Ask a manufacturer who owns the corporate network and you will get a name. Ask who owns the network on the plant floor and you will usually get a pause, then something like "the equipment vendor, I think," or "whoever installed the line."
That pause is the risk. Not the firewall, not the antivirus, not the thing a security vendor will offer to sell you. The pause.
Why the seam exists
Twenty years ago the plant floor was genuinely separate. The machines spoke proprietary protocols, sat on their own cabling, and had no reason to reach anything else.
Then the business wanted production data in the ERP. The equipment vendor wanted remote support access. Somebody needed a shared drive for programme files. Each of those was a reasonable request granted individually, and the cumulative effect is a plant network that touches the business network in a dozen places nobody has ever mapped together.
Meanwhile the machines themselves run operating systems the manufacturer will not let you patch, because patching voids the support agreement or the validation. So you have unpatched systems, reachable from a network that receives email.
What actually happens
The pattern in the incidents we see is boring and consistent. Somebody in accounts opens an attachment. The malware moves laterally, finds a flat network, and encrypts everything it can reach, which turns out to include the file share the line depends on and the historian the quality team needs.
The production equipment itself is often untouched. It does not matter. If the machines cannot get their programme files, the line stops, and the loss is measured in dollars per minute against a fixed cost base that does not pause.
The recovery conversation is then not about technology at all. It is about how many days of production you can lose, and whether your insurance will pay for them, which turns on questions about controls you answered on an application form eighteen months ago.
What to do about it that plants can live with
The advice that gets ignored is "segment the network." It is correct and it is useless on its own, because it lands on an operations team that hears "add a step to production."
What works is narrower and sequenced.
Map the seam first. Before any control changes, find every place the plant network touches the business network, including the remote support connections vendors opened years ago and the laptop that lives on the line and also collects email.
Separate what cannot be patched. You are not going to patch the machine the vendor forbids you to touch. Put it where a compromise on the business side cannot reach it, and where its own compromise cannot spread.
Fix the file share before the firewall. The dependency that actually stops production is usually a shared drive or a historian. Getting that recoverable, and testing the recovery, buys more resilience per dollar than most perimeter work.
Write down who owns it. The single highest-value output of this work is a name against the plant network. Not a vendor, a person on your side.
The insurance question you will be asked
Cyber insurance applications now ask about segmentation, about privileged access, about tested backups. Answering optimistically is worse than answering no: a warranty you cannot support is a claim the insurer can decline, at exactly the moment you need it.
If you cannot answer those questions about the plant floor with evidence, that is worth knowing before the renewal rather than during the incident.

