Podcast: How AI changes cybersecurity for manufacturers

In this episode of Great Question: A Manufacturing Podcast, Dennis Scimeca of IndustryWeek and Scott Achelpohl of Smart Industry examine several recent AI-driven cyberattacks in manufacturing facilities.

Key Highlights

  • AI is accelerating cyberattacks, shortening the window manufacturers have to detect vulnerabilities and deploy defenses.
  • Widely deployed PLCs are attractive targets, making OT cybersecurity critical for factories and infrastructure operators.
  • Patching is essential, but large manufacturers face complex barriers from legacy systems, software versions and operational requirements.
Listen on Apple buttonListen on Spotify buttonListen on iHeartRadio buttonListen on Podbean button

In this episode of Great Question: A Manufacturing Podcast, IndustryWeek technology editor Dennis Scimeca and Smart Industry head of content Scott Achelpohl discuss the evolving cybersecurity challenges facing manufacturers. They examine recent attacks targeting PTC product lifecycle management software and Siemens S7 PLCs, highlighting the complexities of patching vulnerabilities across industrial environments. The conversation also explores how AI is accelerating cyberattacks and shortening the time available for organizations to respond.

Below is an excerpt from the podcast:

DS: Hello, and welcome to our next episode of the Great Question Podcast. I'm Dennis Scimeca, Senior Editor for Technology at IndustryWeek, and I'm joined by my friend and colleague Scott Achelpohl, Smart Industry's Head of Content.

SA: Heya, Dennis. Nice to be on the program.

DS: Thanks for joining us. So today we're talking cybersecurity, Scott. It's one of the least sexy topics we've covered at IndustryWeek, but also one of the most important. Scott's joining us today because cybersecurity is a much hotter topic over at Smart Industry, where they can get into some of the technical aspects of the hacks that we cover.

Now, IndustryWeek, of course, covered Verizon's annual Data Breach Investigations Report when it was released in late May. You can also look up additional coverage of that on Smart Industry. I recommend looking up these stories for a condensed 50,000-foot view of the cybersecurity situation as a whole, not only in manufacturing, but in terms of major events or attempts to break into a system with no tangible results and major breaches – roughly defined as successful attempts to break into systems that likely include data theft – 2026 has been fairly quiet.

That was until last week, when it rains, it pours, and we had two stories to report on, both at IndustryWeek and Smart Industry.

First, the CLOP  C-L-O-P ransomware gang claimed responsibility for 43 cyber attacks against targets including GE, Philips, and Shell. The attacks were targeted specifically at two product life cycle management or PLM tools developed by PTC, Windchill, and Flex PLM. The number of victims gives you an idea as to how widely these systems are deployed. Now this story turned into a conversation about patching. Whenever you hear cybersecurity experts describe optimal cybersecurity hygiene, they always talk about the importance of patching. And in this case, PTC began releasing patches for this known vulnerability in mid-June.

So how do companies the size of GE, Phillips, and Shell, that ostensibly have large IT departments with people keeping an eye out for these patch releases, not have their systems patched two months later?

Well, we spoke to some experts, and it turns out that's an incredibly simplistic way to look at the problem. And we can't assume that GE Philips and Shell weren't on the ball here. In fact, the larger the company, the more difficult to apply patches org-wide.

There can be different versions of the software running across the org, and every version might not have a patch released at the same time. If the technology is old, especially an end-of-life system, it might not be easily updatable.

There might be operational or regulatory issues that slow things down. And for all anyone knows, the ransomware gang may have been inside these PTC environments long before anyone realized the security issue existed, in which case the security battle was over before it began.

So the short version is that cybersecurity experts can talk all they want about the importance of patching, but it isn't that simple. And we can't assume that just because a company fell victim to a known vulnerability, even with plenty of advance notice, that means said company isn't monitoring for patch releases and applying them as soon as possible.

Contributors:

About the Author

Dennis Scimeca

Dennis Scimeca is a veteran technology journalist with particular experience in vision system technology, machine learning/artificial intelligence, and augmented/mixed/virtual reality (XR), with bylines in consumer, developer, and B2B outlets. At IndustryWeek, he covers the competitive advantages gained by manufacturers that deploy proven technologies. If you would like to share your story with IndustryWeek, please contact Dennis at [email protected].

Scott Achelpohl

Scott Achelpohl is the managing editor of Smart Industry. He has spent stints in business-to-business journalism covering U.S. trucking and transportation for FleetOwner, a sister website and magazine of SI’s at Endeavor Business Media, and branches of the U.S. military for Navy League of the United States. He's a graduate of the University of Kansas and the William Allen White School of Journalism with many years of media experience inside and outside B2B journalism.

Sign up for our eNewsletters
Get the latest news and updates