NOUSEC addresses the two things that make human risk different in manufacturing and energy: the supply chain and the shop floor. Third parties are involved in 61% of manufacturing breaches, the highest share of any sector in the Verizon DBIR, so the pretexts that matter are vendor bank-detail changes, supplier onboarding and recruiter approaches to operational staff. And because much of the workforce has no assigned workstation, NOUSEC simulates across QR code, USB drop, SMS and WhatsApp as well as email, and delivers training in short formats — including posters and infographics for areas where nobody has a screen.
The most attacked industry, five years running.
Your supply chain is a social attack surface.
Sixty-one per cent third-party involvement is not a vendor-risk-questionnaire problem. It is a people problem with a purchase order attached.
| Pretext | Why it works | The control that holds |
|---|---|---|
| Vendor bank-detail change | It arrives from a real relationship, in the right tone, at a plausible moment in the billing cycle. | Verification through the contact already on file, never the contact in the request. |
| Supplier onboarding / spoofed quote | Procurement's job is to be responsive to new suppliers. | A defined onboarding path that does not accept documents out of band. |
| Recruiter approach to operational staff | Flattering, personal, and outside every corporate channel. | Training that names the pattern, and a reporting route that costs the employee nothing. |
This is not hypothetical. In its 2026 OT year in review, Dragos describes the threat group it tracks as PYROXENE running multi-year supply-chain campaigns that use social engineering against operational personnel, including fake LinkedIn profiles posing as recruiters.[13]
Many of the people you need are not reading email.
Shift patterns, shared terminals, and in many roles no individual mailbox at all. Three populations, three different answers.
Plant and field
Shift patterns, shared terminals, and in many roles no individual mailbox at all. Simulation via QR code and USB drop reaches them where email cannot; training arrives as posters, infographics and short modules rather than a 20-minute course.
Procurement, AP and engineering
The population the supply-chain pretexts actually target. Email, SMS, WhatsApp and callback simulation, the shipped BEC and credential-harvesting modules, and adaptive assignment on measured failure.
OT and control-room staff
Trained on the process controls, not on the detection of synthetic media. Escalation routes and out-of-band verification, plus the honest position on what people can and cannot tell apart.
Content reality: 14 formats, 30 languages — 9 fully localised today, 21 more on request, 10 of 20 curriculum topics shipped. Full white-label with automatic currency handling for multi-country groups.
Two annexes, two classifications, one evidence chain.
| Instrument | Article | What it requires | How NOUSEC evidences it |
|---|---|---|---|
| NIS2 — energy[3] | Annex I.1 | Electricity, district heating and cooling, oil, gas and hydrogen are sectors of high criticality. Larger entities are essential under Art. 3. | Server-side completion gate; audit-adjusted scorecard. |
| NIS2 — manufacturing | Annex II.5 | Medical devices and IVDs; computer, electronic and optical products (NACE 26); electrical equipment (27); machinery n.e.c. (28); motor vehicles and trailers (29); other transport equipment (30) — important entities. | The same evidence chain, a different fine ceiling. |
| NIS2 | Art. 21(2)(g) | Cyber hygiene and cybersecurity training as a minimum mandatory measure. | Completion evidence, not assignment records. |
| NIS2 | Art. 34(4)–(5) | Member states must provide for maximum fines of at least €10m or 2% of worldwide turnover (essential), €7m or 1.4% (important), whichever is higher. | — |
| GDPR | Art. 39(1)(b) | Awareness-raising and training in the DPO's monitoring remit. | Policy acknowledgement with version tracking. |
| ISO/IEC 27001:2022[5] | Cl. 7.2 / 7.3, A 6.3 | Competence, awareness, training. | Certificate public verification page. |
Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement and certificate public verification at Professional; audit log and SIEM export at Enterprise.
The four mechanisms this page rests on.
QR code and USB drop
Formats that work without a screen
Adaptive assignment on measured failure
White-label across countries
Related reading: QR code phishing attacks, and the glossary entries for invoice fraud, OSINT and pretexting. Our own posture is on Trust and Security.
Questions
What a group CISO across plants and countries asks first.
Every figure on this page, and where it came from
Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.
- 2026 Data Breach Investigations ReportVerizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026Used for: Manufacturing (31–33) — 3,627 incidents; 61% third-party involvement; 77% of social attacks were phishing; social engineering as the sector's second most common breach pattern, the one rank the report states in words.
- X-Force Threat Intelligence Index 2026IBM — published 25 February 2026, covering 2025 data · 2026Used for: Manufacturing as the most attacked industry for a fifth consecutive year, at 27.7% of observed incidents.
- OT Cybersecurity Year in ReviewDragos — 9th annual edition, 17 February 2026 · 2026Used for: 119 ransomware groups, up 49% from 80 in 2024, hitting 3,300 industrial organisations, with manufacturing more than two thirds of victims; and PYROXENE's multi-year supply-chain social engineering against operational personnel. The 49% is growth in the number of tracked groups, not in victims or attacks.
- Directive (EU) 2022/2555 (NIS2)Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022Used for: Article 3 on size-based classification, Article 21(2)(g), Article 34(4)–(5) on fine floors, and Annex I.1 and Annex II.5 membership.
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022International Organization for Standardization — 3rd edition · 2022Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.