Skip to Content

4 Tech Myths for Manufacturers That Cost Real Money

September 5, 2025 by
Jay Stoltzfus
Jay Stoltzfus

A two-page security questionnaire comes over from your biggest customer's purchasing group. Someone prints it and sets it on your desk. Multi-factor authentication on company email: yes or no. Backups tested in the last twelve months: yes or no. Endpoint protection on every workstation, including any Macs: yes or no.

You get through four of them before you stop.

The blanks on that page are almost never budget problems. They are tech myths for manufacturers, things somebody told you years ago that were never true, quietly standing in for controls the shop does not actually have. Nobody argues about them because they sound like common sense.

Then they come due in writing.

Ransomware showed up in 48 percent of the breaches analyzed in the 2026 edition of Verizon's Data Breach Investigations Report, up from 44 percent the year before. The prior edition put ransomware in 88 percent of breaches at small and midsize companies, against 39 percent at large ones. Small shops are not slipping under the radar. They are what the radar is pointed at.

Here are the four myths we hear most from shops around Parkesburg and across Chester and Lancaster County, and what each one actually costs.

Myth 1: "A Shop Our Size Isn't Worth Hacking"

This is the expensive one, because it justifies skipping everything else.

The picture in most owners' heads is a person choosing targets. That is not how it works anymore. Automated tools scan every address on the internet looking for an unpatched firewall, an open remote desktop port, or a password that showed up in somebody else's breach. Nothing in that process knows you have nineteen employees. It knows port 3389 answered.

And when a crew does look closer, a shop is an attractive target for exactly the reasons owners assume protect them. There is no IT department to fight back at 11pm. Production stops the moment the network does, which creates enormous pressure to pay fast. And the shop usually has one server holding everything that matters.

Picture what "everything that matters" means on your floor. The JobBOSS or E2 database with every open job in it. The folder of SolidWorks and Mastercam files going back fifteen years. Travelers, inspection records, the QuickBooks company file, the certs a customer will ask for next month. Lock those and the floor does not slow down. It stops.

Then the clock starts on somebody else's calendar. A ship date slips, a buyer calls, and the question changes from "when is my part" to "what is going on over there." That is a hard bell to unring, and it is a much bigger number than whatever you would have spent on the controls that prevented it.

What it actually costs: no multi-factor authentication, no real endpoint protection, backups nobody has tested, all justified by a belief about attacker behavior that stopped being true a decade ago.

Shop office PC beside a CNC control, where tech myths cost manufacturers real money

Myth 2: "Incognito Mode Keeps It Private"

Incognito does exactly one thing: it stops that browser from saving history, cookies, and form data on that one machine. That is the whole feature.

It does not hide anything from your network, your internet provider, or the websites being visited. Google's own Chrome help page says so plainly: it can keep browsing private on the device, but it does not make anyone invisible to the sites they visit or to the organization running the network.

More to the point for a shop: incognito provides no security at all. It does not block a phishing page. It does not stop a download that installs something. It does not protect a saved password from being scraped off the machine.

That matters because of where those machines sit. The quoting PC in the front office gets used by more than one person. The laptop by the inspection bench pulls up whatever a vendor emails over. Somebody checks a personal email account or a bank balance on a shop computer at lunch, believes private browsing covers it, and clicks something they would have thought twice about on their own laptop.

The path from there is short and boring. Credentials get stolen. Somebody watches the email account quietly for a few weeks, learns who pays your invoices and how, and then sends a real-looking message about updated banking details. No alarm goes off, because nothing was hacked in the movie sense. Someone just logged in.

What it actually costs: a false sense of cover that encourages risky clicking on machines connected to everything else, and a wire transfer that goes to the wrong account.

Myth 3: "The Mac in the Front Office Can't Get a Virus"

Macs are not immune, and they never were. Apple builds malware screening into macOS and updates it regularly, which should settle the question by itself. You do not build screening for a threat that does not exist.

But the platform argument misses the real problem, which is that the threats that actually hit small manufacturers do not care what operating system is underneath. A convincing fake login page works the same on a Mac. So does a stolen password, a hijacked email thread, and a message from "your bank" about a failed payment. The Mac in your office signs into the same Microsoft 365 tenant, mounts the same file share, and opens the same PDFs as every Windows machine in the building.

Here is where the myth turns into a hole. When people believe a Mac is safe by nature, it gets left out. It is not in the endpoint count. It is not monitored. Nobody is watching whether it updates. It becomes the one machine on the network that nobody can see, and the whole point of a layered setup is that nothing sits outside it.

That also puts you in an awkward spot on paper. The questionnaire asks about endpoint protection on all workstations. The insurance application asks the same thing. "All except the one in the front office" is not an answer either one accepts.

While you are looking at that, it is worth understanding the difference between antivirus and EDR, because most carriers are now asking for the second one specifically, on Macs included.

What it actually costs: one unmonitored, unpatched machine with full access to your files, plus a "no" you have to write on a customer's form.

Myth 4: "It's in the Cloud, So It's Backed Up"

Sync is not backup. They feel like the same thing and they are not, and this is the myth that surprises the most owners.

OneDrive, Google Drive, Dropbox, and the rest are built to make one folder look identical everywhere. That is the job. So when a file gets encrypted or deleted on the workstation, sync does what it was designed to do and pushes that change up. Fast, faithful, and exactly wrong. Yes, most services keep old versions for a window of time, and yes, you can sometimes claw a folder back. Doing that across thousands of CAD files while the floor sits idle is a different experience than restoring from a real backup.

The bigger gap in a shop is what never syncs in the first place. Your ERP database usually lives on a server, not in a synced folder. So does the QuickBooks company file, the license server, the machine-specific post processors, and the shop drawings sitting on a network share somebody mapped in 2016. Sync covers desktops. It does not cover the systems that stop production when they go.

There are only two questions worth asking about any of this. Can we restore last Tuesday's version of a specific SolidWorks file right now, and can we get the whole system running again if the server is gone? If nobody in the building has answered those out loud in the last year, you do not have a backup. You have a folder that copies itself.

That is why a backup and recovery plan you have actually tested is worth more than any product you could buy this week.

What it actually costs: the discovery happens on the worst possible morning, when the answer needs to be immediate.

What Tech Myths for Manufacturers Actually Cost

Boil the four down and they land in the same four places every time:

  • Money spent in the wrong direction. New hardware while the firewall runs firmware from three years ago.
  • A hole that is technically uninsurable. Answer "yes" on an application when the honest answer is "mostly" and the claim is where you find out.
  • Downtime measured in shifts, not minutes. Second shift does not care what caused it.
  • A contract you cannot defend. OEM customers are asking questions their buyers were not asking five years ago.

None of that shows up as a line item. It shows up as a bad week you did not budget for.

Two Outsiders Who Will Check Your Work

You can settle an argument in the office however you like. Two other parties get a vote, and both of them want it in writing.

The first is your insurance carrier. Renewal applications have gotten specific: multi-factor authentication on email and remote access, endpoint detection and response, tested backups, separate admin accounts. Answer optimistically and you have created a coverage problem you will not discover until you need the policy. It is worth knowing what carriers are actually asking for at renewal before the form shows up.

The second is your customer. Tier-one OEMs now push security questionnaires down to suppliers, and purchasing does not grade on effort. Two shops quote the same part at nearly the same price, one can answer the form and one cannot, and the difference is not the machine time.

The good news is that both audiences want the same handful of controls, so the work is done once. We put the answers together in a package you can hand straight to your broker or your customer's purchasing group, which turns a week of chasing paperwork into an email.

How to Spot the Next One

New myths show up every year. Four questions kill most of them:

  1. Does it use the word "never" or "always"? Nothing in technology is that clean. "Macs never get viruses" and "the cloud always has a copy" are both absolutes, and both are wrong.
  2. Who benefits if you believe it? Some myths are marketing that got loose. Others are one person's shortcut that turned into shop policy.
  3. What happens if it turns out to be false? This is the real filter. Leaving a tablet on the charger all night costs nothing if that myth is wrong. Believing your files are backed up costs a week of production if that one is wrong. Spend your attention accordingly.
  4. Has anyone tested it here? Not in general, in your building, on your equipment, this quarter. A backup that restored fine in 2023 is a story, not a test.

Ask a straight question and get a straight answer, or ask somebody else.

Tech Myths for Manufacturers: Questions Shop Owners Ask

Is OneDrive a backup for a machine shop?

No. OneDrive and Google Drive are sync, not backup. When a file is encrypted or deleted on the workstation, that change syncs to the cloud copy. Sync also usually misses the systems that stop production, like your ERP database and QuickBooks company file, because those live on a server and not in a synced folder.

Does a small manufacturer really need more than antivirus?

Yes. Traditional antivirus matches known threats against a list. Most attacks that stop a shop now use stolen logins and legitimate tools, which never trip that list. Endpoint detection and response watches behavior instead of signatures, and most cyber insurance carriers now ask for it by name on renewal applications.

Does incognito mode hide browsing on the shop's network?

No. Incognito only stops that browser from saving history and cookies on that one machine. Google's own documentation says websites, network operators, and internet providers can still observe the activity. It also does nothing to stop malware, phishing pages, or a download that installs something.

How often should a shop test its backups?

At least once a quarter, plus any time you change a server, move the ERP, or add a major system. A test means restoring an actual file and an actual system and timing it, not checking that last night's job reported success. Most insurance applications now ask when you last tested, in writing.

What should a 15 to 25 person shop expect to pay for managed IT with security included?

Most shops that size land somewhere between $100 and $200 per user per month for fully managed IT with security, monitoring, and backup included. The spread depends on how many servers you run, whether you have CAD and CAM workstations, and how much cleanup the first few months require. Hourly break-fix looks cheaper until the first outage.

Not Sure Which of These Is True in Your Shop?

Starlux IT is based in Parkesburg and works with small manufacturers around Coatesville, Downingtown, Gap, and across Chester and Lancaster County. We know what a SolidWorks or Mastercam file server needs, we know what your carrier wants to see before renewal, and our techs are close enough to be on your floor the same day when something is down.

Give us 30 minutes, free, no pressure. We will look at what you have, show you which of these four is quietly true at your place, and you will know exactly where you stand, whether you hire us or not. If you decide you want managed IT built around how a shop actually runs, we will talk about that. If not, you still leave with the answers.

Book your free 30 minutes →

Jay Stoltzfus
Jay Stoltzfus September 5, 2025
Share this post
Archive