Manufacturing & energyThe way in was a supplier your team already trusts.

Manufacturing carries the highest third-party involvement of any sector in the Verizon DBIR — 61% of breaches — and has been the most attacked industry in IBM X-Force's telemetry for five consecutive years. Social engineering is the second most common breach pattern, and 77% of those social attacks are phishing. The hard part is that the people being worked often have no assigned workstation.

Verizon DBIR 2026, Manufacturing (31–33) · 3,627 incidents · IBM X-Force 2026
NIS2 (Annex I & II) · GDPR · ISO 27001 · EU data residency (Frankfurt) · No endpoint agents
Supplier change request
Simulated — product demonstration
Bank details updated
Supplier
Contract on file
Procurement
Vendor record
AP
Payment file
Payment run
Thursday
Request originated from Norhavn Tooling Partners — not the contracted Norhaven Tooling.
Verify with the contact on fileHeld — not applied
Illustrative. The third-party involvement figure is from the DBIR 2026 manufacturing snapshot. Both supplier names are invented; no real company, domain or bank detail appears.
Supplier change request
Simulated — product demonstration
Bank details updated
Supplier
Contract on file
Procurement
Vendor record
AP
Payment file
Payment run
Thursday
Request originated from Norhavn Tooling Partners — not the contracted Norhaven Tooling.
Verify with the contact on fileHeld — not applied
Illustrative. The third-party involvement figure is from the DBIR 2026 manufacturing snapshot. Both supplier names are invented; no real company, domain or bank detail appears.
Human risk in manufacturing and energy

NOUSEC addresses the two things that make human risk different in manufacturing and energy: the supply chain and the shop floor. Third parties are involved in 61% of manufacturing breaches, the highest share of any sector in the Verizon DBIR, so the pretexts that matter are vendor bank-detail changes, supplier onboarding and recruiter approaches to operational staff. And because much of the workforce has no assigned workstation, NOUSEC simulates across QR code, USB drop, SMS and WhatsApp as well as email, and delivers training in short formats — including posters and infographics for areas where nobody has a screen.

What the data says

The most attacked industry, five years running.

61%[1]
of breaches in Manufacturing (31–33) involve a third party — the highest of any sector in the report
27.7%[12]
of incidents IBM X-Force observed hit manufacturing — the most attacked industry for a fifth consecutive year
77%[1]
of social attacks in manufacturing were phishing; social engineering is the sector's second most common breach pattern
119[13]
ransomware groups — up 49% from 80 in 2024 — hit 3,300 industrial organisations in 2025; manufacturing was over two thirds of the victims

Verizon's dataset is contributed casework, not a representative sample of all breaches; industry figures are for prioritisation. The 49% is growth in the number of tracked groups, not in victims or attacks.

The argument

Your supply chain is a social attack surface.

Sixty-one per cent third-party involvement is not a vendor-risk-questionnaire problem. It is a people problem with a purchase order attached.

Three supply-chain pretexts, why each works, and the control that holds against it
PretextWhy it worksThe control that holds
Vendor bank-detail changeIt arrives from a real relationship, in the right tone, at a plausible moment in the billing cycle.Verification through the contact already on file, never the contact in the request.
Supplier onboarding / spoofed quoteProcurement's job is to be responsive to new suppliers.A defined onboarding path that does not accept documents out of band.
Recruiter approach to operational staffFlattering, personal, and outside every corporate channel.Training that names the pattern, and a reporting route that costs the employee nothing.

This is not hypothetical. In its 2026 OT year in review, Dragos describes the threat group it tracks as PYROXENE running multi-year supply-chain campaigns that use social engineering against operational personnel, including fake LinkedIn profiles posing as recruiters.[13]

Who we have to reach

Many of the people you need are not reading email.

Shift patterns, shared terminals, and in many roles no individual mailbox at all. Three populations, three different answers.

No mailbox

Plant and field

Shift patterns, shared terminals, and in many roles no individual mailbox at all. Simulation via QR code and USB drop reaches them where email cannot; training arrives as posters, infographics and short modules rather than a 20-minute course.

The actual target

Procurement, AP and engineering

The population the supply-chain pretexts actually target. Email, SMS, WhatsApp and callback simulation, the shipped BEC and credential-harvesting modules, and adaptive assignment on measured failure.

Process, not perception

OT and control-room staff

Trained on the process controls, not on the detection of synthetic media. Escalation routes and out-of-band verification, plus the honest position on what people can and cannot tell apart.

Content reality: 14 formats, 30 languages — 9 fully localised today, 21 more on request, 10 of 20 curriculum topics shipped. Full white-label with automatic currency handling for multi-country groups.

What you have to evidence

Two annexes, two classifications, one evidence chain.

Instruments, articles, what each requires, and the NOUSEC mechanism that evidences it
InstrumentArticleWhat it requiresHow NOUSEC evidences it
NIS2 — energy[3]Annex I.1Electricity, district heating and cooling, oil, gas and hydrogen are sectors of high criticality. Larger entities are essential under Art. 3.Server-side completion gate; audit-adjusted scorecard.
NIS2 — manufacturingAnnex II.5Medical devices and IVDs; computer, electronic and optical products (NACE 26); electrical equipment (27); machinery n.e.c. (28); motor vehicles and trailers (29); other transport equipment (30) — important entities.The same evidence chain, a different fine ceiling.
NIS2Art. 21(2)(g)Cyber hygiene and cybersecurity training as a minimum mandatory measure.Completion evidence, not assignment records.
NIS2Art. 34(4)–(5)Member states must provide for maximum fines of at least €10m or 2% of worldwide turnover (essential), €7m or 1.4% (important), whichever is higher.
GDPRArt. 39(1)(b)Awareness-raising and training in the DPO's monitoring remit.Policy acknowledgement with version tracking.
ISO/IEC 27001:2022[5]Cl. 7.2 / 7.3, A 6.3Competence, awareness, training.Certificate public verification page.

Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement and certificate public verification at Professional; audit log and SIEM export at Enterprise.

A precision point.
Energy sits in Annex I and manufacturing in Annex II, so a group operating in both may hold two different classifications at once — with different fine ceilings and different supervisory regimes. Being listed in Annex I does not by itself make an entity essential; size under Article 3 decides.[3] Where a state-owned utility is involved, note that fines against public administration are at member-state discretion while the training obligation is not.
Product proof

The four mechanisms this page rests on.

QR code and USB drop

The two channels that reach staff without a mailbox, alongside SMS, WhatsApp and callback for the office population.
Phishing simulation

Formats that work without a screen

Posters and infographics for the floor, short modules for shared terminals, with completion still measured in watched seconds.
Security awareness training

Adaptive assignment on measured failure

Procurement and AP get the pretexts that target them, assigned by what they actually failed rather than by job title.
Human Risk Score

White-label across countries

Your branding, automatic currency handling, and one tenant reporting against several frameworks at once.
Integrations

Related reading: QR code phishing attacks, and the glossary entries for invoice fraud, OSINT and pretexting. Our own posture is on Trust and Security.

What this will not do.
NOUSEC is an IT-side human risk platform. It does not monitor OT networks, does not deploy into a control system, and installs nothing on any device. If your requirement is OT network visibility, that is a different vendor — we train and measure the people whose credentials and approvals are the way in.

Questions

What a group CISO across plants and countries asks first.

Can you train people who have no company email address?

Yes. QR-code and USB-drop simulation reach staff without a mailbox, and training is delivered in formats that work without an assigned workstation.

Are we an essential or an important entity?

Energy sub-sectors sit in NIS2 Annex I and manufacturing sub-sectors in Annex II — but classification follows size under Article 3, not the annex alone. A group in both may hold both classifications.

Does anything get installed in our OT environment?

No. Nothing is installed anywhere. No endpoint agents, no OT sensors.

How do you simulate supplier fraud without naming a real supplier?

Campaigns use invented counterparties. Every simulated message carries a visible disclaimer, and lures never impersonate a real brand.

We operate across several countries. Does the platform handle that?

Full white-label, automatic currency handling, and 30 languages — nine fully localised today, twenty-one more on request, built to the same four-gate localisation process.

Receipts

Every figure on this page, and where it came from

Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.

  1. 2026 Data Breach Investigations Report
    Verizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026
    Used for: Manufacturing (31–33) — 3,627 incidents; 61% third-party involvement; 77% of social attacks were phishing; social engineering as the sector's second most common breach pattern, the one rank the report states in words.
  2. X-Force Threat Intelligence Index 2026
    IBM — published 25 February 2026, covering 2025 data · 2026
    Used for: Manufacturing as the most attacked industry for a fifth consecutive year, at 27.7% of observed incidents.
  3. OT Cybersecurity Year in Review
    Dragos — 9th annual edition, 17 February 2026 · 2026
    Used for: 119 ransomware groups, up 49% from 80 in 2024, hitting 3,300 industrial organisations, with manufacturing more than two thirds of victims; and PYROXENE's multi-year supply-chain social engineering against operational personnel. The 49% is growth in the number of tracked groups, not in victims or attacks.
  4. Directive (EU) 2022/2555 (NIS2)
    Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022
    Used for: Article 3 on size-based classification, Article 21(2)(g), Article 34(4)–(5) on fine floors, and Annex I.1 and Annex II.5 membership.
  5. ISO/IEC 27001:2022 and ISO/IEC 27002:2022
    International Organization for Standardization — 3rd edition · 2022
    Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.

Send us a purchase order you nearly paid.

We will build the campaign from it and measure whether the process control holds.

GDPR native · EU data residency (Frankfurt) · No endpoint agents · Pricing