Cybersecurity conversations often focus on prevention: how do we stop an attack, block phishing, and keep ransomware out?
Those are important questions. But for manufacturers, one question may matter even more: How quickly can the business recover?
The cyber incident involving Asahi Group offers a useful case study for packaging manufacturers because it shows how a cyberattack can become a prolonged operational disruption. It also reinforces an important lesson: prevention matters, but recovery readiness determines the size of the business impact.
Why the Asahi Example Matters to Packaging
Asahi is not a packaging manufacturer, but the example is highly relevant to the packaging industry. Beverage companies depend heavily on packaging. Labels, folded cartons, corrugated cases, pallets, and distribution packaging all play a role in getting product to market. When a major beverage operation experiences disruption, that disruption can ripple into packaging demand, shipping schedules, suppliers, and customers.
For packaging manufacturers, the Asahi case is useful because it makes cyber risk tangible. It is not a theoretical IT event. It is a real operational disruption that affected business performance.
Asahi experienced a disruption in late September 2025 and had to manage operations manually for months. Normal operations and logistics were not fully restored until February 2026. That means the business spent more than a quarter operating under abnormal conditions.
That is the part packaging manufacturers should pay attention to. The biggest cyber risk is not always the moment of attack. It is the long recovery period that follows.
Manual Operations are Expensive
Teams know how to use spreadsheets, phone calls, paper notes, and manual workarounds when systems are unavailable. That said, manual operations are rarely efficient at scale. When a business has to operate manually for days, weeks, or months, costs rise quickly because:
- Employees spend more time coordinating work.
- Production visibility decreases.
- Scheduling gets harder.
- Errors become more likely.
- Customer service teams have less reliable information.
- Shipping and invoicing can slow down.
Even if the plant keeps running, the business is no longer operating efficiently. That creates an immediate revenue problem and a serious customer retention problem.
The Asahi Group’s incident led to year-over-year revenue declines across core business units during the affected quarter. The point is not just that a cyberattack occurred, it’s that the attack created a measurable operational and financial drag.
For packaging manufacturers, that is the key takeaway: a cyber incident can reduce throughput and revenue even when equipment is still physically capable of producing.
Recovery Speed Changes the Outcome
Imagine two similar packaging plants:
- Both experience a cyber incident.
- Both have some preventive controls.
- Both have customers depending on them.
The difference is what happens next.
One plant has partial cybersecurity maturity. It has some tools, policies, and backups, but limited evidence that recovery will work under pressure. Leaders are not sure who makes which decisions. Vendor access is not fully documented. Critical systems are not clearly prioritized. Recovery processes have not been tested recently.
The other plant has stronger recovery readiness. It knows it’s critical systems, has tested backups, named decision-makers, created a response plan and practiced tabletop scenarios. It knows which systems must come back first and what “all clear” means.
The first plant may spend weeks struggling to restore normal operations.
The second may still experience disruption, but it has a better chance of containing the incident, restoring systems, and catching up. That difference can be worth millions.
Backups Are Not Enough Unless They Are Tested
Many companies believe they are protected because they have backups, but these only matter if they are restorable.
A common ransomware pattern is to encrypt not only production systems, but also backups that are connected to the same environment. If backup systems are not protected, isolated, or tested, the company may discover during a crisis that recovery is much harder than expected.
That is why manufacturers need to ask more specific questions:
- Can we restore our critical systems from backup?
- When was the last restore test performed?
- How long did the restore take?
- How much data would we lose?
- Are backups protected from ransomware encryption?
- Who owns recovery decisions?
“We have backups.” is not a business continuity plan. The goal is to prove, “We can recover the systems we need within a timeframe the business can tolerate.”
Cyber Insurance Does Not Replace Operational Resilience
Cyber insurance is important, and many manufacturers are recognizing that they need it, but it does not eliminate operational disruption. Insurance may help cover certain expenses such as support response and investigation costs. But it does not automatically restore customer trust, recover lost production capacity, or protect customer relationships.
Consider this: would you rather cancel key customer orders or call a cross-town competitor to deliver them late? That kind of moment creates damage that goes beyond the financial statement. When a customer sees another supplier’s product filling the gap, the risk becomes strategic.
Cyber insurance should be viewed as one layer of protection, not the recovery plan itself.
What Packaging Manufacturers Should Learn
The Asahi example points to several lessons for packaging manufacturers:
- Cybersecurity incidents can disrupt operations for months if recovery is not ready.
- Manual workarounds are not a complete business continuity strategy.
- Tested recovery matters as much as preventive security.
- Cyber incidents should be evaluated in terms of revenue, uptime, customer impact, and operational confidence.
Finally, the best time to improve recovery is before an incident happens.
Start with One Critical Process
Packaging manufacturers do not need to solve every recovery challenge at once.
A practical starting point is to select one critical business process and test recovery for the systems that support it.
For example:
- Can we restore scheduling?
- Can we restore ERP access?
- Can we ship product?
- Can we invoice customers?
- Can we operate a critical production line?
Run the test, measure the recovery time, document the gaps, and improve the process. Then move to the next critical area. That simple discipline can materially change the outcome of a future incident.
The lesson from Asahi is clear: the cost of a cyberattack is not only determined by whether attackers get in, it is determined by how prepared the business is to recover.
Take this quick survey to understand your cyber risk and its potential impact.
