Manufacturing Named in Annex II
NIS2 Annex II covers machinery, electronics, electrical equipment, motor vehicles and other transport, medical devices, chemicals and food.
A ransomware attack doesn’t just steal data, it stops your production line. Cybersecurity for manufacturing means closing the same gaps every time: a supplier with remote access, an unpatched machine controller, a credential stolen months ago. Since 2002, eBuilder Security has protected Swedish manufacturers, machine builders and industrial suppliers without needing a 24/7 team of their own.
Download the Manufacturing NIS2 Readiness ChecklistTrusted by Swedish Manufacturers and Industrial Suppliers Since 2002








On 15 January 2026, Sweden’s Cybersäkerhetslagen (2025:1506) brought the EU’s NIS2 rules into national law. Manufacturing is named directly in NIS2 Annex II as a critical sector. If you’re a medium or large manufacturer, you’re likely in scope and it’s now a board-level issue, not just IT’s problem.
Manufacturers are an easy target: valuable IP, production lines that can’t afford downtime, and suppliers who often have standing access to your systems. That’s exactly why manufacturing keeps ranking among the most attacked sectors for ransomware. eBuilder Security helps you meet these obligations without building a 24/7 team from scratch.
NIS2 Annex II covers machinery, electronics, electrical equipment, motor vehicles and other transport, medical devices, chemicals and food.
If something happens, you’ve got 24 hours to send MCF an early warning. Article 23 starts that clock the moment you spot it.
Article 21 means any vendor with system access, machine builders included, needs a real risk assessment on file, not just a name on a spreadsheet.
Leadership has to complete cybersecurity training themselves under Article 20 and can be held personally liable if risk management falls short.
Swedish manufacturers hold exactly what attackers are looking for: valuable intellectual property, production lines with zero tolerance for downtime and a web of suppliers and machine vendors with standing remote access. By the time most realise they are under attack, the attacker has already been inside for days.
Play ransomware compromised IT systems, causing operational disruption across sites. Deliveries resumed within days. Total cost was estimated at 4.4 MSEK. Source: Nilörngruppen press release.
For the fifth year running, manufacturing was the #1 target with over a quarter of all cyberattacks. Source: IBM X-Force Threat Intelligence Index 2026.
Impacting roughly 3,300 organisations in 2025. Manufacturing was more than two-thirds of all victims. Source: Dragos OT/ICS Cybersecurity Report 2026.
Mean recovery cost for a manufacturing ransomware incident in 2025 excluding any ransom paid. Source: Sophos State of Ransomware in Manufacturing 2025.
What used to be best practice is now the law. Our services directly address all Article 21 technical controls and support Article 20 management accountability through CISO as a Service.
Your risk register gets mapped against both production and IT systems, then kept current for the board.
Watching for the pivot from IT into your production network with a 2m 50s average analyst response.
A 24-hour early warning, a 72-hour notification and a final report within a month, evidence packages and runbooks keep you on schedule.
Every machine vendor, integrator and IT supplier with standing access gets a risk assessment and ongoing monitoring.
Continuity plans built around what actually stops a production line, not a generic office disaster-recovery template.
Office accounts and the systems that touch production get MFA policy, identity monitoring and access hardening.
Web, cloud, API, network and Active Directory tested the way an attacker would including the IT layer closest to production.
Office staff and the shop floor both get phishing simulations and training built for their reality.
Leadership gets a clear, personal answer on NIS2 accountability through board training and governance documentation.
Sweden’s Cybersäkerhetslagen brought NIS2 into national law, and manufacturing is named directly in Annex II. The Manufacturing NIS2 Readiness Checklist maps your current state against Articles 20 and 21, written for the Swedish regulatory context.
Plain language, built for the Swedish regulatory context, takes around 20 minutes to complete.
See where your organisation stands on Articles 20 and 21, mapped in plain language. Board-ready, built for manufacturers, delivered to your inbox instantly.
No spam. EU data residency. Unsubscribe any time.
Five services, one point of contact, no gaps to slip through. eBuilder Security is Sweden-based, Swedish-speaking and knows the vendor relationships and IT/OT boundaries specific to Swedish manufacturers.
Safe AI Adoption
Design files, planning data and quality records are increasingly flowing through AI tools. AIDR watches how those tools are used and where the data actually goes, catching problems as they happen.
Managed Detection & Response
Nobody’s staffing a night shift just to watch for intrusions so we do it for you. The SOC covers endpoints, identities and cloud accounts around the clock plus the IT systems that sit next to your production floor.
Offensive Security
We test web applications, cloud environments, APIs, network infrastructure and Active Directory setups the way an attacker would, then hand you findings ranked by what actually matters first.
Training & Phishing Simulation
Short lessons, built around each role, paired with phishing tests that actually look like the ones your staff will see. Results show up in the numbers from week one, not just a completion certificate.
Strategic Advisory
A full-time CISO doesn’t make sense for most manufacturers’ budgets. You still get senior-level direction on NIS2 governance, MCF reporting and supplier risk, just scaled to what you actually need.
FREE 30-MIN SECURITY REVIEW
Give us 30 minutes and we’ll point at what genuinely needs fixing first, no sales pitch attached.
Talk to a Security AnalystHere’s how eBuilder Security’s SOC responds when a Swedish manufacturer gets hit.
2m 47s
Mean Time to Contain
A Swedish manufacturer was targeted after hours. Our SOC detected anomalous lateral movement, isolated the infected host and notified the responsible IT lead within 2 minutes 47 seconds. No files were encrypted. No production line was disrupted.
94%
NIS2 Readiness Completion
A Swedish manufacturer needed to understand its cybersecurity gaps before preparing leadership reporting. eBuilder Security helped map key areas against NIS2 Article 21 including incident handling, access control, supplier risk and staff awareness.
14 days
Time to Close Critical Findings
A security assessment identified weaknesses in access control including standing remote access left open for a machine vendor. Critical findings were closed and confirmed through retesting within 14 days.
72hrs
Time to MDR Coverage
A manufacturer needed faster detection and response without building an internal 24/7 team and without any disruption to a live production schedule. Coverage activated once access and approvals were in place.
Manufacturers don’t need another vendor promising the world. They need a partner who shows up the same way every time. One of our longest active MDR engagements has run for over 4 years with zero breaches recorded.
See How We Map to Article 21Most vendors quote response times in hours. Ours is minutes, fast enough that an analyst is already on it before real damage happens.
Real analysts, not just automated alerts, watching your environment every hour of every day. Every log stays on Sweden-based infrastructure.
Access approved, and you’re live in our SOC within 72 hours, no multi-quarter rollout project.
eBuilder has run a dedicated cybersecurity practice since 2002, inside a Swedish tech company with a longer history than that.
Our SOC holds ISO 27001 certification, audited by an independent third party, not a badge we awarded ourselves.
Every service ties back to a specific NIS2 Article 21 control, checked against current MCF guidance for manufacturers.
Every third-party vendor with system or remote machine access is assessed and documented, supporting NIS2 Article 21 supply chain requirements.
Manufacturing teams worry that onboarding means downtime on the line, so we built the rollout to work around your production schedule, not the other way round. Most clients are live within 72 hours with zero interruption to the shop floor.
Agents install through your existing device management. Nobody on the shop floor or in the office notices a thing.
Detection systems learn what normal looks like across your environment, so the alerts that follow are the ones that matter.
Your organisation is active inside our 24/7 SOC with a named senior analyst and runbooks built specifically around how you operate.
Monthly summaries and quarterly reviews keep leadership briefed and your NIS2 records audit-ready.
Through their range of security services and our decision to choose their MDR solution, eBuilder Security has significantly elevated our security posture. The transition from project to production has been smooth and their backend team quickly grasped our business needs. eBuilder Security is a valued partner for our future security efforts.
Gerth Ericsson
IT Manager, Vandewiele, Sweden
Real questions a board or plant manager asks before engaging on cybersecurity, answered in two to three sentences.
Yes, if you’re in a covered sub-sector, machinery, electronics, electrical equipment, motor vehicles, medical devices, chemicals or food, with at least 50 employees or over €10 million in turnover. Cybersäkerhetslagen has been in force since 15 January 2026, and it covers your whole business once any part qualifies, not just the in-scope division. Even below the threshold, larger customers are increasingly passing these requirements down contractually anyway.
Essential entities face penalties of up to 10 million euros or 2% of global annual turnover. Important entities face up to 7 million euros or 1.4% of turnover. Beyond fines, supervisory authorities can prohibit a senior manager from exercising management functions.
Article 21(2)(d) requires every third-party vendor relationship to be assessed, documented and kept current and this explicitly includes machine builders, integrators and IT suppliers with remote access to your systems. Standing remote-access accounts left open after a service visit are one of the most common entry points attackers use against manufacturers.
IT support keeps the lights on. MDR is the team watching for the break-in while that’s happening, dedicated analysts monitoring your environment around the clock, investigating anything unusual and shutting it down before it spreads. Most manufacturers don’t have anyone watching at 2am on a Saturday which is exactly when ransomware groups tend to move against a production environment.
Our MDR covers endpoint, identity and cloud monitoring, plus the IT systems that support your production environment. That distinction matters: OT ransomware dwell time averages 42 days, versus 5 days for organisations with full OT visibility. Every factory’s setup differs, so we map exactly where your production network meets what we monitor and we’re upfront if a dedicated OT/ICS specialist would serve you better alongside us.
MDR for Swedish manufacturing is configured around escalation runbooks, NIS2 incident reporting aligned to MCF requirements, data handling in Sweden-based infrastructure and analyst awareness of the IT/OT boundary and vendor access points common in industrial environments.
Yes, if that’s what makes sense for your operation. Deployment is silent enough that most clients don’t need to wait for a shutdown window, but if you’d rather align sensor rollout with a planned changeover or maintenance period, we’ll build the schedule around it rather than the other way round.
Not for the core MDR rollout. Deployment focuses on endpoints, identities and the IT layer around production, not direct connections into PLCs or SCADA. If deeper OT visibility comes up later, that’s a separate conversation with clear boundaries agreed upfront.
No, we’re not in your CAD or PLM systems. What we collect is security telemetry, endpoint activity, identity logs, network and cloud signals, not the content of your design files. Where AIDR is in scope, it watches how AI tools interact with that data, again from a security standpoint, not by reading engineering IP itself.
Mostly three things: engineering designs and product IP, production schedules and order data that let them time an attack for maximum disruption and standard staff and payroll records. The IP angle is what makes manufacturing different from most industries, a stolen design file can be worth more to a competitor than any ransom payment.
A flat monthly fee based on your endpoint count, full stop. Incident response, analyst escalation and alert handling are already in that number, not billed separately. Penetration testing, CISO as a Service and the other add-ons are quoted on their own.
Global platforms are built to sell licenses to enterprise IT departments, not to know your plant. eBuilder Security has worked with Swedish manufacturers and industrial suppliers since 2002, speaks Swedish and sizes the service for teams that don’t have the headcount to run a 24/7 operation themselves.
Book a free 30-minute call with a Sweden-based analyst. We’ll review your current security posture and show how our SOC works in practice, with no sales pitch and no commitment.
Get the Manufacturing NIS2 Checklist