Manufacturing in the Crosshairs: 18.4% of Known Cyber Incidents in Italy in H1 2026
According to Clusit data presented in Milan on 7 October 2026, manufacturing accounted for 18.4% of publicly known cyber incidents in Italy in the first half of 2026, versus 5.4% globally. The gap matters to anyone connecting machines, MES and shop-floor data to corporate networks.
On 7 October 2026 in Milan, at the opening of the Security Summit OT 2026, researchers from Clusit (the Italian Association for Information Security) presented data on successful cyber attacks in the manufacturing sector in the first half of the year. The event, dedicated to the security of industrial systems and OT infrastructure, is organized by Clusit together with Astrea, with the support of CSET, ANIPLA and Consorzio PI Italia.
The numbers: Italy versus the global average
Between January and June 2026, manufacturing accounted for 18.4% of publicly known cyber incidents in Italy. Over the same period, the worldwide share was just 5.4%. In practice, nearly one known incident in five in Italy hits a manufacturing company, a proportion more than three times the global figure.
Nearly one cyber incident in five in Italy involves manufacturing.
Cybercrime remains the dominant threat, both in Italy and elsewhere: most events are therefore driven mainly by criminal motives rather than geopolitical or demonstrative ones.
What the data tells us, and what it doesn't
Some caution is needed. The information available at the time of writing is limited to the opening data of the presentation: the absolute number of incidents, the breakdown by attack technique or manufacturing sub-sector, and the comparison with previous half-years are not known. It would therefore be incorrect to draw conclusions on those points.
It should also be noted that these are known incidents, meaning those made public. It is reasonable to assume the real number of events is higher, because not every company discloses an attack. This is an inference, not a stated figure, but it helps put the percentages in realistic perspective.
Why it matters to anyone running a plant
For plant managers, production directors and IT/OT leads, the message is that Italian industry is a disproportionate target compared with the global average. This matters most in factories that are connecting lines, machines, MES and shop-floor data to wider networks: every new connection enlarges the attack surface.
A production stoppage caused by an attack is not just an IT problem: it means late orders, idle lines and, in more sensitive sectors, risks to quality and safety. That is why OT security should be designed in from the start of digitalization projects, not bolted on afterwards.
Practical guidance
A few points to check in factory connectivity projects, in line with general good practice:
- Map all connected assets (machines, PLCs, gateways, supervisory systems) and keep the inventory up to date.
- Segment the network, clearly separating the OT side from the IT network and from external access.
- Control and log remote access, including access by maintenance vendors.
- Define a response and recovery plan involving production, IT and OT together, and test it regularly.
- Include security requirements in specifications for new machines and shop-floor software.
The data presented in Milan on 7 October 2026 does not tell the whole story, and it will be useful to dig deeper once more details are available. Even now, however, the gap between Italy's 18.4% and the global 5.4% is a good reason to put OT security at the center of decisions about the connected factory.