Leverage What You Do Well: Brilliant at the Basics
Manufacturers build our nation, and they do it well.
I grew up in Aerospace manufacturing. Worked a metal lathe when I was sixteen and then taught myself CAD because we got a new laser cutter and that room had air conditioning. Real air-conditioning. I know manufacturers do many things well. Small business owners who can make payroll on 7-10% margins. True Yankees. Too often it feels like the CMMC world looks down down on the Defense Industrial Base because NIST-SP-800-171 requirements have existed for years.
But companies aren’t skimping on security out of necessity. They want to do the right thing, but too often do not know where to begin. I am a fan of the Department of War’s Brilliant at the Basics because it provides a roadmap to getting started.
We need to start with what manufacturer’s do well. A quality program does not begin with the most advanced inspection equipment. It begins with controlled processes. You need trained people and maintained machines. Companies now how to track approved materials in a BOM. They have records that prove the work occurred.
Cybersecurity works the same way.
Brilliant at the Basics
Defense manufacturers often approach NIST SP 800-171 as a list of technical tasks. You might install a firewall, write policies, run a scan, and fill out a System Security Plan. Those activities matter, but a checklist alone does not create a cybersecurity program. A company can buy security tools and still leave major business risks unmanaged.
The better approach is to leverage cybersecurity to get better at business. Address the common conditions that allow attackers to steal credentials, move through a network, expose sensitive data. You do not want bad guys to interrupt production. You do not want some hacker gang to hold systems for ransom. Those basic practices reduce real operational risk while creating many of the policies, procedures, configurations, and records that support NIST SP 800-171.
NIST SP 800-171 is not a cybersecurity framework
NIST SP 800-171 Rev. 3 provides security requirements for protecting the confidentiality of Controlled Unclassified Information, or CUI, in nonfederal systems. It applies to the system components that process, store, or transmit CUI and to components that protect them. 171 is a set of security requirements, and not complete framework for managing a manufacturer’s cybersecurity program.
To pass a CMMC assessment you only have to protect CUI confidentiality. To keep a business running a cybersecurity program must also keep production available. You must preserve the integrity of drawings and inspection data. You need to manage suppliers. Based on the most common attacks your cybersecurity program must prepare your company for incidents with good backups. You need to recover from ransomware without downtime.
Each of these is a risk-based investment decisions. NIST SP 800-171 contributes to that program, but it does not organize the mitigation strategies for the business.
I Use X Framework in my Cybersecurity Program
You can’t build a cybersecurity program around NIST-SP-800-171. Instead you should adopt a framework that builds a program which meets the requirements of NIST-SP-800-171.
I like to start with the NIST Cybersecurity Framework 2.0, which organizes cybersecurity risk around Govern, Identify, Protect, Detect, Respond, and Recover. Another good choise.The CIS Critical Security Controls v8.1, which provide a prioritized set of safeguards against common attacks also works well for manufacturers.
You embed applicable NIST SP 800-171 requirements into that larger program. In practical terms, the framework or control set tells leadership how to manage cybersecurity as an ongoing business function. NIST SP 800-171 tells the company which security outcomes it must achieve for the systems that handle or protect CUI.
Let’s use a framing manufacturers know. think of NIST SP 800-171 as a customer specification inside a mature quality management system. The specification matters, but the management system supplies the governance, ownership, and operating rhythm. It details corrective action, and continuous improvement needed
Become Brilliant at the Basics to Do Business Better
Manufacturers face a difficult mix of business and technical risk. They often depend on older equipment, specialized software, and remote vendor access. They have small or no IT teams, and tight delivery schedules. A patch or configuration change can affect production. A ransomware event can stop the plant. A stolen email or cloud account can expose drawings. An employee can paste sensitive information into an unapproved artificial intelligence service in seconds.
Attackers do not need to defeat every safeguard. They need one workable path. NIST-SP-800-171 does not address many of these risks. As a business owner worry about your information system before you protect the Government’s.
Brilliant at the Basics closes the paths attackers use most often and limits the damage when prevention fails. It helps a manufacturer:
- Reduce account hijacking
- Count the stuff that requires protection;
- Deal with end of life and out dated software
- Segment off legacy OT that can’t get updated.
- Keep an incident in one area from spreading across the business;
- Find and correct vulnerabilities according to operational risk;
- Prevent sensitive data from flowing to unapproved services;
- Restore operations after ransomware or system failure
- Make security part of every employee’s job, not just the IT department’s job.
These outcomes matter even when a particular practice does not directly satisfy a NIST SP 800-171 requirement. CMMC does not care about your backups beyond CUI. A backup architecture protects manufacturers from extended downtime A flexible technology stack reduces operational and supplier risk even though the publication does not require a manufacturer to avoid vendor lock-in.
From manufacturing risk to NIST SP 800-171 controls
Manufacturing often don’t have basics of cyber hygiene place. Why start building to NIST SP 800-171 when you have risks to address that fall outside of 171.
To get better at business get brilliant at the basics:
| Risk to Business | Brilliant at the Basics | SOP | 171 Rev. 3 |
|---|---|---|---|
| Stolen passwords give an attacker access to email, remote connections, cloud systems, or administrator tools. One compromised administrator account can affect the entire company. | 1. Phishing-resistant MFA | Require MFA for every in-scope user and administrator. Prefer phishing-resistant methods such as passkeys, FIDO2 security keys, or certificates. Give administrators separate privileged accounts, limit elevated access, and review privileges regularly. |
Direct: 03.05.03 Multi-Factor Authentication; 03.05.04 Replay-Resistant Authentication. Supporting: 03.01.05 Least Privilege; 03.01.06 Privileged Accounts. |
| The company cannot protect devices, software, cloud services, or CUI repositories that it does not know exist. Unmanaged assets create blind spots. | 2. Comprehensive asset inventory management | Maintain an inventory of in-scope hardware, software, virtual and cloud assets, identities, CUI repositories, interfaces, owners, support status, and authorization status. Reconcile the inventory after changes and on a defined schedule. |
Direct: 03.04.10 System Component Inventory. Supporting: 03.12.03 Continuous Monitoring. |
| Unsupported operating systems, abandoned applications, unnecessary services, and unapproved software increase the chance of compromise and unplanned downtime. | 3. Strategic technical debt reduction | Track vendor support dates. Replace unsupported components or document and operate alternative protections. Remove unnecessary ports, protocols, features, and software. Maintain secure configurations and an approved-software process. |
Direct: 03.16.02 Unsupported System Components; 03.04.06 Least Functionality; 03.04.08 Authorized Software. Supporting: 03.14.01 Flaw Remediation; 03.11.02 Vulnerability Monitoring and Scanning. |
| A critical security tool or service may become unsupported, unaffordable, insecure, or impossible to replace. Poorly understood supplier dependencies can trap the company in a risky architecture. | 4. Flexible technology stack | Define security engineering principles and approved integration patterns. Evaluate external providers, document service boundaries, place CUI safeguards in contracts, and plan how the company will transition data and services if a supplier relationship ends. | Supporting: 03.16.01 Security Engineering Principles; 03.16.03 External System Services; 03.17.02 Acquisition Strategies, Tools, and Methods; 03.17.03 Supply Chain Requirements and Processes. |
| Malware or ransomware that enters through one workstation can move into engineering systems, CUI repositories, servers, or production networks. | 5. Logical segmentation to limit lateral movement | Define the CUI security boundary and approved data flows. Separate business, guest, CUI, vendor, and production networks according to risk. Use firewalls and access rules that deny traffic by default and allow only approved connections. Test both allowed and blocked paths. | Direct: 03.13.01 Boundary Protection; 03.01.03 Information Flow Enforcement; 03.13.06 Network Communications—Deny by Default—Allow by Exception. |
| Uncorrected vulnerabilities expose the company to compromise, but poorly planned patching can also interrupt specialized systems and production. | 6. Risk-based vulnerability management | Define what the company scans, how often it scans, who reviews findings, and how quickly it responds. Consider severity, exploitability, exposure, production impact, and available safeguards. Assign owners and deadlines, document risk decisions, track corrective actions, and retest fixes. | Direct: 03.11.02 Vulnerability Monitoring and Scanning; 03.11.01 Risk Assessment; 03.11.04 Risk Response; 03.12.02 Plan of Action and Milestones. |
| A custom application, script, integration, or automation can introduce weaknesses that become expensive and disruptive to correct after deployment. | 7. Integrate security early in the development lifecycle | Apply security requirements during specification, design, development, implementation, and operation. Review architectures, manage software dependencies, scan code and components where appropriate, track defects, and require approval before release. |
Direct: 03.16.01 Security Engineering Principles. Supporting: 03.11.02 Vulnerability Monitoring and Scanning; 03.14.01 Flaw Remediation. |
| Employees can place CUI, customer drawings, contract data, or proprietary information into an unapproved public AI service. The provider may retain, reuse, or expose the data. | 8. Secure AI adoption and data protection | Approve AI services by use case and data type. Prohibit CUI in unapproved services. Define acceptable-use rules, assess providers, configure data-loss prevention or web controls where practical, train users, and monitor compliance. Remember that proprietary information does not automatically become CUI; identify and handle each data type according to its actual requirements. | Supporting: 03.01.03 Information Flow Enforcement; 03.01.16 CUI Confidentiality; 03.15.01 Policy and Procedures; 03.15.03 Rules of Behavior; 03.16.03 External System Services. |
| Ransomware, equipment failure, or administrative error can stop production or destroy access to critical records. Unprotected backups can also expose CUI. | 9. Resilient backup and disaster recovery architecture | Encrypt backup data, restrict and monitor backup administration, separate backup credentials, protect encryption keys, verify backup jobs, and test restoration. Connect recovery activities to incident response and risk decisions. | Supporting: 03.13.08 Transmission and Storage Confidentiality; 03.13.11 Cryptographic Protection; 03.11.04 Risk Response; 03.06.01 Incident Handling. |
| Employees, administrators, engineers, executives, and incident responders may not understand their security responsibilities. Knowledge may reside with one person or one service provider. | 10. Continuous technical workforce readiness | Train all in-scope personnel on CUI handling, phishing, AI use, and incident reporting. Create role-specific training for administrators, developers, CUI handlers, incident responders, and executives. Track course content, attendance, completion, and required refreshers. | Direct: 03.02.01 Literacy Training and Awareness; 03.02.02 Role-Based Training. |
For a full mapping check out this spreadsheet
Quality of Your Cyber Hygiene
As a manufacturer leverage what you do well. Build controls the way you build quality
Manufacturers should resist the urge to begin with a stack of policies copied from templates. You need to leverage procedures to drive your work flows. Then develop plans to integrate these SOPs/
For each risk and mapped NIST requirement, build four connected layers:
- Policy: What does leadership require, and why?
- Procedure: Who performs the work, when do they perform it, and what happens when something fails?
- Implementation: Which people, processes, configurations, and technologies enforce the requirement?
- Evidence: Which records prove that the company performs, reviews, tests, and improves the control?
For example, a one-page MFA policy has little value if users can still connect through an old protocol that bypasses MFA. The manufacturer needs an enforced authentication configuration, an exception process, test results, enrollment records, and periodic review. Likewise, a network diagram does not create segmentation. Firewall rules, approved flows, change records, monitoring, and test results make segmentation real.
This approach should feel familiar. A written work instruction does not prove that a manufacturing process operated correctly. The company also needs trained personnel, calibrated equipment, completed records, inspection results, and corrective action. Cybersecurity requires the same operational discipline.
Good Operations Lead to Strong Compliance
The strongest manufacturers do not separate cybersecurity from the business. They treat it as part of quality, production resilience, supplier management, engineering, workforce development, and executive risk management.
NIST SP 800-171 provides essential requirements for protecting CUI, but it should sit inside a broader program based on CSF 2.0 or the CIS Controls. Brilliant at the Basics gives manufacturers a practical place to begin. It addresses the everyday weaknesses that cause many security incidents, reduces the likelihood and impact of business disruption, and creates a foundation for many NIST SP 800-171 controls.
Start with the risks. Build the operating discipline. Map the resulting controls to the requirements. Then collect the evidence that proves the program works.