Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

MxD’s July 2024 report found that 76% of surveyed manufacturing cybersecurity decision-makers expressed high confidence that their organizations could prevent cyber risks and respond to attacks. Yet only 16% reported extensively detailed cybersecurity policies and 34% reported comprehensive system security plans. The contrast suggests a confidence gap—but it is a gap in self-reported opinions and practices, not proof from an independent technical audit.

What the MxD manufacturing cybersecurity survey actually measured

APCO Insight conducted the survey for MxD from November 30 through December 15, 2023. It questioned 750 senior-level cybersecurity decision-makers at manufacturing companies doing business in the United States. Respondents described their organizations’ confidence, plans, leadership arrangements and reported practices; the study did not perform penetration tests, inspect systems or independently verify control effectiveness.

The sample included 630 small-medium manufacturers with 500 or fewer employees and 120 large manufacturers with more than 500 employees. Sector groups were aerospace and defense (106 respondents), the defense industrial base (102), chemicals (137) and other manufacturing (405). MxD notes that the responses represent respondent opinions and do not necessarily represent MxD’s views.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because the fieldwork occurred in late 2023 and the report was released in July 2024, these figures are a survey-period snapshot. They do not establish the exact cybersecurity readiness of U.S. manufacturing in 2026.

The headline disconnect: confidence is higher than formalization

Measure Reported result What it means
High confidence in preventing cyber risks and responding to attacks 76% Respondents’ assessment of organizational capability; not an independently tested outcome.
Extensively detailed cybersecurity policies 16% A small minority reported policies with extensive detail.
Comprehensive system security plans 34% About one-third reported comprehensive plans, a separate measure from policy detail.
Planned cybersecurity budget increase 82% An intention for the upcoming budget cycle, not verified later spending.

The 16% and 34% figures should not be merged. A policy explains required rules and responsibilities, while a system security plan normally documents how particular systems will be protected, managed and monitored. An organization can have a policy without a comprehensive system-level plan, or a plan that is not supported by sufficiently detailed policy.

This is why the report’s “overconfidence” concern should be read carefully. High confidence may coexist with incomplete documentation, uneven implementation or limited resources. The survey reveals that perception and formal preparedness do not line up; it does not prove that any named company’s controls fail.

How many manufacturers have a dedicated cybersecurity leader?

Across the sample, 43% reported employing a dedicated cybersecurity leader. Organization size produced a pronounced difference:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Manufacturer group Definition used by MxD Reporting a dedicated cybersecurity leader
Large manufacturers More than 500 employees 88%
Small-medium manufacturers 500 or fewer employees 35%
All respondents All 750 surveyed decision-makers 43%

A dedicated leader can provide ownership for risk decisions, incident preparation, regulatory work and supplier oversight. The survey does not say that every organization without such a role lacks security expertise; smaller companies may assign duties to an IT manager, operations executive or outside specialist. It does show a large difference in reported leadership capacity between the two size groups.

Why smaller manufacturers may be less prepared

The report does not establish a single cause, but the size split is consistent with several practical constraints: fewer security specialists, less budget for dedicated roles, limited time for documentation and dependence on shared IT responsibilities. Small manufacturers may also face the same customer and supplier requirements as larger firms without comparable administrative capacity.

Those pressures make formal plans and assigned accountability especially important. A small company can start by naming an accountable executive, inventorying critical systems, documenting recovery priorities and setting a recurring review schedule rather than treating cybersecurity as an occasional IT task.

What the survey found about suppliers and customer contracts

Vendor requirements are common but not consistently comprehensive

Among respondents, 68% said they had embedded cybersecurity requirements in vendor contracts. Only 31% rated those requirements comprehensive, while 64% reported provisions allowing vendor checks. These are different controls: a contract clause may state expectations, whereas a check tests or validates whether a supplier meets them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The results point to a maturity gap in third-party risk management. Manufacturers may require security language yet lack consistent review criteria, evidence requests, reassessment schedules or escalation procedures. The figures do not identify which vendors were checked or whether checks found effective controls.

Customer requirements create operational pressure

Seventy-four percent reported moderate difficulty meeting cybersecurity requirements in customer requests for proposals and contracts. That difficulty can reflect documentation demands, technical safeguards, evidence collection, staffing or requirements that differ between customers. It is a reported business burden, not a measurement of whether a manufacturer ultimately won or lost a contract.

What aerospace, defense and other sectors show

MxD’s summary says aerospace and defense led the surveyed sectors in preparedness. The available material does not provide sector-level percentages for every measure, so a precise ranking or numerical comparison among aerospace and defense, the defense industrial base, chemicals and other manufacturing would overstate the evidence.

Defense industrial base manufacturers should separately determine whether their contracts invoke Cybersecurity Maturity Model Certification (CMMC) obligations. MxD says it guides manufacturers through CMMC, but this survey does not verify a particular provider, assessment result or compliance status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the findings mean for a manufacturing security program

The survey supports four practical priorities rather than a specific product purchase:

  • Turn confidence into evidence: test incident-response procedures, recovery assumptions and access controls instead of relying only on executive sentiment.
  • Complete the documentation: maintain detailed policies and system security plans that identify owners, scope, dependencies, safeguards and review dates.
  • Assign accountable leadership: give a named person authority to coordinate security, operations, legal, procurement and incident response.
  • Make supplier oversight repeatable: standardize contract requirements, due diligence, evidence review, remediation and reassessment.

The reported 82% intention to increase spending indicates that many respondents recognized a need for investment around the survey period. It should not be presented as proof that budgets actually increased or that additional spending improved security.

Statements from MxD’s July 16, 2024 release

“We see a sense of overconfidence in our research results, which is concerning given that everyone is at risk, from the largest multinational to small- and medium-sized manufacturers who often lack the proper resources to protect themselves from cyber-attacks.”

— Berardino Baratta, MxD CEO, July 16, 2024

“Manufacturing sector cyber-attacks are no longer rare, one-off events,”

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

— Michael Tanji, MxD Director of Cybersecurity, July 16, 2024

How to read the report without overclaiming

  • It is a poll of senior decision-makers, not an audit of industrial networks or business systems.
  • “High confidence” describes what respondents believed about their organizations’ ability to prevent and respond; it does not demonstrate successful prevention or response.
  • Policy detail, system-plan comprehensiveness, leadership and vendor controls are separate measures and should not be treated as interchangeable.
  • The late-2023 fieldwork cannot serve as a precise 2026 benchmark without newer data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.