Managed IT services for manufacturers should be written around the plant, not the office, because production is where an hour of downtime turns into a shift of lost output. Expect four commitments: a recovery target tied to production lines rather than to the site as a whole, a documented separation between the business network and the equipment network, named ownership of the ERP and machine vendors, and a patching approach that accepts some machinery cannot be updated on a normal cycle. Most agreements we inherit cover desks well and treat the floor as an exception. The exception is the business.
Five Points Behind This Article
Manufacturers often buy IT support on the office side of the operation and discover during a line stoppage that the floor was barely in scope. The points below stay with what happens in production. This is written for operations managers, plant managers, and owners at manufacturers of roughly 20 to 500 employees running one or more facilities.
- Downtime is measured in units, not minutes. A recovery target that means anything is stated per line or per cell, with the cost of a stopped line understood by both parties.
- The equipment network is not the office network. Machine controllers, historians, and human-machine interfaces need separation from email and browsing, and the separation needs to be shown rather than described.
- Some equipment cannot be patched, and pretending otherwise is worse. A controller running an unsupported operating system is common. Isolating it is the honest answer, not a promise to update it.
- ERP has a vendor, and the vendor has a boundary. Production scheduling, inventory, and shipping all depend on it, so somebody must own an incident that crosses between vendor and network.
- Shop-floor users are not office users. Shared terminals, gloves, and shift changes make ordinary sign-in assumptions fail, and a plan that ignores this gets worked around by the people it inconveniences.
Why Managed IT Services for Manufacturers Are Judged on the Plant Floor
Managed IT services for manufacturers are judged on the plant floor because production is the only place where a technical failure immediately becomes lost revenue that cannot be made up later in the day. Our team has stood in enough plants during a stoppage to know how quickly the conversation turns to output. Three patterns account for most of what we are called in to resolve.
An Office Agreement Applied to a Production Line
Most agreements we take over specify site coverage, business-hours support, and a monthly maintenance window. None of those descriptions mean anything to a line running two shifts. A maintenance window at seven in the evening is the middle of second shift.
There is a defensible argument for uniform site coverage. It is simpler to price, simpler to staff, and a manufacturer whose office and plant sit in one building genuinely does share most infrastructure between them.
What the uniform model misses is that consequence is not uniform. A stopped line and a slow spreadsheet share a network and nothing else. What we recommend is a short list of production-critical systems with their own recovery target and their own maintenance rules, negotiated against shift patterns rather than a calendar. That list is the first thing we build when scoping managed IT services for a plant, and it usually takes one walk of the floor to assemble.
Nobody Can Show Where the Networks Separate
Ask a manufacturer where the business network ends and the equipment network begins, and the answer is often a description rather than a diagram. Machine controllers frequently sit on the same flat network as office workstations, which means a problem that starts in email can reach a production cell.
Some plants keep a flat network deliberately, and the reasoning is practical. Machine vendors want remote access for support, engineers want data off the line for analysis, and every separation boundary is one more thing that breaks a working integration.
The counterargument is that a flat network makes the plant’s exposure as wide as its email. The workable arrangement is separation with defined crossings: named data paths, controlled vendor access, and a rule set someone can produce on request. A provider running managed firewall services should be able to show that rule set in writing, and if nobody can produce it, the separation is probably aspirational.
Patch Cycles Collide With Equipment Reality
A great deal of production equipment runs software that cannot be updated without vendor certification, and some of it runs operating systems that stopped receiving updates years ago. A provider promising full patch coverage across the site either does not know this or is not looking at the floor.
There is an argument that unsupported equipment should simply be replaced, and in the long run that is often right. Capital cycles for machinery run in decades, though, and a controller attached to a press that has fifteen good years left is not getting swapped because its operating system aged.
Our position is that the honest answer is isolation plus monitoring: accept that the device cannot be patched, restrict what it can reach and what can reach it, and watch it closely. That is a real plan. A patch report claiming full coverage on a floor full of unsupported controllers is a document that will mislead everyone who reads it, which is why we treat managed security services as an exercise in accurate scope before anything else.
What Managed IT Services for Manufacturers Should Cover on ERP and Vendors
Managed IT services for manufacturers should cover ERP availability and third-party vendor access explicitly, because both cross the boundary between what the provider controls and what someone else does. Boundaries are where incidents stall.
ERP Downtime Reaches Shipping and Receiving, Not Just Reporting
When ERP is unavailable, production scheduling, inventory lookups, and shipping paperwork stop with it. A plant can keep running for a while on printed schedules, then loses the ability to confirm what was made and ship it.
Some manufacturers accept this exposure because ERP redundancy is expensive and outages are rare. That reasoning holds if the exposure has been priced. It usually has not.
What we recommend is a simple continuity arrangement: a printed current schedule available at shift start, a defined manual process for recording production and shipments during an outage, and a written recovery target for the ERP itself. The manual process is the part manufacturers skip, and it is the part that keeps trucks moving. Firms in other document-heavy operations reach similar conclusions, and our piece on measuring a managed IT partnership covers how to hold a provider to those targets over time.
Machine Vendor Remote Access Needs a Front Door
Equipment vendors need access to support their machines, and that access is often arranged directly with a vendor years ago by someone who has since left. We regularly find standing remote connections nobody in current management knew existed.
Vendors argue reasonably that support requires access and that restrictive arrangements slow down repairs, which costs the plant more than the risk does. In a breakdown, that argument feels compelling.
The resolution is a front door rather than a standing key: access that is requested, granted for a window, logged, and closed. Repairs still happen, and the plant knows who connected and when. For manufacturers with internal engineering staff who want to keep vendor relationships themselves, a co-managed arrangement keeps that relationship in house while the access mechanics stay controlled.
Shift Patterns Belong in the Agreement
Coverage should match how the plant runs. A single-shift operation and a two-shift operation need different support hours, and a plant that adds a weekend shift seasonally needs the agreement to say what happens then.
Ask whether the after-hours responder can make changes or only record them, since many agreements offer overnight logging with next-business-day repair. On second shift, that distinction is the whole service. Professional-services firms ask the same question for different reasons, which our guide on managed IT services for law firms frames from the deadline side.
Shared Terminals Need a Workable Sign-In Story
Shop-floor users work in gloves, move between stations, and change shift on a fixed clock. Ordinary office assumptions about individual sign-in break against all three, which is why so many plants end up running one shared account per station with the password taped inside a cabinet door.
The practical case for shared terminals is genuine. A machine operator cannot type a long password with gloved hands mid-run, and a sign-in prompt during a production task is a safety distraction as much as an inconvenience.
The problem is that a shared account makes the record useless. Nobody can say who acknowledged an alarm or changed a setpoint, which matters during a quality investigation as much as a security one. What works in practice is a badge tap or short code at the station tied to an individual, with the session timing out at shift end. Operators keep a fast path, and the plant keeps a trail it can rely on when someone asks what happened on second shift Tuesday.
How to Test a Provider Before You Sign
Testing a provider for plant work is best done on the floor, because the gap between an office answer and a production answer becomes obvious quickly. Two tests do most of the work.
Walk the Floor With Them
Take the candidate onto the production floor and ask them to identify what they see: which devices they would consider unpatchable, where they would expect a network boundary, and what they would want isolated first. A provider with plant experience will point at controllers and ask about vendor certification. One without it will talk about the office switch.
This costs an hour and tells you more than any proposal, and it is worth doing with the maintenance engineer present rather than only with management, since the person who keeps the line running usually knows which devices are fragile and which vendor connections exist. Engineering-led firms often use a similar test for a different reason, which our piece on IT services risks for architecture and engineering firms touches on from the design-data angle.
Ask for the Exclusion List and the Maintenance Rules
Request the coverage exclusion list and the standard maintenance policy in writing. For a manufacturer, the exclusion list is the more revealing document, because it says what happens with equipment the provider will not take responsibility for.
If the policy specifies a maintenance window that lands during a shift, that is not a dealbreaker, it is a negotiation. What matters is whether the provider recognizes the conflict without being told. Seasonal operations face a comparable scheduling problem, and our accounting firm guide covers how to write a peak-period clause that actually binds.
Frequently Asked Questions
Should the plant network be separated from the office network?
Yes, with defined crossings for the data and vendor access the plant genuinely needs. Ask your provider to produce the rule set that enforces the separation rather than describing the intent, since a flat network is common and rarely deliberate.
What happens with equipment that cannot be patched?
It gets isolated and monitored rather than updated, and the agreement should say so plainly. A patch report claiming full site coverage while unsupported controllers run on the floor is misleading to everyone who relies on it.
How should maintenance windows work for a two-shift plant?
They should be negotiated against shift patterns, with the plant holding veto rights and a defined notice period. A standard evening window sits in the middle of second shift, which makes it unusable without anyone noticing until the first conflict.
Who owns an incident that involves the ERP vendor?
Whoever your agreement names, and if it names nobody, the plant manager ends up mediating. Ask for a sentence stating the provider owns the incident through restoration regardless of eventual fault.
How should machine vendor remote access be handled?
Through access granted for a defined window and logged, rather than a standing connection. Standing vendor access set up years ago is one of the most common findings when we audit a plant, and it is usually undocumented.
Who Is Behind This Advice
Our team has spent a lot of time on production floors, and it changes how you read an IT agreement. What matters in a plant is not the most current technology, it is knowing exactly which devices cannot be touched and making sure nothing dangerous can reach them. Most of what is written above came from plants we were called into after a stoppage, where the office side of the environment was in decent shape and nobody had ever drawn the boundary around the floor. We would rather draw it first, with the people who run the lines.
Mindcore is led by Matt Rosenthal, who focuses on making availability and security commitments measurable for operating businesses, so a plant manager can confirm what is being delivered without a technical background.
Talk Through Your Plant’s Setup
Four commitments tell a manufacturer most of what it needs to know about its current arrangement: a recovery target tied to production, a network separation someone can show you on paper, an honest position on equipment that cannot be patched, and one party who owns an incident through restoration. Reading an existing agreement against those four rarely takes long, and the gaps tend to sit in the same places.
If you would like a second read on where your plant is exposed, we are glad to walk the floor with you. Bring the agreement, your shift schedule, a list of equipment you know cannot be updated, and your most recent monthly report if you receive one. We will tell you which of the four you already hold and which are missing, and if your provider is handling the plant well we will say so directly. Bring your maintenance policy too, since that is where the shift conflict usually hides, and a plant that fixes only the maintenance window often recovers more production than one that replaces its whole support arrangement. You can book a free strategy call and we will work through it together.

