Key Findings
IoT attacks generated 46.2 million hits in manufacturing, making IoT the sector's second-largest attack category by volume.
Ten ransomware families were active against manufacturing networks in H1 2026.
Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.
Manufacturing recorded 474 million intrusion prevention events in the first half of 2026.
The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260) generated 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks.
Manufacturing recorded a 56.2% year-over-year decline in intrusion prevention (IPS) volume in the first half of 2026, the steepest drop of any tracked vertical.
The Zhen ransomware family generated 22.2 million hits concentrated on just two devices in manufacturing networks.
Bad bot traffic accounts for 37% of all global internet traffic.
Identity, cloud, and credential compromise accounted for 85% of actionable security alerts.
A single SMB breach can exceed $4.91 million when downtime and recovery are included.
VPN Common Vulnerabilities and Exposures (CVEs) grow 82.5% over the analyzed period.
Automated bots generate more than 36,000 vulnerability scans per second.
SMBs account for nearly half of private sector employment.
In 2025, 88% of SMB breaches involved ransomware, more than double the rate at large enterprises.
The average breach goes undetected for 181 days.
Automated bots account for more than half of all internet traffic.
Log4j generated 824.9 million IPS hits in 2025.
High- and medium-severity attacks surged 20.8% to more than 13 billion hits.
IoT attacks climbed 11% to 610 million hits.