There’s a particular kind of nightmare that keeps industrial facility owners and developers up at night. It’s not a burst pipe or a delayed shipment or a failed inspection. It’s the quiet, invisible threat of someone walking out the digital back door with years’ worth of proprietary engineering designs — and you don’t find out until the damage is done.

If you own or develop large-scale industrial construction properties — processing plants, manufacturing facilities, chemical refineries, food production lines — your survival relies on your cybersecurity position.

The Mondelez Wake-Up Call

Let’s start with a story that should make every facility owner pay close attention.

Back in 2017, global food giant Mondelez became collateral damage in one of the most destructive cyberattacks in history — the NotPetya ransomware outbreak. The attack wasn’t even aimed specifically at Mondelez. It spread through a routine software update, infecting systems indiscriminately across hundreds of companies worldwide. In a matter of hours, Mondelez’s computer systems froze. Warehouses backed up with Oreos, Ritz crackers, Cadbury eggs, and Philadelphia cream cheese that couldn’t move because the logistics systems running the operation were locked down.

The total financial damage? Over $100 million, according to court documents later reviewed by The New York Times. And here’s the part that stings the most: their insurer refused to pay out, citing a “war exclusion” clause in the policy — arguing the attack was effectively an act of nation-state warfare.

Industrial Facilities Are High-Value Targets

Processing facilities and industrial construction properties hold assets that are extraordinarily valuable to the right adversary:

Proprietary engineering designs and schematics. The specialized equipment configurations you’ve developed to hit production quotas didn’t come cheap. Those designs represent years of R&D, engineering labor, and operational refinement. To a competitor — or a foreign state actor — they’re worth stealing outright.

Operational technology (OT) systems. The programmable logic controllers (PLCs), SCADA systems, and industrial control systems (ICS) that run your facility floor are increasingly networked. That connectivity is efficient. It’s also an attack surface.

Production and capacity data. Knowing your throughput, your bottlenecks, your vendor relationships, and your production schedules gives adversaries significant leverage — in competitive markets and in geopolitical ones.

Supply chain access. Your facility doesn’t exist in isolation. Attackers often use one company as a stepping stone to reach a larger target. Your network may be the door to your biggest client’s.

Cyber attack

The Unique Vulnerability of Industrial Environments

Cybersecurity in industrial settings is genuinely harder than in a typical office environment, and here’s why.

Legacy systems designed before cybersecurity were a concern. Much of the operational technology running industrial facilities was engineered decades ago for reliability and uptime — not for network security. These systems often can’t be patched in the traditional sense without risking production downtime. So, they run, exposed, sometimes for years.

The IT/OT convergence problem. As facilities modernize, business IT systems (your ERP, project management tools, design files) increasingly connect with operational technology (the equipment on the floor). That’s great for efficiency and data visibility. It also means a breach in your corporate network can potentially reach your physical equipment. The line between a stolen file and a halted production line is getting shorter.

Third-party and contractor access. Construction and industrial development rely heavily on contractors, subcontractors, equipment vendors, and engineering consultants — all of whom may need access to your systems. Every one of those access points is a potential vulnerability if not effectively managed.

Intellectual property scattered across tools and users. Your proprietary designs might live in CAD software, project management platforms, email threads, shared drives, and the personal laptops of three different engineering firms. Knowing where your sensitive data lives is the first step to protecting it.

What Sophisticated Attacks Look Like

The attacks targeting industrial and construction firms tend to be methodical, patient, and infuriatingly mundane in their entry points.

Spear phishing. A targeted email, crafted to look like it’s from a known vendor or colleague, tricks an employee into clicking a link or opening an attachment. From there, attackers can establish a foothold in your network and move laterally — often for weeks or months before doing anything detectable.

Supply chain compromise. Much like Mondelez, your exposure may not even come from your own systems. If a software vendor you rely on is compromised, the malicious code can arrive packaged as a legitimate update.

Ransomware. Your operational data — designs, schedules, vendor contracts — gets encrypted. You pay to get it back, or you lose it. And increasingly, attackers don’t just lock your data; they exfiltrate it first, so they can threaten to publish it even if you restore from backups.

Insider threats. Disgruntled employees, contractors with broad access, or individuals approached by outside parties — the threat doesn’t always come from outside the perimeter.

Protecting What You’ve Built

Meaningful risk reduction doesn’t require a complete overhaul of your operations overnight. It requires a clear-eyed assessment of where you’re exposed and a disciplined approach to closing the most critical gaps.

  1. Know what you’re protecting. Conduct a thorough data inventory. Identify every location where your proprietary designs, equipment specifications, and production data exist. This includes cloud storage, contractor systems, email archives, and physical USB drives people have forgotten about.
  2. Segment your networks. Your corporate IT network and your operational technology network should not be the same network. Proper segmentation — ideally with an “air gap” or tightly controlled connection between them — means that a breach on the business side doesn’t automatically mean access to your facility floor systems.
  3. Enforce least-privilege access. Not everyone needs access to everything. Contractors should have access only to what they need, for only as long as they need it. When a project ends, access should end with it. Role-based access controls, multi-factor authentication, and regular access audits are foundational.
  4. Patch and update systematically. Patching legacy OT systems is complicated and sometimes requires scheduled downtime. That’s a reason to plan carefully — not a reason to skip it indefinitely. Work with your vendors to understand patching options and prioritize systems that are network-connected.
  5. Vet your vendors and contractors. Third-party risk management is essential. Ask the engineering firms, equipment suppliers, and software vendors you work with about their own security practices. Require contractual security standards. Understand what access you’re granting and to what systems.
  6. Have an incident response plan. When a breach occurs, the cost of response escalates dramatically without a pre-established plan. Who makes decisions? Who do you call? How do you communicate with clients, regulators, and insurers? Tabletop exercises that walk your team through a simulated attack scenario are enormously valuable and surprisingly inexpensive.
  7. Revisit your cyber insurance. The Mondelez story is a cautionary tale not just about the attack itself, but about the aftermath. Review your cyber insurance policy with your legal counsel. Understand what’s excluded. War exclusion clauses have become a major point of contention in the industry. Know what you’re covered for before you need to find out the hard way.

The Cost of Inaction

Every day that proprietary designs sit on an unprotected network, every month that legacy OT systems run unpatched, every contractor with unchecked access represents accumulating risk.

The Mondelez breach cost over $100 million — and that was a company that at least had insurance (even if it didn’t pay out). For a mid-sized industrial facility or development operation, a ransomware event or design theft could be existential.

The competitive advantage you’ve built into your production processes, your proprietary equipment configurations, your hard-won operational knowledge — these are worth protecting with the same seriousness you protect your physical assets.

Your blueprints didn’t build themselves. Don’t let someone else walk away with them.

At KBCm, we understand the operational complexity of large-scale industrial facilities — and what’s at stake when proprietary designs and critical systems are left exposed. If you’re unsure where your project stands, we can help you assess your risk and build a protection strategy that fits your environment.

Contact Skyler at 940-366-2231 or sblankenfeld@kbcmgroup.com to discuss current or new projects.