by Gary Mintchell | Apr 30, 2026 | Security
The typical cybersecurity firm releases reports. Here is one from a company called Resiliance. The unique take on this concerns linking cybersecurity technology to insurance risk. I’ve talked with people from various standards committees who believe a combination of insurance risks plus board-level concern with those insurance risks will drive management to pay more attention to the situation.
So consider this report as part of a larger management strategy.
Proprietary claims data reveal the simple practices manufacturing cybersecurity leaders should implement to limit financial risk
The best responses to change and management are the search for the simplest. Not too simple, but definitely trying to defeat overly complex processes.
Manufacturing is currently the single most targeted industry for cyberattacks. Given their critical role in the modern interconnected economy and low tolerance for downtime, manufacturers have become a prime target for threat actors looking for bigger payouts. On April 28, 2026, Resilience released The State of Cybersecurity in Manufacturing to identify the key drivers of financial losses based on real claims data and security practices that deliver measurable reductions in financial risk across its manufacturing portfolio. The report offers manufacturing security leaders, risk managers, and brokers clear, evidence-based solutions grounded in real claims.
Key findings from Resilience’s manufacturing claims data include:
- Over 90% of total incurred losses in Resilience’s manufacturing portfolio were attributable to ransomware, despite ransomware making up only 12% of claim volume among manufacturers. This shows that when attacks do happen, the losses are severe.
- Phishing and transfer fraud accounted for 30% of manufacturing claims, showing that human error is still one of the leading causes of cyber disruption.
- About 26% of all portfolio losses came from an MFA misconfiguration as the point of failure. The single most expensive event in Resilience’s manufacturing portfolio, attributed to BlackCat, was enabled by misconfigured MFA.
- Wrongful data collection caused 12% of claims, driven primarily by website tracking and pixel-related litigation, rather than operational data collection from connected manufacturing systems.
- There are five specific, implementable security controls that manufacturers can undertake to meaningfully address material risk and harden their defenses against cyber threats.
Importantly, Resilience’s new data illustrates that the controls security leaders should implement aren’t complicated. Simple adjustments are all that’s needed to strengthen their posture against cyber risk.
What security controls deliver the highest ROI for manufacturing organizations? Based on Resilience’s analysis of manufacturing insurance claims data and financial risk modeling, five controls consistently delivered the most significant identified impact on financial exposure:
- Auditing and validating MFA deployment supports consistent enforcement across all accounts, elimination of bypass conditions, and proper configuration of conditional access policies.
- Strengthening vulnerability management for external-facing systems hardens organizations from software vulnerability exploited directly linked to expensive ransomware outcomes.
- Implementing procedural controls for financial transfers can protect against phishing and transfer fraud attacks that represent the most frequent claim activity in the portfolio. This is a strategic cost-saving practice, as the average transfer fraud event costs roughly ten times more than the average email compromise.
- Extending security requirements to vendors and supply chain partners is designed to help insulate manufacturers from a distinct cause of loss in the claims data. Manufacturers should extend their security requirements to critical vendors, including contractual MFA and patching requirements, continuous monitoring of vendor risk posture, and contingency plans for disruptions to critical suppliers.
- Cyber risk quantification and transfer support the translation of cybersecurity risk into financial language that resonates with CFOs and boards to assist in securing adequate investment. Resilience’s claims data provides a concrete basis for this conversation: ransomware dominates loss, a single point of failure (MFA misconfiguration) drives the largest share of exposure, and unpatched software is a direct line to the most expensive outcomes. These findings are intended to inform specific control investments and insurance coverage decisions.
by Gary Mintchell | Apr 29, 2026 | Robots
Robotics pioneer ABB has released a new cobot family. The news in brief:
- New, high-speed, higher payload PoWa cobot family meets need for industrial-grade performance in collaborative robotics, lowering the barrier to automation for both SMEs and large enterprises
- Payloads from 7kg to 30kg, best-in-class top speed of 5.8 m/s, longest reach and highest arm load on the market
- Powered by ABB OmniCore controller platform and seamlessly integrated with ABB Robotics’ suite of software tools
ABB Robotics is combining the flexibility of cobots with higher payloads and performance, with the launch of its new PoWa cobot family into the rapidly expanding global collaborative robot market, which ABB Robotics estimates will grow by 20 percent annually through to 2028.
“Cobots are growing significantly faster than traditional industrial robots, driven by demands from both small and midsized companies starting their automation journey as well as large enterprises,” said Andrea Cassoni, Head of Collaborative Robots at ABB Robotics. “These customers are seeking higher speeds and payloads, but also greater ease of use, and compact designs. Established manufacturers want to automate heavier, fast cycle applications, without the complexity and operational rigidity of traditional industrial robots. We are meeting these needs with the global launch of our high-speed PoWa cobot family – a name that symbolizes its powerful, industrial-grade performance in a compact collaborative robot form.”
The new PoWa family addresses a long‑standing gap in the market between traditional cobots, that often lack the speed and payload required for industrial applications, and conventional industrial robots, which are designed for highly specialized, large-scale automation environments, going beyond the needs of many collaborative tasks.
PoWa extends ABB Robotics’ comprehensive cobot offer with industrial-grade performance including six different payload categories, from 7kg to 30kg, the longest reach and highest arm load on the market and best-in-class top speed of up to 5.8 m/s.
Purpose-built for compact environments and ideally suited for applications such as high-speed machine tending, palletizing, screwdriving and arcwelding, PoWa enables manufacturers to automate heavier and faster processes, while maintaining the flexibility, ease of use and compact footprint of collaborative robotics.
PoWa cobots are exceptionally easy to use, through programmable buttons on the arm-side interface and no-code programming and are compatible with an extensive ecosystem of third-party accessories. PoWa can be unboxed and operational within an hour and enables seamless plug-and-play with a wide range of tools, blending industrial-grade connectivity and performance with collaborative robot flexibility.
Powered by the ABB OmniCore controller platform, the new PoWa cobots deliver best-in-class motion control, speed, and precision and can be integrated with ABB Robotics’ expanding suite of AI-powered software, including Robot Studio and Wizard Easy Programming, enabling intuitive programming, fast deployment and maximum uptime.
Ensuring collaborative robots can do more things, in more places, and do it faster, safer and smarter is part of ABB Robotics vision for more autonomous and versatile robotics (AVRTM). By developing a new generation of intelligent, flexible, adaptative, and collaborative multi-skilled robots, ABB Robotics furthers robots’ ability to learn, understand and plan independently, giving them greater autonomy and versatility.
by Gary Mintchell | Apr 23, 2026 | Networking, Organizations, Security
This news release falls clearly into the category of Duh!!!
Human social engineering and humans gaining unauthorized access while serving as contractors and the like have long been known to be a cybersecurity risk. But, I’m happy to note that an august group has perceived the obvious.
The Industrial Security Harmonization Group (ISHG) has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.
Or, maybe, it’s along the lines of “it’s not all our fault?”
The ISHG—comprising leading industry organizations including the FieldComm Group, ODVA, OPC Foundation, and PROFIBUS & PROFINET International—collaborates regularly to align security concepts across Ethernet and non-Ethernet communication protocol technologies. Their shared mission is to reduce complexity for end users and promote consistent, effective cybersecurity practices in industrial automation systems.
I once set at an industrial communication organization meeting where an end-user pleaded for application guidelines. He was studiously ignored.
Industrial communication protocols serve as the backbone of modern automation, enabling seamless connectivity between devices, systems, and applications across both process and factory environments. However, many widely used protocols were originally developed without cybersecurity as a primary design consideration.
It now emphasizes a more practical and realistic approach:
- Security is context-dependent — It relies on how protocols are configured, where they are deployed, and the surrounding operational environment.
- Built-in security features are not sufficient alone — Even advanced protocols require correct implementation and maintenance.
- Compensating controls are essential — Network architecture, segmentation (zones and conduits), monitoring, and physical safeguards play a critical role, especially for legacy and non-Ethernet systems.
by Gary Mintchell | Apr 16, 2026 | Automation, Security
Cybersecurity news will not wither during my lifetime. I think that is a safe prediction. Especially given all the hype around Anthropic’s latest news velocity releases. Not enough media pays attention to potential huge problems with attacking critical infrastructure. You would think they would given Russia’s attacks on the Ukraine’s infrastructure.
This news concerns another partnership of a cybersecurity vendor and a control and automation vendor. This news from OPSWAT cites a strategic collaboration expanding operational technology (OT)-safe patch management capabilities to Emerson’s Ovation Automation Platform customers worldwide.
The April 16, 2026 announcement states the two companies have announced a global strategic reseller agreement that will bring OPSWAT’s cybersecurity technologies to Emerson’s power and water industry customers. As the first initiative under this enterprise-wide agreement, Emerson will integrate OPSWAT’s scalable and safe operational technology (OT) patch management capabilities into its Ovation Automation Platform.
The new OT patch management solution further builds on the collaboration to date by securing the Ovation Platform through OPSWAT’s MetaDefender Endpoint and My OPSWAT Central Management On-Premises, part of Emerson’s purpose-built power and water cybersecurity suite of solutions.
Critical infrastructure operators, including power generation and water/wastewater utilities, continue to face increasing cyber threats, regulatory pressure, and operational risk stemming from unpatched vulnerabilities. OPSWAT’s solution for the Ovation Automation Platform delivers a modernized patch management approach designed specifically for industrial environments, addressing challenges posed by a mix of modern and legacy tools and the ongoing surge of nation-state and ransomware activity targeting the energy and water sectors.
The new strategic collaboration expands on the well-established DeltaV Alliance agreement between OPSWAT and Emerson for OPSWAT’s MetaDefender Kiosk, and MetaDefender Unidirectional Security Gateway for the DeltaV Automation Platform.
The new global partnership also underscores Emerson’s strategy to collaborate with proven and effective cybersecurity providers, a shift driven by evolving global regulations and the need for continuous response to new vulnerabilities.
by Gary Mintchell | Apr 2, 2026 | Technology, Wireless
Proponents of cellular 5G private networks have touted benefits for a few years. The uptake seems slow. But there must be a market. In this news, Siemens announces expanding its private 5G infrastructure to eight more countries—including here in the US.
Siemens is bringing its industrial-grade private 5G infrastructure to the United States and seven additional countries. The expansion is enabled by two new radio units covering the 3.8–4.2 GHz band and the US-specific CBRS band bringing the solution to a total of 15 countries across Europe and the Americas. The dedicated CBRS-band radio unit opens the door for US manufacturers to deploy Siemens’ private 5G on their own premises, fully independently, serving a wide range of industrial sectors – including manufacturing, food and beverage, pharmaceuticals, intralogistics, heavy industries and crane operations.
Additionally, Siemens has enhanced its 5G routers with edge runtime capabilities, allowing apps to run directly on the device – eliminating the need for additional hardware and enabling real-time, AI-ready data processing directly on the shop floor. Both updates respond to a growing connectivity challenge at the heart of modern manufacturing.
Why?
As AI adoption in factories accelerates, data volumes are growing exponentially – and unlicensed Wi-Fi frequencies, prone to overloading in dense industrial environments, can no longer keep pace. Siemens’ private 5G infrastructure addresses this directly by operating on a licensed spectrum, delivering deterministic, interference-free connectivity for business-critical applications.
Siemens developed its private 5G infrastructure specifically with industrial use cases, operational requirements, OT cybersecurity, and end users in mind. The result is a rugged, industry-native end-to-end solution for independent, on-premises wireless network operation – without relying on third-party providers or mobile network operators. The solution integrates seamlessly into Siemens’ IT/OT landscape and is part of the Siemens Xcelerator portfolio.
The system supports key automation protocols, such as PROFINET, and offers freely adjustable upload and download capacities (TDD patterns). Configuration requires setting approximately 20 variables in a clear, accessible web-based dashboard designed for use by even non-IT personnel.
The solution has been certified by the German safety and certification body TÜV to support wireless PROFIsafe communication, making it suitable for safety-related use cases in combination with 5G routers and Siemens’ Safety Automation Equipment.
Newly added: Belgium, Canada, Finland, France, Norway, Poland, United Kingdom. USA will be available in Summer 2026
Already available: Austria, Brazil, Denmark, Germany, Netherlands, Sweden, Switzerland
Click on the Follow button at the bottom of the page to subscribe to a weekly email update of posts. Click on the mail icon to subscribe to additional email thoughts.
by Gary Mintchell | Mar 31, 2026 | Generative AI, News, Security
Several people involved with standards have shared with me the insight that the driving force for adoption of some of these will come from company boards due to insurance and risk management pressures. Therefore, I found this paper interesting looking at trustworthy AI from the point-of-view of risk management.
Høvik, Norway, 25 March 2026 – New research from assurance and risk management company DNV has identified the foundations to achieving trustworthy artificial intelligence in the context of safety critical industrial processes. According to the paper, Assurance of AI-Enabled Systems, established risk management principles can be adapted to meet the complexity and uncertainty of AI enabled systems. While AI introduces new risks, proven assurance methods from safety critical industries already provide a robust starting point for addressing them
The paper shows that AI reshapes risk because it does not operate as a fixed, predictable component. This makes traditional one‑time assurance insufficient, and highlights the need for continuous and adaptive assurance throughout the lifecycle
Christian Agrell, Programme Director for AI Assurance at DNV, said, “Creating trustworthy artificial intelligence does not require us to start from zero. We already have strong foundations in modern assurance and risk science and our long experience managing digital technologies in high‑risk environments. Applying these principles thoughtfully allows us to build systems that remain safe and reliable, even as they evolve. Trustworthy AI depends on predictable behaviour under uncertainty, and that is exactly what these foundations help deliver.”
The research draws on DNV’s decades-long assurance and risk management experience in critical infrastructure, including the maritime and energy sectors. The foundational principals to create trustworthy AI include:
- A system model that captures the entire AI-enabled system
- This model reflects how AI interacts with humans, digital and physical components, and its operational environment. It enables understanding of emergent behaviour, unintended interactions and context specific risks that cannot be detected by examining the AI component alone.
- Taking a modular approach
- A risk model, applying uncertainty-based assessment and modular risk principles to break down complex systems with their complex and emergent risks into manageable parts across system levels.
- Linking claims to evidence
- These structured arguments connect claims such as “the system is safe” to verifiable evidence, assumptions and rationale. This provides a transparent, auditable framework for demonstrating trustworthiness throughout the lifecycle.
- Continuous, context aware assurance that adapts as AI evolves
- AI-enabled systems change over time as models are updated, data shifts and operating conditions vary. To maintain trustworthiness, assurance must be ongoing rather than a onetime check. This includes real-time monitoring, regular updates to evidence, and reevaluating risks and requirements so that confidence in the system remains valid throughout its lifecycle
“These foundations give industry a clear, actionable way to build and maintain trustworthy AI. We are already working with companies that recognize the potential of AI, as well as the risks it can pose to the critical services they deliver. I urge more organizations to join us in addressing and managing the risks associated with artificial intelligence,” Agrell added.
The position paper is part of DNV’s broader work to help industry adopt AI responsibly and aligns with the company’s recommended practice (DNV‑RP‑0671) for AI assurance.
Click on the Follow button at the bottom of the page to subscribe to a weekly email update of posts. Click on the mail icon to subscribe to additional email thoughts.