5% of Your Downtime Is a Cyberattack. The Other 95% Is Just… Nobody’s Fault?

5% of Your Downtime Is a Cyberattack. The Other 95% Is Just… Nobody's Fault?

5% of Your Downtime Is a Cyberattack. The Other 95% Is Just… Nobody's Fault?

Written by Ketsol Manufacturing Suite

Industrial Data & AI Practitioners | OT/IT Convergence Specialists.

Ketsol is an industrial technology firm specialising in data infrastructure for manufacturing environments. With over 15 years of experience across discrete and process industries, the team has delivered large-scale data architecture and IIoT implementations, including work with Tier-1 manufacturers.

Core expertise includes Unified Namespace (UNS) architecture, industrial data modelling, and AI readiness for production systems. Ketsol combines deep operational understanding with modern data engineering practices to bridge the gap between OT and enterprise systems.

Published: Aug 2026

 

When a production line stops without warning, the first assumption in most plants is the same: “We’ve been hacked.” Headlines about ransomware in manufacturing make that the easiest story to believe.

But the data tells a different story. According to a 2026 benchmark study by Macrium Software, conducted with the research agency Newton X, only about 5% of unplanned manufacturing downtime is due to cyberattacks, based on a survey of verified IT and OT decision-makers at mid-to-large manufacturers (2,500+ employees) across North America and the UK.¹ The remaining 95% comes from misconfigurations, network issues, and gaps in how plant systems talk to each other, which the study calls the “recovery gap.”

For manufacturers running a mix of legacy PLCs, modern controllers, and half a dozen communication protocols, that “other 95%” usually traces back to one place: industrial connectivity.

This article looks at what’s really causing downtime, what it’s costing manufacturers, and how an industrial protocol gateway helps close the gap.

What Really Causes Unplanned Downtime in Manufacturing?

Unplanned downtime is rarely caused by one single failure. More often, it’s a small problem with how different systems communicate with each other.

And those systems were often never designed to work together in the first place.

Most factory floors run a mix of:

  • Legacy PLCs speaking Modbus TCP or older serial protocols
  • Newer controllers built around OPC UA
  • Sensors and edge devices publishing over MQTT
  • Building and energy systems on BACnet
  • Utility and power equipment using DNP3 or IEC 61850

Each protocol was built for a different era, a different vendor, and a different purpose.

When these systems need to share data, which modern manufacturing requires constantly, something has to translate between them.

When that translation breaks, so does the flow of data. And sometimes, production stops with it.

Is Cybersecurity Really the Biggest Threat to Uptime?

It’s a smaller threat than most manufacturers assume.

Manufacturing is genuinely a high-risk sector for cyberattacks, and security investment is justified. But when it comes to unplanned downtime specifically, the Macrium/Newton X study found cyberattacks account for a small share of the problem, while operational failures, planned maintenance gone wrong (18%), configuration loss or change (16%), and network failures (16%) make up the larger, recurring share.¹

 

The bulk of lost production time has nothing to do with an intruder. It comes from ordinary operational failures that often go unnoticed until a line stops.

 

That’s an important distinction when deciding where manufacturers focus their attention and allocate their budgets.

 

Security matters. But so does the everyday reliability of how data moves across the plant floor.

What Does the Other 95% of Downtime Actually Look Like?

Once you rule out an attack, the real causes are usually one of three things:

  • Protocol mismatches — a new sensor or device is added to the network but isn’t correctly mapped to the gateway or controller reading it. Data may stop flowing or arrive corrupted.
  • Ordinary network issues — dropped connections, overloaded access points, or physical faults that have nothing to do with security
  • Maintenance and configuration errors — a setting doesn’t carry over during an update, a device gets added without updating documentation, or a step gets missed during a shift handover

None of this requires a sophisticated attacker.

It requires exactly what most manufacturing environments already have: a patchwork of legacy and modern equipment, with limited visibility into how it all connects.

How Much Does This Downtime Actually Cost a Mid-Size Manufacturer?

The numbers are larger than most plant managers expect.

The same Macrium/Newton X study puts the cost of this “recovery gap” downtime at up to $100,000 per hour at current exchange rates; that’s close to ₹95 lakh, or nearly ₹1 crore, per hour.¹ It’s worth treating this as a general industry benchmark rather than a precise figure for any specific plant; actual costs vary widely by sector, plant size, and what’s included in the calculation (lost output alone vs. lost output plus labour, penalties, and recovery costs). The study also found that almost half of North American manufacturers and over a third of those in the UK estimate that their losses exceed the $ 100,000-per-hour mark.

 

Consider what that means over a single month.

 

A four-hour unplanned stop could represent tens of crores of rupees in annualised exposure, even before accounting for missed delivery windows, overtime, or the costs of getting production back on schedule.

 

At the higher end, research from IDS-INDATA projects that manufacturers across the UK and Europe will lose between £124 billion and £157 billion to unplanned downtime in 2026 alone, up sharply from over £80 billion in 2025.²

 

The bigger issue isn’t always how often a line stops. It’s how long it takes to understand what went wrong and restart safely. IDS-INDATA’s own analysis points directly to this: manufacturers with limited OT visibility or fragile industrial connectivity consistently see incidents run longer than they should.²

 

That’s where connectivity visibility matters.

 

A plant that can quickly distinguish between “we’ve been attacked” and “a gateway needs reconfiguring” can recover in minutes rather than hours.

Why Do Protocol Mismatches Cause So Much Downtime?

Because most manufacturing environments are brownfield rather than greenfield.

 

Very few plants run a single, unified technology stack.

 

It’s far more common to find a 15-year-old PLC running Modbus TCP sitting next to a newer OPC UA-capable controller, feeding into an MQTT broker for cloud analytics. The legacy PLC integration may have been patched together over years, often without consistent documentation.

 

That creates a problem.

 

Every connection is another point where translation can fail. Without a dedicated layer designed to standardize and manage that translation, manufacturers can end up with fragile, one-off integrations.

 

And those integrations can break when a device is added, replaced, or updated.

What Is an Industrial Protocol Gateway, and How Does It Help?

An industrial protocol gateway sits between your plant-floor devices and the systems that need their data SCADA, MES, ERP, or cloud analytics platforms and translates between protocols automatically.

Instead of building a custom, one-off integration every time a new device or system needs to connect, a multi-protocol gateway handles the translation centrally:

  • Reads data from legacy equipment over Modbus TCP or serial connections
  • Converts it into OPC UA, MQTT, or whatever format downstream systems expect
  • Supports PLC data integration across mixed-vendor equipment without custom coding for every device
  • Acts as an edge gateway, buffering and forwarding data reliably even when connectivity is intermittent
  • Provides a single point to monitor for the misconfigurations that quietly cause most unplanned downtime

For manufacturers dealing with a mix of old and new equipment, which is most manufacturers, this can make a fragile, patchwork network much easier to see and manage.

If you’ve dealt with the kind of OEE tracking gaps that come from disconnected shop-floor data, you’ve probably seen the problem firsthand. A properly implemented gateway can help close those gaps and make the source of missing data easier to identify.

 Why Your OEE Score Might Not Reflect Reality?

How Can Manufacturers Reduce Unplanned Downtime?

A few practical starting points:

  • Audit your protocol landscape to know exactly which devices speak which protocol, and where translation happens
  • Centralise translation through a gateway instead of relying on custom, device-by-device integrations
  • Monitor connectivity health continuously, not just after a line stops
  • Document every connection, especially after maintenance or equipment changes
  • Treat connectivity audits as routine, the same way you’d treat a scheduled security review.

The goal isn’t to eliminate every possible failure.

It’s to make connectivity problems easier to see, diagnose, and fix faster.

The Bottom Line

Cybersecurity deserves attention, but it’s not where most manufacturing downtime actually comes from.

The real, recurring cost sits in the everyday reliability of plant connectivity: legacy PLCs, mismatched protocols, and integrations that quietly break.

An industrial protocol gateway doesn’t just solve a technical problem. It can close the gap between “we don’t know what happened” and “we fixed it in minutes.”

At close to ₹1 crore an hour, that difference isn’t small.

Curious what a protocol audit of your own plant floor would actually turn up? Get in touch no pitch, just a look at what’s connecting (or not) on your production line.

Frequently Asked Questions:

What percentage of manufacturing downtime is caused by cyberattacks?

Roughly 5%, according to a 2026 Macrium Software/Newton X study of mid-to-large manufacturers.¹ The remaining 95% comes from misconfigurations, network issues, and maintenance errors unrelated to security incidents.

 

What is an industrial protocol gateway?

An industrial protocol gateway is a device or software layer that translates data between different industrial communication protocols such as Modbus TCP, OPC UA, MQTT, BACnet, DNP3, and IEC 61850 so that legacy and modern equipment can share data with SCADA, MES, or cloud platforms.

 

Why do legacy PLCs cause connectivity problems?

Legacy PLCs often use older, vendor-specific protocols that weren’t designed to communicate with modern systems. Without a translation layer, integrating them requires custom, one-off connections that can be difficult to maintain as equipment changes.

 

How much does unplanned downtime cost a manufacturer?

Estimates vary by plant size and sector, but Macrium’s 2026 study found manufacturers’ “recovery gap” downtime costs run up to $100,000 (roughly ₹95 lakh, or close to ₹1 crore) per hour, with almost half of North American manufacturers and over a third in the UK reporting losses at or above that level.¹ Larger and more complex facilities can lose significantly more.

 

Do I need a separate gateway for every protocol I use?

No. A multi-protocol gateway is designed to handle multiple protocols, such as Modbus TCP, OPC UA, and MQTT, through a single integration point, rather than requiring separate hardware or custom code for each.

 

Is protocol fragmentation a security risk as well as an uptime risk? Yes. Poorly managed protocol translation can create unmonitored entry points into the network. That’s one reason connectivity audits and cybersecurity reviews increasingly overlap.

References

  1. Macrium Software & Newton X, The State of Backup & Recovery in Manufacturing 2026 (survey of 100 IT/OT decision-makers, mid-to-large manufacturers, North America & UK) — source for both the 5% cyberattack figure and the $100,000/hour recovery-gap cost figure. https://www.macrium.com/blog/manufacturing-downtime-recovery-gap-macrium-report.
  2. IDS-INDATA, The Real Cost of Manufacturing Downtime (2026): Sector Impact & Resilience Outlook. https://idsindata.co.uk/manufacturing-downtime-costs-and-forecasting-2026.

Cost estimates are industry benchmarks and vary by sector and plant size; currency conversions are approximate.

Published Jul 2026  |  Store and forward | Industrial IoT | Edge Computing | WAN outage | Protocol Conversion | Hot Standby Redundancy | Industrial Gateway.