In the machinery manufacturing industry, the shutdown of a CNC machine tool can mean the halting of an entire production line, and the leakage of a design drawing can mean years of R&D investment going down the drain. Yet for a long time, security building in this industry has faced a dilemma: if management is too strict, there are concerns about disrupting engineers’ access to drawings, delaying production line debugging, and slowing project delivery; if management is too loose, drawings fly everywhere, USB drives are plugged in at will, and industrial computers run unprotected—one ransomware attack can bring the entire workshop to a standstill.
Ping64 was created precisely so that machinery manufacturing enterprises do not have to choose between “security” and “efficiency.”
I. How many security vulnerabilities are exposed during the journey of a single drawing?
A medium-sized machinery equipment manufacturer in Zhejiang, specializing in non-standard automation production lines and precision components, has over eighty workstations in its design department and more than a hundred CNC machines and industrial computers running in its workshops. The company has deployed PLM, ERP, and MES systems, and its level of digitalization is not low. However, security has always been a weak point.
Drawing circulation in the design department is almost completely uncontrolled. Engineers are accustomed to sending drawings via WeChat and QQ, backing up project files to personal cloud drives, and plugging USB drives back and forth between design and the workshop. The IT department has considered enforcing controls, but every time they mention “disabling USB drives” or “restricting WeChat,” the design department pushes back strongly: “The customer is waiting to see the drawings, the supplier is waiting to process them. If you block these, will the work still get done?”
The industrial computers in the workshop are even more troublesome. Most are running Windows 7 or even XP, with almost no patches applied, and antivirus software either cannot be installed or causes severe performance issues once installed. Some equipment still runs control software installed ten years ago, and the original vendors no longer provide maintenance. On one occasion, a worm infected an industrial computer and spread through shared folders to the MES server, causing production data from two workshops to be unable to upload and shutting down the production line for half a day. After the investigation, the source of the virus turned out to be a USB drive brought in by a supplier’s technician.
These problems are not isolated cases. The security risks of machinery manufacturing enterprises are often hidden in these seemingly trivial daily operations.
II. How can security controls avoid becoming a stumbling block to production?
The company eventually chose Ping64. At first, the IT department’s biggest concern was employee resistance, since every previous attempt at control had been rejected by business departments. But Ping64’s approach is not “blanket prohibition” but rather “differentiated management and flexible release.”
For design drawings, the first thing Ping64 did was to make everything “visible.” The platform automatically mapped the design department’s software assets and file flow paths, giving IT a clear picture for the first time: which terminals have unauthorized CAD plugins installed, which files are being copied to USB drives, and which drawings are being sent out via WeChat. With data in hand, management is no longer based on guesswork.
Next, Ping64 set up layered policies for drawing circulation. File sharing within the design department is not affected, and engineers can open, modify, and save drawings as usual. But once a file attempts to be copied to a USB drive, sent through instant messaging tools, or uploaded to a personal cloud drive, the system blocks it in real time and issues a prompt. For scenarios where it is truly necessary—such as taking drawings to a customer site or sending them to an external processing vendor—employees can submit an online request, and after supervisor approval, they receive temporary permission that is automatically revoked when no longer needed. As a result, drawing distribution changed from “unconscious loss of control” to “controlled flow,” and engineers gradually adapted to the new operating path because most normal work was not affected.
For industrial computers in the workshop, Ping64’s strategy is even more refined. The platform can enforce whitelist control on industrial endpoints, allowing only designated control software and CNC program transfer tools to run while prohibiting all other irrelevant software from starting. Even if an employee accidentally inserts a virus-infected USB drive, the virus cannot execute on the industrial computer, cutting off the infection chain at the source.
To address the problem of legacy systems that cannot be patched, Ping64 provides virtual patching and network micro-segmentation capabilities. Industrial computers do not need to upgrade their operating systems, and installing security software will not affect equipment operation. However, the system automatically blocks malicious traffic targeting known vulnerabilities while logically isolating industrial computers from the office network and the external network, allowing only necessary MES data uploads and remote operation and maintenance channels.
III. The Ping64 security platform is also an “efficiency tool.”
Many machinery manufacturing enterprises resist security controls essentially because they worry about increased operational burden. But Ping64’s actual effect is the opposite—it makes many previously cumbersome tasks much simpler.
Take software distribution, for example. In the past, installing a patch or updating control software on workshop industrial computers required IT staff to visit each machine one by one. Some devices are located in cleanrooms, where entering requires changing clothes, making the process extremely inefficient. With Ping64’s software store and remote distribution capabilities, IT can push updates centrally from the backend, and industrial computers install them automatically without anyone needing to be on-site. For equipment distributed across different factory locations, this also saves a significant amount of travel time.
Another example is remote operation and maintenance. When equipment fails, previously the only option was to wait for the supplier’s engineer to arrive on-site, sometimes waiting an entire day. Now, through Ping64’s remote assistance feature, suppliers can remotely connect to troubleshoot problems under controlled and auditable conditions, ensuring fast response while avoiding the security risks of casually opening remote desktop access.
For management, the unified reports provided by Ping64 are also highly valuable. Endpoint security status, software compliance rate, file exfiltration records, and abnormal alert trends can all be seen at a glance. In the past, when IT gave security reports, they had no data and could only verbally describe “we have done a lot of work.” Now, with visual reports, the effectiveness of security investment is visible, and it is easier to justify budget requests to management.
IV. From “fearing incidents” to “daring to innovate.”
After deploying Ping64 for some time, a subtle change occurred in this machinery manufacturing enterprise: security was no longer seen as a department that “restricts business” but as a partner that “safeguards business.” The design department began proactively requesting screen watermarks during critical project stages to prevent external contractors from photographing and leaking information. Workshop supervisors began actively asking what compliance checks should be performed before new equipment is connected. When suppliers visit the site, they have also become accustomed to registering their terminals and undergoing access scans.
Behind this change is the security trust brought by Ping64. When an enterprise knows that its drawings will not easily leak, that the production line will not stop because of a single USB drive, and that supplier access will not bring lateral penetration risks, it dares to advance deeper digitalization—such as connecting more devices to the network, opening remote operation and maintenance, and integrating with upstream and downstream supply chain systems. Security has shifted from being a “cost” to being a source of confidence.
The machinery manufacturing industry is undergoing a leap from traditional manufacturing to intelligent manufacturing, but the premise of this leap is a solid security foundation. The value of Ping64 lies in its integrated approach, which binds together previously fragmented capabilities—endpoint security, data protection, software compliance, network access control, and behavior auditing—into a single rope, enabling enterprises to gain real security control without sacrificing efficiency.