IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants

A manufacturer needs IT that keeps production running and keeps the plant floor separate from everyday office risk: a network where machine and controller systems are segmented from email and web browsing, an ERP or MRP system with a tested recovery plan, controlled remote access for equipment vendors, backups that include machine programs and configurations, multi-factor authentication on every account, and support that understands shifts and planned shutdowns. The difference from an office business is the cost of an outage. When a ransomware infection or a failed switch stops the ERP, label printers or machine PCs, the line stops with it.
This guide is a practical checklist for owners, plant managers and controllers at small and mid-sized manufacturers in Ontario. It covers why manufacturers are targeted, how to separate office IT from operational technology, what to protect on the plant floor, how to handle vendor access and customer security questionnaires, and what to ask when you choose an IT provider. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT.
Why Manufacturers Are a Target
Attackers choose victims who cannot afford to be down. A plant that cannot ship has a strong reason to pay quickly, which makes manufacturers attractive to ransomware groups even when the business is small. The way in is usually ordinary: a phishing email that captures a Microsoft 365 password, a remote access tool a machine vendor installed years ago and nobody manages, an unpatched server exposed to the internet, or a shared login that former staff still know. Once inside, an attacker on a flat network can reach the office file server, the ERP and the PCs that drive production equipment alike.
Payment fraud is the other common loss. Manufacturers pay suppliers by electronic transfer all the time, so a compromised mailbox at your company or a supplier can be used to send a convincing change of banking details on a real invoice thread.
Separate Office IT From the Plant Floor
The single most valuable control for most manufacturers is network segmentation: putting production systems on their own network segments so a problem in the office cannot spread to the floor, and the reverse.
- Machine PCs, controllers, HMIs, scanners, label printers and cameras sit on separate VLANs from office computers and guest Wi-Fi, with firewall rules that allow only the traffic production actually needs.
- Production machines do not browse the web or read email. If an operator needs either, they use a separate office device.
- The ERP, MRP or MES servers that both sides use are reachable from the floor only on the ports they require.
- Guest and contractor Wi-Fi is isolated from both office and production networks.
- You have a current diagram of the network, including which switch and access point serves which area of the building. If the only person who understands the wiring is the person who installed it, that is a risk in itself.
Legacy Machine PCs and Controllers
Many plants run equipment whose control PC is tied to an old version of Windows because the machine software was never updated for anything newer. Replacing the machine is rarely an option, so the job is to contain the risk:
- Keep an inventory of every machine PC: what it runs, its operating system version, who supplies the software and whether it can be patched.
- Isolate unsupported systems on their own segment with no internet access and only the connections the machine needs, such as file transfer of programs from engineering.
- Control USB use, because removable media is how programs, and malware, often reach the floor.
- Keep a known-good image or installation media and licence information for each machine PC, so a failed drive is a few hours of work rather than a call to a vendor that may no longer support the model.
Office machines are different: they should be on a supported operating system. If you still have Windows 10 or Windows Server 2016 in the office or the server room, our guides on Windows 10 end of support and Windows Server 2016 end of support cover the planning.
ERP, MRP and EDI Uptime
The ERP is usually the system a manufacturer can least afford to lose, because quoting, purchasing, production scheduling, shipping and invoicing all run through it. Check that:
- You know where it runs (on-site server, hosted, or vendor cloud), who supports which part of it, and how to reach the software vendor when the problem is theirs.
- The ERP database is backed up separately from a plain file copy, using the method the vendor supports, and a restore has been tested.
- You have written down how long the business can run without it and what staff do in the meantime, such as printed pick lists or a manual shipping process.
- EDI connections with customers and suppliers are monitored, because a silent EDI failure can mean missed orders or chargebacks before anyone notices.
- Updates and upgrades are scheduled around production, ideally in planned shutdowns, with a tested rollback.
Backups That Cover the Floor
Office files and mailboxes are only part of what a manufacturer needs to recover. A complete backup plan also includes:
- CNC programs, machine recipes, PLC and HMI project files, and equipment configuration exports, with versions you can roll back to.
- Engineering and CAD data, quality records and certificates of conformance.
- The ERP database and its configuration.
- Microsoft 365 or Google Workspace data, which is not fully protected by the vendor's own retention.
Backups should be automatic, encrypted and monitored, with at least one copy that ransomware on your network cannot reach. Test a restore of a real machine program and of the ERP, not just a sample file. Our disaster recovery plan guide covers recovery targets and testing, and the ransomware protection guide covers prevention.
Vendor and Remote Access
Equipment builders, integrators and ERP consultants often need remote access, and it is one of the most common weak points in a plant. Good practice:
- One managed remote access method, with named accounts for each vendor technician and multi-factor authentication, instead of remote-control tools installed ad hoc on machine PCs.
- Vendor access is off by default and enabled for a session when it is needed, then disabled again.
- Sessions are logged, and you know which vendor can reach which machine.
- Default passwords on equipment, cameras, switches and controllers are changed, and recorded in a password manager the business controls.
Accounts, Email and Payment Fraud
- Multi-factor authentication is enforced on every Microsoft 365 or Google Workspace account, including managers, shared mailboxes and service accounts.
- Everyone has their own login for the ERP and other systems; shared shift logins are replaced with individual accounts wherever the software allows it.
- SPF, DKIM and DMARC are configured on your domain so it is harder to impersonate. Our guide to SPF, DKIM and DMARC explains each record.
- Any change to supplier banking details, or any unusual request to send money, is confirmed by phone using a number already on file, never one from the email.
- Shop-floor kiosks and shared terminals sign out automatically and do not keep personal email signed in.
Customer Security Questionnaires and Requirements
Larger customers increasingly send suppliers a security questionnaire before awarding or renewing business, and some supply chains carry specific requirements. Automotive customers may ask about information security assessments; companies that examine, possess or transfer controlled goods in Canada must register under the federal Controlled Goods Program; and suppliers in United States defence supply chains may be asked about CMMC. Which of these applies depends on your customers and contracts, so confirm the requirement with the customer before investing. In every case, a business with the controls in this checklist in place, and written down, can answer most questionnaire items honestly and quickly. Our cyber insurance readiness checklist covers many of the same questions insurers ask.
This is IT guidance, not legal or compliance advice. Confirm specific obligations with the customer, program or your advisor.
Shifts, Shutdowns and On-Site Support
Plants rarely work nine to five. Make sure your IT support matches how you operate:
- The helpdesk is reachable during every shift you run, including early mornings and weekends if you work them.
- Someone is watching for security alerts and failed backups outside business hours, not only when a ticket arrives.
- Disruptive work such as server, switch and firewall changes is planned for scheduled shutdowns or low-volume windows, agreed with the plant manager in advance.
- A technician can reach the plant on-site when a physical problem, like a failed switch in a production area, cannot be fixed remotely.
- There is a written one-page plan for a ransomware infection, an ERP outage and a fraudulent payment, with phone numbers for your IT provider, bank, ERP vendor and cyber insurer. Our IT emergency checklist is a starting point.
What to Ask an IT Provider for a Manufacturing Business
- How would they segment our office and production networks, and how do they handle machine PCs that cannot be patched?
- Will they work directly with our ERP vendor and equipment builders when a problem belongs to them?
- Which backups do they monitor and test, and does that include machine programs and the ERP database?
- How is vendor remote access controlled and logged?
- Is support available during our shifts, and can they send someone on-site?
- Is the agreement clear about what is included, and is project work scoped and quoted in writing before it starts? Our guide on what a managed IT contract should include lists the clauses to check.
How IT Rapid Support Works With Manufacturers
IT Rapid Support provides managed IT, cybersecurity and network support for manufacturers and distributors across the Greater Toronto Area from our office at 7810 Keele St in Vaughan, in the middle of one of the region's largest industrial areas. Support, monitoring, security and backup sit on one agreement scoped to the users, devices and sites we cover, and project work such as network segmentation or a server replacement is scoped and quoted in writing. The service details are on our page for managed IT services for manufacturing, and plants in Vaughan, Concord and Woodbridge can also see our page on IT support for manufacturers in Vaughan. To review your plant against this checklist, call (289) 582-9930 or contact us.
Frequently Asked Questions
What IT support does a manufacturing company need?
At minimum: a segmented network that keeps production systems apart from office computers and guest Wi-Fi, managed and patched office devices, a contained plan for machine PCs that cannot be updated, multi-factor authentication on every account, backups that include the ERP database and machine programs and are tested by restoring them, controlled vendor remote access, and a helpdesk and monitoring that cover the shifts you actually run.
What is the difference between IT and OT in manufacturing?
IT is the office side: computers, email, file storage, the ERP and the network that connects them. OT, or operational technology, is the equipment and systems that run production, such as machine controllers, PLCs, HMIs and the PCs attached to equipment. OT often cannot be patched or restarted on the same schedule as office IT, which is why it should sit on its own network segment with tightly limited connections.
How do we protect machines that run old versions of Windows?
Keep an inventory of them, put them on an isolated network segment with no internet access, allow only the connections each machine needs, control USB use, and keep a recovery image, installation media and licence details so a failure can be rebuilt quickly. Plan replacement of the control PC or software with the equipment vendor when the opportunity arises.
Should equipment vendors have permanent remote access to our machines?
No. Give each vendor technician a named account on one managed remote access method with multi-factor authentication, keep it disabled until a session is needed, log the sessions, and remove access when the work or the relationship ends. Unmanaged remote-control tools left on machine PCs are a common way into plants.
What should a manufacturer back up?
Office files and mailboxes, the ERP database using the vendor-supported method, engineering and CAD data, quality records, and the files needed to rebuild production: CNC programs, recipes, PLC and HMI project files and equipment configuration exports. Keep at least one copy out of reach of ransomware and test restores of real files and of the ERP.
How do we answer a customer's cybersecurity questionnaire?
Answer honestly from what is actually in place, and keep the evidence: your MFA policy, backup test records, network diagram, patching approach and incident plan. If the customer requires a specific framework or program, confirm exactly which one before starting work on it, and close the gaps in this checklist first, because they cover most of what questionnaires ask.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorRelated Resources

What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses
How to tell an IT emergency from an urgent ticket, first-15-minute checklists for network outages, server failures, email down, ransomware and payment fraud, what to have ready before you call, and a one-page emergency plan.
Read more: What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses
What Are IT Professional Services? A Guide for GTA Businesses
IT professional services are project work with an end date: migrations, network builds, server replacements, office moves. How they differ from managed IT and consulting, and what a statement of work should include.
Read more: What Are IT Professional Services? A Guide for GTA Businesses
What Does an IT Security Assessment Include? A Guide for GTA Businesses
What an IT security assessment checks (MFA, email, patching, firewall, backups, access, monitoring), what the report should contain, free vs paid, and how to prepare.
Read more: What Does an IT Security Assessment Include? A Guide for GTA BusinessesNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch