top of page
T500定制 (72) [轉換]-01.png

Ensuring Unprecedented Safety in a Connected World with Janus.

LATEST NEWS

Ransomware Forces fairlife to Halt U.S. Production: Factory Networks Must Move Beyond Visibility to Control

  • 2 days ago
  • 6 min read

In July 2026, fairlife, a dairy brand owned by The Coca-Cola Company, experienced a ransomware attack. Unauthorized actors accessed certain fairlife systems, including systems related to production. To contain the incident, fairlife temporarily suspended production operations in the United States and activated its incident response and business continuity plans.

The Coca-Cola Company stated that there was no indication that product quality or safety had been affected, and fairlife’s operations in Canada remained unaffected. However, at the time of the announcement, the full scope of the attack, its actual impact, and the timeline for restoring U.S. production were still under investigation.

This incident once again highlights a critical reality for manufacturers:

When digital systems and physical production are deeply interconnected, a cyberattack does not only threaten data. It can determine whether an entire production line continues to operate.

From System Intrusion to Production Shutdown

In a conventional office environment, a cyberattack may temporarily disrupt email, file access, or internal applications.

In smart factories and automated production environments, however, IT systems, manufacturing execution systems, equipment management platforms, engineering workstations, and production machinery are highly interdependent. If one critical component is taken offline, the impact can quickly spread across operations, including:

  • Production scheduling

  • Equipment connectivity and data exchange

  • Raw material, order, and inventory information

  • Quality inspection and product release processes

  • Logistics, shipment, and supply chain coordination

  • The ability to determine which devices and systems remain trustworthy

As a result, having backups does not necessarily mean production can be restored immediately.

The real challenge is whether an organization can determine the security status of its internal network, identify the affected scope, isolate abnormal connections, and gradually restore operations without introducing additional risk.


Food and Manufacturing Companies Are High-Impact Ransomware Targets

Fairlife is not the first consumer or manufacturing business to experience physical supply disruption as a result of a cyberattack.

In 2019, U.S. beverage manufacturer Arizona Beverages suffered a ransomware attack that affected a large number of computers and servers. The company was reportedly unable to process customer orders through its normal computer systems for nearly a week.

In 2025, major U.S. food distributor United Natural Foods, Inc. identified unauthorized activity in parts of its IT environment and proactively took certain systems offline. The incident disrupted order fulfillment and product distribution, resulting in delivery delays and empty shelves at some retail locations.

From beverage production and food distribution to dairy manufacturing, these incidents reveal the same underlying risk:

Attackers do not necessarily need to take direct control of production machinery. Disrupting the digital systems that support production may be enough to halt physical operations.

The IT–OT Boundary Is Disappearing

Traditionally, many organizations treated information technology and operational technology as two relatively separate environments.

As factories adopt remote maintenance, cloud-based management, industrial IoT, data analytics, and automated equipment, the connections between IT and OT continue to increase. Office computers, servers, engineering workstations, manufacturing systems, and production equipment now form a highly interconnected internal network.

This means that perimeter firewalls and endpoint antivirus alerts alone are no longer sufficient.

Once attackers bypass the external perimeter, they often begin exploring the internal network:

  • Which devices are reachable?

  • Which accounts have elevated privileges?

  • Which servers and production systems trust one another?

  • Which network zones lack effective isolation?

  • Which system would cause the greatest operational impact if disrupted?

Without a clear understanding of internal devices and communication relationships, organizations may struggle to determine the attack scope and prevent threats from moving laterally across the network.


Why Visibility Alone Is Not Enough

Many organizations have introduced asset inventory, network monitoring, or traffic analysis tools to identify internal devices and understand how they communicate.

This is an essential first step. However, seeing a risk does not mean the risk is under control.

When an abnormal connection is detected, organizations may still need to answer:

  • Who decides whether the connection is necessary?

  • Who modifies the firewall or switch rules?

  • Does the equipment vendor need to be consulted?

  • Could blocking the connection interrupt production?

  • Must existing policies be revised whenever a new device is added?

  • Are all sites applying the same management standards?

In environments with large numbers of devices and constant operational changes, organizations cannot sustainably rely on manual asset reviews, traffic analysis, policy creation, and rule adjustments.

Monitoring platforms may eventually produce large volumes of alerts and traffic records, while security teams still struggle to answer the most important question:

Which connection should be blocked right now?

Factory network security must therefore move beyond visibility and toward enforceable control.


From Visibility to Control: Building Automated Internal Network Management

Effective internal network security should operate as a continuous management loop.

1. Automatically Discover Internal Assets

Organizations should continuously identify the devices, systems, and communication endpoints operating within the internal network, reducing the gaps and omissions caused by manual inventory processes.

It is not enough to know which devices exist. Organizations should also understand:

  • Where each device is located within the network

  • Which systems it communicates with

  • Which protocols and services it uses

  • Whether new or unknown devices have appeared

  • Whether its communication behavior has changed

2. Establish Communication Baselines

By continuously observing normal communication behavior, organizations can establish network baselines that reflect actual operational requirements.

Unlike policies based only on predefined assumptions, real communication baselines help determine:

  • Which connections are essential to production

  • Which connections are no longer being used

  • Which cross-zone communications lack a valid purpose

  • Which devices are behaving differently from their historical patterns

3. Automatically Generate Least-Privilege Policies

Asset discovery and communication analysis should be converted into enforceable security policies, allowing each device to maintain only the access necessary to perform its intended function.

Policies based on actual behavior can reduce excessive access caused by manual configuration and simplify the deployment of microsegmentation.

4. Prevent Lateral Movement

If a computer, server, or production device is compromised, the impact should not automatically spread across the entire internal network.

Granular segmentation and communication control can restrict the reach of an infected device, preventing a single endpoint incident from becoming a cross-site or production-wide shutdown.

5. Continuously Adapt to Operational Changes

Manufacturing environments are never static.

Devices are added, replaced, or relocated. Production lines are reconfigured, and vendors may require temporary remote access. If security policies cannot adapt to these changes, they quickly become inaccurate or obsolete.

The objective of automated internal network management is not to create a one-time set of rules. It is to continuously identify environmental changes, reassess communication requirements, and keep security policies aligned with actual operations.


Automation Does Not Mean Blocking Everything Automatically

In manufacturing, cybersecurity controls cannot come at the expense of production stability.

Automated internal network management does not mean indiscriminately blocking every unusual connection. Instead, automation helps security and operations teams carry out repetitive and complex tasks more efficiently, including:

  • Asset identification

  • Communication relationship analysis

  • Risk prioritization

  • Policy recommendations

  • Rule deployment

  • Continuous monitoring and adjustment

Changes that may affect production can still be reviewed, simulated, or deployed in stages to ensure that essential process communications are not interrupted.

The value of automation lies in allowing systems to handle large volumes of repetitive, complex, and error-prone work, enabling human teams to focus on risks and decisions that genuinely require expert judgment.


The Key to Ransomware Resilience: Limit the Blast Radius

No organization can guarantee that every email, credential, or device will remain secure forever.

A mature cybersecurity strategy should therefore ask more than:

“Can we prevent attackers from getting in?”

It must also ask:

“If one endpoint is compromised, can we prevent the attack from spreading?”

The suspension of fairlife’s U.S. production demonstrates that digital systems have become inseparable from physical production. Internal network security is therefore no longer only an IT issue. It is a fundamental part of operational continuity.

Organizations need more than additional alerts. They need the ability to continuously understand internal network conditions, control device communications, and rapidly reduce the scope of impact when an incident occurs.


Janus netKeeper: Moving Internal Network Security from Visibility to Control

Janus netKeeper helps organizations establish automated internal network management and microsegmentation capabilities.

By continuously identifying network assets and analyzing real communication behavior, Janus netKeeper supports the creation of internal network policies based on the principle of least privilege.

Organizations can not only visualize devices and communication relationships, but also actively control which devices are allowed to communicate with one another, reducing the risk of unauthorized access and lateral movement.

Through automated policy generation and continuous adjustment, Janus netKeeper reduces the management burden associated with traditional, manually configured segmentation. It enables organizations to gradually build an internal security architecture that is enforceable, maintainable, and sustainable, while preserving operational stability.

Because in the face of ransomware, organizations do not only need to detect attacks faster.

They need to ensure that even when an attack occurs, it cannot spread freely.

From visibility to control, internal network security becomes a true foundation of operational resilience.
Safer with Less Effort.
bottom of page