For decades, manufacturing security was defined by fences, guards, badges and investigations into theft or misconduct – while these fundamentals remain essential, they alone are no longer sufficient, writes RC Miles.
The modern manufacturing environment is shaped by a complex multidimensional interchange of globalised supply chains, geopolitical volatility, rapid automation and the convergence of physical and cyber systems.
Threats now extend far beyond perimeter breaches to include OT cyber-attacks, insider risk, cargo theft, intellectual property espionage and cascading disruptions across logistics networks, creating a dynamic and opaque situation that will overwhelm the traditional approach.
For security executives, this reality demands a strategic shift. Manufacturing security must evolve from a narrowly scoped protective function into a business enabler that safeguards operational continuity, corporate reputation, regulatory compliance and long-term competitiveness.
This requires close collaboration among operations, human resources, IT, supply chain management, health and safety and executive leadership, often placing the security executive in the role of enabler, seeking tools that serve as a lens to make clear what is out of focus.
Incorporating frameworks like ESRM (enterprise security risk management) helps translate these threats into actionable strategies, ensuring security investments directly support manufacturing resilience and growth.
ESRM as the strategic foundation
ESRM provides a governance framework that aligns security investments with business priorities.
Rather than treating security as an isolated function, ESRM recognises that assets belong to the organisation and that leaders own the risks associated with those assets.
Within manufacturing environments, asset ownership is distributed across functions: Production lines and throughput targets reside with operations; workforce management with human resources; digital infrastructure and industrial control systems with IT and engineering; supplier and transportation networks with supply chain leadership; regulatory compliance with health, safety and environmental teams.
A practical ESRM implementation begins with a plant-specific risk register that identifies critical assets, credible threats, vulnerabilities and business impacts.
Framing impacts in operational terms – lost production hours, missed customer commitments, regulatory penalties and safety incidents – enables executives to assess risk in language that supports informed decision-making, which can only be achieved by working collaboratively with the key leaders who own the asset and support the manufacturing process.
In most cases, the general manager (GM) sits at the top of this pyramid.
The relationship with this individual is not only meaningful, but essential. They typically have the best cross-functional view of all plant operations and, more importantly, hold P&L responsibility; as such, their views on the risks are essential.
Transparency regarding organisational risk tolerance further strengthens governance, particularly in the context of the aforementioned GM. Not all risks can be eliminated economically or operationally.
Documenting which risks are accepted, mitigated, transferred or avoided elevates security discussions to the executive level and enables disciplined resource prioritisation.
Building a robust physical asset protection framework
Physical asset protection (PAP) translates risk assessments into layered, performance-based safeguards proportionate to business impact.
In manufacturing environments, this typically includes perimeter controls, access controlled entry points, internal zoning of production areas and targeted protection for high-value tooling, hazardous materials and research and development assets.
Effective programs extend beyond technology deployment. They rely on measurable performance metrics such as time to detect, delay effectiveness and response capability.
Regular testing, audits and exercises validate whether controls function as designed under realistic conditions.
Security executives should ensure that safeguards are continuously evaluated against evolving threats, facility expansions, automation initiatives and workforce changes. This ongoing process can foster a sense of control and confidence in their security posture, emphasising operational resilience and safety.
Workforce, identity and access management
Manufacturing operations depend on complex labour ecosystems that include permanent employees, contractors, temporary workers, integrators and logistics personnel.
High turnover, project-based staffing and regulatory requirements increase identity management complexity.
Modern programs emphasise role-based access controls, automated provisioning and de-provisioning linked to human resources systems and time bound credentials for temporary personnel.
These measures reduce admin error, limit unnecessary access and improve auditability.
Visitor management programs should incorporate pre-registration, identity verification, escorting and exit accountability. From an insider risk perspective, many significant incidents involve individuals who were authorised to be present but exceeded their legitimate access.
In fact, the insider threat poses the most important ongoing challenge that a manufacturing operation faces. In 2025, current and former employees of Ford Motor Company were charged with stealing millions of dollars in parts from the company’s Dearborn facility.
Detecting this type of threat, which can result in increased black or grey market losses, can be very challenging and should be incorporated into the ESRM risk registry. In doing so, it will allow the team to understand their losses better and develop methods to prevent them.
A key element in increasing detection levels is gaining the support of the employee population. Here, a combination of training programs and reporting mechanisms is essential.
The training program should articulate and define the expected behaviour, encourage anomaly reporting and further strengthen prevention. Engaging employees in this fashion is often challenging, as many feel greater loyalty to their fellow workers than to the organisation that employs them.
However, even if only a small portion of employees are impacted by the training, the results will far exceed the effort invested in these programs.
Employees are often the earliest indicators of emerging risk when they are empowered to report concerns without fear of retaliation. To capitalise on this training, there should be effective reporting mechanisms in place.
Two critical mechanisms that should be available are incident reporting and an anonymous “whistle-blower” process. Both systems should be readily available and platform-agnostic, allowing employees to report them via computer or smartphone.
Protecting manufacturing information and OT systems
The integration of OT with enterprise information systems has transformed manufacturing efficiency while simultaneously increasing cyber-risk.
Industrial control systems that were once isolated now connect to corporate networks and external service providers.
Security leadership must therefore partner closely with IT and engineering teams to implement network segmentation between IT and OT environments, enforce strict remote access controls for vendors and maintain disciplined vulnerability management and backup practices.
Cyber-incidents increasingly result in physical consequences. Ransomware or unauthorised system manipulation can halt production, damage equipment and create safety hazards. As a result, cyber scenarios should be integrated into emergency response planning and executive level crisis exercises.
Securing supply chains and logistics operations
Manufacturing security extends well beyond facility boundaries. Raw material sourcing, transportation networks, third party warehouses and final distribution represent some of the organisation’s most significant vulnerabilities.
Best practices include driver identification protocols, seal control procedures, load verification, yard management oversight and contractual security requirements aligned with recognised standards such as the Customs Trade Partnership Against Terrorism (C TPAT) and Authorized Economic Operator (AEO) programs.
Disruptions within logistics networks can rapidly cascade into production stoppages, contractual penalties and customer dissatisfaction. Executive awareness of critical dependencies and contingency planning is therefore essential to organisational resilience.
Emergency management, incident response and business continuity
Comprehensive security programs assume that disruptive incidents will occur. Fire, industrial accidents, workplace violence, cyber-attacks and natural disasters are inherent operational risks.
All hazards planning anchored in recognised command structures such as the Incident Command System (ICS) and National Incident Management System (NIMS) enables coordinated decision making during crises.
Plant specific response plans should define leadership roles, communication protocols, evacuation or shelter in place procedures and coordination with public authorities.
Regular tabletop exercises and full-scale drills validate readiness and reveal gaps in authority, training and communications. Business continuity planning further defines recovery priorities, restoration sequencing and alternative sourcing strategies.
Security as a core component of executive leadership
Manufacturing security in the current risk environment is inherently interdisciplinary and inseparable from enterprise risk management.
Organisations that integrate ESRM principles, performance-based physical protection, modern access management, cyber-physical coordination, resilient supply chain practices and disciplined continuity planning are better positioned to withstand disruption and sustain long-term growth.
For executive leadership, security is no longer a supporting function. It is a strategic capability that protects operational continuity, regulatory compliance, workforce safety and corporate reputation.
In an era where a single incident can halt global production, manufacturing security has become a defining element of responsible governance and competitive advantage.
About the Author
Ralph (RC) Miles, CPP, is a highly accomplished global security leader with decades of experience in corporate security, emergency management and risk mitigation.
He is Global Director of Security for Bombardier Recreational Products (BRP), a global manufacturer of powersports vehicles. BRP employs nearly 16,000 people worldwide and operates in 130 countries across all five continents.


