
October 2026 | Industrial Cybersecurity Salt Lake City | Cybersecurity Awareness Month | Manufacturing Security Myths
October is Cybersecurity Awareness Month — a good time to take stock of what you actually know versus what you think you know about protecting your Salt Lake City manufacturing operation. Not all of the advice out there is accurate. Some of it has circulated around plants and shop floors for so long that it sounds like fact, even when it's outdated or flat-out wrong.
Here's the blunt truth: when bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. In manufacturing, those blind spots don't just leak data — they stop production lines. Every hour a line sits idle, revenue walks out the door.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from manufacturers regularly, along with the truth behind each one.
Myth 1: "Hackers Only Target Tech Companies, Not Manufacturers"
This one is dangerously backwards. Manufacturing is consistently ranked among the top three most-targeted industries for ransomware — and attackers know exactly why. When your ERP goes dark and the production line stops, every hour of downtime costs real money. That pressure makes manufacturers more likely to pay quickly, and cybercriminals count on it.
It doesn't matter what you make or who you sell to. If you run SAP, Epicor, Infor or Microsoft Dynamics, if you have SCADA systems or internet-connected machines on the floor, you're a target. Attackers choose victims based on opportunity and pressure to pay — and manufacturers have both.
Fact: Manufacturing is one of the most attacked industries precisely because downtime forces fast payouts.
Myth 2: "Our Shop Floor Staff Will Recognize a Phishing Email"
The days of obvious phishing emails full of typos are gone. Today's scams arrive as polished, personalized supplier invoices, purchase order confirmations and freight notifications — the exact emails your front office and production and operations team see dozens of times a day.
Thanks to AI, it's become nearly impossible to catch a scam from the text alone. Instead, your production and operations team needs to think about sender behavior. Ask whether the supposed supplier or customer would:
- Make an unusual request outside the normal ordering process
- Change payment or banking instructions on an existing account
- Request sensitive information like pricing, specs or credentials
- Send a new or unusual login link to your ERP or supplier portal
If anything seems off, verify through a known phone number before clicking or responding. Remember: many shop floor employees spend their day running machines, not email — they haven't been drilled on phishing the way office workers have, which makes training everyone, not just the front office, non-negotiable.
Fact: A convincing supplier invoice can still be a scam.
Myth 3: "MFA Fully Protects Our ERP"
Multi-factor authentication (MFA) is important, but it's not invulnerable. Hackers use MFA fatigue to their advantage — "prompt bombing" floods a controller's or purchasing manager's phone with approval requests until they tap yes just to make it stop. One tired approval, and an attacker is inside the system that runs your scheduling, inventory and financials.
MFA is a tool, not a shield. That's doubly true in manufacturing, where OT vendors often have remote access into your equipment and legacy systems on the plant floor can't run modern authentication at all. MFA needs support from the security controls around it — network segmentation between IT and OT, monitored vendor access and locked-down remote connections.
Fact: MFA should be one layer in a broader industrial cybersecurity strategy — not the whole plan.
Myth 4: "Our Backups Have Us Covered"
Ask yourself: if ransomware hit your plant tomorrow, could you actually restore your ERP database, your production data and your CAD files? How long would it take? Could you rebuild the configurations that keep your MES — whether that's Rockwell or Siemens Opcenter — talking to the machines on the floor?
A backup is great when you know it's going to work. An untested backup isn't something you can rely on while your line sits idle and orders slip past due dates. Knowing your realistic recovery time — in hours of lost production, not vague promises — can save you serious money.
Fact: Having backups is not the same as being able to restore production.
Myth 5: "Cybersecurity Is Only IT's Job"
Your IT team does a lot to keep your operation safe, but they can't control every click — from the front office processing invoices to the supervisor checking email at a shared terminal on the floor. Cybersecurity decisions happen across the entire operation, and it takes only one bad click to open a path from the office network to your production systems.
There's another wrinkle unique to manufacturing: your OT vendors. Machine builders, integrators and maintenance contractors routinely connect remotely to your equipment. Every one of those connections is a door into your plant, and IT can't secure doors it doesn't know exist. Security awareness has to include everyone who touches a keyboard — and every vendor who touches your network.
Fact: Training your production and operations team — and governing vendor access — strengthens your entire security posture.
Myth 6: "We'd Know What to Do If Something Happens"
It's Tuesday morning. The ERP is unreachable, terminals on the floor are locked and the line is down. Many manufacturers discover in that exact moment that nobody has answered the basic questions:
- Do we shut down machines and workstations, or keep them running?
- Who calls IT — and who has authority to stop the line?
- Can we keep producing on paper travelers if the MES is down?
- When does the insurance company get involved?
- Who communicates with customers about delayed orders — and how?
Don't rely on memory in the moment. The line-down decision chain needs to be documented, printed and practiced before you ever need it.
Fact: Your recovery plan shouldn't debut during an incident.
Frequently Asked Questions
Do you offer IT and cybersecurity support for manufacturing companies in Salt Lake City?
Yes. Qual IT provides manufacturing IT services across Utah, including industrial cybersecurity, threat detection and response, email security, phishing protection, employee security awareness training, MFA implementation, backup and recovery for ERP and production data, and incident response planning built around keeping your line running.
What is the biggest cybersecurity mistake manufacturers make?
Assuming they're covered without verifying it. Untested ERP backups, unmanaged OT vendor remote access and security tools nobody monitors create a false sense of protection — which is often more dangerous than a known gap, because it stops you from looking.
How do I know if my plant's cybersecurity is actually working?
Through testing and review: verified restores of production data and CAD files, simulated phishing exercises across office and floor staff, an audit of every remote connection into your equipment, and a periodic assessment by an IT partner that understands both IT and OT environments.
Cybersecurity Awareness Starts With the Facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your decisions are correct. Myths are comfortable — they let you feel covered without digging deeper. But in manufacturing, cybersecurity gaps rarely come from a missing product. They come from believing you've already got it handled when you don't — and finding out when the line stops.
We work with Salt Lake City manufacturers to protect production systems and reduce operational downtime. If any of these myths sound familiar, it's time to take a closer look at where your operation stands. Providers of IT support for manufacturers in Salt Lake City should be able to show you the difference between what's protecting you and what's only giving you peace of mind — in plain numbers.
Schedule a free 10-minute discovery call with Qual IT. Book your discovery call here.

