Segmentation & Zero Trust

How a Single Compromised Laptop Can Shut Down a Factory

Coca-Cola's Fairlife breach forced every U.S. production line offline after ransomware reached IT systems, a reminder that most manufacturers can't see where IT ends and OT begins on their network.

What Every Manufacturer Should Learn from the Fairlife Breach About Network Segmentation

On July 16, 2026, Coca-Cola revealed that its Fairlife dairy subsidiary, a business that brings in roughly $4 billion in annual revenue, had been hit by a ransomware attack. The intruders reached "a portion of its systems, including production-related infrastructure." The reaction was fast and drastic: every U.S. manufacturing line was taken offline. The product itself was never compromised, yet production halted across the entire country while Canadian operations continued to run untouched.

Coca-Cola's filings still have not confirmed whether the attackers genuinely reached operational technology (OT) on the plant floor, or whether the shutdown was a precautionary barrier raised the instant information technology (IT) systems looked suspicious. That uncertainty is the real story. When a company with Coca-Cola's resources cannot say for sure, days afterward, whether an attack crossed from IT into OT, it reveals something uncomfortable: most organizations have no clear picture of what is talking to what on their own networks.

That gap, not knowing what is happening and being unable to contain what you cannot see, is where the Fairlife problem begins.

The Path of Least Resistance Is Rarely the Plant Floor Itself

Attackers hardly ever breach a PLC or an HMI first. They land on something ordinary, a phished laptop, an exposed remote-access account, a vulnerable file server, and from there they move. This is known as lateral movement, and it is the connective tissue between "we had a phishing incident" and "we shut down every factory in the country."

Lateral movement succeeds for structural reasons, not technical ones. IT and OT networks that were once air-gapped are now connected by design: MES integrations feed production data into ERP systems, remote vendors dial into control systems for support, and engineering workstations sit on segments that also touch the corporate domain. Each of those connections serves a legitimate business purpose. Each is also a hallway an attacker can walk down once inside, if nothing is watching for footsteps that do not belong.

The data supports this. A 2024 industry survey of more than 1,100 security and operations professionals found that nearly 90 percent had faced at least one attack in the previous year that began with third-party access into their cyber-physical systems environment, and more than half admitted they only partly understood, or did not understand at all, how extensive that third-party connectivity really was. You cannot defend a boundary you cannot see.

Detection Must Happen Before the Alarm, Not After the Shutdown

Most incident response plans are built around a moment that is already too late: the moment production stops. By then the attacker has had the run of the network for however long it took someone to notice. The real leverage point comes much earlier, at the first unusual connection, the first protocol that should not be there, the first host reaching out to systems it has never spoken to before.

This is a solvable problem, but it takes two things working in tandem:

1. Ongoing behavioral baselines

You cannot spot an anomaly without first knowing what normal looks like. That means passively mapping every device on the network, IT and OT alike, and learning its typical communication patterns: what it talks to, what protocols it uses, and when it is active. Once that baseline exists, deviations become visible almost immediately. A corporate workstation that suddenly initiates RDP sessions to a device that only ever speaks Modbus is not a coincidence. It is a signature.

2. Automatically enforced least-privilege segmentation

Visibility on its own does not stop an attack; it simply narrates it. Real containment comes from segmentation built on the principle that every device should reach only what it strictly needs, and nothing more. Done well, this turns lateral movement from a smooth hallway into a series of locked doors. An attacker who compromises one IT endpoint hits a wall the moment they try to reach OT, because the network was never configured to allow that conversation in the first place. And when a genuine anomaly appears, that same segmentation infrastructure, whether NAC, firewalls, or switching fabric, can quarantine the offending device in seconds rather than hours.

The Cost of Getting This Wrong Is Not Hypothetical

Fairlife's shutdown was not a worst-case scenario invented in a tabletop exercise. It happened to a subsidiary of one of the most well-resourced companies on earth, and it happened fast enough that there was no time to determine whether OT had been compromised. There was only time to assume it might be and shut everything down rather than find out the hard way.

Every manufacturer, hospital system, and critical infrastructure operator running converged IT/OT environments is one phished credential away from the same decision. The organizations that will handle it better are those that already know, in real time, exactly what is connected to their network, exactly how those devices normally behave, and exactly where the walls stand between IT and the systems that make the product.

Early detection and least-privilege segmentation are not compliance checkboxes. They are the difference between isolating one compromised laptop and shutting down a country's worth of production lines while you work out what happened.

The "Easy Button" for Containing Threats Without Stopping Production

Reaching this level of protection is no longer as hard as it once was. ORDR gives manufacturers complete visibility into every connected device within days, then uses that device and behavioral intelligence to recommend and enforce least-privilege segmentation policies through the infrastructure they already own. With AI agents guiding teams from discovery through action, ORDR makes it far easier to contain a compromised laptop before it becomes a company-wide production shutdown.

ShareLinkedInX