Where manufacturing actually stops
| Scenario | Typical trigger | What decides the damage |
|---|---|---|
| Fire or explosion | Hot works, fuel storage, dust, external impact | Compartmentation and isolation distances — designed years before |
| Utility failure | Power, gas, water, cooling interruption | Ride-through capacity and safe-shutdown discipline |
| OT / IT incident | Ransomware reaching SCADA or ERP; the line is fine, the control is not | Network segmentation and a rehearsed manual-mode |
| Supplier failure | A single-source input stops arriving | Stock policy and a qualified second source — decided in peacetime |
| Area closure | An incident nearby closes the zone; the facility is intact but inaccessible | Remote monitoring, skeleton-crew permits, restart sequencing |
Two features distinguish manufacturing from office businesses. First, restart is a process, not a switch: lines restart in sequence, with quality checks, purges and safety verifications — a 6-hour stoppage can cost a 20-hour recovery. Second, the physics is fixed: compartments, isolation distances and utility redundancy are decided at design time, which makes the continuity review of any facility change the cheapest insurance you will ever buy.
The manufacturing continuity plan, in five artefacts
- Downtime cost per line. Lost margin, contract penalties, restart cost, scrap — per hour and per day. The number that prices every other decision.
- Safe-shutdown and restart runbooks. Who stops the line, in what order things come back, which checks are non-negotiable. Written for the shift that has never done it.
- Manual-mode for OT/IT loss. Which operations can run without the ERP or MES, on what paper records, for how long — tested once a year.
- Single-source register. Every input with one supplier, one route or one tank — with the mitigation decision recorded: stock, second source, or accepted risk with a name on it.
- First-hours authority. Stopping a line costs money; not stopping it can cost the facility. The authority to decide, in writing, at shift-supervisor reach.
The pattern from regional incidents: facilities rarely die of the event itself — they die of the uncontrolled restart, the missing second source, or the week nobody could enter the zone. All three are plannable.
The GCC context
Industrial facilities in the Emirates sit close to the NCEMA 7000 perimeter — directly if designated critical infrastructure, indirectly as suppliers to those who are. Insurers have sharpened business-interruption questions after recent regional loss events; large buyers run supplier continuity audits. A manufacturer with a tested plan and a priced downtime number answers all three conversations from the same folder.
Frequently asked questions
What is the single highest-value step for a mid-size plant?
The downtime cost per line, honestly computed, then the restart runbook. Together they typically take three to four weeks and change how leadership prices every risk decision after.
How do we handle the drone/airspace scenario without overreacting?
As an area-closure and fire scenario: passive protection where proportionate (mesh over open fuel storage, compartmentation), a 72-hour inaccessibility plan, and business-interruption insurance wording checked for external-impact fire. Operational discipline, no drama.
Our OT network is air-gapped. Is ransomware still relevant?
Ask when the gap was last verified — vendors' remote access, USB procedures, engineering laptops. Most «air-gapped» plants are gapped on the diagram and bridged in practice. The manual-mode rehearsal is cheap insurance either way.