Moscow-based F6 reports manufacturing as top cyberattack target, as 80% of industrial firms face security staffing shortage

Data from Russian cybersecurity firm F6 identified that manufacturing is the top target for cyberattacks in 2026, while... The post Moscow-based F6 reports manufacturing as top cyberattack target, as 80% of industrial firms face security staffing shortage appeared first on Industrial Cyber.

Data from Russian cybersecurity firm F6 identified that manufacturing is the top target for cyberattacks in 2026, while about 80% of companies, including critical information infrastructure facilities, face a shortage of qualified information security personnel. It revealed that filling a single cybersecurity vacancy can take several months, while building a 24/7 security team from scratch can take 12 to 18 months, creating a gap that attackers can exploit as industrial threats accelerate. 

The assessment is designed to determine whether industrial organizations have effective visibility and response capabilities rather than simply maintaining compliance checklists. F6 said organizations should bring raw events from endpoints, networks, email gateways, and cloud environments into a single database, and analysts should be able to reconstruct an intrusion chain within five minutes without switching between multiple interfaces. The company also highlights contractor compromise as a key route into internal networks and warns that if an organization receives negative answers on at least three of the seven criteria, its monitoring may create only the appearance of security.

F6 recommends that CISOs assess industrial security against seven criteria, including telemetry coverage, phishing response, alert processing, incident response, attacks through contractors, false positives and integration of security solutions.

It identified that raw events from endpoints, the network, mail gateways, and clouds should be collected into a single database rather than remaining as disparate logs in separate consoles. Many factories purchase separate tools for each threat class, resulting in a ‘zoo’ of tools where engineers must manually correlate events from different interfaces. During an attack, every minute counts, and jumping between windows consumes time that is already in short supply. A specialist should be able to reconstruct the entire chain of a single intrusion in five minutes without opening more than one interface. If this cannot be accomplished, the defense architecture requires reconsideration.

F6 mentioned that phishing remains the primary penetration vector, with malicious code most often delivered via email attachments. Password archives pose a particular challenge because they bypass standard antivirus software, as the contents cannot be verified without entering the password, which the attacker provides in the body of the same email, a subsequent email, or a private message on instant messaging apps. 

Effective phishing defenses must cover the entire lifecycle of email messages, including blocking malicious attachments and links before they are delivered to the recipient, conducting Time-of-Click behavior analysis, analyzing email context to determine whether it corresponds to the expected behavior of the sender, and providing post-delivery protection in case the threat still gets through the filters. If the defense only checks the moment of delivery rather than the entire path of the message, a single bypass of the filter will be enough for an attacker to gain a foothold undetected.

F6 also identified that thousands of security events per day are a common reality for plants of any size. The problem is not the volume of data but what happens to it next: without correlation and classification by criticality, analysts often fail to process part of the flow. 

The key metric is not the total number of alerts but the percentage of confirmed cases requiring human intervention. If this figure is low, specialists spend most of their time sifting through noise instead of investigating genuine threats, a recipe for burnout for the few remaining specialists. Departments should know the exact percentage of false alarms over the past month, and if they do not, the alert processing process is based on operator intuition rather than a well-established methodology.

The speed of Source: Industrial Cyber