İçereği Atla

Cybersecurity and Data Backup for Stone Fabricators

24 Ağustos 2026 yazan
Dynamic Stone Tools

Most fabrication shops treat computers as overhead. The saw makes money, the CNC makes money, and the office machine that runs the quoting software is a cost centre nobody thinks about until it stops. That framing is a decade out of date. A modern shop's actual working capital is increasingly digital: the digital templates from every job you have measured, the CAD files and toolpaths built up over years, the machine parameter sets that make your equipment cut the way you have tuned it, the quote history that tells you what a job should cost, and the customer records that let you sell to a builder again next year.

Lose the machines to a fire and insurance replaces them. Lose the data and there is nothing to replace it with, because none of it exists anywhere else. That asymmetry is what makes small manufacturers attractive to ransomware operators and invoice fraudsters alike: the damage is severe, the defences are usually thin, and the victim often has no realistic alternative to paying. The good news is that the controls which actually work at this scale are not expensive or exotic. They are backups you have tested, multi-factor authentication on the accounts that matter, a payment process that cannot be changed by email, and a plan written down before you need it.

What a Fabrication Shop Actually Stands to Lose

Start with the digital template library. A shop that has been laser or photo templating for several years holds thousands of measured jobs, and those files support warranty work, remakes, repeat commercial contracts and any dispute about what was actually measured. The CAD and CAM libraries sit alongside them: nested layouts, edge profile programs, sink and cooktop cutout templates, and the tool libraries that map a program to the specific tooling on your machine. Rebuilding that from scratch is not a weekend of work, it is years of accumulated refinement gone.

Machine controller PCs are the blind spot almost every shop shares. The industrial computer driving a CNC or waterjet typically runs an older operating system that the machine vendor will not let you patch, holds parameter files and compensation tables tuned over the life of the machine, and is almost never included in whatever backup the office runs. When that drive fails or gets encrypted, the shop discovers that the only copy of its machine configuration was on the machine, and that the vendor's factory default is not what the operators have been working with for the past six years.

Then there is the business layer: the accounting system, the quoting and job management software, payroll records, and the customer database with names, addresses, contact details and in some cases stored payment information. If you take card payments, you have obligations about how that data is handled that do not disappear because you are a fifteen-person shop. If you hold builder and designer contact lists, that is the asset your sales effort has been building for a decade and it is worth something to whoever takes it.

The realistic threat picture at this scale is not a targeted attack by a sophisticated crew. It is opportunistic and automated: a phishing email that harvests a password, an internet-facing remote desktop service with a weak login, an unpatched server, or a compromised supplier email account used to send a convincing invoice. The federal guidance published jointly by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA and the MS-ISAC in the #StopRansomware Guide consistently points at those same initial access routes, which is useful because it means a small number of controls covers most of the exposure.

Backups That Survive a Bad Day

The 3-2-1 Rule and Its Modern Extensions

The long-standing baseline is the 3-2-1 rule: keep three copies of your data, on two different types of media, with one copy stored offsite. It has survived because it is simple and because it addresses the three ways backups usually fail, which are a single copy corrupting, a single storage technology failing, and a single location burning down or being burgled. It remains the starting point recommended by federal cybersecurity guidance and it is achievable in any shop with a network drive, a rotation of external disks, and a cloud account.

Ransomware has forced an extension, because attackers now deliberately hunt for and encrypt backup targets before touching production data. The commonly cited modern variant is 3-2-1-1-0: the same three copies on two media with one offsite, plus one copy that is offline or immutable so that it cannot be altered even by an attacker with full network access, and zero errors in verified recovery tests. That extra copy is the whole defence. A backup drive permanently connected by USB, or a cloud sync folder that mirrors deletions, is not a backup against ransomware. It is a second victim.

Backing Up Machine Controllers

Machine controllers need their own procedure because they are usually isolated from the office backup and often cannot run standard backup agents. Ask the vendor how to export parameter files, compensation tables, tool libraries, PLC configuration and any licence keys, and get a written procedure your maintenance lead can follow. Where the controller allows it, take a full disk image of the machine PC so a failed drive can be restored rather than rebuilt. Store those exports with the office backups, and repeat the export whenever a significant change is made rather than on a calendar.

Testing the Restore

An untested backup is a hypothesis. The only thing that proves a backup works is restoring from it, and the failure modes that testing exposes are mundane and lethal: a job that has silently been failing for months, a set of folders nobody added to the selection, an encryption passphrase nobody recorded, a restore that technically works but would take eleven days to pull down over your internet connection. Restore a sample of real files quarterly and do one full restore drill a year to a spare machine, and write down how long each step actually took.

Data set Where it lives Backup approach that works
Digital templates and job files Templating workstation or file server Nightly to server plus cloud; offsite copy retained by job year
CAD and CAM program library Programming workstation Versioned nightly backup; monthly copy to offline media
CNC parameters and tool tables Machine controller PC, often isolated Vendor export procedure after every change; disk image annually
Accounting and quoting system Local server or vendor cloud Confirm vendor retention, then take your own independent export
Customer and contact records Business software or spreadsheets Included in the daily set; access restricted to who needs it
Email and shared documents Cloud productivity suite Third-party backup; provider retention is not a backup

Cloud software vendors protect their platform, not necessarily your ability to recover your data.

The last row deserves emphasis because it catches people out. Subscribing to a cloud accounting package or a hosted email service does not mean your data is backed up in the sense you need. Providers protect against their own infrastructure failing; they generally do not protect you from an employee deleting a mailbox, an attacker purging records with valid credentials, or a subscription lapsing. Read the retention terms, then arrange an independent export or a third-party backup for anything you could not run the business without.

Set retention deliberately rather than by default. Ransomware often sits quietly for weeks before triggering, so a backup scheme that only holds seven days of history may contain nothing but already-compromised copies by the time you discover the problem. Keep daily backups for a few weeks, weekly for a few months, and monthly or annual snapshots for as long as your warranty and contractual obligations require. Template files in particular are worth keeping for the life of the warranty you offer on the work.

Document the whole thing on one page: what is backed up, where it goes, who checks it, how often, and who to call. Backup systems fail silently, and in most small shops the only person who understood the arrangement is the one who left. A one-page description taped inside the server cabinet and stored with the offsite copy is not sophisticated, but it is the difference between a two-hour recovery and a two-week one.

Pro Tip

Once a quarter, physically disconnect your offline backup copy and try to restore three real files from it on a machine that is not part of your network. If you cannot do that in under an hour with the documentation you have on hand, you do not yet have a working backup, whatever the software dashboard says.

Email Fraud and the Accounts Payable Problem

The most common way a shop loses money to a computer is not ransomware. It is business email compromise, where a fraudster either takes over or convincingly imitates a supplier's or executive's email account and gets a real employee to send a real payment to the wrong bank account. The FBI's guidance on business email compromise describes exactly the pattern fabricators see: a familiar supplier writes to say their banking details have changed, the invoice looks right, the amount is plausible, and nothing about the message triggers alarm until the actual supplier calls a month later asking to be paid.

The defence is procedural, not technical, and it is the single highest-value control in this article. No change to supplier payment details is ever actioned on the basis of an email. The person handling payables calls the supplier back on a number already held in your records, never a number contained in the message, confirms the change verbally with a known contact, and records who they spoke to and when. Federal guidance makes the same point about calling a known number rather than one supplied in the request.

Give the rule teeth by making it a policy rather than a preference, and by making sure everyone who can initiate a payment knows that nobody in the company will ever be annoyed at being called to verify. A large share of these frauds succeed because a junior employee received an urgent instruction that appeared to come from the owner and did not feel able to question it. Say out loud, in front of the team, that urgency is itself a warning sign and that verification is never insubordination.

Phishing is the entry point for both fraud and ransomware, and staff training is more effective when it is specific to your trade. Show people the actual messages your shop receives: fake shipping notifications for stone deliveries, spoofed invoices from tooling suppliers, false requests from a general contractor's procurement address. Teach two habits rather than twenty rules, which are to check the sender's full address rather than the display name, and to open the supplier portal directly rather than following a link in a message.

Build a reporting culture that assumes mistakes will happen. The worst outcome is an employee who clicks something, realises it was wrong, and says nothing for three days out of embarrassment. Publish one route for reporting, respond with thanks rather than recrimination, and make clear that reporting a click within minutes turns a possible breach into a password reset. Shops that punish the click end up finding out about incidents from their bank.

Multi-factor authentication and password management carry the rest of the load. Turn on multi-factor authentication for email, banking, accounting, remote access and anything internet-facing, using an authenticator app or hardware key rather than text messages where the option exists. Give every person their own login instead of a shared account, so that access can be revoked when they leave and activity can be attributed. Use a password manager so that unique passwords are actually practical rather than a rule everyone quietly ignores.

Access, Segmentation and Keeping It Working

Separate the machine network from the office network. Controllers on legacy operating systems cannot be patched and should not be reachable from the same network segment as the machine where somebody reads email. A basic segmented setup, with a firewall rule allowing only the specific file transfer you need between programming workstation and controller, prevents an office infection from spreading to production. It is the difference between losing a day of administration and losing the ability to cut stone.

Remote access is how machine vendors support you and it is also a standing open door. Vendor support connections should be disabled by default and enabled only for a scheduled session, with someone in the shop watching, and disabled again afterwards. Never leave remote desktop exposed directly to the internet; put it behind a virtual private network with multi-factor authentication. Ask each vendor in writing how they connect, who at their end has access, and what happens to that access when their technician leaves.

Do vendor due diligence before you commit critical data to a platform. Ask any quoting, templating or job management provider where your data is stored, how you export it in a usable format, what happens to it if you cancel, whether they support multi-factor authentication, and whether they will notify you of a breach. A vendor that cannot answer those questions clearly is telling you something. Getting an answer in the sales conversation is far easier than getting one during a migration.

Patching and lifecycle management need a rhythm. Office computers and servers should install updates automatically, and machines running operating systems that no longer receive security updates need to be either replaced or fully isolated. Keep an inventory of every computer, including the ones nobody thinks about, such as the shop floor terminal, the templating laptop and the office machine in the corner running a single old application. You cannot protect equipment you have forgotten you own.

Write a one-page incident response plan and keep a printed copy, because the plan you need is the one you can read when the screens are locked. It should name who declares an incident, how to disconnect affected machines from the network without powering them off, who calls the insurer and the lawyer, who notifies customers if their data is involved, how to reach law enforcement and file a complaint with the FBI Internet Crime Complaint Center (IC3), and where the backups live with who can restore them.

Review the whole arrangement annually, ideally at the same time as the insurance review. Check whether your cyber coverage exists and what it requires of you, because policies increasingly demand multi-factor authentication and tested backups as a condition. Confirm that leavers have lost access, that the backup covers systems added in the last year, and that whoever handles payables still remembers the callback rule. Security in a small shop is not a project with an end date; it is a short annual checklist someone owns.

Protecting the digital side of the business is the same discipline as protecting the physical side: know what you have, control who touches it, and keep a spare. If you are reviewing shop systems this year, it is also a good moment to make sure the machine files, tooling libraries and setup sheets those systems hold are backed up alongside the office data, and our full catalog covers the consumables and machinery that keep production moving. The team at Dynamic Stone Tools can help you specify tooling that matches the programs and profiles already in your library.

Keep Production Running While You Tighten the Back Office

We stock the diamond tooling, machinery consumables and shop supplies that fabrication businesses depend on daily. Talk to our team about standardising what your shop keeps on the shelf.

Shop the catalog →

Free Tool

Free Guides & Tools — A set of free calculators and reference guides for planning jobs, tooling and consumables, useful when you are rebuilding standard operating procedures or documenting how your shop actually runs.

Open the free guides →
Dynamic Stone Tools 24 Ağustos 2026
Bu gönderiyi paylaş
Arşivle