
Internet exposure reduction is now a top priority for manufacturers after the Cybersecurity and Infrastructure Security Agency (CISA) released specific guidance to help businesses lock down systems that cybercriminals are actively hunting. If your factory floor runs on programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, or any industrial control systems (ICS) connected to your network, this guidance speaks directly to your risk.
What does internet exposure reduction mean for a manufacturing business?
Every device, server, and controller that accepts connections from the public internet is a potential door for an attacker. Internet exposure reduction means closing the doors you don’t need open and adding strong locks to the ones you do.
For manufacturers, this often includes remote access portals that let vendors service equipment, human-machine interfaces (HMIs) that operators use to monitor production, and even IP-enabled cameras or environmental sensors. Each one is an attack surface. CISA’s guidance identifies common exposure points across both information technology (IT) and operational technology (OT) environments, the latter being the systems that actually run your machines.
The cost of ignoring this? A single compromised remote desktop protocol (RDP) connection or exposed SCADA interface can allow ransomware to spread from an office workstation straight into the systems controlling your assembly line. We’ve seen Connecticut manufacturers lose entire production shifts because an attacker pivoted from an unpatched VPN appliance into OT networks. The average cost per hour of downtime in manufacturing ranges from $25,000 to over $100,000, depending on the operation.
Why is CISA issuing this guidance now?
Threat actors have shifted tactics. Instead of only targeting large enterprises, organized cybercrime groups now scan the internet for exposed industrial systems at small and mid-sized manufacturers who often lack dedicated security staff. CISA observed a sharp increase in attacks exploiting internet-facing OT devices, many of which were never designed with security in mind.
The agency’s guidance responds to real incidents where attackers used publicly accessible interfaces to reconnaissance targets, steal credentials, deploy ransomware, or sabotage production schedules. In some cases, attackers found exposed systems simply by using search engines like Shodan, which indexes internet-connected devices. If your equipment is visible there, so is your vulnerability.
What are the five core steps CISA recommends?
CISA’s internet exposure reduction framework breaks down into five actionable areas that even resource-constrained SMBs can tackle:
1. Identify and inventory all internet-facing assets. You can’t protect what you don’t know exists. Map every system that accepts inbound connections, including remote access tools, web portals, cloud services, and any OT devices with network interfaces. Many manufacturers discover forgotten or shadow IT during this process, like a contractor-installed remote monitoring tool that’s been running unpatched for years.
2. Eliminate unnecessary exposure. Ask a hard question for each exposed system: does this truly need to be reachable from the internet? If the answer is no, disconnect it or move it behind a firewall. For example, an HMI used only by on-site operators should never have a public IP address. CISA estimates that 60 to 80 percent of exposed assets in SMB environments can be removed from the internet entirely without disrupting operations.
3. Implement strong access controls. For systems that must remain accessible, require multi-factor authentication (MFA), disable default credentials, and enforce least-privilege access. If a vendor needs remote access to service a piece of equipment, grant temporary, monitored access rather than leaving a permanent backdoor open. This alone prevents a large percentage of credential-based attacks.
4. Segment your networks. Separate your IT and OT environments so a breach in one doesn’t automatically cascade into the other. A properly segmented network means that even if ransomware infects your accounting department, it can’t reach the controllers running your CNC machines. This is not exotic engineering; it’s achievable with VLANs, firewalls, and clear traffic rules.
5. Monitor and maintain visibility. Deploy logging and alerting on all internet-facing systems. You need to know when someone attempts to access your exposed assets, especially after hours or from unusual locations. Regular vulnerability scanning helps you catch newly exposed systems before attackers do.
Do I need to hire a specialist to implement this?
Not necessarily, but you do need expertise. Many SMB manufacturers work with managed service providers (MSPs) who understand both IT and OT environments. The challenge is that traditional IT support often lacks experience with industrial protocols like Modbus, EtherNet/IP, or Profinet. You want a partner who can assess your shop floor systems without causing unplanned downtime.
If you have in-house IT staff, they can handle the IT side (servers, workstations, cloud services) while bringing in OT-focused consultants for the production environment. CISA provides free tools and assessment frameworks to help guide the process. The cost of a professional assessment typically ranges from $5,000 to $25,000 for an SMB, a fraction of what a single ransomware incident or regulatory fine would cost.
What happens if we don’t reduce our internet exposure?
The risks are tangible and immediate. Exposed systems invite ransomware, data theft, sabotage, and regulatory scrutiny. For manufacturers, the consequences often include:
Production downtime. Attackers encrypting or disabling OT systems can halt your entire operation until you restore from backups or pay a ransom (which we never recommend and which often fails anyway).
Supply chain impact. Missing delivery deadlines erodes customer trust and can trigger penalty clauses in contracts. Some manufacturers have lost anchor clients after cyber incidents caused repeated delays.
Regulatory and insurance fallout. If you handle controlled data (such as International Traffic in Arms Regulations, or ITAR, materials), a breach can trigger federal investigations. Cyber insurance carriers are also tightening underwriting; exposed systems can lead to coverage denial or premium increases of 30 percent or more.
Intellectual property theft. Exposed engineering workstations or file servers can leak proprietary designs, formulas, or processes to competitors or nation-state actors. Once that information is out, you can’t claw it back.
How does this tie into compliance frameworks like CMMC or NIST?
If you’re a Department of Defense (DoD) supplier, you’re likely familiar with the Cybersecurity Maturity Model Certification (CMMC), which requires you to demonstrate control over your attack surface. Internet exposure reduction directly supports CMMC practices around access control (AC), system and communications protection (SC), and risk assessment (RA).
Similarly, the National Institute of Standards and Technology (NIST) Cybersecurity Framework identifies asset management and protective technology as core functions. CISA’s guidance maps cleanly onto these frameworks, making it easier to show auditors that you’re managing risk appropriately. For SMBs pursuing CMMC Level 2, reducing internet exposure is often one of the first gaps assessors identify.
Can I phase this in, or does it need to happen all at once?
Phasing is not only acceptable, it’s often the smartest path. Start with the highest-risk systems: anything controlling safety-critical processes, customer-facing production lines, or systems holding sensitive data. Eliminate the low-hanging fruit (unpatched remote access, default passwords, unnecessary public IPs) in the first 30 days.
Then move to segmentation and access controls over the next quarter. Continuous improvement matters more than perfection. Document each step so you can demonstrate progress to insurers, auditors, and customers who ask about your security posture.
What tools or technologies support internet exposure reduction?
You don’t need a massive budget, but you do need the right stack. Firewalls with intrusion prevention systems (IPS), virtual private networks (VPNs) with MFA, and network access control (NAC) solutions all play a role. For OT environments, consider industrial firewalls from vendors like Palo Alto Networks, Fortinet, or Cisco, which understand industrial protocols.
Asset discovery tools (such as Nmap, Nessus, or Armis) help you find what’s exposed. Security information and event management (SIEM) or even simpler logging solutions give you visibility into access attempts. Cloud-based secure access service edge (SASE) platforms can consolidate remote access without exposing individual systems.
Many of these capabilities are available through managed services, letting you benefit from enterprise-grade protections without hiring a full security team.
Where can I find CISA’s full guidance and additional resources?
CISA publishes its internet exposure reduction guidance on its official website, along with companion documents covering specific industrial sectors. The agency also offers free vulnerability scanning through its Cyber Hygiene services and hosts webinars for SMBs looking to understand the fundamentals.
For manufacturers in Connecticut, regional resources like the state’s Cybersecurity Action Plan and industry groups such as the Connecticut Business & Industry Association (CBIA) often host workshops that walk through CISA guidance in plain language. Taking advantage of these free resources can save you thousands in consulting fees while building internal capability.
The bottom line: internet exposure reduction is not a luxury reserved for Fortune 500 manufacturers. It’s a practical, necessary step that protects your operations, your customers, and your reputation. CISA has handed you a roadmap. The question is whether you’ll use it before an attacker does.
Keep reading
- cybersecurity risks facing manufacturers
- understanding data breach risk
- preventing IT downtime and business disruption