
Manufacturers rely on industrial control systems (ICS) and devices to monitor and control physical processes that produce goods for public consumption. As operational technology (OT) systems like ICS become more interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience. Though a defense-in-depth security architecture can help mitigate cyber risk, it may not entirely eliminate it.
The US National Institute of Standards and Technology (NIST) recommends that organizations have a plan to recover and restore manufacturing operations should a cyber event impact plant operations. To this end, the NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026.
The NCCoE, together with the NIST Communications Technology Laboratory and industry collaborators, will demonstrate an approach for responding to and recovering from an ICS attack within the manufacturing sector by leveraging the following cybersecurity capabilities: event reporting, log review, event analysis, and incident handling and response. The NCCoE will implement each of these capabilities in a discrete manufacturing work cell that emulates a typical manufacturing process. The project will result in a freely available NIST Cybersecurity Practice Guide.
The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities.
This draft publication provides actionable guidelines on responding to and recovering from cyberattacks in manufacturing environments, including how to:
Understand the risks and potential impact of cyber incidents on operations.
Develop a comprehensive response and recovery plan.
Implement best practices to minimize downtime and restore operations quickly.
Find out more about the industrial cybersecurity challenges and solutions.