SeriousIT
Manufacturing

The floor doesn't wait
for IT.

Managed IT for Utah manufacturers, from the front office to the machines: ERP and CAD kept running, the shop floor walled off from the internet, and NIST 800-171 and CMMC readiness for shops that hold defense contracts.

A production line inside a modern manufacturing plant
Line 1, running, no unplanned stops
Two tracks

Most shops need the floor to keep running. Some also need to keep the contract.

A plant with no defense work needs uptime, a walled-off machine network, and someone who answers before second shift. A plant with DoD flow-downs needs all of that plus a program an assessor can score. We run both, and we will tell you which one you are.

Plant track: keep it running

Job shops, fabricators, food and consumer producers, anyone without a DFARS clause
  • Machine network isolated from the office, so a phishing click on a laptop cannot reach a controller
  • Patch windows agreed with the plant manager, never mid-shift
  • ERP, CAD, and MES backed up with restores tested on a schedule
  • Vendor remote sessions time-boxed, logged, and shut behind them
  • Shop-floor Wi-Fi that reaches the far bay and survives the forklift
  • A person who answers at 5 a.m. when a line will not start
Secured plan for most plants. The security baseline plus the OT segmentation the floor needs.
If you hold defense work

Defense track: keep the contract

Primes and subs with DFARS 252.204-7012 flow-downs, CUI on site, or a CMMC level in the contract
  • Everything in the plant track
  • A system security plan and plan of action that match the plant, not a template
  • CUI on its own segment with MFA, encryption, and logging an assessor can check
  • SPRS score posted and kept honest
  • Evidence kept for every practice, so the assessment is a review, not a scramble
  • Incident reporting to DIBNet rehearsed, with the clock understood
Hardened plan. The NIST 800-171 program below is the defense track written out.

If you are not sure which track you are on, send us a contract. We will find the clause in ten minutes and tell you what it obligates.

The plant, as we watch it

IT that reads like the line board.

Our work shows up in the same vocabulary the floor uses: what is running, what is planned, what was verified last night, and who is on the network right now.

Nothing happens mid-shift
Updates, firmware, and network changes land in windows the plant manager approves, with a rollback plan for the line.
The machine network is a wall, not a suggestion
Controllers, HMIs, and the machine builder’s remote tool live on their own segment. The office cannot reach them by accident.
Someone answers before first shift
A line that will not start at 5 a.m. gets a person, not a ticket queue.
Plant statuslive
  • Line 1 running HMI patched in last window, controller isolated from office since 05:02
  • Line 2 planned stop Firmware window agreed with the plant manager, rollback staged Sat 02:00
  • ERP backup verified Restore tested by opening last month’s orders on the standby 03:10
  • Vendor remote session scheduled Machine builder, time-boxed, MFA, recorded, closed behind them Tue 15:00
  • CUI enclave isolated Only defense work touches it. Logged, encrypted, scored continuous
  • Shop-floor Wi-Fi 14 handhelds online Separate from office Wi-Fi, reaches the far bay now
Shown as a picture of a week, not a live feed. Clients see the real one.
An open industrial control panel with wiring and modules
Day one

Day one: what we usually find.

An inventory, not a pitch. These are the conditions we walk into at most plants, in the order we find them.

  1. Machines on the office network

    CNC controllers and PLCs running Windows from another decade, reachable from any laptop in the building and, too often, from the internet.

  2. ERP down means the plant is down

    Orders, routing, inventory, and shipping stop together. Nobody has tested restoring the ERP server since it was installed.

  3. A prime asking for your SPRS score

    The contract says NIST 800-171. The self-assessment was guessed at, and there is no system security plan behind the number.

  4. Shared logins at every station

    One account per machine, one password per shift, no way to tell who did what.

  5. CAD files everywhere

    Drawings and customer data on desktops, USB sticks, and a NAS with no backup and no access control.

  6. IT that only knows the office

    The last provider handled email and printers and refused to touch the floor. So nobody did.

AI, done right

AI quoting, CAD copilots, and drawings that must never leave the country.

Estimators feed drawings to AI quoting tools. Engineers use copilots in CAD and paste work instructions into chatbots. Maintenance wants machine data in a predictive model. For most parts that is fine. For a controlled drawing it is an export violation you cannot undo.

Already happening on your network
  • Customer drawings uploaded to AI quoting tools on a free trial
  • Copilots inside CAD and the ERP, switched on by the vendor
  • Work instructions and quality procedures rewritten in a chatbot
  • Machine-monitoring vendors pulling controller data off the floor
Nobody meant to create a risk. They wanted the work done faster. The fix is a short list and a few settings, not a ban.
CUI and ITAR data stay in the enclave

Controlled drawings and specs live on the segment the system security plan describes. AI touches them only when the provider meets the same bar the enclave does.

An approved list for the front office

Quoting, CAD, ERP, and general copilots the shop pays for, each with a rule for what it may see, so estimators do not guess.

Machine data on its own path

Predictive-maintenance and monitoring vendors get a one-way feed from the machine network, never a login to it.

A person signs the quote and the traveler

AI drafts the estimate and the work instruction. An estimator and a quality lead approve them, and the record says who.

Never leaves the building
  • Controlled or export-restricted drawings in any AI tool outside the enclave
  • Customer part files in free chatbots
  • Machine-network logins for monitoring vendors
  • Quality records rewritten without review

For defense work the AI rules are written into the system security plan. For everyone else they are a one-page policy the team can follow.

NIST 800-171 and CMMC readiness

Assessment-ready, with the evidence kept for you.

If you hold or want DoD work, the requirement is NIST SP 800-171 today and CMMC certification as it phases in. We implement the controls, write the system security plan, and keep the evidence, so the assessment is a review, not a rebuild.

Not a defense supplier? The same controls are what keeps a plant running through a ransomware attempt, and what your insurer asks for at renewal.

What a covered shop looks like
What we keep current for a manufacturer with defense work
  • System security plan current current
  • SPRS score posted this quarter current
  • CUI on its own segment enforced current
  • MFA on every login, shop floor included enforced current
  • Machine network isolated from office verified current
  • ERP backup restore test scheduled scheduled
  • Incident response plan rehearsed current
  • Cyber-insurance attestation ready current
Every line is documented and evidence-backed, so when a prime, an assessor, or an insurer asks, the answer is a file, not a scramble.
The assessment year, item by item
A year of the program, item by item. Dots are the months we act; bars run all year.
Gap assessment and SSP

Where you stand against all 110 requirements, the plan of action for the gaps, and the system security plan an assessor expects.

CUI enclave

Controlled unclassified information kept on its own segment with its own access rules, so the rest of the plant stays out of scope.

MFA and access control

Named accounts and multi-factor everywhere, including remote access and the shop floor.

OT network isolation

Machines and controllers on their own network, with only the traffic they need crossing to the office.

Backups with tested restores

Immutable offsite copies of ERP, CAD, and file servers, restore-tested on a schedule.

Detection and response

24/7 monitoring on office and floor systems, with an incident plan that is rehearsed.

Workforce training

At hire and every year, with records, and phishing tests that look like your suppliers.

Evidence and attestation

SPRS submissions, insurer questionnaires, and prime flow-down requests answered with files, not memory.

The systems we live in

Front office to shop floor.

ERP and engineering, the machines and the network they sit on, and the office systems around them.

ERP and engineering
  • ERP such as Epicor, NetSuite, and JobBOSS
  • SolidWorks and Autodesk workstations
  • CAD and drawing file servers with access control
  • Barcode, label, and shipping systems
Shop floor
  • CNC controllers and PLCs on an isolated network
  • Ruggedized floor PCs and scanners
  • Vendor remote support, gated and logged
  • Machines patched in planned windows
Front office
  • Microsoft 365 and identity
  • Frontline plans for floor workers without a desk
  • Plant Wi-Fi with separate guest and machine networks
  • Cameras and door access managed after install

We support the ERP you run and stay vendor-neutral on the floor; the goal is a plant that keeps running and a network that keeps the machines out of reach.

After go-live

What changes for the people in the building.

The front office, the floor lead, and the owner each feel it differently. This is what each of them gets.

Front office

Orders keep moving.

  • ERP up, backed up, and restore-tested.
  • Email and drawings under control instead of on desktops and USB sticks.
  • A new hire working on day one.
Floor lead

Machines run, and nobody touches them by accident.

  • Controllers on their own network with no path to the internet.
  • Vendor remote sessions scheduled and logged, not standing open.
  • Patching in windows you approve, never mid-shift.
Owner

The prime gets a real answer.

  • An SPRS score you can defend, with the plan behind it.
  • The evidence kept for the assessor and the insurer.
  • One bill and one number to call.
Which plan

Defense work lands on Hardened. Most others on Secured.

Same plans as every SeriousIT client. Frontline plans cover shop-floor users who share stations, so you are not paying office rates for people without a desk.

Hardenedmost common
NIST 800-171 and CMMC readiness, the CUI enclave, 24/7 detection and response, log retention, and the evidence for primes and assessors.
Secured
Plants without defense work that want the security baseline: EDR, email security, tested backups, OT isolation, and cyber-insurance readiness.
Managed
Front-office-only coverage for shops that handle the floor themselves. We will tell you if it is enough.
Questions we get

Straight answers.

Can you get us CMMC certified?

We get you assessment-ready and keep the evidence: controls implemented, system security plan written, SPRS score posted. Certification itself comes from an accredited assessor, and we work alongside them through it.

Will you touch the machines?

Yes, carefully. We isolate them, gate vendor remote access, and patch in windows you approve. The goal is never an unplanned stop.

What if our ERP is old and on-prem?

We support it, back it up properly, and test the restore. Modernizing is your call and your timeline.

Do floor workers count as users?

Shared-station and mobile-only workers go on Frontline plans, which are built for exactly that.

Can you work with our machine vendors?

Yes. We coordinate patch windows and remote sessions with them, and log every session.

Do you cover multiple plants?

Yes. Standardized builds per site, one help desk, and evidence rolled up across locations.

An engineer at a machine control panel on the shop floor

Start with a security audit of the whole plant.

Send us your current bills and, if you have one, your last 800-171 self-assessment. We come back with what is exposed, what it would take to fix, and what consolidating would cost.