Cybersecurity improvement does not have to start with a massive transformation.
For many packaging manufacturers, the best first step is not a large new platform, a complex security overhaul, or a multimillion-dollar initiative. It’s focus.
There are several practical actions manufacturers can take in the next 60 to 90 days that can materially improve cyber resilience. These actions do not eliminate risk, but they can change the outcome of an incident by improving visibility, access control, decision-making, and recovery readiness.
Here are five high-impact actions packaging manufacturers can start with:
1. Govern Supplier Remote Access
Remote supplier access is one of the most important cyber risks for packaging manufacturers because many plants rely on OEMs, vendors, and support partners to access systems remotely. That access can be useful and sometimes necessary, but every remote connection into a production environment is also a potential risk point. While remote access is not a problem itself, the problem lies with unmanaged remote access.
Shared accounts, stale vendor credentials, informal VPN access, and unclear approval processes all create exposure. If a supplier or support partner can reach plant systems, the manufacturer should know who has access, why they need it, when they use it, and how activity is monitored.
A practical 90-day goal is to create a supplier remote access inventory. Some key things to document are:
- Which vendors have access
- Which systems they can reach
- Which individuals use the access
- Whether MFA is required
- Whether access is logged
- Who approves access
- How often access is reviewed
After completing documentation, be sure to remove stale accounts and replace shared access with named identities wherever possible. This is one of the highest-leverage actions a packaging manufacturer can take.
2. Identify your OT Crown Jewels
Not every system carries the same business risk. While some systems may be inconvenient if unavailable, others may stop production, shipping, invoicing, or customer service.
Packaging manufacturers should identify their OT and operational “crown jewels.” These are the systems, equipment, connections, and processes that matter most to business continuity.
Examples may include:
- ERP
- MES
- Scheduling systems
- Corrugator controls
- Plant floor HMIs
- PLCs
- Shipping systems
- Backup systems
- Key SaaS workflows
- Remote support paths
The goal is to understand what would happen if these systems were unavailable for 24, 48, or 72 hours. This does not require a sophisticated tool to begin. A disciplined spreadsheet and conversations with plant leaders, operations managers, IT, and support teams can provide a strong starting point.
For each critical system, document:
- What it does
- Who owns it
- Who supports it
- What it connects to
- Who can access it
- What business process depends on it
- What happens if it goes down
If you cannot name your critical assets and remote entry points, you cannot manage the real risk.
3. Test Recovery for One Critical Process
Many businesses believe they are protected because backups exist, but backups are only valuable if they can be restored. During ransomware events, backups may be encrypted, corrupted, incomplete, or too slow to restore within the timeframe the business needs.
That is why packaging manufacturers should test recovery for at least one critical process.
Choose one process that matters to the business, such as scheduling, shipping, invoicing, ERP, or a critical production workflow. Then test whether the supporting systems can be restored by measuring:
- How long the restore takes
- How much data is lost
- Who needs to be involved
- What documentation is missing
- What decisions need to be made
- Whether the restored system works as expected
This gives the business practical evidence and helps leadership understand the difference between having backups and having a recovery capability.
The goal is not to test every system immediately. The goal is to start with one critical process, learn from the test, and build from there.
4. Reduce Standing Privileges
Standing privileges are permissions that remain in place whether or not someone actively needs them.
Over time, many organizations accumulate excess access which can increase risk. These can include standing privileges such as:
- Employees keeping admin rights after job changes.
- Vendor accounts that stay active after support work ends.
- Shared credentials that remain in use because they are convenient.
- Daily-use accounts that may have more permissions than necessary.
If an attacker compromises an account with broad access, they can move faster and cause more damage.
Packaging manufacturers should review privileged access across IT, OT, and vendor accounts. Start by asking:
- Who has admin access?
- Do they still need it?
- Are admin accounts separate from daily-use accounts?
- Are vendor accounts named and current?
- Are inactive accounts disabled?
- Is MFA enforced for privileged access?
The goal is to give people the access they need to do their jobs, but not more than they need. This may create some operational friction, however, it significantly reduces attack paths. It is important that convenience does not quietly become a cybersecurity strategy.
5. Run a Tabletop Exercise
A tabletop exercise is one of the most practical ways to improve cyber readiness.
It brings together the people who would be involved in a real incident and walks them through a realistic scenario.
For a packaging manufacturer, a useful scenario could be:
- A ransomware alert appears on a laptop.
- A supplier remote access account shows unusual activity.
- ERP becomes unavailable.
- A production system cannot communicate normally.
- Shipping cannot access order data.
The exercise should include operations, IT, security, leadership, customer service, finance, and anyone else who would play a role in business response.
The point is not to embarrass anyone or prove the company is unprepared, but to identify gaps before an incident happens.
A tabletop exercise can clarify:
- Who makes containment decisions
- Who communicates with customers
- Who contacts insurance or legal support
- Who decides whether to move to manual operations
- Who approves system restoration
- What information leadership needs
- What documentation is missing
The value of a tabletop exercise is that it turns assumptions into discussion and discussion into action.
What to Measure During the First 90 Days
These five actions become more powerful when they produce evidence.
By the end of a 90-day effort, a manufacturer should aim to have artifacts such as:
- Supplier access inventory
- MFA coverage report
- Critical asset list
- Vendor access review log
- Backup restore test results
- Incident contact matrix
- Tabletop exercise summary
- Remediation backlog
These do not need to be perfect, but they need to be useful, current, and owned. The goal is to move from informal confidence to documented readiness.
Cybersecurity Progress is Achievable
Most packaging manufacturers do not need to solve every cybersecurity problem immediately, however, a practical starting point can look like:
- Governing supplier access.
- Identifying critical systems.
- Testing recovery.
- Reducing unnecessary privileges.
- Practicing incident response.
These steps can materially improve resilience without requiring a massive transformation.
The companies that recover fastest are not the ones that assume they will never be attacked. They are the ones that prepare for disruption, practice their response, and prove they can recover.
In packaging, cybersecurity is more than protecting data. It is about protecting production, customers, and the ability to keep the business moving.
Take this quick survey to understand your cyber risk and its potential impact.
