Why Forgers Can No Longer View Cybersecurity as an IT Problem

Written by: Katie Hensley, Vice President, Cottingham & Butler
(563) 587-5464 | kahensley@cottinghambutler.com
Introduction
When forging companies think about risk, the focus often falls on equipment breakdown, workers’ compensation, and property losses. However, cyber risk has become a growing concern for manufacturers, customers, and insurance carriers. Today’s forging operations rely on interconnected technologies to manage scheduling, engineering specifications, inventory, shipping, quality documentation, and financial transactions. A successful cyberattack can disrupt operations just as effectively as a major property loss.
Why Forgers Are Targets
Forgers support defense, aerospace, energy, transportation, and critical infrastructure industries. They frequently possess valuable engineering drawings, production specifications, customer requirements, testing data, and proprietary manufacturing information. The combination of sensitive customer data, intellectual property, interconnected systems, and the financial consequences of downtime makes forging operations attractive targets for cybercriminals.
Cyber Events Become Business Events
The greatest exposure is often not stolen data. It is the inability to operate. A forge may have fully functional equipment, but if ERP systems, production schedules, engineering files, customer communications, or shipping platforms become unavailable, operations can quickly grind to a halt. This is why underwriters increasingly view cybersecurity as a business continuity issue.
Why Cyber Insurance Matters
Even organizations with strong cybersecurity programs can become victims of a cyberattack. Cyber insurance provides far more than financial reimbursement. Many policies provide access to digital forensic investigators, breach coaches, privacy attorneys, cybersecurity response specialists, public relations consultants, crisis management teams, data restoration experts, and accountants who help quantify business interruption losses. For manufacturers, the largest cyber loss is often lost production. Cyber insurance helps organizations navigate operational disruption, recovery costs, communications, and business interruption exposures.
Top Cyber Lessons Every Forger Should Remember
Application Accuracy Is Your First Line of Defense Cyber insurance applications have become increasingly detailed. Inaccurate information can create claim challenges and potentially jeopardize coverage. Coverage begins with accurate information.
Attackers Are Patient. Proactive Detection Is Not Optional Cybercriminals often spend weeks or months inside a network before taking action. Artificial intelligence now enables more convincing phishing campaigns, automated reconnaissance, and highly targeted attacks. Continuous monitoring and cyber preparedness assessments are essential.
A Response Plan on Paper Is No Plan at All Organizations should know who to call, how to engage insurance carriers, and what actions should occur during the first critical hours of an incident. Tabletop exercises should be conducted regularly.
Compliance Satisfies Auditors. Security Protects Your Business. Compliance is often the floor rather than the ceiling. Passing an audit does not mean attackers cannot access systems. Effective security requires continual improvement.
The Cloud Shifts Responsibility. It Does Not Eliminate It. Cloud providers secure infrastructure, but organizations remain responsible for identities, applications, data protection, and incident response.
Your Supply Chain Can Become Your Weakest Link. Forgers routinely exchange engineering documents, specifications, certifications, and quality records. A cyber incident affecting a supplier, software vendor, or logistics partner can disrupt operations throughout the supply chain.
Acquisitions Create New Exposure. Attackers may compromise smaller organizations and remain undetected while transactions progress. Cybersecurity reviews should carry the same weight as financial and legal due diligence.
Business Interruption Is Often the Largest Loss. For many manufacturers, the greatest impact of a cyber event is lost production rather than stolen data.
Cyber Insurance Is More Than a Financial Tool. A quality cyber policy provides access to specialized experts and recovery resources that most organizations do not maintain internally.
Cybersecurity Is Becoming an Insurability Issue. Underwriters increasingly evaluate multi-factor authentication, employee training, backups, incident response planning, monitoring, vendor management, and governance controls. Preparedness can directly influence coverage and pricing.
Conclusion
Cyber risk is no longer just an IT concern. It is a business interruption issue, a supply chain issue, and increasingly an insurability issue. Organizations that combine strong cybersecurity
controls, cyber preparedness, effective response planning, and appropriate cyber insurance will be best positioned to recover from future incidents.