What Does Manufacturing IT and OT Security Look Like in the Pacific Northwest?

Manufacturing IT and OT security in the Pacific Northwest looks like a hard boundary between your office network and your production floor, an asset inventory of every PLC and HMI you own, patched and monitored OT workstations where possible, segmented vendor remote access, and a documented incident response plan that contemplates production stoppage. The reference is NIST SP 800-82 Revision 3, published in September 2023 – not the 2015 version your prior IT person handed you. The threats are real, the consequences are physical, and the supplier-security expectations from aerospace and defense primes are rising every quarter.

What Makes Manufacturing Different from “Regular” IT?

A typical office network handles email, file shares, and a finance system. A manufacturing environment runs all of that plus an operational technology (OT) layer: PLCs (programmable logic controllers), HMIs (human-machine interfaces), SCADA systems, CNC controllers, robot teach pendants, MES (manufacturing execution systems), historians, and a long tail of single-purpose Windows boxes the vendor will not let you patch.

The differences that matter for security:

  • Uptime requirements are physical, not just commercial. A 4 a.m. ransomware event in an office means lost productivity. The same event on a CNC fleet means scrap, damaged tooling, and missed delivery on a defense contract.
  • Patching windows are narrow or nonexistent. A controller that has been running fine for eight years has a reason it has been running fine – and the vendor often refuses to support updates.
  • Vendor remote access is everywhere. Tooling vendors, robot integrators, and machine OEMs all want VPN or “we’ll just install TeamViewer for support” – and rarely document any of it.
  • The lifecycle is long. Office laptops turn over every three to five years. A CNC controller may run for 20.

NIST SP 800-82 Rev 3 (“Guide to Operational Technology Security”) is the canonical reference. Pacific Northwest manufacturers should treat it as the playbook against which you build your environment, not as optional reading.

Why the Pacific Northwest Manufacturing Sector Is a Target

The PNW manufacturing base is unusually deep and unusually visible. Boeing’s Everett facility is the largest building in the world by volume; Naval Station Everett is the most modern Navy installation on the West Coast; the Tri-Cities corridor hosts national-lab adjacent suppliers; and Snohomish County alone has hundreds of machine shops, composites fabricators, and aerospace tier-2 and tier-3 suppliers.

That ecosystem makes the region a known target. The general lesson from Colonial Pipeline in 2021 – the most cited OT incident in the last five years – is widely misunderstood. The ransomware affected the IT/billing systems. The operator chose to shut down the OT pipeline because they could not reliably bill customers without those IT systems, not because the ransomware directly compromised the pipeline controllers. The point for a Western Washington manufacturer: even if your OT network is “air-gapped,” a ransomware event on your ERP, scheduling, or quality systems can stop production. The dependency chain matters more than the network diagram suggests.

For ransomware fundamentals, ransomware protection for small business walks through the controls that actually move the needle. The OT layer needs everything in that article plus segmentation and asset inventory.

What Do Aerospace and Defense Primes Actually Require of Suppliers?

This is where careful reading matters. Boeing’s published Information Security Requirements for Suppliers and its supplier-portal guidance lean on NIST Cybersecurity Framework and ISO/IEC 27001 as the general baseline – not CMMC. CMMC only flows down to a supplier when that supplier is performing work involving DoD Controlled Unclassified Information (CUI). A machine shop making commercial 737 brackets is not in CMMC scope from the contract; a shop making parts for a DoD program with CUI specifications absolutely is.

The practical translation for a Snohomish County tier-2 supplier:

  • If you do any DoD CUI work, assume CMMC Level 2 is in your future. See our detailed walkthrough of CMMC compliance in Washington for what that requires.
  • If you do only commercial aerospace work, your prime is still going to push you toward NIST CSF alignment, MFA, EDR, and supplier-security questionnaire responses that match reality.
  • Either way, the trend is clear: primes are auditing suppliers, asking for SOC 2 reports or equivalent attestations, and dropping suppliers that cannot answer basic questions about their security program.

Do not let a vendor convince you that “Boeing requires CMMC for all suppliers.” That is overreach and it muddies the waters with finance leadership. Get clear on which of your contracts involve CUI and which do not.

What Does a Real IT/OT Architecture Look Like?

Stripped of jargon, a defensible architecture for a small-to-midsize PNW manufacturer looks like this:

  • A firewalled boundary between IT and OT. Not a “DMZ” that allows unrestricted RDP. An actual policy-driven boundary with logged, justified rules.
  • An asset inventory of every device on the OT side, including model, firmware version, owner, and patch posture. You cannot defend what you do not know exists.
  • Segmented vendor remote access through a jump host with MFA and session recording – not a permanent VPN tunnel to a machine OEM.
  • EDR on every IT endpoint, and on OT workstations where the vendor permits it. For the rest, compensating controls: USB lockdown, allow-listed applications, and network monitoring.
  • Backups that include OT data – recipe files, PLC programs, HMI configurations, historian data – and that have been tested for restore.
  • Patched, supported operating systems. A Windows 7 HMI on a flat network is the most common high-severity finding we see in Washington shops. Compensate or replace.
  • A documented incident response plan that contemplates production stoppage, including who decides to shut a line down and who calls the prime.

For more on the broader regional threat picture, see cybersecurity threats for Pacific Northwest businesses.

What Does Onboarding Look Like for a Manufacturer?

A manufacturing onboarding is heavier than a typical office onboarding. The first 90 days usually look like:

  1. Days 1-30: Asset discovery on IT and OT, network mapping, identifying every vendor remote-access path, inventorying every Windows box on the production floor.
  2. Days 31-60: Closing the obvious holes – MFA everywhere, EDR everywhere supported, deny-by-default firewall rules between IT and OT, backups verified.
  3. Days 61-90: Documentation – supplier security questionnaire answers, written information security policy, incident response plan, vendor-access procedures, and a roadmap for the long-lifecycle OT assets that cannot be remediated quickly.

It is not glamorous work. It is also the work that keeps your DoD-adjacent contract eligibility and keeps your production line running when the rest of your peer group is getting hit.


ROI Technology Inc. supports Pacific Northwest manufacturers – aerospace tier-2 and tier-3 suppliers, machine shops, composites fabricators, and food and beverage producers – with IT/OT segmentation, supplier-security readiness, and NIST-aligned operations. Contact us or call (888) 707-3652 for a no-cost shop-floor assessment focused on the gap between your office network and your production line.