{"id":125453,"date":"2026-08-26T11:31:45","date_gmt":"2026-08-26T10:31:45","guid":{"rendered":"https:\/\/www.realvnc.com\/?post_type=blog&#038;p=125453"},"modified":"2026-08-31T11:03:41","modified_gmt":"2026-08-31T10:03:41","slug":"ransomware-prevention-in-manufacturing","status":"publish","type":"blog","link":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/","title":{"rendered":"Ransomware Prevention in Manufacturing: Strategic Priorities"},"content":{"rendered":"<p>A production line pauses, shipments slip, and customers start asking for answers before IT knows which systems are safe to reconnect. Plant operations, procurement, finance, and supplier teams all feel the disruption at once.<\/p>\n<p><strong>Ransomware prevention in manufacturing means reducing the routes attackers use to enter and limiting their ability to move between business and production systems. It includes restoring core operations through tested recovery plans. It requires shared decision rights across IT, operational technology (OT), engineering, plant leadership, and suppliers, so containment protects both uptime and safe operations.<\/strong><\/p>\n<p>The challenge grows where office networks connect with OT &#8211; the hardware and software that runs industrial processes. Older equipment may require planned maintenance windows, and engineering workstations, remote-support connections, and supplier access create routes that need clear ownership. Think of network segmentation as fire doors in a factory: a problem in one area must stay contained rather than reach every production zone.<\/p>\n<p>A perimeter control alone does not answer the questions leaders face during an incident. Who can isolate a zone? Which systems must return first? Which supplier needs to be contacted, and who approves remote access during the investigation? Those decisions need to be agreed before production is under pressure.<\/p>\n<p>This article sets out a practical leadership model for mapping operational dependencies, governing access routes, separating critical network zones, and testing restoration order. The article explains how to sequence prevention investments, define IT\u2013OT accountability, and avoid the planning gaps that turn a technical incident into a prolonged production interruption.<\/p>\n<h2 id=\"why-is-manufacturing-ransomware-a-continuity-issue\">Why Is Manufacturing Ransomware a Continuity Issue?<\/h2>\n<p>A plant\u2019s resilience is tested when a digital incident forces physical operating decisions. <strong>Ransomware prevention in manufacturing<\/strong> must protect the systems that schedule work, move materials, record quality data, and coordinate suppliers; disruption in any one of them can delay the whole production chain.<\/p>\n<p>The business effect reaches beyond IT. Plant leaders may need to slow production, procurement may need to contact suppliers, and customer teams may need to explain missed commitments before incident responders know which systems are safe to reconnect. The <a href=\"https:\/\/www.weforum.org\/stories\/2024\/06\/manufacturers-face-cyber-threats-cyber-resilience-culture\/\">World Economic Forum<\/a> reported in 2024 that manufacturing accounted for 25.7% of cited cyber incidents, with ransomware involved in 71% of them.<\/p>\n<p>This is why decision rights matter. IT owns many enterprise controls, but operational technology (OT) &#8211; the hardware and software that runs industrial processes &#8211; has safety, uptime, and engineering constraints that plant teams understand best. Procurement needs a role where suppliers, original equipment manufacturers, and support providers hold remote access or data connections.<\/p>\n<p>The operational effect is concrete. Sensata Technologies disclosed that a ransomware event disrupted shipping, receiving, and manufacturing production after devices were encrypted, as reported by <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/sensor-rich-technology-giant-sensata-suffers-a-ransomware-attack-that-disrupted-various-operations\/\">CPO Magazine<\/a> in 2025. A continuity plan needs shared authority for containment, supplier communication, and safe recovery sequencing.<\/p>\n<h2 id=\"why-is-ransomware-prevention-in-manufacturing-urgent\">Why Is Ransomware Prevention in Manufacturing Urgent?<\/h2>\n<p>Manufacturers need a prevention program that reduces entry routes, controls movement between systems, and preserves a tested route back to operations. The work joins security controls with production governance, so containment decisions do not create unsafe or unplanned plant consequences.<\/p>\n<p>The scale of reported activity reinforces that urgency. <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/the-state-of-ransomware-in-manufacturing-and-production-2024\">Sophos<\/a> reported in 2024 that 65% of manufacturing and production organizations had experienced ransomware in the prior 12 months. Robert M. Lee, CEO and Founder of Dragos, <a href=\"https:\/\/www.sdxcentral.com\/articles\/analysis\/dragos-warns-of-rising-ransomware-inaccurate-vulnerability-advisories\/2024\/02\/\">told SDxCentral<\/a>: \u201cThe ransomware problem is not under control nor a \u2018falling off.\u2019\u201d<\/p>\n<p>A perimeter firewall and antivirus product remain useful controls, but they do not answer the full factory question: who can reach an engineering workstation, what that workstation can reach, and how the plant operates during zone isolation. Prevention needs visibility, identity governance, segmented communications, and recovery exercises that plant leadership has accepted.<\/p>\n<h3 id=\"which-forces-raise-factory-ransomware-risk\">Which Forces Raise Factory Ransomware Risk?<\/h3>\n<p>Manufacturing combines low tolerance for interruption with connected systems that were often built for availability rather than modern security oversight. <a href=\"https:\/\/www.ibm.com\/thought-leadership\/institute-business-value\/report\/2025-threat-intelligence-index\">IBM\u2019s X-Force Threat Intelligence Index 2025<\/a> placed manufacturing first among targeted industries for a fourth consecutive year, representing 26% of covered incidents.<\/p>\n<ul>\n<li><strong>Downtime pressure:<\/strong> A stalled line affects output, shipments, and supplier schedules, which raises the business pressure around containment decisions.<\/li>\n<li><strong>Connected production:<\/strong> IT-OT convergence links office systems with production support, so access governance must cover both sides of the connection.<\/li>\n<li><strong>Legacy constraints:<\/strong> Older controllers and engineering systems may need carefully scheduled updates, compensating controls, and documented support ownership.<\/li>\n<li><strong>Third-party pathways:<\/strong> Supplier and maintenance access requires defined identity, approval, and session-accountability rules.<\/li>\n<\/ul>\n<p>Think of the shared IT-OT environment as a loading dock with several doors into the same facility. If one connected route is compromised and movement is uncontrolled, the issue can reach areas that were never the initial target. Plant-specific governance decides which doors stay open, who approves them, and when they close.<\/p>\n<table>\n<thead>\n<tr>\n<th>Legacy Assumption<\/th>\n<th>Manufacturing Consequence<\/th>\n<th>Modern Governance Response<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Perimeter security defines the boundary<\/td>\n<td>Connected support paths bypass the assumed boundary<\/td>\n<td>Map every approved route into plant-support systems<\/td>\n<\/tr>\n<tr>\n<td>IT can isolate systems alone<\/td>\n<td>Isolation may interrupt accepted production dependencies<\/td>\n<td>Preapprove isolation authority with OT and plant leaders<\/td>\n<\/tr>\n<tr>\n<td>Backups prove readiness<\/td>\n<td>Recovery dependencies remain unknown until an incident<\/td>\n<td>Test restoration order, access, and operating procedures<\/td>\n<\/tr>\n<tr>\n<td>Vendor access is routine administration<\/td>\n<td>Standing credentials widen supplier-related risk<\/td>\n<td>Apply least privilege and time-bound access rules<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"which-model-contains-an-it-ot-ransomware-event\">Which Model Contains an IT-OT Ransomware Event?<\/h2>\n<p><img decoding=\"async\" src=\"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img3__KEYWORD_DISTRIBUTION_PLAN__1787650143109.jpg)\" alt=\"\"><\/p>\n<p>A workable containment model gives executives four decisions: <strong>Govern, Map, Contain, Recover<\/strong>. It connects enterprise oversight to plant realities, so leaders know who accepts operational trade-offs, which assets matter first, how zones are isolated, and what must be restored before production resumes.<\/p>\n<p>NIST Cybersecurity Framework (CSF) 2.0 gives organizations a common language for outcomes. The IEC 62443 zone-conduit model translates risk tolerance into communication boundaries between enterprise, plant, and safety-relevant environments. <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/02\/nist-releases-version-20-landmark-cybersecurity-framework\">NIST<\/a> states that CSF 2.0 organizes its core around Govern, Identify, Protect, Detect, Respond, and Recover. The two frameworks serve different decisions and work best together.<\/p>\n<p>The operating context remains demanding. <a href=\"https:\/\/www.dragos.com\/resources\/press-release\/dragos-ot-cybersecurity-year-in-review-reports-rise-in-geopolitically-driven-attacks-ransomware-and-threat-groups\">Dragos<\/a> reported in 2024 that ransomware remained the leading industrial-sector incident type and had risen 50% from 2022. That trend makes clear ownership and rehearsed recovery more valuable than a document that sits unused.<\/p>\n<ul>\n<li><strong>Govern:<\/strong> Assign decision rights for risk acceptance, isolation, supplier access, and production restart.<\/li>\n<li><strong>Map:<\/strong> Identify assets, dependencies, owners, support status, and recovery priorities.<\/li>\n<li><strong>Contain:<\/strong> Define approved zone boundaries and the authority to isolate communications.<\/li>\n<li><strong>Recover:<\/strong> Validate clean recovery copies, restoration order, and degraded operating procedures.<\/li>\n<\/ul>\n<table>\n<thead>\n<tr>\n<th>Framework Dimension<\/th>\n<th>Executive Decision<\/th>\n<th>Operational Evidence<\/th>\n<th>Related NIST CSF 2.0 Function<\/th>\n<th>Common Misread<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Govern<\/td>\n<td>Who accepts production-risk trade-offs?<\/td>\n<td>Named owners and escalation authority<\/td>\n<td>Govern<\/td>\n<td>Security owns every operating decision<\/td>\n<\/tr>\n<tr>\n<td>Map<\/td>\n<td>Which systems require priority recovery?<\/td>\n<td>Asset, dependency, and criticality records<\/td>\n<td>Identify<\/td>\n<td>An enterprise inventory captures plant assets<\/td>\n<\/tr>\n<tr>\n<td>Contain<\/td>\n<td>Which paths can be isolated safely?<\/td>\n<td>Approved zone and conduit rules<\/td>\n<td>Protect, Detect, Respond<\/td>\n<td>Segmentation means blocking all traffic<\/td>\n<\/tr>\n<tr>\n<td>Recover<\/td>\n<td>What proves a safe restart?<\/td>\n<td>Restoration tests and accepted procedures<\/td>\n<td>Recover<\/td>\n<td>A completed backup equals recovery readiness<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 id=\"govern-and-map-the-production-risk-surface\">Govern and Map the Production Risk Surface<\/h3>\n<p>Governance begins with an asset and dependency record that plant teams recognize as accurate. <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators\">CISA<\/a> advised OT owners in 2024 to build that understanding through physical inspection and logical survey before managing cyber risk. A configuration management database is useful, but it must be reconciled with engineering knowledge of what each asset actually supports.<\/p>\n<p>Leaders need a short, maintained checklist:<\/p>\n<ul>\n<li><strong>Asset owner:<\/strong> Who approves maintenance, isolation, and restart?<\/li>\n<li><strong>Production dependency:<\/strong> Which line, process, or quality record depends on it?<\/li>\n<li><strong>Support status:<\/strong> Is the system supported, monitored, and patchable?<\/li>\n<li><strong>Recovery priority:<\/strong> What must be available before safe operations resume?<\/li>\n<\/ul>\n<p>This record turns an incident call from guesswork into a sequence of accountable choices.<\/p>\n<h3 id=\"contain-and-recover-without-unsafe-shortcuts\">Contain and Recover Without Unsafe Shortcuts<\/h3>\n<p>Containment means controlling defined communications without losing sight of safe operating conditions. Daniel dos Santos, Head of Security Research at Forescout, <a href=\"https:\/\/ifsecindia.com\/Post.aspx?Id=39865\">said in IFSEC Insider<\/a>: \u201cUnsecure OT L1 devices often become the target of cyber attackers through deep lateral movement.\u201d Zone-conduit rules must identify the approved paths that remain necessary for plant operations and the paths that must close immediately.<\/p>\n<p>On a flat network, a compromised support workstation may reach systems far beyond its intended role. With preapproved isolation decisions, incident leaders can close a defined zone, retain evidence, and begin recovery from known dependencies. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/newpark-resources-hit-by-ransomware-activates-cybersecurity-response\/\">Industrial Cyber<\/a> reported in 2024 that Newpark Resources continued manufacturing and field operations in all material respects through downtime procedures amid disruption to internal systems and applications. Tested degraded procedures give leadership an operating option during recovery.<\/p>\n<h2 id=\"which-controls-reduce-manufacturing-ransomware-exposure\">Which Controls Reduce Manufacturing Ransomware Exposure?<\/h2>\n<p>Control investment should be judged by whether it reduces a real attack path, preserves safe operations, and produces evidence that leadership can review. <strong>Ransomware prevention in manufacturing<\/strong> depends on connected controls: each one must improve prevention, containment, detection, or recoverability without encouraging unsafe workarounds.<\/p>\n<p>Product selection needs an OT lens. The <a href=\"https:\/\/www.nsa.gov\/Press-Room\/Press-Releases-Statements\/Press-Release-View\/Article\/4027075\/nsa-and-others-publish-guidance-for-secure-ot-product-selection\/\">NSA\u2019s Secure OT Product Selection guidance<\/a> identified secure-by-default design, logging, secure communications, strong authentication, vulnerability handling, and upgrade tooling as evaluation criteria in 2025. The point is not to collect features. It is to establish whether a control produces an operationally usable result.<\/p>\n<ol>\n<li><strong>OT asset and dependency inventory:<\/strong> Maintain a living record of controllers, human-machine interfaces, engineering workstations, remote routes, support status, and production dependencies. It supports prioritization when maintenance windows or incident decisions compete.<\/li>\n<li><strong>Zone-conduit segmentation:<\/strong> Restrict lateral movement and preserve approved production communications. Over-segmentation that drives engineers to bypass formal routes is a governance failure.<\/li>\n<li><strong>Identity and privileged access:<\/strong> Require multi-factor authentication (MFA), least privilege, separate administrative roles, and controlled third-party access. Shared engineering credentials remove individual accountability.<\/li>\n<li><strong>Detection and patch-risk management:<\/strong> Use OT-aware telemetry and prioritize vulnerabilities by operational criticality. Patch counts alone do not show whether the most consequential routes have been addressed.<\/li>\n<li><strong>Immutable recovery and manual fallback:<\/strong> Maintain isolated recovery copies, test clean builds, and accept documented downtime procedures. Backup completion rates without restoration testing create false assurance.<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>Control Domain<\/th>\n<th>Leadership Signal<\/th>\n<th>Decision Supported<\/th>\n<th>Common Error<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Asset inventory<\/td>\n<td>Owners and dependencies are current<\/td>\n<td>Recovery and maintenance priority<\/td>\n<td>Treating discovery as a one-time project<\/td>\n<\/tr>\n<tr>\n<td>Segmentation<\/td>\n<td>Approved communications are documented<\/td>\n<td>Isolation authority<\/td>\n<td>Blocking traffic without plant review<\/td>\n<\/tr>\n<tr>\n<td>Identity governance<\/td>\n<td>Privileged users are individually accountable<\/td>\n<td>Access approval<\/td>\n<td>Sharing engineering accounts<\/td>\n<\/tr>\n<tr>\n<td>Detection and patching<\/td>\n<td>Findings are ranked by service criticality<\/td>\n<td>Maintenance-window allocation<\/td>\n<td>Measuring only patch volume<\/td>\n<\/tr>\n<tr>\n<td>Recovery readiness<\/td>\n<td>Restores work under realistic conditions<\/td>\n<td>Restart approval<\/td>\n<td>Assuming backup existence proves readiness<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Bassett Furniture disclosed that data files were encrypted and its manufacturing facilities were not operating during containment, according to <a href=\"https:\/\/therecord.media\/furniture-giant-manufacturing-shut-down-cyberattack\">The Record<\/a> in 2024. That example shows why executives must approve containment and operating procedures before the pressure of an event.<\/p>\n<h2 id=\"how-should-leaders-sequence-prevention-investments\">How Should Leaders Sequence Prevention Investments?<\/h2>\n<p>The right investment order depends on service criticality, existing staff capacity, and customer or regulatory obligations. A multi-site manufacturer with a mature security operations center starts in a different place from a mid-market plant with limited OT security staff, yet both need accountable owners and a clear view of their most consequential routes.<\/p>\n<p>Start with known weaknesses that create immediate operating uncertainty, then build toward broader modernization. <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.1305.pdf\">NIST SP 1305<\/a> describes cybersecurity supply-chain risk management as a systematic process spanning response strategies, policies, processes, and procedures. Supplier governance belongs in the same investment plan as internal controls.<\/p>\n<ol>\n<li><strong>Establish ownership before technology expansion:<\/strong> Define decision rights across IT, OT, engineering, procurement, legal, and plant management.<\/li>\n<li><strong>Prioritize known access routes:<\/strong> Address unmanaged assets, shared credentials, unsupported systems, and uncontrolled vendor connections before wider programs.<\/li>\n<li><strong>Fund recoverability alongside prevention:<\/strong> Resource restoration exercises, manual procedures, communications plans, and alternate operating modes.<\/li>\n<li><strong>Govern suppliers as part of the risk surface:<\/strong> Set access terms, identity requirements, logging expectations, and incident-notification responsibilities for OEMs, integrators, and managed providers.<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>Starting Condition<\/th>\n<th>First Investment Focus<\/th>\n<th>Implication<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Multi-site enterprise with a mature SOC<\/td>\n<td>Reconcile central visibility with plant dependencies<\/td>\n<td>Enterprise monitoring needs local operating context<\/td>\n<\/tr>\n<tr>\n<td>Mid-market manufacturer with limited OT staff<\/td>\n<td>Establish inventory, ownership, and controlled remote access<\/td>\n<td>Focus resources on the routes most likely to affect production<\/td>\n<\/tr>\n<tr>\n<td>Regulated supplier<\/td>\n<td>Map customer obligations to system owners and evidence<\/td>\n<td>Contractual duties shape priority and documentation<\/td>\n<\/tr>\n<tr>\n<td>Plant with aging equipment<\/td>\n<td>Document support limits and compensating controls<\/td>\n<td>Modernization must follow safe maintenance planning<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>For remote support, the <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-06\/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf\">CISA, NSA, FBI, MS-ISAC, and Israel National Cyber Directorate guidance<\/a> recommends zero-trust or least-privilege configurations that may be endpoint- or identity-based. That principle gives leaders a practical purchasing test: access must be limited to a named purpose, a named user, and a defined period.<\/p>\n<h2 id=\"where-do-ransomware-plans-fail-before-recovery\">Where Do Ransomware Plans Fail Before Recovery?<\/h2>\n<p><img decoding=\"async\" src=\"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img6_Section_2_1787650217711.jpg)\" alt=\"\"><\/p>\n<p>Most recovery failures begin before anyone restores a system. They start with unknown dependencies, undocumented access routes, or escalation plans that treat production leadership as an afterthought. A response playbook must define operational authority as clearly as technical tasks.<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/simpson-manufacturing-shuts-down-it-systems-after-cyberattack\/\">Simpson Manufacturing<\/a> disclosed in 2023 that a cyberattack caused IT and application outages, disrupted operations, and led the company to shut down IT systems during response. That containment pressure is familiar: leaders need enough information to act quickly without reconnecting systems before dependencies and evidence are understood.<\/p>\n<ul>\n<li><strong>Unknown dependencies:<\/strong> A clean recovery copy is insufficient when licensing, engineering tools, network prerequisites, and recovery order remain unclear.<\/li>\n<li><strong>Unapproved emergency access:<\/strong> Expedient remote sessions can weaken accountability and complicate evidence review during containment.<\/li>\n<li><strong>Untested recovery assumptions:<\/strong> Backup existence differs from restoration capability, recovery-time performance, and safe restart procedures.<\/li>\n<li><strong>IT-only escalation paths:<\/strong> Plant leadership needs predefined authority for production slowdown, isolation, and manual operations.<\/li>\n<li><strong>Supplier blind spots:<\/strong> OEMs, integrators, maintenance providers, and managed service providers need governed access and notification duties.<\/li>\n<\/ul>\n<table>\n<thead>\n<tr>\n<th>Failure Pattern<\/th>\n<th>Governance Correction<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Incomplete asset ownership<\/td>\n<td>Assign accountable owners and validate records with plant teams<\/td>\n<\/tr>\n<tr>\n<td>Flat or undocumented dependencies<\/td>\n<td>Maintain zone maps and recovery sequencing evidence<\/td>\n<\/tr>\n<tr>\n<td>Untested backups<\/td>\n<td>Run restoration exercises under realistic operating conditions<\/td>\n<\/tr>\n<tr>\n<td>Ungoverned remote sessions<\/td>\n<td>Require named approval, least privilege, and reviewable records<\/td>\n<\/tr>\n<tr>\n<td>Missing plant authority<\/td>\n<td>Define isolation and restart decision rights in advance<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>A sound exercise tests decisions and technology. Leadership should ask whether the right people can identify the affected zone, approve a safe operating mode, contact dependent suppliers, and explain the restart conditions without relying on informal knowledge.<\/p>\n<h2 id=\"how-realvnc-closes-the-manufacturing-ransomware-gap\">How RealVNC Closes the Manufacturing Ransomware Gap<\/h2>\n<p>The remote-access gap often appears during routine maintenance, supplier support, or an incident when teams need fast access to production-support systems but cannot accept standing credentials or unclear accountability. Asset records, segmentation rules, supplier governance, and incident evidence all depend on knowing who connected, why they connected, and what permissions they received.<\/p>\n<p>RealVNC Connect supports controlled remote-support workflows through access controls that align with least-privilege principles. This approach reflects the <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-06\/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf\">CISA partner guidance<\/a> on identity- or endpoint-based zero-trust configurations for remote-access software.<\/p>\n<ul>\n<li><strong>Multi-factor authentication and single sign-on (SSO) with Microsoft Entra ID or Okta:<\/strong> Strengthens identity assurance for internal support teams and approved external users.<\/li>\n<li><strong>Role-based access controls with granular action-based permissions:<\/strong> Separates keyboard, mouse, and file-transfer permissions, supporting access that matches a defined support task.<\/li>\n<li><strong>Session monitoring, recording, and detailed audit logs:<\/strong> Creates reviewable evidence for privileged support, supplier sessions, and incident investigation.<\/li>\n<\/ul>\n<p>These controls do not replace segmentation, detection, recovery copies, or incident management. They govern one important route into the environment: the remote session used by IT, engineers, OEMs, or third parties. The <a href=\"https:\/\/www.nsa.gov\/Press-Room\/Press-Releases-Statements\/Press-Release-View\/Article\/4027075\/nsa-and-others-publish-guidance-for-secure-ot-product-selection\/\">NSA guidance<\/a> identifies strong authentication and logging among relevant OT product-selection criteria, which makes controlled session evidence part of a defensible access model.<\/p>\n<p>For manufacturing leaders, the outcome is clearer operational accountability during normal support and containment. RealVNC Connect helps teams apply controlled, auditable remote access within a broader manufacturing ransomware-resilience program, so remote assistance remains governed when the operating environment is under pressure.<\/p>\n<h2 id=\"final-words\">Final Words<\/h2>\n<p>Ransomware prevention in manufacturing works when leaders treat a cyber event as a production-continuity decision from the start. Assign decision rights across IT, OT, plant operations, and suppliers; map the systems and dependencies that keep production moving; define how network zones are isolated; and test the restoration order before an incident forces rushed choices. That approach turns containment from a technical scramble into a managed operating response, with clear authority for safe slowdown, supplier communication, and restart.<\/p>\n<p>Controlled remote access belongs inside that discipline. RealVNC Connect supports identity-led support workflows through multi-factor authentication (MFA) and single sign-on (SSO), role-based access controls with granular session permissions, and session monitoring, recording, and detailed audit logs. Those controls give your teams a clearer record of who entered a production-support environment, why they connected, and what they were allowed to do, alongside segmentation, recovery testing, and incident governance. Leaving these decisions informal creates uncertainty when uptime and evidence matter most. Arrange a meeting to discuss how RealVNC Connect can support controlled, auditable remote access within your manufacturing ransomware-resilience program.<\/p>\n<h2 id=\"faqs\">FAQs<\/h2>\n<p>These answers clarify the governance model, standards, control priorities, and controlled-access decisions behind manufacturing ransomware resilience.<\/p>\n<h3 id=\"what-is-the-ransomware-resilience-model-for-factories\">What Is the Ransomware-Resilience Model for Factories?<\/h3>\n<p>Ransomware prevention in manufacturing is best organized through four decisions: Govern, Map, Contain, and Recover. Governance assigns authority across IT, operational technology (OT), engineering, and plant leadership; mapping records assets and dependencies; containment defines safe isolation; and recovery validates restoration order and operating procedures. <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators\">CISA\u2019s OT asset-inventory guidance<\/a> (2024) supports asset and dependency discovery as an early risk-management foundation.<\/p>\n<h3 id=\"how-do-nist-csf-and-iec-62443-differ\">How Do NIST CSF and IEC 62443 Differ?<\/h3>\n<p>NIST Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. IEC 62443 adds OT-focused architectural thinking, including zones and conduits that separate systems and control approved communications. Use NIST CSF 2.0 for enterprise governance and outcome tracking, then apply IEC 62443 concepts when translating those decisions into plant-network design; neither replaces risk assessment or recovery rehearsal. <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/02\/nist-releases-version-20-landmark-cybersecurity-framework\">NIST<\/a> (2024) describes the CSF 2.0 functions.<\/p>\n<h3 id=\"what-should-a-manufacturing-ransomware-prevention-checklist-include\">What Should a Manufacturing Ransomware Prevention Checklist Include?<\/h3>\n<p>A useful checklist covers asset ownership, production dependencies, controlled access, network separation, recovery testing, and supplier responsibilities. It must record who approves isolation, which systems return first, and how plant teams operate during a degraded mode. A checklist becomes decision evidence only when owners review it against physical and logical conditions in the plant.<\/p>\n<h3 id=\"which-industry-has-the-most-ransomware-attacks\">Which Industry Has the Most Ransomware Attacks?<\/h3>\n<p>Manufacturing ranked as the most targeted industry in IBM X-Force\u2019s covered incidents for the fourth consecutive year, representing 26% of those incidents in its 2025 index. That ranking reflects the sector\u2019s connected production systems and the business pressure created by operational interruption. It does not mean every manufacturer faces the same route or level of exposure; leaders still need site-specific asset, access, and dependency analysis. (<a href=\"https:\/\/www.ibm.com\/thought-leadership\/institute-business-value\/report\/2025-threat-intelligence-index\">IBM X-Force Threat Intelligence Index 2025<\/a>, 2025.)<\/p>\n<h3 id=\"what-does-the-cisa-guide-recommend-for-remote-access\">What Does the CISA Guide Recommend for Remote Access?<\/h3>\n<p>The CISA, NSA, FBI, MS-ISAC, and Israel National Cyber Directorate guide recommends zero-trust or least-privilege configurations for remote-access software where appropriate. In practice, manufacturers need named identities, defined permissions, and access that matches a specific support purpose rather than relying on broad standing access. The guidance provides a policy benchmark; plant leaders still need to align remote support with OT dependencies and incident authority. (<a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-06\/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf\">Guide to Securing Remote Access Software<\/a>, 2023.)<\/p>\n<h3 id=\"how-does-realvnc-support-controlled-factory-access\">How Does RealVNC Support Controlled Factory Access?<\/h3>\n<p>RealVNC Connect supports controlled remote support through multi-factor authentication (MFA) and single sign-on (SSO), role-based access controls with granular permissions, and session monitoring, recording, and detailed audit logs. These features help govern internal support and approved third-party sessions by strengthening identity checks, limiting session actions, and creating reviewable evidence. They form one access-governance layer within a broader program that still requires segmentation, detection, recovery testing, and incident response.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations &#8211; before the next incident.<\/p>\n","protected":false},"author":37,"featured_media":125449,"template":"","blog_category":[271],"class_list":["post-125453","blog","type-blog","status-publish","has-post-thumbnail","hentry","blog_category-manufacturing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.7 (Yoast SEO v28.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Ransomware Prevention in Manufacturing: Strategic Priorities<\/title>\n<meta name=\"description\" content=\"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ransomware Prevention in Manufacturing: Strategic Priorities\" \/>\n<meta property=\"og:description\" content=\"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/\" \/>\n<meta property=\"og:site_name\" content=\"RealVNC\u00ae\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/realvnc\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-31T10:03:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@realvnc\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/\"},\"author\":{\"name\":\"Justin Wagg\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#\\\/schema\\\/person\\\/3f67130a14b477ffe49c5620c9d48054\"},\"headline\":\"Ransomware Prevention in Manufacturing: Strategic Priorities\",\"datePublished\":\"2026-08-26T10:31:45+00:00\",\"dateModified\":\"2026-08-31T10:03:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/\"},\"wordCount\":3164,\"publisher\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/nanobana_img0_Hero_Image_1787650060776.jpg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/\",\"url\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/\",\"name\":\"Ransomware Prevention in Manufacturing: Strategic Priorities\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/nanobana_img0_Hero_Image_1787650060776.jpg\",\"datePublished\":\"2026-08-26T10:31:45+00:00\",\"dateModified\":\"2026-08-31T10:03:41+00:00\",\"description\":\"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/nanobana_img0_Hero_Image_1787650060776.jpg\",\"contentUrl\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/nanobana_img0_Hero_Image_1787650060776.jpg\",\"width\":1376,\"height\":768},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/ransomware-prevention-in-manufacturing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blogs\",\"item\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Ransomware Prevention in Manufacturing: Strategic Priorities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/\",\"name\":\"RealVNC\u00ae\",\"description\":\"The world&#039;s safest remote access software\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#organization\",\"name\":\"RealVNC\u00ae\",\"url\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/realvnc-logo-blue.png\",\"contentUrl\":\"https:\\\/\\\/www.realvnc.com\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/realvnc-logo-blue.png\",\"width\":300,\"height\":41,\"caption\":\"RealVNC\u00ae\"},\"image\":{\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/realvnc\",\"https:\\\/\\\/x.com\\\/realvnc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/realvnc\\\/\",\"https:\\\/\\\/www.youtube.com\\\/RealVNCLtd\",\"https:\\\/\\\/en.wikipedia.org\\\/wiki\\\/RealVNC\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.realvnc.com\\\/en\\\/#\\\/schema\\\/person\\\/3f67130a14b477ffe49c5620c9d48054\",\"name\":\"Justin Wagg\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g\",\"caption\":\"Justin Wagg\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Ransomware Prevention in Manufacturing: Strategic Priorities","description":"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/","og_locale":"en_US","og_type":"article","og_title":"Ransomware Prevention in Manufacturing: Strategic Priorities","og_description":"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.","og_url":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/","og_site_name":"RealVNC\u00ae","article_publisher":"https:\/\/www.facebook.com\/realvnc","article_modified_time":"2026-08-31T10:03:41+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@realvnc","twitter_misc":{"Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#article","isPartOf":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/"},"author":{"name":"Justin Wagg","@id":"https:\/\/www.realvnc.com\/en\/#\/schema\/person\/3f67130a14b477ffe49c5620c9d48054"},"headline":"Ransomware Prevention in Manufacturing: Strategic Priorities","datePublished":"2026-08-26T10:31:45+00:00","dateModified":"2026-08-31T10:03:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/"},"wordCount":3164,"publisher":{"@id":"https:\/\/www.realvnc.com\/en\/#organization"},"image":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/","url":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/","name":"Ransomware Prevention in Manufacturing: Strategic Priorities","isPartOf":{"@id":"https:\/\/www.realvnc.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#primaryimage"},"image":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg","datePublished":"2026-08-26T10:31:45+00:00","dateModified":"2026-08-31T10:03:41+00:00","description":"Ransomware prevention in manufacturing starts before production stops. Learn how leaders secure IT\u2013OT access, contain disruption, and restore critical operations - before the next incident.","breadcrumb":{"@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#primaryimage","url":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg","contentUrl":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2026\/08\/nanobana_img0_Hero_Image_1787650060776.jpg","width":1376,"height":768},{"@type":"BreadcrumbList","@id":"https:\/\/www.realvnc.com\/en\/blog\/ransomware-prevention-in-manufacturing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.realvnc.com\/en\/"},{"@type":"ListItem","position":2,"name":"Blogs","item":"https:\/\/www.realvnc.com\/en\/blog\/"},{"@type":"ListItem","position":3,"name":"Ransomware Prevention in Manufacturing: Strategic Priorities"}]},{"@type":"WebSite","@id":"https:\/\/www.realvnc.com\/en\/#website","url":"https:\/\/www.realvnc.com\/en\/","name":"RealVNC\u00ae","description":"The world&#039;s safest remote access software","publisher":{"@id":"https:\/\/www.realvnc.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.realvnc.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.realvnc.com\/en\/#organization","name":"RealVNC\u00ae","url":"https:\/\/www.realvnc.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.realvnc.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2023\/05\/realvnc-logo-blue.png","contentUrl":"https:\/\/www.realvnc.com\/wp-content\/uploads\/2023\/05\/realvnc-logo-blue.png","width":300,"height":41,"caption":"RealVNC\u00ae"},"image":{"@id":"https:\/\/www.realvnc.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/realvnc","https:\/\/x.com\/realvnc","https:\/\/www.linkedin.com\/company\/realvnc\/","https:\/\/www.youtube.com\/RealVNCLtd","https:\/\/en.wikipedia.org\/wiki\/RealVNC"]},{"@type":"Person","@id":"https:\/\/www.realvnc.com\/en\/#\/schema\/person\/3f67130a14b477ffe49c5620c9d48054","name":"Justin Wagg","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4dd2423f302b220584d64141b3ab826e1007708b1030b66127a8c66247ae583?s=96&d=mm&r=g","caption":"Justin Wagg"}}]}},"_links":{"self":[{"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/blog\/125453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/users\/37"}],"version-history":[{"count":1,"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/blog\/125453\/revisions"}],"predecessor-version":[{"id":125831,"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/blog\/125453\/revisions\/125831"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/media\/125449"}],"wp:attachment":[{"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/media?parent=125453"}],"wp:term":[{"taxonomy":"blog_category","embeddable":true,"href":"https:\/\/www.realvnc.com\/en\/wp-json\/wp\/v2\/blog_category?post=125453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}