Create a free Industrial Equipment News account to continue

Minimizing Human Error and Credential Theft

The good news is that we know the problem. The bad news is that we're not fixing it.

Red warning alert symbol glowing above laptop with hands, surrounded by digital data icons and circuit patterns on dark background
istock.com/PUGUN SJ

A new Thales report found that manufacturers are preparing for increasingly sophisticated cyber threats, but everyday data-security gaps are posing more immediate risks to production continuity, intellectual property and supply chains. The syncs with additional research showing that awareness of cybersecurity threats has never been higher in the industrial sector, but this group still lags in taking real action to combat threats.

According to the report:

  • Manufacturers that have experienced a data breach cite human error as the leading cause (30 percent). While humans will always be the biggest internal threat, regardless of industry, more needs to be done in expanding worker engagement with cybersecurity planning and protocols - going beyond "check-the-box" training that fails to resonate with many front-line workers.
  • 42 percent of sensitive cloud data in manufacturing is encrypted, down from 57 percent in 2025. The speed at which production environments need to operate continues to contribute to lagging security protocols that bad actors are just waiting to exploit. This balancing act between meeting production goals and implementing cybersecurity measures will continue to be a key issue as the OT attack landscape expands in the face of greater connectivity and digital transformation goals.
  • 57 percent report increased credential theft or misappropriated secrets in cloud-management environments. The use of administrative and shared passwords that are simplified in prioritizing speed over security has led to more and more credentials being stolen and sold on the dark web. Many manufacturers feel they're too small to matter to hackers, but the increasing number of logins and passwords being obtained by hacking groups shows this to be a dangerously false narrative.
  • Manufacturers use an average of eight data-protection and monitoring tools, and 83 percent use five or more. The total number of tools is rarely the issue. Rather, it's the redundancy found within these arsenals that can create a negative narrative. Obtaining funding for cybersecurity can be daunting for many organizations, and failing to optimize these resources can lead to a less enthusiastic response when more funds are requested.
  • 61 percent are evaluating post-quantum cryptography to protect their IP and sensitive data, though 56 percent are behind or unsure about interoperability. Q-day is coming and organizations not only need to prepare for the encryption challenges this will create, but obtain a foundational understanding of what quantum cryptography is all about, and how it can help their company in multiple ways.

To obtain a bit more insight on this report and its findings, I recently sat down with Todd Moore, Global VP/GM of Data Security Products at Thales.

Jeff Reinke, Editorial Director: What can manufacturers do to improve credential security?

Todd Moore, Global VP/GM at Thales: To improve credential security, they should make sure only the right people and machines can get into the right systems, and only give them access to what they actually need. 

For example, a factory worker’s password is stolen, but the hacker still can’t access the production system because it requires a second form of verification and that employee’s account isn’t authorized to control factory equipment. 

The highly distributed nature of manufacturing infrastructure and range of human entry points have made this industry particularly vulnerable to data breaches. To build effective security resilience without slowing down production, security teams need a practical approach that fits both the shop floor and IT. Digitalization only works when you can establish trust across your entire ecosystem, including between employees, partners, connected devices, and services.  

Solid identity and access management (IAM) systems are the key to making that happen, and Zero Trust should be the default for manufacturers in the heightened risk of today’s cybersecurity environment. Plus, credential security isn’t just about people anymore. As factories introduce automated scripts, OT devices, and AI agents, these machine identities need strict least-privilege guardrails and centralized vaulting to protect the supply chain both up and downstream.

JR: What are some of the negative impacts of overspending on too many cybersecurity tools?

TM: Having too many different security tools can actually make security harder, because teams have more alerts, systems and information to keep track of and important things can fall through the cracks.

For example, a company has 20 different security tools sending alerts, and an employee misses the one alert that actually matters because it’s buried among hundreds of others.

When companies overspend on overlapping cybersecurity tools, also known as tool sprawl, they’re inherently increasing their risk. Complex security tech stacks mean teams have to deal with multiple modes of control across different platforms, less overall visibility, and a higher risk of human error, especially when sensitive data is already under-protected. Managing these disparate point solutions can lead to alert fatigue and fragmented visibility, creating gaps where sensitive data can go undetected.

JR: What are some best practices for trying to minimize the number of human errors?

TM: To minimize human errors, it’s critical to make security simpler and more automatic, so protecting sensitive information doesn’t depend on someone remembering to do the right thing every single time.

Instead of expecting an employee to recognize and manually protect a sensitive customer file, the company’s security system automatically finds it, identifies it as sensitive and applies the appropriate protection.

At its most basic, reducing complexity and friction reduces the chance for human error. Platform consolidation simplifies security operations for human users, and also frees up budget for continuous data discovery and better encryption practices. At the same time, designing security mechanisms around how people naturally work will minimize friction so users don't feel forced to create risky workarounds. 

At a system level, it’s impossible to effectively protect your data when you don’t know where it is. Humans cannot manually classify or secure data at the speed of modern cloud and AI workflows. Deploying automated Data Security Posture Management (DSPM) ensures that sensitive files and databases are discovered, classified, and encrypted by default without relying on manual user intervention.

More in Safety