SOC for manufacturing: monitoring IT and OT together
During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.
How this compares to neighbouring topics
This page covers SOC for manufacturing and industrial operations with IT/OT convergence. For a general frame, see SOC as a Service Switzerland. SMEs without OT belong on SOC for SMEs. To clarify SOC versus MDR, read SOC vs. MDR.
Making IT/OT convergence visible
Modern manufacturing is connected manufacturing. MES systems, predictive maintenance and cloud analytics connect OT with IT. The most interesting attack paths sit right at that seam: from the IT domain down to the PLC.
Downtime as the core risk
An hour of downtime in serial production costs payroll and machine costs, blocked orders and late deliveries. Ransomware targets exactly that pain point: encrypted file shares, unusable engineering stations, blocked orders.
What we monitor concretely
- Active Directory and engineering endpoints
- Remote-maintenance access (VPN, jump hosts)
- MES, ERP and file share activity
- East-west traffic between IT and OT
- Suspicious processes on Windows-based HMIs
Placement in SOC operations
See SOC as a Service Switzerland for details of the framework and operating model.
Frequently asked questions
Can a SOC monitor OT without disruption?
Yes, we work passively (SPAN/TAP), read from historian and OT protocols and do not write to the PLC. Active measures always take place in the IT segment.
What happens during an incident in production?
The SOC isolates affected IT systems, prevents spread into OT, coordinates with plant management and triggers IR playbooks. The goal is to restart production cleanly as quickly as possible.
How fast do you detect ransomware in a manufacturing environment?
We typically detect ransomware within minutes of the first encryption or lateral-movement signals. Halcyon adds a kill-switch.
How does SOC operation fit the 24-hour ISG reporting deadline?
Detection and triage run around the clock so that reportable incidents can be reported to the National Cyber Security Centre (NCSC) within the deadline. See [ISG reporting duty](/en/soc/soc-isg-24h-reporting).
What does a SOC typically cost for a Swiss manufacturer?
The cost depends on the number of sites and endpoints. See the ranges on [SOC cost Switzerland](/en/soc/soc-cost-switzerland).
Related terms
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Supply Chain Attack A supply chain attack targets an organisation through a trusted supplier, software, or service provider with access.
- Insider Threat An insider threat comes from individuals with legitimate access who misuse it, either intentionally or negligently.