In my experience, few industries manage physical risk as rigorously as manufacturing. Every hazard on a plant floor has a name, an owner, a control, and a scheduled check.
Manufacturing security teams have their own version of that discipline. It just runs on a different clock. Getting the two clocks to talk to each other is what stands between a routine fix and a stopped production line.
A controller on a computer numerical control (CNC) machine fails. Maintenance swaps it out, tests it, and has the line running again before the shift ends. It's perfect execution, except the replacement part has been sitting on a shelf since commissioning. Its software is two versions behind. And it has a flaw that’s already been used in attacks on other plants.
Nobody catches it because the work order and the vulnerability list live in different systems. Six weeks later, a security scan flags the exposure, but there's no line of sight back to the repair that caused it. Fixing it now means stopping a production line that's running full.
The same problem runs backward: Security isolates a compromised device and unknowingly trips a function a safety system was counting on. Neither team made a mistake. They just couldn't see what the other had done to the same piece of equipment.
According to the SANS Institute’s 2025 State of ICS/OT Security Report, "More than one in five organizations (21.5%) reported experiencing a cybersecurity incident over the past year, and four in 10 of those events caused operational disruption.”
Manufacturing has been the most-attacked industry for five years running, according to Resilience’s The State of Cybersecurity in Manufacturing. Ransomware gets the headlines, but the damage comes from something quieter: the disparity between what safety knows about a machine and what security knows about that same machine.
Folding cyber risk into the safety review process sounds like the fix. It isn't. A hazard register is a formal document. Touching it means revalidating the analysis behind it. That slowness is the control.
Exposure management has to move continuously because the threat does. Review a vulnerability queue on safety's quarterly schedule, and you're three months behind before you start. Run safety on cyber's schedule instead, and you're relitigating hazard analysis every time a scan runs.
AI agents can make this worse. They're being used to open work orders and request access with no person in the room, carrying authority without any of the training or accountability the safety system assumes. So the two disciplines remain separate. They have to.
However, manufacturers can't afford to keep them disconnected. Yet that’s where most plants are today.
Stop letting the two disciplines work off two different accounts of the same asset.
In a manufacturing plant, every piece of equipment needs to exist as a single record with multiple views into it. A safety engineer pulls up what a safety review needs. A security analyst pulls up what a vulnerability assessment needs. They both see the same underlying truth through a different lens.
This is what ServiceNow calls Shift Zero: closing exposure before it becomes an incident, rather than managing an ever-growing backlog of it.
Armis from ServiceNow continuously sees the connected asset estate, including equipment that never made it into a formal inventory. Veza from ServiceNow shows who and what can reach those assets: human, machine, vendor, or AI agent.
ServiceNow then layers in production context: which line the asset is on, which customer order depends on it, and what happens if the issue sits. The system routes the action through the change process the plant already trusts, with AI Control Tower helping to keep the automation auditable and reversible.
When a maintenance team closes a repair, that change flows to the security view. When a security team isolates a device, that action is visible to safety before production planning depends on it. That’s because both are finally reading the same data.
Regulators that mandate a hard boundary between operational and security systems aren't an obstacle here. One record doesn't cross that boundary.
KEC International, a global manufacturer of electric power transmission towers, deployed Armis from ServiceNow to gain full IT/operational technology (OT) visibility. Mean time to respond dropped 20% to 30%. The same asset data is now feeding cleaner input into its AI and machine learning reliability models than manual tracking ever provided.
A large poultry processor deploying Armis from ServiceNow across IT and OT cut network investigation time from an hour to five minutes. The company now catches misconfigurations before they become outages, and audit prep takes less time.
Both outcomes come from the same thing: one record every discipline can read.
The best place to begin is to pick one security finding sitting in your queue. Don't work around it. Push it through the change process. Then ask: What stops on the line if we act today?
Next, take a repair your team already closed. Ask your maintenance and security leads what that repair changed about your plant's exposure.
If nobody can answer either question from the record, that's a problem worth fixing. It's a lot cheaper to address on your own terms than during an incident.
Siemens’ The True Cost of Downtime 2024 puts the cost of an idle automotive production line at $2.3 million an hour. That’s more than $600 a second. Cyber incidents add to that bill rather than sitting beside it.
The manufacturers who pull ahead won't be the ones automating operations the fastest. They'll be the ones with the clearest read on what each change to a machine means for the plant floor.
Find out how ServiceNow can help you connect safety and security operations on one platform.