New data from the 2026 Thales Data Threat Report Manufacturing Edition identified that AI (artificial intelligence) has become a leading data security concern for manufacturers, with 67% of respondents citing rapid changes in AI ecosystems as their top AI security risk. The report found that 83% have invested in specific security tools or services because of concerns about AI. It also found that 61% of manufacturers have experienced deepfake attacks, with a majority reporting reputational damage from AI-fueled attacks.
Thales also detected gaps in manufacturers’ ability to track and protect data across increasingly complex environments. Only 31% of manufacturing respondents said they have complete knowledge of where their data is stored, compared with 34% surveywide, while 37% said they can classify all their data, a necessary step to effective data protection. Less than half of sensitive data in the cloud is encrypted. At the same time, 83% of manufacturers have five or more data protection tools and 42% have five or more key management systems, highlighting the complexity of their data security environments.
The report noted that protecting this data from increasingly sophisticated, machine-speed attacks is of paramount concern for security teams because manufacturing companies operate complex, interconnected physical and digital systems that are increasingly vulnerable to cyberattacks.
Cloud infrastructure remains a significant target for attackers, according to the report, with cloud storage identified by 36% of manufacturers as a leading target, followed by cloud-delivered SaaS applications at 29% and cloud management infrastructure at 26%. Credential theft was identified as the leading attack technique against cloud infrastructure, with 57% of manufacturers reporting increases in credential theft and the misappropriation of secrets. The report also found that 59% of manufacturers identified future encryption compromise as their top quantum computing concern, while 61% are prototyping and evaluating post-quantum cryptographic algorithms.
The 2026 Data Threat Report found that manufacturers reported a lower share of sensitive data stored in the cloud, at 45% compared with 51% across all respondents. Only 8% of manufacturers reported encrypting 75%-100% of their sensitive cloud data, just under half the surveywide figure of 14%. This is clearly an area that needs urgent improvement across all organizations, particularly since the volume of sensitive data stored in the cloud increases each year.
“Comparing automotive manufacturers to other manufacturing firms, 12% of automotive respondents experienced a cloud breach in the past 12 months, 7 percentage points lower than all manufacturers,” according to the Thales report. “Human error was the top-cited root cause of data breach by both groups (25% automotive, 34% general manufacturing). Failure or compromise of identity/access control other than MFA was cited by 11% of automotive respondents, 5 percentage points higher than general manufacturing respondents. Automotive organizations also reported greater tool sprawl: 43% said they have 5-7 data discovery tools, 13 percentage points higher than other manufacturers.”
This comes as automotive respondents were more concerned about malicious insiders with financial motivation. 39% ranked it as their top concern, versus 32% of other manufacturers. Automotive manufacturers were also more likely to cite increases in certain types of AI/LLM attacks, including prompt injection (48% of automotive versus 34% of other manufacturers), sensitive information disclosure (67% versus 55%) and supply chain attacks (48% versus 32%). Non-automotive manufacturing respondents were significantly more concerned about security for AI as a pressing discipline: 27% ranked it as the most pressing security discipline, compared with only 7% of automotive respondents.
Among key areas of security spending, cloud security for IaaS/PaaS is the highest priority, with 34% ranking it among their top three categories, followed by security for AI (28%) and application and API security (24%). This is unsurprising, given that AI workloads run predominantly in cloud environments and depend heavily on APIs, and concern about the security of AI systems is high.
The 2026 Thales Data Threat Report recognized that, given the accelerating pace of technology evolution, rapid change in the AI ecosystem is the top AI-related security concern of manufacturing respondents: 67% identified it as a top source of risk (70% surveywide). Trust came second (63%), 5 points higher than surveywide (58%), and agency was the third-ranked concern (45%). Interestingly, manufacturing respondents were more concerned with agency than the overall survey population, which ranked confidentiality as the number three concern. This could be due to concerns that rogue or misconfigured AI agents could wreak havoc on manufacturing processes and other critical operational systems.
Attackers are also using AI, necessitating changes in defense tactics. Manufacturing respondents reported increases in various AI-powered attacks, most notably sensitive information disclosure (59%), followed by AI-generated misinformation, including deepfakes (54%) and system prompt leakage (45%). Surveywide, respondents reported the greatest increases in the same top two attack types (61% and 57%, respectively), followed by prompt injection (52%). This could imply that manufacturing organizations are more concerned about losing sensitive data through user prompts than about LLMs divulging it.
It also noted that infrastructure supporting AI applications and data remains a prime attack target: Cloud-based assets remain the top three cited targets in this year’s survey. Given the large volumes of data used by AI and the increases in discoverability associated with AI agents, encryption is critical. If an organization’s stakeholders cannot find, classify and secure valuable data, agents will likely find ways to access it, with unpredictable results. In many ways, AI represents a new insider threat.
Thales reported that manufacturing organizations face a diverse array of attack vectors targeting their cloud infrastructure, with credential theft and compromise presenting the most significant challenge. According to security data, credential theft or compromise, including misappropriated secrets, affects 57% of manufacturing organizations’ cloud management estates. This is closely followed by vulnerabilities stemming from third parties, including external code and APIs, which impact 53% of organizations.
Additional prominent attack modes include denial of service attacks (49%), infrastructure compromise (48%), malware injection (47%), and exploitation of identity and access controls (47%). Human error and misconfiguration round out the primary threats at 42%, revealing a persistent vulnerability across technical and operational domains.
Threat actor landscape demonstrates that manufacturing organizations must contend with multiple categories of adversaries, each presenting distinct risks. External attackers with geopolitical goals represent the single largest concern, with 258 total respondents ranking this threat category—122 ranking it first, 74 second, and 62 third in terms of concern.
Nation-state actors are closely followed by accidental incidents arising from human error, which garnered 229 total respondent votes, suggesting that unintentional breaches remain a critical vulnerability. External attackers motivated by ideological goals (224 respondents) and financial gain (222 respondents) round out the top external threats, while malicious insiders with financial motivations (179 respondents) and non-financial motivations (139 respondents) represent the internal threat dimension.
Thales also reported that manufacturing organizations currently deploy multiple tools across data security domains, though adoption levels vary significantly by function. Data protection and monitoring tools see the widest distribution, with an average of 8 tools deployed across organizations, with 38% of organizations deploying 5–7 solutions. Key management systems average 6 tools per organization, with 41% maintaining 3–4 solutions.
Security for AI and LLM-based applications and data discovery and classification represent emerging security priorities, averaging 6 and 5 tools, respectively. However, adoption remains limited in these newer domains, with only 39% of organizations deploying 5–7 data security tools for AI/LLM applications and 44% deploying 3–4 data discovery and classification solutions.
Data breaches in manufacturing organizations stem overwhelmingly from human and configuration factors rather than sophisticated zero-day exploits. Based on 272 respondents whose organizations experienced breaches, misconfiguration or human error accounts for 30% of incidents, making it by far the leading breach cause.
Exploitation of known vulnerabilities represents the second leading cause at 20%, followed by exploitation of zero-day or previously unknown vulnerabilities at 13%.
Authentication failures compound the problem, as 12% of breaches result from failure to implement multi-factor authentication on privileged accounts, while improperly configured MFA accounts for 10% of incidents. Other contributing factors include identity and access control failures (8%) and improper data classification or handling (7%), underscoring the role of operational practices in breach prevention.
Cloud infrastructure emerges as primary target for attackers targeting manufacturing organizations across multiple asset categories. Cloud-based storage represents the most heavily targeted asset, with 150 total respondent concerns—71 ranking it as the top target, 43 as second priority, and 36 as third. Cloud-delivered applications (123 concerns) and cloud management infrastructure (120 concerns) follow closely, reflecting the industry’s extensive cloud adoption.
Beyond cloud assets, internal networks (88), third-party vendor networks (84), and end-user devices (81) remain significant targets. Web applications (72), AI- or agentic-based applications (71), on-premises databases and applications (62), and IoT devices (62) round out the primary attack surface, indicating that threats span both modern cloud-native architectures and legacy on-premises systems.
In conclusion, Thales reported that manufacturing organizations should prioritize strengthening foundational data security and management practices. This requires enhanced efforts to map and understand all data storage locations across on-premises and cloud environments, a challenge many organizations currently struggle with.
Equally critical is achieving comprehensive data classification, particularly given that only 37% of manufacturing organizations can fully classify their data. Organizations should also increase encryption of sensitive cloud data, as on average 58% of sensitive data remains unencrypted, and address the underlying issues causing 45% of organizations to fail compliance audits in the past year.
Complementing these fundamentals, manufacturing organizations must improve breach prevention and incident response capabilities while simultaneously optimizing their security tool landscape. Since 16% experienced cloud breaches and 15% experienced on-premises breaches within the past year, robust prevention strategies for both environments are essential. This includes stronger controls to mitigate misconfiguration and human error and timely vulnerability patching. Organizations should also consolidate their security tool portfolios to reduce sprawl and complexity, while improving staff confidence and competency in operating deployed solutions, as only 11% of respondents express high confidence in understanding all their tools.
Finally, manufacturing organizations must prepare for emerging security challenges that will define the next phase of digital transformation. This includes developing strategies to counter evolving threats from nation-state actors and financially motivated adversaries, with particular focus on securing cloud-based storage, cloud-delivered applications, and identity infrastructure. Organizations must simultaneously prepare for quantum computing security impacts, proactively manage AI and LLM-specific risks, including prompt injection and sensitive data exposure, and execute digital sovereignty strategies to maintain control over software and data while meeting compliance requirements.


