IT support and cyber security for manufacturing and fabrication shops

Southwest Saskatchewan. Drawings protected, shop-floor machines handled sensibly, and downtime measured in hours rather than weeks.

The call usually comes for one of these

Shops tend to run their own IT until something forces the question. It's usually one of these four.

  • A customer sent a supplier security questionnaire A larger buyer is screening its supply chain, and continuing to be on their vendor list depends on the answers.
  • A cyber insurance renewal The application asks whether multi-factor authentication is enforced and whether backups have been tested. Answering optimistically is what voids a policy at claim time.
  • Something on the shop floor can't be updated A machine runs an operating system the vendor stopped supporting years ago, and someone has finally asked what happens if it's hit.
  • A near miss, or a real one A file share came up encrypted, or a fake invoice nearly got paid, and the question of how long the shop could run without its drawings suddenly has a deadline on it.

What downtime costs a shop

For an office business, ransomware is an interruption. For a shop it's a delivery failure. Drawings, job files, quoting history and machine programs are the production line as much as the equipment is, and orders keep arriving while you rebuild. The ransom is rarely the expensive part; the missed dates and the customer who finds a second supplier are.

The work that changes the outcome is all done beforehand:

Backups the ransomware can't reach
Drawings, job files, machine programs and Microsoft 365 email backed up somewhere an attacker who owns your network still can't delete. That single property is what separates days from weeks.
A restore you've actually done
A backup nobody has restored from is a hope, not a control. I run the test, and give you the date and the result to put on the insurance form.
Monitored detection on every machine
Managed antivirus and threat detection with someone watching the alerts. Most encryption events announce themselves for an hour or two first, in ways nobody sees if nobody is looking.
A one-page incident plan
Who is called, in what order, and who is allowed to tell the shop to stop. Decided in advance, because the morning it happens is the worst time to work it out.

Shop-floor machines and the office network

Nearly every shop has at least one machine running something old because the equipment vendor never supported anything newer. Replacing a working machine tool over an operating system is rarely the right answer, and it's not the one I'll push.

The answer is to make it harmless. Put it on its own network segment with no route to the internet and no route into the office beyond the one connection it genuinely needs. Get files onto it by a controlled path instead of an open shared drive. Watch the segment. Once the unsupported machine can only reach the thing it drives, it stops being a company-wide risk, and it stops being the answer that fails a customer questionnaire.

Network segmentation
Separating shop floor, office and guest traffic so a problem in one doesn't become a problem in all three.
CAD, CNC and drawing files
Version history, controlled access, and backups that include the machine programs, not just the office documents.
Customer intellectual property
If you hold a buyer's drawings, you hold their IP, and their questionnaire will ask who can reach it. Access limited to the people who need it, and a record of that to attach.
Aging equipment on a plan
A quarterly look at what's out of support, what's about to be, and what it costs to deal with, so it lands in a budget instead of an emergency.

Supplier questionnaires and insurance applications

Whether it comes from a buyer, an insurer or a prime contractor, the security section asks about the same six things.

Multi-factor authentication
On email and remote access, for everyone including the owner. The most common gap, and an afternoon's work to close.
Tested backups
Microsoft 365 is not backed up the way most people assume, and neither is the drawing server in the corner of the office.
Monitored endpoint protection
On office machines, the estimator's laptop, and anything on the floor that can run it.
Written policies
IT security, acceptable use and a password standard. Documents that describe your shop as it actually runs, signed by staff.
Security awareness training
Short sessions and phishing simulations, with a completion record to attach.
An incident response plan
One page naming real people. Short is fine. Absent is what costs you the answer.

I go through your questionnaire with you, tell you where you honestly stand on each line, fix what's short, and give you the evidence to attach. Where you already meet it, I'll say so.

Why local matters for this

A shop's IT problems have a habit of being physical: a machine on the floor, a link between buildings, a server in a room that gets to forty degrees in July. Providers in Calgary or Regina handle those by asking you to send someone a photo. It works until it doesn't.

I work across southwest Saskatchewan, on site or remote depending on the job: Swift Current, Kindersley, Moose Jaw, Maple Creek, Shaunavon, Assiniboia and the country between. One person, a short client list on purpose, and the same person every time, the one who set the system up and knows why it's the way it is. There's a named backup consultant if I'm ever unavailable, everything is documented, and every password lives in a vault you own rather than in my head.

More on how I work, including pricing and after-hours.

Questionnaire from a customer, or a machine that worries you?

Send it over and I'll tell you what's involved before you commit to anything. If it's already fine, I'll tell you that instead.

Get in touch