SOC for manufacturing: monitoring IT and OT together

During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.

All

How this compares to neighbouring topics

This page covers SOC for manufacturing and industrial operations with IT/OT convergence. For a general frame, see SOC as a Service Switzerland. SMEs without OT belong on SOC for SMEs. To clarify SOC versus MDR, read SOC vs. MDR.

Making IT/OT convergence visible

Modern manufacturing is connected manufacturing. MES systems, predictive maintenance and cloud analytics connect OT with IT. The most interesting attack paths sit right at that seam: from the IT domain down to the PLC.

Downtime as the core risk

An hour of downtime in serial production costs payroll and machine costs, blocked orders and late deliveries. Ransomware targets exactly that pain point: encrypted file shares, unusable engineering stations, blocked orders.

What we monitor concretely

  • Active Directory and engineering endpoints
  • Remote-maintenance access (VPN, jump hosts)
  • MES, ERP and file share activity
  • East-west traffic between IT and OT
  • Suspicious processes on Windows-based HMIs

Frequently asked questions

Can a SOC monitor OT without disruption?

Yes, we work passively (SPAN/TAP), read from historian and OT protocols and do not write to the PLC. Active measures always take place in the IT segment.

What happens during an incident in production?

The SOC isolates affected IT systems, prevents spread into OT, coordinates with plant management and triggers IR playbooks. The goal is to restart production cleanly as quickly as possible.

How fast do you detect ransomware in a manufacturing environment?

We typically detect ransomware within minutes of the first encryption or lateral-movement signals. Halcyon adds a kill-switch.

How does SOC operation fit the 24-hour ISG reporting deadline?

Detection and triage run around the clock so that reportable incidents can be reported to the National Cyber Security Centre (NCSC) within the deadline. See [ISG reporting duty](/en/soc/soc-isg-24h-reporting).

What does a SOC typically cost for a Swiss manufacturer?

The cost depends on the number of sites and endpoints. See the ranges on [SOC cost Switzerland](/en/soc/soc-cost-switzerland).