Market Watch

Loading metals, manufacturing indicators, and industrial stocks...

How to Keep Shipping When Your Plant Systems Go Dark
Industrial IoT

How to Keep Shipping When Your Plant Systems Go Dark

Manufacturing Mag Staff·September 4, 2026

This article may contain AI-assisted content. Verify details with primary sources before acting on them.

Share:
Share

Why It Matters

Boston Scientific's order intake kept running while its ability to ship did not. That gap — EDI up, fulfillment down — is the outage most discrete manufacturers have never rehearsed, and the fix is mostly paper, printers and pre-approved procedure.

Most plants drill the fire. Most plants drill the evacuation. Almost none of them drill the shift where the machines are fine, the material is on the floor, the people are clocked in — and nothing can ship because the systems that say what to ship are unreachable.

That is the shape of what happened to Boston Scientific. The company detected a cybersecurity incident on Aug. 25, 2026 and disclosed it the next day in a Form 8-K filed under Item 8.01 (Other Events), stating it "has not yet determined whether the incident is reasonably likely to have a material impact." The filing describes "disruptions and limitations of access to certain of the Company's information systems and business applications that support aspects of the Company's operations, including the ability to process and ship customer orders."

Read that sentence like an operator, not a lawyer. Information systems and business applications. Order processing and shipping. Nine days into it, the Sept. 3 company update said it had "begun restoring shipping capabilities for the majority of our products at our major distribution centers globally," with "time to work through the existing backlog" still ahead and no full-restoration date offered.

And here is the detail that should reorganize your continuity plan: customers could keep submitting orders by EDI and local applications the entire time. Orders were not rejected. They queued. Intake survived; fulfillment did not.

Be honest about what actually broke

Nothing in the public record says industrial control systems were compromised. Boston Scientific described unauthorized activity as limited to certain on-premises systems, with cloud-based systems and applications unaffected; Ireland-based employees were directed to work from home during the response. SecurityWeek reports the company engaged CrowdStrike and other third-party specialists — a company statement, not something in the 8-K. Remote activations for certain cardiac monitors were interrupted, while already-implanted cardiac rhythm management devices continued to function. No cybercrime group publicly claimed the attack. Cybersecurity Dive confirms the global scope of the disruption.

That is not a weaker story. It is the more common one, and it is worse for planning purposes. Your line is physically capable of running. Your PLCs are executing. The failure is that the systems telling the cell what to build, recording that it was built, printing what goes on the box, and telling the carrier where it goes are gone — and they are gone for days, not hours. Detection and disclosure worked here (detect Aug. 25, disclose Aug. 26, and the Aug. 30 update reported no signs of activity after the 25th). Degraded operations is the part that takes nine days.

Ask nine days what it costs. Brunswick Corporation's June 2023 IT incident took nine days to recover and hit roughly $85 million in second-quarter revenue, about $13 million of it at Navico. CEO Dave Foulkes made the point that matters to any scheduler: lost high-horsepower outboard production days were hard to recover because the schedule was already full. You do not make up a week when you were already running at capacity.

1. Decide in advance what "dark" means

Continuity plans fail on the first morning because nobody has authority to declare the mode. Define tiers and pre-write the trigger for each:

  • Tier 1 — MES down, ERP up. Work orders exist, but the floor cannot consume or confirm them. Paper travelers, batch confirmations posted retrospectively.

  • Tier 2 — ERP down, MES up. The plant can build to the current queue and cannot see demand, allocation, or shipping. This is the Boston Scientific-shaped failure.

  • Tier 3 — both down, plus Active Directory and file shares. Authentication itself is gone. This is where most plants discover their real dependency graph.

The hidden dependency, in almost every plant we've seen documented, is authentication. HMIs and MES clients that authenticate against enterprise Active Directory stop accepting logins when the domain controllers are isolated. Then license servers, DNS and NTP — all of which usually live on the IT side of the house. A cell that is mechanically perfect will sit idle because a CAM seat cannot check out a license.

Write the trigger as a decision, with a name attached: if the MES client cannot authenticate for 30 minutes and the service desk cannot give an ETA, the shift supervisor declares Tier 1 and pulls the day-one pack. Not a committee. A person, per shift, with a binder.

2. Pre-stage the paper that keeps the cell running

The day-one pack is a physical artifact, refreshed on a schedule, stored where an outage cannot reach it. At minimum, a nightly export to a segregated, offline-readable location containing:

  • Open orders with quantities, due dates and ship-to, sorted by cell

  • Current BOM and routing for every active part number

  • A lot-genealogy snapshot — what lots are where, so traceability does not break at the moment you most need it

  • Printed or PDF pick lists per cell for the current and next shift

Then the piece most plants skip: numbered paper travelers with pre-assigned control numbers. Pull a block of document control numbers in advance, print them, keep them in the binder. Records created on paper during the outage carry IDs the system already knows are reserved, which means reconciliation afterward is a data-entry exercise instead of a duplicate-ID forensics project.

3. A manual batch record that survives the audit

For medical device manufacturers, the rules changed this year. FDA's Quality Management System Regulation took effect Feb. 2, 2026, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. Device history record content now maps to ISO 13485 §7.5 (production and service provision, including traceability) and §8.2.6 (acceptance and monitoring records) rather than the old QSR headings. If your paper fallback form was drafted against the previous wording, it captures the wrong sections on its face.

The decisive point is procedural, not clerical. The fallback must be an approved, change-controlled, trained-on SOP with pre-issued controlled forms. Ad-hoc paper invented at 2 a.m. during an incident is the finding. A controlled outage-mode procedure that was exercised and documented is a demonstration of control.

Note also that FDA's Quality System Inspection Technique was withdrawn on Feb. 2, 2026 and replaced by the inspection process in Compliance Program 7382.850. Whatever records your plant generates in outage mode will be inspected under the new approach, not the one your quality team trained on a decade ago.

Your procedure needs to answer three questions before you need it: who is authorized to sign retrospective data entry, how hybrid paper-and-electronic records are reconciled into a single reviewable DHR, and what the second-person verification step looks like when the automated check is part of what is down.

4. Offline labels are the real bottleneck

You can build product on paper. You cannot ship it without a compliant label, and label content remains governed by 820.45 (labeling and packaging controls), one of the FDA-specific provisions retained in Part 820 under QMSR. UDI carriers have to stay correct and traceable whether or not your label server is reachable.

Practically, that means a standalone label workstation with its own local database copy, refreshed on the same nightly cadence as the day-one pack; printers and ribbon stock tested against that workstation, not assumed; a controlled reconciliation of label serial ranges issued while offline; and a documented proof-of-print check, because the automated verification you normally rely on is part of the system that is down. Every plant that has run this drill discovers the same thing — the printer works, the label template does not resolve, because the template lives on a share.

5. Tie customer communication to queue depth

EDI 850s keep arriving. That is not a nuisance; it is your best available demand signal and the only honest measure of how deep the hole is. Publish queue depth internally, daily, as a number.

Then run a ladder:

  • 0–24 hours: acknowledge the disruption. Confirm orders are being received. Promise no ETAs you cannot hold.

  • 24–72 hours: publish an allocation policy, assign named contacts to major accounts, and issue manual order confirmations by email.

  • 72 hours and beyond: prioritized allocation for life-supporting and clinically urgent SKUs; manual ASN and invoice workarounds pre-agreed with the receiving and AP teams at your top customers; and a written statement customers can forward inside their own organizations without editing it.

That last item is underrated. Your customer's materials manager has to justify a stockout to their own leadership. Give them a document that does it.

6. The clocks running in parallel

Three sets of obligations move at once, and they do not move at the same speed.

SEC. A material cybersecurity incident is reported under Item 1.05, with the materiality determination made without unreasonable delay. Filing under Item 8.01 while that assessment is in progress — what Boston Scientific did — is a legitimate path, not an evasion.

FDA. Be precise here, because this is commonly overstated: Section 506J notification of a manufacturing interruption is mandatory only during, or in advance of, a declared public health emergency. Outside one, FDA encourages voluntary notification. Notification is due six months in advance where possible and otherwise as soon as practicable. A cyber outage does not by itself trigger a mandatory filing — but if supply of a life-supporting device is at risk, voluntary notification is the right call and buys goodwill you will want later.

Your customers. Quality agreement notification clauses routinely bite faster than any regulator. Someone should have read yours before the incident, not during it.

7. The segmentation decisions that determine whether IT can stop the line

Everything above is what you do when the plan fails. Segmentation is what keeps an enterprise-side compromise from reaching the floor at all.

The reference architecture is NIST SP 800-82 Rev. 3 (September 2023): industrial DMZ, controlled conduits, unidirectional gateways where the data flow genuinely is one-way. The method for deciding where the boundaries go is ISA/IEC 62443-3-2:2020 — partition the system under consideration into zones by risk, treat every inter-zone communication path as a conduit, and assign each a target security level. That is an engineering exercise with a deliverable, not a diagram someone drew once.

It has a prerequisite. In August 2025, CISA, NSA, FBI, EPA and five international partners published asset inventory guidance for OT owners and operators, framing inventory as the precondition for defensible architecture rather than a cleanup task. You cannot zone what you cannot enumerate.

And be careful importing IT security fashion onto the floor. CISA, the Department of War, DOE, FBI and State published Adapting Zero Trust Principles to Operational Technology on Apr. 29, 2026, warning explicitly that IT-centric zero trust cannot be applied wholesale to OT given availability requirements, decades-long asset lifecycles and legacy protocols. Continuous re-authentication is a fine idea on a laptop and a hazard on a safety-instrumented loop.

The concrete items: a separate credential store for OT so a compromised enterprise domain does not lock every HMI; historian and MES replication one-way where feasible; and local, offline PLC program backups with tested golden images. Tested, meaning someone has actually restored one.

8. Eight questions for your integrator before the next patch window

  • Can this cell run to end of shift with the enterprise uplink physically unplugged?

  • What authenticates the HMI, and what happens when that authority is unreachable?

  • Where does the license server live, and how long is the grace period?

  • If the historian is unreachable for 72 hours, does the collector buffer or drop?

  • Who holds the PLC source, and when was a full restore last tested end to end?

  • Is remote vendor access through our broker, or their VPN?

  • What is the documented island-mode duration, in hours?

  • Who has tested it, and when?

If any answer is a shrug, that is your finding, and it costs nothing to have found it today.

9. What this costs against what the outage costs

Sophos's State of Ransomware in Manufacturing and Production 2025 (332 manufacturing respondents out of 3,400 across 17 countries, organizations of 100–5,000 employees, surveyed January–March 2025) puts average recovery cost at $1.3 million, down 24 percent, with 58 percent fully recovered inside a week — up from 44 percent. Encryption rates fell to 40 percent from 74 percent. Exploited vulnerabilities were the leading root cause at 32 percent. Fifty-eight percent recovered using backups; 51 percent paid a ransom.

Set that against what this article asks you to buy: a label workstation, a couple of tested printers and ribbon stock, a nightly export job, a validated fallback SOP, a block of pre-issued control numbers, and one tabletop a year. In most mid-market plants that is a five-figure line item — our estimate, not a survey figure — against a benchmark recovery of $1.3 million and, at the bad end, Brunswick's nine days and $85 million.

Run the exercise this quarter. Pick one cell, schedule it, get safety sign-off, and unplug the enterprise uplink for a shift. Do not simulate it in a conference room. Watch what stops, write down the minute it stopped, and fix that list. The point of the drill is not to prove the plan works; it is to find the license server nobody knew about.

When LockerGoga hit Norsk Hydro on March 19, 2019, the company shifted to manual, paper-based operations across a global organization and rebuilt encrypted systems from backup. Total cost: roughly 800 million Norwegian kroner, partly offset by cyber insurance.

The detail worth putting in your workforce plan is who made the paper system work. Retired employees came back — because they remembered how to run it. That institutional knowledge is a real operational asset, and it has a retirement date. If the only people who can run your plant on paper are the ones who did it before the ERP went in, name them, document what they know, and pair them with someone under 40 before the knowledge walks out with them.

Sources

Share

More Articles