Office Network vs. Shop Floor: IT for a Small Rhode Island Manufacturer

In most small manufacturing shops I walk into for the first time, the office side is in reasonable shape. Modern enough computers, a real firewall, someone gave it thought at some point. The shop floor is a different story, and not because anyone was careless. It grew.

Old switches in a panel nobody opens. Unmanaged devices. Networking gear a machine vendor brought with him during an install and left behind. Cable runs added one at a time as equipment came in. The result is a network nobody designed and usually nobody can fully diagram.

Underneath all of it is the same mistake, over and over: the whole building is treated as one flat network. Office computers, printers, cameras, guest Wi-Fi, and production equipment can all see far too much of each other.

Why Rhode Island shops end up this way

Rhode Island manufacturing is old and it is small. A lot of it sits in mill buildings in Pawtucket, Woonsocket, Central Falls, and parts of Cranston, in shops that have been in the same family and often the same footprint for decades. Jewelry, metal, plastics, marine work. Equipment gets added and kept running rather than swapped on a refresh cycle, and the network follows the same pattern. It is a series of additions, not a design.

There is a second local factor that matters more than people expect. Machine vendors are usually out of state. When a controller will not boot or a machine drops off the network mid-run, remote support only goes so far. At some point somebody has to stand in front of it. That is a practical argument for IT that can be in your building the same morning instead of dispatching from Boston or waiting on a vendor travel schedule. In a shop, downtime is measured in production, not in tickets.

The risk is not really the data. It is the line stopping.

Most security advice written for small businesses is about protecting information. For a manufacturer that framing is incomplete. If the office takes a hit and production keeps running, you have a bad week. If production stops, you have missed ship dates, idle people, and customers who need an answer you do not have yet.

That is why a flat network matters more in a shop than in a typical office. A compromised office computer should not automatically have a path to a CNC machine or another production system. On a flat network, it does.

"It has worked this way for 15 years"

That is the pushback I get most, and it is a fair thing to say. My answer is that the network did not change, the risk did. Fifteen years ago ransomware was not built to spread laterally on its own the moment it lands. Vendors were not routinely remoting in over the internet to service equipment. The setup that was a reasonable bet then is a different bet now, and the shop is carrying the difference without having agreed to it.

The machine that cannot be patched

Nearly every shop has one: a system stuck on an old version of Windows because the equipment vendor will not support anything newer. Telling the owner to buy a new machine is not advice, it is a wish. What I actually recommend is managing the risk around it.

  • Isolate it so it can only talk to what it genuinely needs to talk to.
  • Limit or remove its internet access.
  • Restrict what is allowed to connect to it, including vendor access.
  • Back it up, and confirm the backup covers the machine configuration and not just files.
  • Document exactly why it exists and what is holding it back.

That last one gets skipped and it matters. Write down why the machine is on an old OS, which vendor and which software version is the constraint, and revisit it. Otherwise three years from now the answer to "why is that thing still running Windows 7" is a shrug, and nobody notices when the vendor finally does support something newer.

Replacement may eventually be the answer. But you can make an old system a great deal safer without pretending it can be patched like a normal office PC.

A 20-person shop still needs segmentation

People assume network segmentation is an enterprise concern and a 20-person company has no business doing it. For a manufacturer I disagree. Headcount is not the variable that matters. Device types are.

If you have office computers, production equipment, security cameras, guest Wi-Fi, printers, and vendor-connected machines all in one building, there is a good reason those things should not live together, and it has nothing to do with how many people are on payroll. A few well-planned VLANs reduce risk substantially without making the network hard to manage. This is not a complicated design exercise, and it should not become one.

What I would change first

When a shop asks me where to start, the first step is not a purchase. It is finding out what is actually connected to the network and which systems would stop production if they failed. You cannot protect a floor you have not inventoried, and the second half of that question sets the priority for everything after it.

  1. Inventory what is connected, and identify which systems halt production if they go down.
  2. Separate critical production equipment from the office network.
  3. Clean up old and unmanaged devices, including whatever a vendor left behind years ago.
  4. Verify the backups, including the machines nobody thinks of as computers.
  5. Get remote vendor access under control so it is granted deliberately rather than standing open.

None of that requires replacing production equipment, and most of it can be done without interrupting a shift.

The point

Manufacturing changes the priority. Protecting data still matters, but keeping the line running is the job, and the network is part of the line whether it was ever treated that way or not.

If you run a shop in Rhode Island and cannot say with confidence what is on your network, or what a compromised office computer could reach from where it sits, that is worth an afternoon of attention. We are happy to walk the floor with you and tell you plainly what we find.