The plant is already in the cloud, even if no one decided it
This series consists of three weekly installments covering the industrial cloud and operational continuity. In the first installment, we will address the context.
No industrial management ever signed off on a decision to move their plant to the cloud, and yet, if the external services on which their monitoring, traceability, or support systems depend were interrupted today, a large part of Spanish factories would feel the impact within hours. This first installment describes how that dependency was formed and what mechanisms can halt a production line without anyone ever touching the machinery.
A migration that happened without a migration project
Cloud adoption in industry did not follow the pattern of corporate systems, where there is usually a project, a committee, and an associated risk analysis. What actually happened was an accumulation of small, reasonable decisions made over several years.
The monitoring system provider shifted to offering its platform as a service, the packaging line manufacturer made the warranty conditional on permanent remote access, and the process historian found in the cloud the storage capacity that the server room never had. Each decision, evaluated separately, was correct, but the aggregate result is that day-to-day operations depend on a constellation of external services that no one chose as a whole and, in many cases, no one has inventoried as a whole either.
That evolution has brought real capabilities, because predictive maintenance, end-to-end traceability, or energy optimization would be unfeasible at the current scale without cloud infrastructure.
The question posed by this series is different, as these capabilities have come with dependencies that affect plant availability and rarely receive the same risk management treatment as a critical physical asset.
The blind spot of operational risk analysis
Industrial risk analysis frameworks were built looking inside the perimeter and evaluate the machine, the PLC, the control network, and the power supply, while external services live in the contract managed by procurement, measured in availability percentages, and not in the risk map managed by operations, measured in downtime hours and unproduced goods.
That separation carries over to continuity exercises, whose usual script covers fire, power failure, and ransomware on internal systems without ever contemplating the outage of a third-party service while the plant itself is operating normally.
Three mechanisms with the same outcome
-
The first is provider failure without any cyberattack involved. On October 20, 2025, an incident in name resolution within one of the major cloud infrastructure providers cascaded across more than a hundred of its services and dragged down unrelated organizations worldwide for hours, from financial institutions to logistics platforms. INCIBE documented the incident in its security log. There was no attacker, only a dependency operating as designed that, for that very reason, failed for everyone simultaneously.
-
The second is provider compromise as an entry point. In July 2021, the attack on the Kaseya remote management platform spread downstream to affect, according to published estimates, around fifteen hundred organizations that were never the direct target, and a Swedish supermarket chain closed hundreds of stores because its checkout terminals depended on a provider that, in turn, depended on the compromised software.
-
The third is the loss of an operational third party. In March 2022, Toyota suspended production across its fourteen plants in Japan for a day because the target was Kojima Industries, a supplier whose digital connection to the procurement system forced a preventive disconnection. Jaguar Land Rover took that pattern to a larger scale in the autumn of 2025, with several weeks of downtime and an impact that the British Cyber Monitoring Centreestimated at around £1.9 billion, a large portion of which was borne by the more than five thousand organizations affected downstream.
Spain is no exception. INCIBE handled 122,223 incidents during 2025, twenty-six percent more than the previous year, and ransomware reports for the first half of 2026 keep manufacturing among the most targeted sectors worldwide. In almost all documented cases the damage did not stop at the victim’s perimeter, it spread through its dependencies.
A risk without an owner
If the dependency is so real, one might wonder why it remains unmanaged, and the explanation lies in the division of responsibilities. The OT team looks toward the process and its control systems, IT toward corporate systems, and procurement toward pricing and the service level agreement, so that this dependency crosses all three territories without belonging entirely to any of them, and each area reasonably assumes that another is monitoring it. Without an assigned owner, that risk is not reviewed until it materializes.
The second installment will examine what shared responsibility actually covers when the plant stops, what supplier concentration implies, and what sovereignty questions management should be able to answer before signing the next renewal.
Maribel Perozo
Business Development Manager at Aire, member of the Industrial Cybersecurity Center community.