Not who should. Who does.
That's the question most electronics manufacturers can't answer with confidence. Somewhere between the ERP system, the shared engineering workstation, the contractor VPN that was supposed to be temporary 14 months ago, and the MES terminal that three shifts use with the same login, the picture gets blurry fast.
And blurry is exactly what attackers count on. Palo Alto's Unit 42 Global Incident Response Report for 2026 found that identity weaknesses played a material role in nearly 90% of incident response investigations. Identity-based techniques, including phishing, stolen credentials, brute force, and insider activity, were the initial access method in 65% of cases.
Manufacturing isn't immune to those numbers. It's worse. IBM's 2026 X-Force data showed valid account abuse accounted for 16% of manufacturing breaches. Not a zero-day. Not a sophisticated exploit. Someone using real credentials they shouldn't have had.
For an electronics manufacturer, that's not an abstract risk. Your Gerber files, your BOM data, your test procedures, your process recipes, these have direct competitive and contractual value. One mismanaged account, one orphaned contractor login, one shared workstation with no session timeout, and the exposure is real.
That's the problem identity and access management is built to solve.

