factory floor.

Engineering and design assistance

The value
Faster design iterations and documentation.
What needs governing
Designs and export-controlled data sent to services the organisation has not approved.

Supply chain and production planning

The value
Better scheduling and inventory decisions.
What needs governing
Plans built on poor data, and no clear owner when an automated recommendation is wrong.

AI Factory Design sets which AI services may use engineering and production data, and how their outputs are approved, so AI can scale without exposing intellectual property or production systems. It is part of our AI Governance and Transformation practice.

Regulation that may apply

NIS2 (EU)

Applies to
Manufacture of electronic and electrical products, machinery, motor vehicles, other transport equipment, and medical devices is among the other critical sectors, where entities meet the size thresholds in each Member State's law.
What it asks
The management body approves the cybersecurity risk management measures, oversees their implementation, and undergoes training. A significant incident requires an early warning to the CSIRT or competent authority without undue delay and within 24 hours of becoming aware.
Timing
Applies through national law. The transposition deadline was 17 October 2024, and Member States have adopted their laws at different times.

Cyber Resilience Act (EU)

Applies to
Manufacturers of products with digital elements made available on the EU market.
What it asks
Security requirements across design, production, and the support period, vulnerability handling, and reporting of actively exploited vulnerabilities and severe incidents.
Timing
Reporting obligations apply from 11 September 2026 and the main requirements from 11 December 2027.

Def Stan 05-138 (UK defence)

Applies to
Suppliers on Ministry of Defence contracts that include DEFCON 658, and their own supply chains.
What it asks
Controls set by the contract's Cyber Risk Profile, from Cyber Essentials at the lowest level to the full control set at the highest, evidenced through the Supplier Assurance Questionnaire.
Timing
Issue 4 and Cyber Security Model version 4 have applied to contracts containing DEFCON 658 since 3 December 2025.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.