← All insights

The three IT problems we see most in Tameside manufacturers

Three problems come up on almost every first visit to a Tameside factory — a flat network, an ERP nobody backs up properly, and a firewall that hasn't been patched in over a year. Here's what they look like on the ground, why they matter more now than they did last year, and what a sensible fix costs.

Editorial illustration for The three IT problems we see most in Tameside manufacturers

Every week we walk into a manufacturer we've never worked with before — usually somewhere between Denton, Hyde and Ashton — and we run the same short assessment. It takes about ninety minutes. And every single time, three of the same problems show up. Not five. Not ten. The same three.

That's worth writing down, because if you run a fifteen-to-fifty-person manufacturer in Tameside or the wider Greater Manchester area, the odds are very good that at least two of them are true of your business right now. And the reason it matters more this year than last is straightforward: Make UK reported in August 2026 that nearly a third of UK manufacturers — 30% — had suffered a cyber incident on themselves or through a supplier in the past twelve months, and the Cyber Monitoring Centre now estimates that the Jaguar Land Rover attack alone cost the UK economy at least £1.9bn. The attackers have worked out that manufacturing pays. And the smaller the manufacturer, the fewer defences are usually in place.

This is what we find, in the order we usually find it.

Problem one: one flat network doing everything

Almost every Tameside factory we visit for the first time has a single network. The CNC machine, the ERP terminal on the shop floor, the laser cutter's control PC, the label printer, the office laptops, the guest wifi, the CCTV — all on the same VLAN, all with a route to each other. Sometimes the guest wifi has a different SSID but sits on the same underlying LAN, which is not the same thing as segmenting the network.

The reason this matters is not really about the machines being hacked directly. The reason it matters is what happens when someone in accounts opens the wrong invoice. Ransomware spreads laterally through a flat network at line speed. If your CNC controller, your ERP database and your shared drives are all on the same broadcast domain as the laptop that just got infected, they are all encrypted within minutes. And a modern ransomware strain will actively look for VMware hosts, Windows Server backup targets and SQL databases and hit those first — because those are the ones that hurt when you lose them.

The fix isn't glamorous and it isn't a product. It's an afternoon with a decent firewall, three VLANs, and a written zone diagram. Corporate on one, production on a second, guest and IoT (cameras, printers, temperature loggers) on a third. Traffic between zones goes through the firewall with explicit allow rules, and that's it. This is exactly what the NCSC's Secure Connectivity Principles for OT call for, and it's what any cyber insurer worth their premium is going to ask about at your next renewal.

We've done this on a working shop floor at a Denton engineering firm without stopping production. It took a Saturday morning, a firewall change window and a documented rollback plan. The line ran on Monday. The bill was under £2,000 for the work, on top of the existing kit.

Problem two: the ERP nobody quite backs up

The second finding is more uncomfortable, because it's usually a surprise to the owner. The Sage 200 or Unleashed or Cin7 database gets backed up. But it gets backed up to the same server it lives on, or to a NAS in the same building, or — worst case — to a USB drive that was last plugged in eight months ago and now lives in a drawer.

The point of a backup is not that it exists. The point is that it exists somewhere the ransomware can't reach and that it can actually be restored. Both of those need testing. Neither is usually tested.

What we typically find is one of three specific failure modes. The first is same-server backup: the SQL database has a maintenance plan writing .bak files to a folder on the same VM. When that VM is encrypted, the backup goes with it. The second is same-site backup: the .bak files copy to a NAS on the same LAN, so ransomware finds it, encrypts it, and moves on. The third is untested tape or removable drive: the backup exists, was never verified, and when the restore is attempted eleven months later, the tape is corrupt or the drive doesn't spin up.

The manufacturer's actual worry isn't the data. It's the downtime. If your MRP is down for a week, you cannot invoice, cannot dispatch, cannot cost jobs, cannot pay staff on time. Make UK's August 2026 report found that among manufacturers hit through their supply chain, around 30% reported delivery delays or output cuts, and only half of affected firms had a formal incident response plan. That's the tell — the plan is missing because nobody's ever had to write one.

The fix is a proper 3-2-1 backup: three copies of the ERP database, on two different types of media, with one copy off-site and immutable — meaning ransomware can't overwrite it even if it steals your backup admin credentials. For a Sage 200 or Unleashed instance, this is typically an on-prem daily backup plus an immutable cloud copy to Wasabi or Azure Blob with object-lock enabled. Cost per year for a mid-sized manufacturer runs to hundreds of pounds, not thousands. And then — this is the important part — you test it. Quarterly. You restore a copy of the database to a sandbox VM, you log in, and you spot-check that the invoices from last month are actually there. If the test fails, you fix it before the emergency.

Problem three: the firewall nobody's touched in a year

The third finding tends to be the shortest conversation and the most awkward. We ask when the firewall was last patched. There's a pause. Then someone says "when it was installed, I think."

This is the exact problem the June brief spent an entire section on: attackers get in through firewalls and VPNs, not through passwords. And it's a bigger problem for a Tameside manufacturer than for an accountancy in the same postcode, because the firewall on a factory network is often the same firewall segmenting production traffic — so a compromise doesn't just leak client data, it steps straight into the shop floor.

The mechanics are worth understanding. Firewall and VPN appliances — Fortinet, SonicWall, WatchGuard, Cisco ASA, Meraki, occasionally a Draytek — release critical firmware patches several times a year. Some of those patches close active zero-days that are already being exploited in the wild by the time the patch is published. If your firewall's firmware is a year old, there is a realistic chance that a well-documented public exploit exists against it and that automated attackers are already probing your public IP for it. The SonicWall research published in August 2026 recorded manufacturing as having the highest SCADA attack detection rate of any tracked vertical, and 46 million IoT attack hits in the first half of the year, with more than half of monitored manufacturing networks detecting exploitation attempts. That's the traffic already hitting your public interface — the only question is whether the appliance in front of it is current or not.

The fix is unglamorous and cheap: a documented patch cadence. Firmware review monthly. Critical patches within seven days. Full annual firmware review with change control. If you don't have someone who can do this, this is exactly the kind of thing a managed IT provider takes over — we do it for every one of our manufacturing clients as part of the standard service, because the alternative is watching a client's production line go down for a fortnight while a ransom is negotiated.

Why the three tend to travel together

There's a pattern in why these three problems co-occur in the same businesses. Manufacturers grow production capacity fast — a new machine, a new line, a new warehouse — and the IT grows underneath it in whatever way is quickest at the time. The flat network came from adding a machine on a Friday and just plugging it in. The unbacked-up ERP came from a server refresh that didn't include a backup strategy. The unpatched firewall came from "we haven't had any problems with it." Each individual decision was rational in the moment. Taken together, they build a factory where a single compromise costs a fortnight of production and half your customer relationships.

The good news is that the fix is proportionate. None of these are six-figure projects. All three, done properly on a fifteen-to-fifty-person manufacturer in Tameside, sit comfortably inside a project budget of £8,000 to £15,000 plus the ongoing managed service. That's less than a week of stopped production. And the cyber insurer, once the work is documented, will usually take a meaningful chunk off the premium.

If you'd like to know which of these three (or which combination) is actually the case at your factory before you commit to fixing anything, our first-visit assessment is ninety minutes and free. We'll walk the shop floor, look at the network, ask three questions of your ERP administrator and one of whoever pays the firewall renewal, and write it up as a two-page report. If you're on our patch — Tameside, Stockport, Trafford, north Cheshire — we can usually be with you within a fortnight. Get in touch or call us on 0161 503 3535.

FAQ

We're too small to be a target, aren't we?

That was the story a decade ago. It stopped being true around 2020 and it's stopped being remotely defensible now. The 2025-2026 Cyber Security Breaches Survey found roughly 4 in 10 UK businesses reported an attack in the last twelve months, and the ransomware groups running most of the damage are using automated tooling that scans the whole IPv4 internet for vulnerable devices. They don't pick you. They pick your firewall model. Being small means less noise; it doesn't mean less signal.

Is there really a difference between a Cyber Essentials-certified manufacturer and one that isn't?

Yes, and it's larger than most owners think. The NCSC's own figures suggest around an 80% reduction in incident volume for organisations that consistently implement the five Cyber Essentials controls. That's a meaningful number for a business that would otherwise lose a week of production to a preventable event. We wrote about what Cyber Essentials Plus audit day actually looks like separately if you want the specifics of the certification itself.

We already have IT support. Why would we look at this again?

Not every IT provider looks at manufacturing IT the same way. A generalist MSP will typically manage laptops and Microsoft 365 well, and then treat the shop floor as "the machines" — someone else's problem. That's fine until the ransomware doesn't care about the distinction. If your current provider hasn't asked about your OT/IT segmentation, your ERP backup immutability, or your firewall patch cadence in the last year, those three questions are a reasonable audit of whether they're the right fit for a manufacturer.

How long does the fix actually take?

For the three problems in this piece, on a typical fifteen-to-fifty-person manufacturer, we plan a four-to-six-week project. Week one is the assessment and the written plan. Weeks two to four are the network segmentation and firewall work, done in evenings and Saturdays to avoid production impact. Weeks four to six are the backup rebuild and the first successful test restore. You are not in a big-bang cutover at any point.

What does this look like inside the cyber insurance renewal?

We complete the questionnaire alongside you and provide technical evidence for the answers. Insurers now ask specifically about OT segmentation, immutable backup, and firewall patch cadence — the exact three items in this piece. Getting from three "no" answers to three "yes" answers with evidence typically saves several thousand pounds a year on the premium, and — more importantly — means the claim actually pays out if you ever need it. We wrote up a longer take on cyber insurance and evidence separately in the context of ISO 27001, but the principle is the same either way.

Ready to talk to a real Manchester MSP?

If any of this raised a question about your own setup, get in touch. We'll give you a straight answer — no sales pitch, no scaremongering.

Talk to a human