news
The Cybersecurity Imperative in Smart Factories
Primary tabs
As manufacturing systems become more connected, the cyberthreat grows with them. Saman Zonouz has spent years documenting how vulnerable smart manufacturing environments are. He’s an associate professor in the School of Cybersecurity and Privacy and the School of Electrical and Computer Engineering, where he co-leads the Cyber-Physical Security Lab with Raheem Beyah, Georgia Tech’s provost and executive vice president for Academic Affairs.
"Disrupting the manufacturing sector doesn't just shut down individual shops. It can directly impact national security and public safety," Zonouz said. Because manufacturing is one of 16 federally designated critical infrastructure sectors, it is deeply intertwined with energy, water, and defense, meaning disruptions can cascade far beyond the factory floor.
The threats Zonouz documents go beyond ransomware. His research has demonstrated how adversaries can insert logic bombs into design files, compromising Computer Numerical Control machines or 3D printers.
"We've shown how logic bombs can be inserted remotely into design files so that everything looks normal when the part is printed, but once it's in operation, the attacker can decide when it fails," Zonouz said, citing drone propellers, aircraft wings, and power grid transformer components as examples where invisible sabotage could have catastrophic consequences.
Internet-wide scans conducted by his team found that many shop-floor controllers are directly exposed to the internet, with no meaningful barrier between an adversary and the machines running a production line. Imported equipment compounds the risk, because controllers and firmware from unknown developers may carry unintentional vulnerabilities or deliberately planted backdoors. "In manufacturing, many controllers and machines can still be accessed easily from outside," Zonouz said, echoing the kind of supply chain exposure seen in high-profile attacks on widely used software platforms.
His prescription is straightforward but still largely unimplemented across the sector: Build security into the system design rather than adding it afterward. "The number one principle is to think about cybersecurity and risk when you design the system, not as an afterthought once everything is already built," Zonouz said.
His team has explored this through the $65 million Georgia AIM initiative, a collaboration with Aaron Stebner, Steven Ferguson, and Animesh Chhotaray, led by Ph.D. student Twisha Chattopadhyay. Using AI for automated anomaly detection allows complex production lines to be monitored continuously without requiring constant human oversight.
Georgia Tech's standing at the intersection of manufacturing and cybersecurity is, by most measures, singular. "Georgia Tech is the only top university with a dedicated School of Cybersecurity and Privacy, with about 30 professors focused solely on cybersecurity, and you rarely see this level of collaboration between cybersecurity and manufacturing faculty anywhere else," Zonouz said. That collaboration is already producing joint publications and a patent application for AI-driven attack detection systems developed through Georgia AIM.
Not every attacker wants a quick payoff. Zonouz also tracks advanced persistent threats, where a nation-state actor quietly compromises a controller and does nothing for months, waiting for the right geopolitical moment to act. "They get into the house and just sit there, because by sitting still nobody can detect them," Zonouz said. That patience turns an idle, exposed controller into tomorrow's leverage.
Manufacturers do not need to solve every problem at once, Zonouz said. Finance and energy already operate under mandatory cybersecurity frameworks, while manufacturing's own standard, the Cybersecurity Maturity Model Certification, is still being phased in. "The security of these systems right now is so weak that basic, easy-to-deploy solutions would stop the majority of attacks that are succeeding simply because the door is wide open," he said. The hardest attacks will always be the patient, targeted ones, and closing the obvious gaps first is what buys manufacturers time.
Status
- Workflow status: Published
- Created by: ychernet3
- Created: 08/13/2026
- Modified By: ychernet3
- Modified: 08/13/2026
Categories
Keywords
User Data