Subscribe Home Conversations On AI App Development CRM Enterprise IT Ethics & Governance Futures HR Industries ServiceNow on ServiceNow Platform Foundations Products & Solutions All topics For Leaders In IT & Dev Customer Experience Finance, Operations & Strategy Employee Experience Security & Risk News & Events People & Culture My List Explore All
September 18, 2026 4 min Different manufacturing security clocks can make production pay Safety and security teams need the same asset view to avoid production line disruption or shutdown Industries Explainer
Keith Dunnell
Keith Dunnell VP Manufacturing Industry GTM, ServiceNow
Pink-lit conveyor belt in a warehouse
Top takeaways Shared asset context can help teams catch risks before they affect operations. Separate records make simple fixes more difficult to trace when new risks appear. Fast response requires knowing which equipment, access, and orders are exposed.
Alt text

In my experience, few industries manage physical risk as rigorously as manufacturing. Every hazard on a plant floor has a name, an owner, a control, and a scheduled check.

Manufacturing security teams have their own version of that discipline. It just runs on a different clock. Getting the two clocks to talk to each other is what stands between a routine fix and a stopped production line.

When a repair creates exposure

A controller on a computer numerical control (CNC) machine fails. Maintenance swaps it out, tests it, and has the line running again before the shift ends. It's perfect execution, except the replacement part has been sitting on a shelf since commissioning. Its software is two versions behind. And it has a flaw that’s already been used in attacks on other plants.

Nobody catches it because the work order and the vulnerability list live in different systems. Six weeks later, a security scan flags the exposure, but there's no line of sight back to the repair that caused it. Fixing it now means stopping a production line that's running full.

The same problem runs backward: Security isolates a compromised device and unknowingly trips a function a safety system was counting on. Neither team made a mistake. They just couldn't see what the other had done to the same piece of equipment.

Manufacturing has been the most-attacked industry for five years running. Resilience The State of Cybersecurity in Manufacturing
21.5% of organizations reported experiencing a cybersecurity incident over the past year. And 40% of those events caused operational disruption. SANS Institute 2025 State of ICS/OT Security Report

A problem that’s more common than it should be

According to the SANS Institute’s 2025 State of ICS/OT Security Report, "More than one in five organizations (21.5%) reported experiencing a cybersecurity incident over the past year, and four in 10 of those events caused operational disruption.”

Manufacturing has been the most-attacked industry for five years running, according to Resilience’s The State of Cybersecurity in Manufacturing. Ransomware gets the headlines, but the damage comes from something quieter: the disparity between what safety knows about a machine and what security knows about that same machine.

Why the 2 clocks can't merge (and shouldn't)

Folding cyber risk into the safety review process sounds like the fix. It isn't. A hazard register is a formal document. Touching it means revalidating the analysis behind it. That slowness is the control.

Exposure management has to move continuously because the threat does. Review a vulnerability queue on safety's quarterly schedule, and you're three months behind before you start. Run safety on cyber's schedule instead, and you're relitigating hazard analysis every time a scan runs.

AI agents can make this worse. They're being used to open work orders and request access with no person in the room, carrying authority without any of the training or accountability the safety system assumes. So the two disciplines remain separate. They have to.

However, manufacturers can't afford to keep them disconnected. Yet that’s where most plants are today.

Two clocks showing different times in an old factory
The fix: 1 record, not 2 systems

Stop letting the two disciplines work off two different accounts of the same asset.

In a manufacturing plant, every piece of equipment needs to exist as a single record with multiple views into it. A safety engineer pulls up what a safety review needs. A security analyst pulls up what a vulnerability assessment needs. They both see the same underlying truth through a different lens.

This is what ServiceNow calls Shift Zero: closing exposure before it becomes an incident, rather than managing an ever-growing backlog of it.

In a manufacturing plant, every piece of equipment needs to exist as a single record with multiple views into it.

How 1 record works in practice

Armis from ServiceNow continuously sees the connected asset estate, including equipment that never made it into a formal inventory. Veza from ServiceNow shows who and what can reach those assets: human, machine, vendor, or AI agent.

ServiceNow then layers in production context: which line the asset is on, which customer order depends on it, and what happens if the issue sits. The system routes the action through the change process the plant already trusts, with AI Control Tower helping to keep the automation auditable and reversible.

When a maintenance team closes a repair, that change flows to the security view. When a security team isolates a device, that action is visible to safety before production planning depends on it. That’s because both are finally reading the same data.

Regulators that mandate a hard boundary between operational and security systems aren't an obstacle here. One record doesn't cross that boundary.

Customer proof

KEC International, a global manufacturer of electric power transmission towers, deployed Armis from ServiceNow to gain full IT/operational technology (OT) visibility. Mean time to respond dropped 20% to 30%. The same asset data is now feeding cleaner input into its AI and machine learning reliability models than manual tracking ever provided.

A large poultry processor deploying Armis from ServiceNow across IT and OT cut network investigation time from an hour to five minutes. The company now catches misconfigurations before they become outages, and audit prep takes less time.

Both outcomes come from the same thing: one record every discipline can read.

A poultry processor deploying Armis from ServiceNow across IT and OT cut network investigation time from an hour to five minutes.

2 tests to get started

The best place to begin is to pick one security finding sitting in your queue. Don't work around it. Push it through the change process. Then ask: What stops on the line if we act today?

Next, take a repair your team already closed. Ask your maintenance and security leads what that repair changed about your plant's exposure.

If nobody can answer either question from the record, that's a problem worth fixing. It's a lot cheaper to address on your own terms than during an incident.

Siemens’ The True Cost of Downtime 2024 puts the cost of an idle automotive production line at $2.3 million an hour. That’s more than $600 a second. Cyber incidents add to that bill rather than sitting beside it.

The manufacturers who pull ahead won't be the ones automating operations the fastest. They'll be the ones with the clearest read on what each change to a machine means for the plant floor.

Find out how ServiceNow can help you connect safety and security operations on one platform.

Next up
Dive into more conversations AI App Development CRM Enterprise IT Ethics & Governance Human Resources Industries ServiceNow on ServiceNow Platform Foundations Products & Solutions All Topics
Stay in the know Join Us
stay in know image
Alt