Cybersecurity Awareness Month: Strengthening resilience across industries

During conversations with organizations across industries, from automotive suppliers to food producers, one theme consistently emerges: cyber resilience is becoming as critical to business performance as operational safety.

This Cybersecurity Awareness Month, I am focused on how organizations can strengthen resilience against ransomware, supply chain intrusions, connected technology vulnerabilities, and emerging AI-related risks that can disrupt operations and undermine trust.

A cybersecurity incident can interrupt production and expose confidential information. Its effects may spread to customer deliveries, supply chains, and stakeholder trust. Cloud services and connected equipment are making these risks increasingly interconnected. Remote access and artificial intelligence add further considerations.

Artificial intelligence is also becoming part of everyday business operations. Organizations are using AI to analyze information, automate activities, and support decisions. These applications can create business value. Organizations should also understand where AI is being used, what information it processes, and who is responsible for overseeing it.

Cybersecurity Awareness Month is an opportunity to step back and ask an important question:

Are we managing cybersecurity as a technical issue, or as a business risk?

Technology is an important part of cybersecurity, but technology alone is not enough. Effective cybersecurity also depends on informed employees and clear responsibilities. Reliable processes, supplier oversight, and plans for responding to disruption are equally important.

The specific risks vary by industry. An automotive supplier may be concerned about protecting prototype information. A food manufacturer may be more focused on maintaining production. An aerospace organization may need to safeguard sensitive technical data across an extensive supplier network.

Understanding this business context is an important first step toward building meaningful cyber resilience.

Cybersecurity begins with awareness

Many cyber incidents begin with ordinary activities. An employee may receive a convincing email requesting urgent action. A supplier’s credentials may be compromised. An organization may continue using unsupported equipment because replacing it would affect production.

Risk can also arise when a new application is introduced without proper review. The organization may not have fully considered how information will be accessed, stored, or shared.

AI adds another consideration. It can make fraudulent emails and impersonation attempts more convincing. The inappropriate use of AI tools may also expose confidential or sensitive information.

Employees should know which AI tools are approved and what information may be entered into them. They should also understand when an AI-generated result needs to be verified.

Employees do not need to become cybersecurity or AI specialists, but they should understand:

  • How to recognize and report suspicious requests
  • Why strong account protection and multifactor authentication matter
  • How their decisions can affect the organization’s security
  • Where sensitive information is stored and shared
  • Which AI tools are approved and how they may be used
  • What to do when something unusual occurs
  • Why cybersecurity procedures apply to their roles

Foundational practices remain essential. Employees should know how to recognize phishing attempts and use strong passwords. Organizations should also enable multifactor authentication and keep software updated.

These preventive measures need to be supported by plans for disruption. Organizations should maintain backups, prepare incident response plans, and be ready to restore important systems.

These actions provide an important foundation. Each organization must then consider how cybersecurity connects to its operations and business objectives. Customer expectations and supplier relationships should also form part of that discussion.

Automotive: Protecting information across a connected supply chain

The automotive industry depends on the continuous exchange of information across a broad business network. Manufacturers and suppliers share information with engineering firms, technology companies, and other service providers.

This may include prototypes, product designs, and test results. Production data and customer information also require protection, as do plans for future technologies.

As vehicles and factories become more connected, organizations must protect this information while meeting growing customer expectations. A weakness at one supplier can create consequences elsewhere in the automotive ecosystem.

Automotive organizations are considering questions such as:

  • How well are prototypes, designs, customer information, and other sensitive data protected?
  • Could a cyber incident at the organization or a supplier interrupt production or delay delivery?
  • Are cybersecurity expectations consistently understood and applied across the supply chain?
  • How are access, remote connectivity, connected equipment, and software dependencies managed?
  • Can the organization demonstrate effective information security practices to customers?

Ransomware or compromised supplier access can affect production and shipments. The loss of critical systems may also expose intellectual property and damage customer trust.

AI is increasingly being used in areas such as engineering and quality inspection. It can also support manufacturing and predictive maintenance. Organizations adopting these applications should establish clear responsibilities and suitable oversight.

ISO/IEC 27001 provides a broad framework for managing information security risks. TISAX® builds on key elements of ISO/IEC 27001 and addresses information security expectations specific to the automotive ecosystem.

Together, these approaches can help organizations establish repeatable security practices and respond to customer requirements. They can also build confidence across the supply chain.

Food and beverage: Connecting cybersecurity with business continuity

Food and beverage organizations increasingly rely on connected production and monitoring systems. Their operations also depend on quality platforms and warehouse technology. Logistics providers and digital traceability tools add further connections.

Information moves between the plant floor and wider business systems. It may also be shared with external service providers.

This connectivity improves efficiency and gives organizations better visibility into their operations. However, it can also allow a cyber incident to affect production and quality. The consequences may extend to distribution and customer fulfillment.

Cybersecurity in this sector is therefore closely connected to operational resilience.

Food and beverage companies are considering questions such as:

  • Could a cyber incident interrupt production, warehousing, or distribution?
  • Are older systems, connected equipment, and vendor remote access appropriately protected?
  • Can critical quality, traceability, sanitation, and environmental information be recovered?
  • How long could operations continue if a plant, system, supplier, or technology provider became unavailable?
  • Are cybersecurity response and business continuity plans coordinated and tested?

A disruption can affect product availability and customer commitments. It may also put perishable inventory at risk. If several facilities depend on the same technology or service provider, recovery can become more difficult.

AI may support activities such as forecasting and production planning. It may also be used for quality inspection or logistics. When AI influences an important operational decision, its results should receive appropriate review.

ISO/IEC 27001 helps organizations manage information security risks in a structured way. ISO 22301 helps them identify critical activities and prepare for disruption. It also supports the continuation and recovery of critical operations.

Used together, these standards can support both information protection and business continuity.

Aerospace: Safeguarding sensitive information and customer trust

Aerospace organizations exchange sensitive information across extensive supply chains. These networks may include manufacturers and engineering companies. Maintenance providers and specialized technology partners may also have access to important information or systems.

The information being shared may include product designs and technical specifications. Test results, manufacturing instructions, and program communications may also require protection.

Protecting this information requires more than controls within one organization. Cybersecurity expectations often need to extend to suppliers and subcontractors that support essential operations.

Common concerns include:

  • Where is sensitive information stored, and who can access it?
  • Are suppliers and subcontractors applying consistent information security practices?
  • Could a cyber incident disrupt engineering, production, maintenance, or customer delivery?
  • How are older systems, connected equipment, remote access, and technology dependencies managed?
  • Can the organization demonstrate that customer, contractual, and relevant cybersecurity requirements are being met?

Supply-chain cybersecurity remains a top concern because an incident affecting one supplier can create consequences across multiple organizations.

Smaller suppliers may handle sensitive information while having fewer cybersecurity resources. At the same time, larger organizations may have limited visibility into how risks are managed across an extensive supplier network.

Organizations therefore need to understand which suppliers and technology providers are most critical. They should also consider how essential activities would continue if one of those providers experienced a disruption.

AI may be used in engineering or maintenance. It may also support inspection and planning activities. When an AI system contributes to an important decision, responsibility for reviewing its use and results should be clear.

ISO/IEC 27001 can provide a consistent framework for identifying risks and protecting sensitive information. It can also support supplier management and the assignment of security responsibilities.

A structured approach helps an organization maintain and improve its information security practices. It can also provide customers with greater confidence in how sensitive information is managed.

Manufacturing: Managing cybersecurity where digital systems meet operations

Manufacturers increasingly rely on connected equipment and digital systems. Cloud platforms and automation now support many production activities. Data analytics and AI are also becoming more common.

These technologies can improve productivity and provide better information about operations. They also create closer connections between business systems and the equipment used to run production.

In this environment, cybersecurity is not only about protecting data. It is also about maintaining the availability and reliability of important systems and equipment.

Manufacturers are considering questions such as:

  • Which systems, equipment, and digital services are most critical to production?
  • Could unauthorized access or ransomware interrupt operations?
  • How are older systems, connected equipment, and third-party remote access managed?
  • Can essential processes continue safely while affected systems are restored?
  • Are responsibilities and recovery priorities clear across IT, engineering, operations, maintenance, and quality?

A cybersecurity incident can expose information or stop production. The effects may include delayed customer orders and quality issues. Safety concerns and wider operational disruption may also result.

Managing these risks can be particularly challenging when older equipment cannot be easily updated. Replacement may be difficult if it requires production to stop.

Remote access creates another potential source of exposure. Equipment vendors and other third parties may need access to production systems, but that access must be carefully managed.

AI-supported activities should also have clear ownership and suitable human oversight. Examples include predictive maintenance and visual inspection. AI may also support production planning or process optimization.

Organizations should understand how important AI-supported results are reviewed. They should also know how operations would continue if the technology became unavailable or performed unexpectedly.

Cybersecurity planning should involve operational and business functions as well as IT. Operations and engineering teams can help identify critical dependencies. Maintenance, quality, and site leadership can explain the practical consequences of disruption.

ISO/IEC 27001 can help manufacturers establish a structured approach to information security. This approach can cover business systems and production environments. It can also address people and suppliers.

ISO 22301 complements this approach by helping organizations identify critical operations and dependencies. It supports preparation for disruption and the controlled recovery of production.

Where AI is used in operational activities, ISO/IEC 42001 can provide additional structure. It can support clear responsibilities, risk management, and appropriate review.

Cybersecurity concerns extend across every sector

Although the consequences differ by industry, many organizations are asking similar questions:

  • Do we understand which information, systems, services, and suppliers are most critical to the business?
  • Are cybersecurity responsibilities clearly assigned and understood across the organization?
  • Do employees know how to protect sensitive information, report suspicious activity, and use approved AI tools responsibly?
  • Can essential operations continue if a critical system, supplier, or technology service becomes unavailable?
  • Can we demonstrate to customers and stakeholders that cybersecurity controls are consistently implemented and improved?

These questions apply across many sectors. They are relevant to organizations in energy and healthcare as well as technology and transportation. Professional service organizations face many of the same considerations.

The appropriate response will depend on the organization’s risks and obligations. Its operating environment and current level of maturity will also shape its priorities.

Cybersecurity should not be separated from the rest of the business. It affects how organizations manage suppliers and train employees. It also influences how they adopt technology, protect customers, maintain operations, and build trust.

Turning awareness into practical action

Cybersecurity Awareness Month can help organizations begin a conversation, but awareness should lead to action.

Organizations can use the month to focus on several practical priorities.

1. Make cybersecurity relevant to each role

General awareness is useful, but employees are more likely to act when they understand how cybersecurity relates to their work.

Training should reflect the situations employees are likely to encounter. The needs of production and engineering teams may differ from those of sales or procurement. Quality professionals and senior leaders may face different decisions again.

Employees who use AI tools should know which tools are approved. They should also understand what information should not be entered and when results need additional verification.

2. Identify critical information and operations

Organizations should identify the information and systems that matter most. They should also understand which services and operational processes are essential.

This helps direct cybersecurity and continuity efforts toward the areas where disruption would have the greatest business impact.

3. Review supplier and technology dependencies

Suppliers may store information or access important systems. They may also support equipment or provide essential digital services.

This means knowing which providers are critical. Organizations should consider what would happen if one experienced a cyber incident or service disruption.

4. Test incident response and continuity plans

A documented plan is valuable, but an exercise can reveal whether responsibilities are understood. It can also test whether the organization’s assumptions are realistic.

Exercises should examine how teams communicate and make decisions. They should also address temporary workarounds, customer obligations, and recovery priorities.

5. Build security into business decisions

Cybersecurity should be considered when selecting suppliers and introducing new systems. It should also form part of decisions about connected equipment, process changes, and AI adoption.

Before implementing an AI application, the organization should understand its purpose and the information it will process. Responsibility and the appropriate level of oversight should also be defined.

Considering these questions early can reduce the likelihood of concerns emerging later. These may involve security and privacy, as well as the wider governance of the technology.

6. Create a consistent management approach

Cybersecurity activities can become fragmented. They may be handled through separate technical projects or introduced in response to individual customer requests. In other cases, they may depend on the efforts of individual teams.

A management-system approach can bring these activities together. It can connect risks and responsibilities with appropriate controls. It also supports training, monitoring, and continual improvement.

The same principle applies to AI. Clear governance can help prevent different teams from introducing tools without common expectations or oversight. That governance should be proportionate to how the technology is used and the risks involved.

Explore practical ways to strengthen awareness and competence through DNV cybersecurity resources and training programs.

Building confidence through a structured approach

Management systems can help organizations move from individual cybersecurity activities to a consistent approach. They provide structure for managing risks and assigning responsibilities. They also support effective controls, employee competence, performance monitoring, and continual improvement.

ISO/IEC 27001 is the international standard for information security management systems. It provides a risk-based framework for protecting information across people and processes. It also addresses the technology used to create, store, and share that information.

The standard can help organizations clarify responsibilities and manage security risks. It may also support customer expectations and contractual requirements. Its management-system structure encourages organizations to monitor and continually improve their information security practices.

ISO/IEC 42001 is the international management-system standard for artificial intelligence. It helps organizations manage AI in a structured way.

The standard supports the assignment of responsibilities and the assessment of AI-related risks. It also addresses appropriate oversight and the monitoring of AI performance. ISO/IEC 42001 complements ISO/IEC 27001 by focusing on the broader governance of AI, not only the security of the information and technology involved.

TISAX®, or Trusted Information Security Assessment Exchange, is an assessment and exchange mechanism developed for the automotive industry. It builds on key elements of ISO/IEC 27001 and focuses on information shared across the automotive ecosystem.

This information may include prototypes and project information. Process data and personal information are also within its scope. For many automotive suppliers, TISAX provides a recognized way to demonstrate information security maturity and respond to customer requirements.

ISO 22301 is the international standard for business continuity management systems. It helps organizations identify critical activities and the resources on which those activities depend.

The standard supports preparation for disruption and the continuation of critical operations. It also helps organizations plan for a controlled recovery. In a cybersecurity context, this connects technical incident response with the wider business decisions needed to continue serving customers.

These standards and frameworks address different but connected needs. ISO/IEC 27001 focuses on information security, while ISO/IEC 42001 supports responsible AI governance. TISAX addresses automotive information security expectations, and ISO 22301 supports business continuity.

They do not eliminate risk. However, they can help organizations establish a disciplined and repeatable approach to resilience. They also support continual improvement as risks and business needs change.

Training can help employees understand their responsibilities and build the required competence. Assessments can identify gaps, while independent certification can give customers and other stakeholders greater confidence in how risks are managed.

Explore DNV solutions for ISO/IEC 27001, ISO/IEC 42001, TISAX, ISO 22301, and cybersecurity training.

The following questions summarize key considerations for organizations seeking to strengthen cybersecurity awareness and resilience.

Frequently asked questions

What is Cybersecurity Awareness Month?

Cybersecurity Awareness Month is an opportunity for organizations to reinforce awareness, clarify responsibilities, and connect cybersecurity with everyday business decisions. It can help bring different functions into the conversation and encourage employees to understand how their actions affect security and resilience.

Why is cybersecurity important for manufacturers?

Manufacturers depend on connected equipment, digital systems, cloud platforms, automation, and third-party access. A cyber incident can expose information, interrupt production, delay customer orders, and affect quality, safety, and operational continuity.

How does ISO/IEC 27001 help organizations manage cybersecurity risks?

ISO/IEC 27001 provides a risk-based framework for an information security management system. It helps organizations assign responsibilities, manage information security risks across people, processes, and technology, monitor performance, and continually improve security practices.

What is TISAX and who may need it?

TISAX is an assessment and exchange mechanism developed for the automotive industry. It focuses on information shared across the automotive ecosystem and can help automotive suppliers demonstrate information security maturity and respond to customer requirements.

How does cybersecurity support business continuity?

Cybersecurity and business continuity are connected because a cyber incident can interrupt critical systems, suppliers, and operations. Coordinated incident response and continuity planning help organizations maintain essential activities and recover in a controlled way.

How is AI changing cybersecurity risks?

AI can make fraudulent emails and impersonation attempts more convincing, while inappropriate use of AI tools may expose confidential or sensitive information. Organizations should know where AI is used, what information it processes, which tools are approved, and who is responsible for oversight and verification.

What first steps can organizations take to improve cyber resilience?

Organizations can make cybersecurity relevant to each role, identify critical information and operations, review supplier and technology dependencies, test incident response and continuity plans, build security into business decisions, and create a consistent management approach.

Cybersecurity Awareness Month is a starting point

Cybersecurity resilience is built through everyday decisions. It depends on how employees respond to suspicious activity and how leaders prioritize risk. Supplier management and the introduction of new technology also play important roles.

Organizations must also be prepared for disruption. That requires people to understand their responsibilities and know how to respond when something goes wrong.

Cybersecurity Awareness Month provides an opportunity to reinforce these connections. It can bring different parts of the organization into the conversation and help employees see how cybersecurity relates to their work.

The goal is not to turn every employee into a cybersecurity or AI specialist. It is to create an organization where people understand their responsibilities and leaders have the information needed to make sound decisions.

Cybersecurity should become part of normal business practices rather than a separate technical activity.

Awareness starts the conversation. A structured, business-focused approach helps turn that awareness into lasting resilience.

Learn how DNV supports cybersecurity resilience through cybersecurity training, independent certification, and industry-focused resources.

 

About the Author:
Cavan Leung is Head of ICT, Business Assurance, North America at DNV. He works with organizations across multiple industries on cybersecurity, governance, risk, assurance, compliance, business continuity, and emerging technology topics.

10/5/2026 6:10:00 PM

ISO/IEC 27001 On-Demand Webinar

ISO/IEC 27001 On-Demand Webinar

Explore the fundamentals of ISO/IEC 27001 and learn how a structured information security management system can help organizations identify risks, protect information, and build stakeholder confidence.