September 25, 2026
September 25, 2026

A stopped production line is not a support ticket. It is lost output, idle labour, scrapped work in progress and a shipment that misses its vessel. Most IT support contracts are still written around office response times, which is why plant managers in Singapore, Johor and Penang so often find their provider technically compliant and practically useless.
The table below is the fastest way to tell whether a provider understands manufacturing. Ask them to describe their service across these seven rows. A generic managed service provider will answer the left column and assume it covers the right.
The single most important row is the fourth. In most plants the machine PC belongs to production, not to IT. A support contract that defines scope as "IT assets" will exclude the exact devices whose failure stops the line. That exclusion is rarely spelled out, and it is usually discovered at two in the morning.

Three structural differences explain almost every failed manufacturing support engagement.
A workstation driving a CNC machine or a packaging line often runs an operating system that the machine builder validated years ago. Patching it can void support from the equipment vendor. Replacing it can require re-validation of the whole cell. The correct answer is not to force the standard corporate patching policy onto it, and it is not to leave it untouched and hope either. It is to isolate it, monitor it, and keep a tested recovery image so that a failed disk becomes a forty minute swap rather than a two day rebuild.
Providers who have only run office estates default to one of the two wrong answers, because their tooling assumes uniform, patchable endpoints.
Support windows are usually negotiated in business hours because that is how contracts are templated. Plants do not run on business hours. A line running a two shift pattern from 6am to 10pm needs cover across sixteen hours. A three shift plant needs cover across all of them. Any gap between the end of the support window and the end of the shift is a period where a stoppage has no owner.
Most service level agreements measure time to first response on a ticket. On a plant floor the number that matters is time to line restart. Those two are only loosely related. A provider can acknowledge a ticket in four minutes, meet its SLA, and still take six hours to restore the line because nobody on the rota knew how to recover that specific machine PC.
This is the same layered structure described in our guide to IT support levels L1, L2 and L3, applied to an environment where escalation delay is measured in units of production.
Almost every article on this subject quotes a single headline number. The two most repeated are roughly USD 260,000 per hour, attributed to Aberdeen research, and roughly USD 125,000 per hour from more recent vendor benchmarks.
Both should be treated with care. When we traced the more recent figure to its source, the publishing page stated the benchmark but cited no study, no sample and no methodology. The Aberdeen figure is now well over a decade old and is reproduced from secondary sources far more often than from the original. Neither number is a defensible basis for a capital request, and a finance director who checks will say so.
The useful approach is to calculate the figure for your own line. It takes about ten minutes and produces a number your finance function will accept.
Cost of one hour of line stoppage:
Run that calculation once, then multiply by your realistic annual stoppage hours attributable to IT and OT faults rather than to mechanical faults. The result is the actual budget envelope for plant IT support, and it is the number that decides whether a night shift retainer is expensive or cheap.
The distinction that matters is between faults that stop the machine and faults that stop the system around the machine. A seized bearing is a maintenance problem. A label printer that will not talk to the MES, a warehouse handheld that has lost its wireless profile, or a machine PC that will not boot after a power dip are IT problems that present as production problems. The second category is the one an outsourced provider can genuinely reduce, and it is the category to size your contract around.

This is where the data is solid, and it is worth being precise about it.
Manufacturing accounted for 27.7% of all cybersecurity incidents in 2025, according to IBM's 2026 X-Force Threat Intelligence Index. That was the fifth consecutive year in which manufacturing was the most attacked industry of any sector. The same research recorded a 44% increase between 2024 and 2025 in the exploitation of public-facing applications.
X-Force's operational technology threat research sharpens the picture for plant environments.
The operationally important finding is where attackers get in. X-Force points to perimeter-facing devices: VPN concentrators, remote desktop gateways and OT protocol converters, several of which allow unauthenticated remote code execution. Attackers are not walking onto the shop floor. They are arriving through the remote access path that was installed so a machine vendor in Germany or Japan could support a piece of equipment in Johor.
That single observation should reshape how a manufacturer scopes IT support. The highest value control is not antivirus on the machine PC. It is knowing every remote access route into the plant, who owns each one, whether it is still needed, and whether it is brokered through a monitored gateway or is a vendor tool sitting on a shared password.
Any provider you are evaluating should be able to produce that inventory within the first month. Building and maintaining it is a core part of what security management covers, and unlike most security promises it is measurable.

Use this as a review checklist against any proposal. Each row is a clause that is routinely missing.
The asset scope row and the OT boundary row are where disputes originate. Settle both in writing before signature, with production engineering in the room rather than only IT and procurement.
Preventive work matters more here than in an office estate, because the cost of a failure is asymmetric. Scheduled system maintenance and updates planned around production shutdowns, combined with proactive monitoring that flags a failing disk or a drifting clock before it stops a line, changes the economics of a support contract more than faster ticket response ever will.
Round the clock cover can be delivered in three ways, and the difference between them shows up on the night shift.
A local team on standby is the most expensive per hour and the hardest to sustain, because a small plant IT team covering three shifts either burns out or turns over. A far offshore team is cheaper but works in a different day. When a line stops at 9pm in Penang, an engineer in Eastern Europe is asleep, and the person who answers is a first line agent reading a script rather than an engineer who knows the plant.
The third option is a delivery centre close enough to share the working day. This is where regional geography does real work. Vietnam is one hour behind Singapore and Malaysia. A team in Ho Chi Minh City is present for the entire Singapore and Malaysian business day and for most of a two shift pattern, without night shift premiums and without the handover losses that come with a six or seven hour gap.
That overlap is the operational argument for the model Serdao runs, with European management and delivery from Vietnam. It is why our technical support practice is structured around shared working hours rather than a follow the sun rota that hands your plant to a different continent every eight hours.
The same principle applies to escalation. An L2 engineer who has been in the same time zone as your plant for the last six hours already knows what changed this morning. One who has just come on shift on the other side of the world does not.

For most manufacturers in Singapore and Malaysia with more than one site, the hybrid model is the realistic answer. One internal person who owns plant IT strategy and vendor relationships, supported by an external team that carries the rota, the monitoring and the escalation depth. Our comparison of outsourced versus in-house maintenance and support works through the trade-off in more general terms.
Transitions fail when they start with the contract instead of the asset register. This sequence produces the fewest surprises.
Days 1 to 7. Inventory. Walk the floor with production engineering. List every device that touches production and is not itself a machine: machine PCs, HMIs, scanners, label printers, scales, terminals. Record operating system, machine vendor, warranty conditions and who currently supports it. This walk almost always finds devices nobody in IT knew existed.
Days 8 to 14. Map remote access and network zones. Identify every route into the plant network from outside, including machine vendor tools. Document the boundary between the corporate network and the OT network, and note where that boundary does not actually exist.
Days 15 to 21. Define severity and coverage. Agree the severity model with production, map coverage to the real shift calendar including planned shutdowns, and write the OT boundary clause.
Days 22 to 27. Build runbooks and recovery images. Capture a tested restore image for every machine PC and write a one page runbook per critical station. This is the deliverable that decides whether an outsourced team is useful at 3am.
Days 28 to 30. Shadow, then switch. Run the provider alongside the current arrangement for a few days before cutover, with a named rollback decision point.
Do not compress the first seven days. Every later step depends on the inventory being right, and every failed transition we have reviewed either skipped it or rushed it.

Conclusion
If your line has stopped in the last quarter for a reason that was not mechanical, the gap is worth measuring. Serdao has run technical support for manufacturing, logistics and banking clients for over eighteen years, from a delivery centre in Ho Chi Minh City that shares the working day with Singapore and Malaysia, under European management.
The practical first step is a review of your plant asset register and remote access routes against the checklist above. Talk to our team about a scoped assessment, or read how our helpdesk support service is structured around severity and shift coverage rather than office hours.
Will an outsourced provider touch our PLCs and machine controllers?
It should not, and a good provider will say so in writing. PLC and controller programming belongs to the machine vendor or to internal controls engineering. The provider role is the layer around it: the machine PC, the network path, the data flow to MES and ERP, the backup and the recovery. Ambiguity here is the most common source of dispute, which is why the OT boundary clause matters.
Can machine PCs running old Windows versions be supported at all?
Yes, but through isolation and recovery rather than patching. That means network segmentation so the device cannot be reached from the general corporate network, application allowlisting where the machine vendor permits it, removal of unnecessary remote access, and a tested restore image so a failure becomes a swap rather than a rebuild. Any provider whose only answer is to upgrade the operating system has not worked in a plant.
How quickly should a provider respond when a line stops?
Agree it in terms of production, not tickets. A common structure is a fifteen minute response with a named engineer at line stopped severity, escalation to L2 within a further thirty minutes, and an on-site attendance trigger if the line is still down after an agreed period. What matters more than the numbers is that the clock stops when production restarts, not when the ticket is acknowledged.
Does outsourcing IT support increase our cyber risk?
It changes the risk rather than simply adding to it. Introducing a provider adds a remote access route, which must be brokered through a monitored gateway with individual accounts and logged sessions. Against that, a provider that maintains the remote access register, patches what can be patched and monitors the IT and OT boundary usually removes more exposure than it introduces. The determining factor is whether the arrangement is governed, and that is a contract question.
We run plants in both Singapore and Malaysia. Should we use one provider or two?
One provider with a single asset register and one severity model is almost always better, because multi-site groups lose more time to inconsistent process than to distance. Confirm that the provider can cover both jurisdictions for data handling, and that on-site attendance is genuinely available at each location rather than quietly subcontracted.
What is the first thing to fix if we are not ready to outsource yet?
The remote access register. It is free, it takes a few days, and it addresses the entry point that the IBM X-Force research identifies as the one attackers actually use. Knowing every route into your plant network, and closing the ones nobody needs, is the highest value hour of work available to a manufacturing IT team today.