The Server In The Corner Won’t Save You

Published Apr 30, 2026

I sat in the audience at an Epicor customer event where their CISO briefed us on the current threat environment.

Thirty-two full-time security staff. Weekly briefings from the FBI, US Department of Homeland Security, Interpol, and UK GCHQ.

It freaked me out.

As a business owner myself, I suddenly realised just how big the guns being pointed at us really are. If Epicor needs that level of firepower to defend itself and its customers, how can your average SME manufacturer hope to do the same?

They can’t.

Why Manufacturers Keep Getting Hit

Manufacturing has become the most targeted industry for cyberattacks for three years running. The numbers tell part of the story, a 71% surge in threat actor activity between 2024 and early 2025.

But the operational reality tells you why.

Manufacturers operate continuously, on thin margins, in highly competitive environments. Every hour of interrupted production generates compounding inefficiency. Losses mount the longer interruptions persist.

Cybercriminals know this.

When a customer gives you an order, they’re doing so because what you produce is a time-critical element in their supply chain. Extended interruptions mean delivery delays, which means direct reputational harm.

Bad actors know this too.

For manufacturers in aerospace, defence, or other sensitive sectors, the stakes multiply. If you’re perceived as a security risk, you won’t win contracts again for years. Your systems contain drawings, specifications, volumes, information threat actors can extract tremendous value from.

And finally, manufacturers are notoriously bad at securing their systems.

The Legacy Systems Trap

Walk into most manufacturing facilities, and you’ll find legacy systems running on on-premise hardware. Many were built before cyberattacks were even a consideration.

Picture that server sitting in a corner, password-protected. Or that old ERP system with an unsecured database. Documents stored on rudimentary networks with basic security layering at best.

How secure is that database? Can someone simply copy it and walk away? Is it encrypted, and if so, to what degree?

For today’s threat actors, that’s trivial to breach.

Suddenly, they know everything about you, your customers, your intellectual property, your customers’ IP, bank details for you, your customers your suppliers.

Everything.

The Conversation Nobody Wants

You can’t just waltz into a third-generation, highly successful manufacturer and tell the owner they’re being unbelievably naive.

It has to be a slowly, slowly educational discussion.

You help paint a picture of what these people are capable of, and how little it actually costs them to go after you. Ransomware-as-a-Service operates like a gig economy, affiliates pay as little as USD 40 per month for sophisticated attack tools.

The goal is to lead them through that learning until they’re frightened into taking action.

Now.

The Cloud Resistance Paradox

When manufacturers hear about moving to cloud-hosted systems, the objections are predictable. Their data will be mixed with competitors’ data. It can be easily lost. The provider can take it away whenever they want.

These fears are exactly backwards.

Moving to the cloud with a specialised provider like Epicor is far more secure than they could economically make their own environment. Data is isolated in its own digital tenancy. Users see only what they’re authorised to access.

Short of compromising someone with admin-level access, a threat actor would have to breach multiple layers of both physical and digital security, all constantly monitored by systems and humans.

Compare that to the server in the corner.

The Human Weakness Remains

Even with professional security infrastructure, humans remain the weakest link.

Education becomes critical, general cyber awareness training, knowing what to do when something doesn’t quite look right.

But even when an application user’s credentials are compromised, properly architected cloud environments limit the blast radius. That user can only access what they’re authorised to see. They cannot reach the database itself, cannot infect network or operating system levels, and cannot lock people out in a ransomware attack.

That level of access simply doesn’t exist for anyone in the customer’s company.

The Timeline You Don’t Have

I’ve watched manufacturers become convinced they need to act, then delay because they want to budget and plan properly.

That’s reasonable.

What’s dangerous is when that delay becomes procrastination as the perceived urgency dulls over time.

Here’s what they’re not calculating: the cost of production interruption, shipping delays, ordering disruptions, payment processing failures. The reputational damage from failing to meet customer commitments. The perception amongst trading partners that their data isn’t safe in your hands.

You can’t put a price on that risk.

Given the cybercrime industry out there, the direct attacks and the outsourced tooling, it’s likely to be months rather than years before someone has a sophisticated enough go at a given company.

If you’re on the web, if you’re in a news story about your success somewhere, AI bots are already cataloguing you and gathering information.

There’s an arms race happening around you between the people trying to protect legacy systems and those wanting to do harm or salvage your data for other purposes.

If you’re an SME or even a mid-sized business, you just can’t afford the tools and focused people to manage defences that are constantly being probed and exploited.

The server in the corner won’t save you.

Thirty-two security staff might.

Mark Batina

Managing Director – Precise Business Solutions | ERP Software

Related Articles

Why Most ERP Implementations Miss the Point

Most ERP implementations focus on technology rather than operational expertise. This article explains how systemising knowledge creates scalable assets that drive sustainable growth.

Related Categories