Data from Russian cybersecurity firm F6 identified that manufacturing is the top target for cyberattacks in 2026, while about 80% of companies, including critical information infrastructure facilities, face a shortage of qualified information security personnel. It revealed that filling a single cybersecurity vacancy can take several months, while building a 24/7 security team from scratch can take 12 to 18 months, creating a gap that attackers can exploit as industrial threats accelerate.
The assessment is designed to determine whether industrial organizations have effective visibility and response capabilities rather than simply maintaining compliance checklists. F6 said organizations should bring raw events from endpoints, networks, email gateways, and cloud environments into a single database, and analysts should be able to reconstruct an intrusion chain within five minutes without switching between multiple interfaces. The company also highlights contractor compromise as a key route into internal networks and warns that if an organization receives negative answers on at least three of the seven criteria, its monitoring may create only the appearance of security.
F6 recommends that CISOs assess industrial security against seven criteria, including telemetry coverage, phishing response, alert processing, incident response, attacks through contractors, false positives and integration of security solutions.
It identified that raw events from endpoints, the network, mail gateways, and clouds should be collected into a single database rather than remaining as disparate logs in separate consoles. Many factories purchase separate tools for each threat class, resulting in a ‘zoo’ of tools where engineers must manually correlate events from different interfaces. During an attack, every minute counts, and jumping between windows consumes time that is already in short supply. A specialist should be able to reconstruct the entire chain of a single intrusion in five minutes without opening more than one interface. If this cannot be accomplished, the defense architecture requires reconsideration.
F6 mentioned that phishing remains the primary penetration vector, with malicious code most often delivered via email attachments. Password archives pose a particular challenge because they bypass standard antivirus software, as the contents cannot be verified without entering the password, which the attacker provides in the body of the same email, a subsequent email, or a private message on instant messaging apps.
Effective phishing defenses must cover the entire lifecycle of email messages, including blocking malicious attachments and links before they are delivered to the recipient, conducting Time-of-Click behavior analysis, analyzing email context to determine whether it corresponds to the expected behavior of the sender, and providing post-delivery protection in case the threat still gets through the filters. If the defense only checks the moment of delivery rather than the entire path of the message, a single bypass of the filter will be enough for an attacker to gain a foothold undetected.
F6 also identified that thousands of security events per day are a common reality for plants of any size. The problem is not the volume of data but what happens to it next: without correlation and classification by criticality, analysts often fail to process part of the flow.
The key metric is not the total number of alerts but the percentage of confirmed cases requiring human intervention. If this figure is low, specialists spend most of their time sifting through noise instead of investigating genuine threats, a recipe for burnout for the few remaining specialists. Departments should know the exact percentage of false alarms over the past month, and if they do not, the alert processing process is based on operator intuition rather than a well-established methodology.
The speed of incident response determines whether an intrusion remains an attempt or turns into downtime. At the same time, forensic artifacts must be preserved for investigation, as without them it will remain unclear how the attacker penetrated the system and what other actions they managed to take. This requires a deterrence model that balances speed and control, necessitating human participation to ensure that rapid response does not compromise the integrity of forensic evidence needed to understand and learn from the attack.
The main route into internal networks is not a direct attack on the perimeter but rather the compromise of a partner such as a service engineer, integrator, or service organization with legitimate remote access. Such sessions are trusted by default, making them an easy target for attackers. Enterprise protection should include tracking contractor sessions as a distinct activity class rather than treating them as just one more user in the overall mix.
The post mentioned that correlation rules should identify atypical behavior, including unusual connection times, access to nodes outside the normal zone, and abnormal data transfer volumes. An intrusion through a partner almost always follows a chain of several steps from compromising their credentials to lateral movement within the client’s network, and independent detection mechanisms must be triggered at each of these stages, as relying on the contractor to notice a problem first is an inherently high-risk strategy.
Even a well-tuned detection solution without manual verification becomes a source of noise, as standard out-of-the-box production rules almost always generate excessive triggers. A properly structured process should provide clients not with a raw stream of alerts but only cases confirmed by analysts, complete with context and ready-made recommendations for action. Response times are reduced not because there are fewer alerts but because the specialist gets straight to the point. Organizations should measure how long it takes on average to confirm that a triggered alert is actually a real threat, and if it is a matter of hours rather than minutes, that represents a direct loss of productivity for small teams.
Disparate security tools such as separate antivirus, next-generation firewalls, and email filters make plant security management labor-intensive and slow, especially during an attack. A unified console and automatic sharing of indicators of compromise between tools is not merely a matter of interface convenience but rather a critical factor in response speed. Without such a connection, the detection chain breaks at the boundary between products from different vendors, and an incident detected by one tool goes unnoticed by others. If a single incident requires specialists to manually cross-check data from three or more unrelated interfaces, unifying the defense architecture is not an improvement but a necessity.
After reviewing the list, F6 identified that organizations should count how many of the seven items have problems identified within their environment and compare the results against the provided assessment table. The post included risk level guidance based on the number of problems identified, with zero to two problems indicates a short risk level with the defense at a good level, three to five problems indicates an average risk level requiring an in-depth information security audit, six to eight problems indicates a high risk level necessitating a Managed XDR pilot, and nine to eleven problems indicates a critical risk level requiring an immediate express assessment.
Key takeaway is that the greater the number of unsecured points within the defense architecture, the less time remains available to close the breach before an actual invasion occurs rather than after the fact. This underscores importance of identifying and addressing vulnerabilities proactively, as remediation delays directly correlate with reduced opportunity to prevent compromise.
In conclusion, F6 wrote, “Assessing a company’s defenses against a seven-point checklist is only the first step, not a final report to be shelved. Attacks on the industrial sector adapt faster than a company can manually check each network segment, so a static annual review is clearly giving way to ongoing monitoring. If your checklist reveals three or more outstanding items, don’t put off resolving them until the next incident.”


