Cyber resilience is a business capability
Cybersecurity has moved beyond the point where manufacturers can regard it as a specialist technology problem. Production, engineering, supply chains and customer delivery are now so dependent on digital infrastructure that a serious cyber incident can quickly become an operational crisis. The issue is therefore not simply whether individual systems can be protected, but whether the organization can continue operating when disruption occurs.
For Paul Knight, Group VP Information Technology and Security at Martin-Baker Aircraft Company, that change is already well established. “The frequency and visibility of cyber incidents mean they are no longer confined to the technology function,” he says. “The gap between a breach occurring and it becoming public knowledge is now often measured in hours rather than weeks, with new incidents and high-profile attacks regularly making headlines. At the same time, organisations face increasing regulatory scrutiny and contractual obligations, particularly in highly regulated industries such as manufacturing, aerospace and defence.
“More fundamentally, cyber resilience is now a business issue because technology and data underpin almost every business process. Manufacturing operations, engineering systems, supply chains, customer services, finance and decision-making all rely on digital platforms and the data they provide. When those systems become unavailable, the impact is not technical, it affects production, customer delivery, revenue, compliance and reputation.”
Connectivity changes the risk equation
Manufacturers have embraced connectivity because it provides greater visibility and operational control. Industrial IoT, cloud platforms and connected equipment can improve production, maintenance, quality and supply chain performance, but they also increase the number of systems and dependencies that organizations must understand and protect. In many cases, the technology is no longer selected or deployed solely through IT.
“Five years ago, IT teams were typically involved in the design, deployment and support of most connected technologies,” Knight says. “Today, many IoT and operational technology solutions are selected, installed and managed directly by engineering, manufacturing and operational teams, often with limited IT involvement. This has created a very different risk profile, with organisations frequently inheriting connected devices, software and network dependencies that may not have been designed or deployed with security in mind.”
That makes complete visibility increasingly difficult. Knight argues that security architecture needs to assume unmanaged devices may exist, using approaches such as segmentation, Zero Trust and continuous monitoring to contain potential compromises. In sectors such as aerospace, that requirement sits alongside an equally strong need to innovate without undermining safety, quality or operational continuity.
“In aerospace, safety and quality are paramount, which means innovation cannot come at the expense of control, reliability or assurance,” he says. “Success comes from embedding security, resilience and compliance into the design and deployment of new technologies from the outset. Organisations need to understand which systems, data and processes are truly critical and apply appropriate controls around them.”
Regulation should build resilience
Manufacturers are also facing a growing range of cybersecurity, resilience and data protection requirements. Addressing every regulation as a separate compliance project risks creating duplicated effort and fragmented controls, while organizations that establish a strong common foundation can adapt more easily as requirements evolve. Knight believes recognized frameworks can provide that starting point.
“There is a baseline set of recognised standards that can put organisations on a much stronger footing whilst also preparing them for future regulatory requirements,” Knight continues. “The key is identifying regulatory headwinds early and aligning security, governance and resilience programmes to the path of least resistance. In my experience, frameworks such as ISO 2700, CE+ and NIST 800-171 provide an excellent foundation, establishing disciplines around risk management, asset control, data protection, governance and incident response that apply across most industries.”
The business value extends beyond proving that a requirement has been met. Established controls can improve asset visibility, accountability and operational resilience while reducing the cost and complexity of responding to future regulations. As Knight puts it, “The real value is not compliance itself, but using these frameworks to drive business maturity, resilience and long-term competitive advantage.”
Supply chain risk requires shared ownership
Cyber risk now extends well beyond the manufacturer’s own infrastructure. Software companies, cloud providers, equipment vendors and other suppliers can introduce dependencies capable of disrupting operations if they fail or are compromised. Manufacturers therefore need to understand which relationships represent material business risk without making procurement unnecessarily slow.
“Establishing an active supplier risk management programme is essential, but there needs to be a pragmatic balance between the speed of vendor onboarding and the level of assessment applied,” Knight explains. “Not every supplier presents the same level of risk, which is why organisations need a risk-based approach. The most effective programmes are built through close collaboration between IT, procurement, supply chain, quality and business stakeholders to define clear rules of engagement, supplier criticality and assessment criteria.”
Technology procurement can be particularly challenging when new systems are acquired without sufficient understanding of their security, resilience and contractual implications. Bringing technology, procurement and operational teams together allows risks to be identified before they become embedded in the business. The objective is not an impossible promise of eliminating supplier risk, but improving the quality of the decisions being made about it.
“The goal is not to eliminate supply chain risk, which is impossible, but to make informed decisions and prevent supplier issues from becoming operational or business disruptions,” Knight says.
Boards need business choices
The shift toward cyber resilience has also changed the boardroom conversation. Knight believes boards increasingly understand that technology and cybersecurity belong alongside financial, operational and regulatory risks. Security leaders therefore need to translate technical exposure into choices executives can evaluate in terms of cost, business impact and acceptable risk.
“As technology leaders, we need to translate technical issues into business outcomes,” Knight adds. “Rather than presenting cyber risk as ‘the sky is falling and we need to spend £X to fix it’, we should present it in terms executives understand: here is the risk, here is the potential business impact, and here are the options available to manage it. Boards are accustomed to making decisions based on risk, cost and opportunity.”
This requires technology leaders who understand more than the technical threat landscape. They need sufficient knowledge of business strategy and operational priorities to explain where investment will have the greatest impact and where risk can reasonably be accepted. Cybersecurity then becomes part of normal enterprise governance rather than an exceptional conversation triggered by an incident.
AI raises the stakes
AI will reinforce many of these challenges. Manufacturing offers substantial opportunities to apply AI to quality assurance, engineering analysis, maintenance, simulation and production planning, but those systems depend on access to trusted information. Weak data ownership and unclear controls can therefore become both an operational and a cybersecurity problem.
“The challenge is ensuring AI is built on trusted data and deployed within appropriate governance frameworks,” Knight says. “AI is only as good as the information it can access, and many organisations still struggle with data ownership, quality and consistency. From a cybersecurity perspective, AI also introduces new risks around data leakage, intellectual property exposure and the use of unapproved tools.”
Knight argues that manufacturers should establish data governance, ownership and clear guardrails before attempting to scale AI. The organizations that do so will be better positioned to capture its productivity benefits without introducing unnecessary new vulnerabilities. More broadly, the manufacturers that build resilience successfully will be those that treat asset visibility, supplier assurance, recovery planning and governance as business capabilities rather than activities owned solely by security teams.
“The organisations that make the best decisions will have leaders with strong technical foundations who also understand business strategy and operational priorities,” Knight says. “They will give technology and security leaders a genuine seat at the table and help them develop into business leaders, not just technical specialists.”
Join the conversation at the Manufacturing Data Summit
Paul Knight, Group VP Information Technology and Security at Martin-Baker Aircraft Company, will join the panel, “Cybersecurity, data security and regulatory readiness: From technical risk to business accountability,” at the Manufacturing Data Summit UK 2026. The discussion will examine how manufacturers can manage cyber and regulatory risk as enterprise issues, strengthen resilience across increasingly connected supply chains and improve board-level accountability for technology risk.
“I’m hoping delegates take away that cyber resilience is no longer something that sits within the IT department, it’s a business-wide responsibility,” Knight says. “Manufacturing organisations are becoming increasingly dependent on data, connectivity, automation and AI to drive efficiency and growth. The question is no longer whether a cyber incident will occur, but how prepared the organisation is to continue operating when disruption happens.”
Taking place in London on October 6, 2026, the Manufacturing Data Summit will bring together manufacturing, operations, data and digital leaders to explore how organizations can unlock greater value from data, AI and connected technologies while addressing the governance, security and operational challenges that accompany them. Register to attend the Manufacturing Data Summit and hear directly from Paul Knight and other manufacturing leaders tackling these issues in real-world environments.

