When the line stops: what ransomware downtime actually costs a manufacturer
The ransom is the small number. Missed ship dates, contract penalties, spoiled work in process and recovery overtime are where a plant really pays.
· Jake Schaaf, Founder of Atticus Rowan
A plant that ships 40 pallets a day goes quiet at 6 a.m. on a Tuesday. Not because a machine broke. The machines are fine. The ERP is encrypted, the label printers cannot pull orders and the scheduling board that tells 3 shifts what to run is a locked screen with a payment demand on it. Production could physically run. Nobody can tell it what to run.
That is what ransomware looks like in manufacturing. The malware rarely touches the PLC on the line. It does not have to. It takes out the systems that feed the line, and the line stops just the same.
The arithmetic nobody runs in advance
Ask a plant manager what an hour of downtime costs and you will get a number. Ask what 10 days of downtime costs and the math changes shape, because the losses stop being linear. The real cost stack looks like this:
- Lost throughput. The obvious one. Daily revenue that did not ship, multiplied by however long recovery takes. Multi-week outages are common in manufacturing ransomware cases, and 2 to 3 weeks of degraded operations is a realistic planning number even when backups are good
- Missed ship dates and contract penalties. Automotive and consumer packaged goods customers do not care why you missed the window. On-time delivery clauses, chargebacks and expedite requirements keep running while your systems do not
- Spoiled work in process. Food, chemical and coatings operations lose batches that cannot sit. A cooler full of product with no lot tracking and no shipping paperwork often cannot legally ship even if it is physically fine
- Expedited freight. When you restart, you air-freight and hot-shot your way back into customer schedules at 2 to 5 times normal shipping cost
- Recovery overtime. Weeks of weekend shifts to burn down the backlog, at premium labor rates, while morale takes its own hit
- The rebuild itself. Incident response, forensics, server rebuilds and the security work that should have happened earlier, now purchased at emergency prices
The ransom demand sits next to that stack and it is frequently the smallest line on it. That is exactly why manufacturers get targeted. Attackers read the same arithmetic. An operation with contractual ship dates and perishable work in process has the lowest tolerance for downtime of almost any business type, and low tolerance converts to payment pressure.
Why the plant is a soft target more often than it should be
Manufacturing environments accumulate risk in predictable ways. We see the same patterns across the plants we support:
- Flat networks where the office, the ERP and the shop floor all sit in one broadcast domain, so one compromised workstation can reach everything
- Legacy operating systems running production-critical software that nobody wants to touch
- Shared logins on shop floor terminals because badge-in workflows were never built
- Backups that exist but were never tested against a scenario where the backup server itself is encrypted
None of these are exotic problems. All of them are fixable in weeks, not years. We covered the backup side in detail in the 3-2-1-1-0 rule and why immutable copies matter.
Recovery order decides how long the outage lasts
When a manufacturer gets hit, the instinct is to restore everything at once. That instinct extends the outage. Recovery is a sequencing problem, and the sequence should be decided now, on a calm day, not negotiated in a war room at hour 30. The order that gets plants shipping fastest:
- Identity first. Rebuild or verify the directory and admin access before anything else. Every other restore depends on being able to log in to it safely
- ERP and inventory. The system of record for orders, BOMs and lots. Until it is up, nothing ships cleanly
- Scheduling and MES. The layer that tells each line and each shift what to run
- Shipping and labeling. Carrier integrations, label printers and ASN feeds. Unglamorous, and the last gate between a finished pallet and revenue
- Everything else. Email, file shares and reporting can wait days without stopping a single order
Write that order down. Attach names to each step. Then test the restore path for the top 3 at least once a year, the way we describe in tested restores.
Prevention priorities that fit a plant
A manufacturer does not need 40 security products. It needs a short list done properly, prioritized for how plants actually fail:
- Segment the shop floor from the business network so an office phishing click cannot reach the historian or the controllers. Our segmentation guide covers the practical version
- Immutable, offline-capable backups for ERP and file data, tested against full-loss scenarios
- MFA on email, remote access and the ERP, in that order
- EDR on every Windows asset that can accept it, with someone actually watching the alerts
- A 1-page recovery sequence like the one above, printed, because the wiki will be encrypted too
For the OT layer itself, the risk model is different enough that we wrote about it separately in OT cybersecurity for manufacturers.
The communication workstream runs in parallel
Restoring systems is half the incident. The other half is managing the people who notice. Plan for 4 conversations that all start in the first 48 hours:
- Customers. Your largest accounts will hear about the outage from their own supply chain teams within days. A proactive call with an honest recovery estimate preserves relationships that a week of silence destroys. Decide now who makes those calls
- Your cyber insurer. Most policies require prompt notice and route you to approved incident response and forensics firms. Calling your own IT provider first and the insurer third can jeopardize coverage for the response costs. The notice number belongs in the printed recovery plan
- Employees. 3 shifts of hourly workers need to know whether to show up tomorrow. Ad hoc answers create rumor, and rumor creates turnover in a labor market that is already tight
- Suppliers. Inbound materials keep arriving at a plant that cannot receive them cleanly. A short pause-and-stage agreement with your top suppliers avoids a dock full of unlogged inventory that takes weeks to reconcile
None of these conversations require a single system to be restored. All of them go better when the talking points were drafted on a calm day. A 2-hour tabletop exercise with plant leadership, like the format we described in tabletop exercises that produce decisions, is the cheapest way to find the gaps while they are still hypothetical.
Run your own number
Take one day of shipped revenue. Multiply by 10. Add your largest customer’s late-delivery penalty and 3 weeks of overtime. That is a defensible planning estimate for an unprepared plant, and it is almost always a multiple of what the preventive short list costs over 3 years. The full breakdown of where the money goes post-incident is in the true cost of ransomware.
Atticus Rowan supports manufacturers across northwest and north central Ohio, and production downtime is the scenario we build their security programs around. If you want a plant-specific read on where your outage would start and how long it would last, start a conversation. The scope call costs nothing and the arithmetic is yours to keep.
Related insights
More on Incident response →July 30, 2026
Wire fraud hit your business: the first 48 hours
A step-by-step response plan for the first 48 hours after a fraudulent wire transfer leaves your account, from bank recall to IC3 to preserving evidence.
July 24, 2026
Business email compromise: the scam built for 15-person companies
No malware, no hacking tools, just email and patience. How BEC actually unfolds at small businesses and the 4 controls that stop it.
July 2, 2026
The cybersecurity tabletop exercise that produces decisions, not a filed PDF
How to run a cybersecurity tabletop exercise that surfaces real gaps and ends with named owners and dates, instead of a 3-hour meeting that produces a PDF for the auditor and nothing else.