Tec Nikan
فارسی
Talk to us
All news

Three Quarters of Large Manufacturers Carry Critical Vulnerabilities

Black Kite's numbers show patching improving slowly, credential exposure not moving at all, and internet-exposed remote-access ports essentially unchanged since 2023.

OT securityransomwaresupply chain riskresearchmanufacturing

A Black Kite report covered by Manufacturing Dive on 18 September puts numbers on manufacturing cybersecurity, and the interesting part is which numbers moved and which did not.

Roughly 75 percent of the top 1,000 manufacturers analysed had critical software vulnerabilities, and 54 percent had vulnerabilities already being exploited by attackers. Around 70 percent had employee or system credentials exposed on the dark web. More than a third showed botnet malware infections, about 30 percent had already experienced data breaches, nearly half were impersonated in phishing campaigns, and more than a third had not properly configured DMARC email anti-spoofing.

Patching improved: critical vulnerability exposure fell from 80 percent in 2024 to 75 percent in 2026. Credential exposure did not budge. And internet-exposed remote-access ports sat at 51.9 percent, against 51.3 percent in 2023 — three years, no change.

That last figure is the one worth sitting with, because those ports are how OT networks get reached. Patching faster while leaving the front door in the same place is not a net improvement in risk, and the data says the industry has been doing exactly that.

The ransomware distribution is equally pointed. Black Kite counted more than 1,180 manufacturing victims since early 2026, and 70 percent were mid-market firms with annual revenue between $10 million and $100 million. Misconfigured technology affected 71 percent of 2026 victims. That revenue band describes companies large enough to be worth attacking and small enough to have nobody whose job is OT security — which is where the risk now concentrates.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.