Understanding how employees’ use of AI tools exposes company data is becoming vital to manufacturing cyber security. Patricia Egger, head of security at Proton Drive and co-founder of Women in Cyber Switzerland, explains how manufacturers can reduce risks and build better security habits.

A report found that 30 per cent of manufacturers have experienced a cyber incident in the past 12 months, with 31 per cent of those reporting delays to customer deliveries following the attack.

With only half of manufacturing firms having an incident response plan in place, cyber security expert Patricia Egger, head of security at Proton Drive and co-founder of Women in Cyber Switzerland, has warned that manufacturing businesses need to make a fundamental shift in their company culture to prevent cyber attacks.

Get the manufacturing cyber security foundations right

Reducing reliance on passwords and moving towards passkeys and cryptographic authentication removes a key attack vector. Pairing this with secure devices, continuous monitoring, awareness training and basic cyber hygiene means treating identity, devices and employees as equally important parts of the strategy.

Provide sanctioned and secure AI tools

New AI tools are appearing every day, making it hard to keep track of what is available and what employees are using. In a business without a dedicated security function, nobody is even trying to keep track, and that is where exposure builds up quietly.

Providing a sanctioned AI tool that meets employees’ needs and is convenient will limit shadow AI use. Configure it according to company policies as much as possible and set up additional security controls. Employees should not need any particular knowledge of security or encryption to be protected; it should come with the product.

To strengthen manufacturing cyber security, reduce the number of tools, applications and systems the organisation uses and must therefore support. Keep the toolset small and permissions minimal to keep the business as secure as possible.cyber security

Set clear norms to prevent accidental oversharing

Often, an AI assistant will be granted access to email, files or calendars without an employee registering it. Its access then outlives the task it was installed for and puts company data at risk.

Employees can also slip into a vicious cycle of feeding AI agents incremental amounts of information until they are sharing data they would not have shared on day one.

Leaders need to interrupt this drift with clear, concrete norms about what goes into which tool, and with sanctioned tools that are secure by default, so employees do not need a security mindset just to do their jobs safely.

Build verification habits into the culture

The vast majority of attacks involve some level of social engineering that no technology can fully fix, so verification habits should be built into the culture. This is especially important as AI makes impersonation cheaper and more convincing.

Employees should feel empowered to hang up and call back through a known channel to check whether a call is legitimate. Organisations should ensure all employees know their most important asset to protect, as well as the level of risk associated with their accounts and systems, to help prevent social engineering attacks.

Keep permissions to a minimum and strengthen authentication

Phishing attacks remain the most prevalent type of breach or attack, but the phishing threat has industrialised. Passwords were conceived in an era when phishing was largely manual. That era is over, and the answer is not stronger passwords, but fewer passwords and defence in depth, with authentication built on cryptographic proof rather than human memory.

Prioritise the first steps in manufacturing cyber security

Patricia Egger said: “The big breaches are almost never one dramatic failure. They’re many small things that seemed entirely unimportant in isolation – that together let an attacker gather intelligence or hop from one system to another. One might be nothing. A hundred nothings can become something.

“The simplest way to secure a manufacturing business is to start by deciding what’s actually important, because if everything’s important, nothing is. It’s uncomfortable, but choose: maybe this year, ‘important’ means your email and your customer data, and you focus your energy there rather than trying to protect everything equally. Don’t aim to achieve perfection as it isn’t conducive to actual change – start small, and in a year the progress compounds.”

Read other recent UK Manufacturing news: https://uk-manufacturing-online.co.uk/category/news/

Screenshot 2026 02 18 at 09.35.09

Screenshot 2026 02 18 at 09.35.28