Direct Action Briefings
Leadership, decision-making, and operational execution under pressure.
Direct Action Briefings
DA Briefing 0045: Navigate Obstacles Rapidly in Manufacturing
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Capability Focus: Navigate Obstacles Rapidly
Industry Focus: Manufacturing Operations
Tool Focus: Critical Intervention
Episode Focus: Suspending untrusted production capability after ransomware and restoring only the operating paths that can be validated.
The ransomware event was the first problem.
The second started when “online” was treated as proof that production could be trusted.
The machines had power.
Operators were available.
Material was staged.
Customer orders were still open.
But the systems supporting production authorization, quality records, lot control, warehouse transactions, traceability, and finished-goods release were still being restored.
In this Direct Action Briefing, Mikey K breaks down what manufacturing leaders must recognize when physical production capability returns before the complete production path can be responsibly defended.
The episode uses the recent fairlife technology disruption as the real-world operating context. Production at its United States facilities was temporarily suspended after unauthorized access affected part of the company’s systems, including production-related systems. Most production later resumed while broader restoration continued.
The public record does not establish that fairlife mishandled the event.
The case matters because it exposes a decision every manufacturer should be prepared to make.
One weak response is to restart because the equipment can run.
Schedules move to spreadsheets.
Instructions move to paper.
Approvals move to phone calls.
Each department creates its own temporary record.
The line produces inventory faster than quality, warehousing, and distribution can establish confidence in it.
The opposite response is to keep every line and facility offline after specific production paths have been separated and validated.
That protects against one exposure while creating new pressure across inventory coverage, labor, material life, distribution, and customer commitments.
Critical Intervention does not mean shutting down everything because the situation sounds serious.
It means acting directly on the production capability that cannot be trusted, preserving unaffected operations where separation is reliable, and treating restart as a second controlled intervention.
The leadership question is not:
Can the machine run?
It is:
Can this production path create output the organization can verify, release, trace, and defend?
A running line is not automatically a trusted line.
Restore only what the operation can validate.
Read the companion article:
https://www.direct-action-system.io/blog/a-running-line-is-not-a-trusted-line
Get the manufacturing-specific Direct Action starter resource:
https://www.direct-action-system.io/manufacturing-starter
Read practical leadership and operations articles on the Direct Action Blog:
https://www.direct-action-system.io/blog
This briefing is part of the Direct Action Briefings series, where Mikey K breaks down practical decision systems for leaders operating under pressure.
Hey, welcome to the briefing. What I'm going to cover with you today is this. A running line is not a trusted line. A factory can have people, equipment, material, customer demand, and open orders. While still having no production path it can responsibly defend. The machines may have power, the operators may be ready, raw material may be staged, the customer may still be waiting. None of that proves the plant can create output. It can verify, release, trace, and stand behind. That is the distinction I want to work through with you. A running line is not automatically a trusted line. In July 2026, Coca-Cola announced that Fairlife had found unauthorized access in part of its systems, including production systems. The company activated incident response and continuity plans, brought in outside cyber specialists and law enforcement, and temporarily suspended Fairlife production in the United States. Eleven days later, the company reported that the majority of production at its four United States facilities had resumed. It also said work to restore impacted systems and operations was continuing, while existing inventory had largely protected retail availability. That sequence matters. Production stopped, most production later resumed, recovery continued. Those are three different operating conditions. Now look, I want to be very clear about the boundary here. This is not a technical postmortem on Fairlife. The public disclosures do not provide enough detail to judge specific shutdown validation, restoration, or restart decisions. Nothing public shows that the company mishandled its response. Actually, the public sequence broadly fits the kind of controlled action a manufacturer may need when production systems are hit. Operations stopped, investigation and recovery began. Production returned in stages, restoration continued. The value of the event is not that it gives us somebody to criticize. The value is that it exposes a plant leadership problem that is harder to ignore. What happens when the plant can move, but the systems controlling, verifying, releasing, or tracing production cannot be trusted. Eventually that becomes a leadership decision. The first problem is the ransomware event. The second problem begins when the organization confuses machine availability with production readiness. Online is a status. Trusted is an operating judgment. Those are not the same thing, and the difference can determine whether the manufacturer protects the objective or creates a second failure during recovery. Now, uh look at the pressure inside the plant. Customer orders do not disappear because technology has been disrupted. Retailers still expect replenishment. Distributors still need allocation information, production planners still see open demand. Raw material may have handling or storage limits. Finished goods inventory continues moving. Employees still need direction. Suppliers still need forecasts. Transportation still needs release information. Executives still want a recovery timeline. The organization begins hearing versions of the same question. Can we keep anything running? That is a reasonable question. It is not reckless to ask it. Downtime is not harmless. A long shutdown cuts inventory, tightens allocations, disrupts labor, threatens material life, and pushes pressure into distribution. The recovery burden spreads. The question is not whether production matters, it does. The question is what the organization must be able to trust before production deserves to resume. That is where leaders fall into two weak extremes. The first is to keep production moving because the physical equipment still appears capable of operating. The machines have power. The operators are present, the material is available, the customer still needs the order, so the organization begins building workarounds. Schedules move to spreadsheets, instructions move to paper, status moves to whiteboards, approvals move to phone calls, teams create manual records, someone starts tracking inventory outside the normal system. Someone else creates a second list because they do not trust the first list. Then a third list appears to reconcile the first two lists, and now the company is conducting a census of its own confusion. Production continues because movement feels better than shutdown. That response can feel practical, it can feel resilient, it can feel like the plant is refusing to surrender the objective. But movement alone is not proof of control. The second extreme is to stop everything and keep everything stopped because nobody wants to own the restart. Every facility is treated as equally exposed. Every line is treated as equally untrustworthy. Every production path stays offline until the entire environment feels perfect. That can also feel responsible. No one wants to authorize a restart and discover the organization moved too early. No one wants their name attached to the decision that created a quality problem, a traceability gap, or a customer failure. So the operation waits and waits and keeps waiting because complete certainty does not arrive on a production schedule. The first response can can create output the manufacturer cannot confidently defend. The second can create unnecessary damage after specific production paths have been separated and sufficiently validated. Neither extreme demonstrates control. The leadership decision is not simply whether to run or stop. The real decision is this. What production capability can no longer be trusted? What must be acted on directly? What unaffected capability can remain protected? What evidence is required before controlled production resumes? That is a harder decision than telling everyone to keep moving. It is also harder than shutting down the entire network and refusing to reconsider it. The leader has to locate the actual interference. Not everywhere the pressure is being felt, where the trust failure sits. Let's place that inside a manufacturing scenario. Renee is the vice president of operations for a multi-site food manufacturer. A ransomware event affects part of the technology environment. The cyber incident team begins isolating impacted systems. Outside specialists are engaged. Production at two facilities is suspended while the organization works to understand the scope of the intrusion. The equipment itself does not appear physically damaged. Operators are available. Material is staged. Customer orders remain open. Finished goods inventory provides some protection, but the buffer is not unlimited. One facility believes it may be able to restart a major packaging line. The proposed path sounds sounds controlled. Run one product family. Use a known material lot. Limit the schedule, create paper records, use temporary manual approvals, hold finished goods until the required checks are complete. Protect the most important customer orders. Do not allow the whole network to remain idle while the investigation continues. That is not a foolish proposal. It may eventually be the correct direction. The plant manager is looking at available people, available equipment, known material, customer demand, and shrinking inventory coverage. The manager is trying to protect the business. Renee's responsibility is not to dismiss that instinct. Her responsibility is to inspect what the proposed restart assumes. Can the plant verify the production sequence? Can it confirm the correct product, formula, component, material, and packaging information? Can the current work instructions be trusted? Can quality complete every required check through an approved path? Can the resulting records be protected, reviewed, and reconciled? Can finished goods be identified correctly? Can lot information remain reliable? Can labels be confirmed? Can warehouse transactions be maintained? Can the organization separate trusted information from information produced by affected systems? Can the output move through release without introducing a second control failure? The visible issue is lost production time. The deeper issue is whether the plant still has a complete and trustworthy path, from production authorization through finished goods release. Those are not the same problem. If Renee focuses only on equipment availability, she may approve a restart that creates output faster than quality, inventory control, warehousing, or distribution can establish confidence in it. If she responds too broadly, she may keep unaffected production capability offline after it has been sufficiently separated and validated. The decision cannot be driven only by fear of downtime. It cannot be driven by fear of ownership. It has to be driven by the actual operating interference. The ransomware event is the initiating condition. The interference forms when production depends on information, systems, approvals, transactions, or controls the organization cannot currently trust. That can affect far more than whether the machinery starts. It can affect production authorization. A line can physically run while one or several of those controls remain unreliable. That is the trap. The equipment may be available. The complete production path may not be. A manufacturer can create inventory faster than it can create confidence in that inventory or see. Then the plant owns a second problem. It is no longer only recovering from a cyber incident. It is also trying to determine what was produced, under which conditions, using which information, with what approval, recorded by whom, and whether the resulting product can be released. The plant may have pallets on the floor, that does not mean it has usable inventory, the cases may be packed, the product may still be held, the line may have produced output, the business may still be unable to allocate or ship it. The pressure to preserve production has now created a larger recovery burden. This is why manual workarounds require discipline. Manual does not automatically mean uncontrolled. Many manufacturers have approved business continuity procedures that include paper forms, offline references, controlled spreadsheets, alternate communication paths, temporary logs, and manual verification. Those methods can be valid when they are planned, protected, owned, and matched to the required controls. But paper does not become accurate through nostalgia. A spreadsheet does not become controlled because someone colored the cells. A verbal approval does not become traceable because five people remember hearing it. A whiteboard does not become an inventory system because it is positioned near the line. And putting the word temporary on a bad process does not make it temporary. Sometimes it just gives the bad process time to settle in and start receiving email. The point is not that manual methods are weak. The point is that the organization still has to understand which controls are required and whether the temporary path can perform those controls reliably. If each department creates its own workaround, the plant may appear active while losing one shared operating picture. Production may have one schedule, planning may have another, quality may maintain a separate release list, the warehouse may track physical inventory on paper, customer operations may work from the last available system report, distribution may have a different understanding of what is ready. Everybody may be acting responsibly inside their own function. The wider operation can still lose control. By this point, the scene has already written itself. Planning, production, quality, and warehousing are standing around four clipboards, each insisting theirs is the legally recognized version of reality, while the palate quietly ages into archaeology. The visual is ridiculous. The operating failure is not. The plant no longer has one shared truth. That is how a reasonable continuity effort becomes a second operating failure. At first, the manufacturer may be able to stabilize the disruption. Affected systems can be isolated. Existing inventory can protect customers temporarily. Unimpacted facilities can preserve some production. Teams can move to protected communication channels. Customer orders can be prioritized. Planning can slow the release of new work. Non-critical production can be deferred. Distribution can manage available inventory carefully, and those are tactical resolution actions. They reduce the immediate interference. They create time. They protect part of the objective while the organization learns more. But tactical resolution has a limit. A temporary control is useful only while it continues protecting the objective. If the affected production path cannot generate output that can be verified, released, and traced under approved controls, the manufacturer cannot keep adding temporary patches around it and call that recovery. The problem has moved beyond inconvenience. The current production path is now directly interfering with the manufacturing objective. The organization may be keeping equipment active while losing confidence in the product, the records, the inventory, or the release path. That is the point where the leader has to recognize that containment is no longer enough. Do not keep stabilizing a problem that now requires direct action. This is where critical intervention enters the read. Critical intervention is used when the problem is active. It is directly interfering with the objective. It cannot be postponed. It cannot be adequately stabilized through tactical resolution. The action point is clear enough to address directly, and the intervention can be contained without creating unacceptable damage around the objective. In this scenario, the action point is not the entire company. The action point is the production capability that depends on information, systems, or controls the organization cannot currently trust. Direct action may require suspending that production path. It may require preserving unaffected operations rather than allowing the shutdown to spread beyond the actual exposure. The intervention is direct because the problem itself must be acted on. The intervention is controlled because the action is bounded to the actual trust failure. Act where the trust failure sits, not everywhere the schedule pressure is felt. That distinction protects the objective in both directions. It prevents the plant from running through a production path it cannot defend. It also prevents the response from damaging unaffected capability simply because the pressure feels broad. Critical intervention is not permission to be dramatic. It is not permission to apply force everywhere. It is not proof that the leader is serious because the largest possible shutdown was ordered. There is always somebody who believes seriousness is measured by how many people they can inconvenience before lunch. That is not leadership. That is theater with a conference bridge. Critical intervention is decisive action aimed at the problem where it sits. Shutdown can be the correct intervention. It is only half the decision. Stopping affected production can protect the manufacturer from creating output under conditions it cannot defend. But the shutdown does not complete the leadership responsibility. The organization still has to determine what capability remains affected. The production shutdown is one intervention. The restart is another. That second intervention deserves just as much discipline as the first. A system becoming available does not automatically mean the dependent production process should resume. That makes restart a controlled production decision, not merely a technical event. The leader has to resist two forms of pressure. The first is the pressure to restore everything at once because the organization is tired of being down. The second is the pressure to keep everything stop because a limited restart feels harder to explain and control. One is uncontrolled optimism. The other is uncontrolled caution. Neither replaces decision quality. The better question is not whether the systems are back. The better question is this. What is the minimum production capability that has been sufficiently validated to resume without introducing unacceptable risk into quality, inventory, warehousing, distribution, or customer commitments. That question does not provide the entire recovery process. It gives the leader the correct target. The objective is not to recreate the appearance of normal operations as quickly as possible. The objective is to restore trustworthy production in controlled stages. Now look at the consequence chain if the plant restarts too early. The line begins running, units are produced, cases are packed, pallets are staged, the immediate production report may look encouraging. Output is moving again. The consequences begin forming behind the visible success. Records require review. Manual entries have to be reconciled. Inventory status becomes uncertain. Finished goods wait for release. Quality teams absorb additional verification work. Warehouse teams maintain temporary controls. Distribution cannot confidently allocate everything the plant produced. Customer operations struggle to explain what is physically available versus what is approved to ship. The organization creates inventory, but confidence in that inventory develops more slowly. The plant may eventually stop stop again. Only now it has more material to review, more records to reconcile, more products sitting in controlled status, and more customer commitments built on uncertain output. The original ransomware disruption created the first operating failure. The premature restart created the second. The line came back from the dead, produced three shifts of inventory, and then asked quality to identify the bodies. That is what uncontrolled recovery looks like. The opposite response also has consequences. If leaders keep every production capability offline after specific paths have been separated and sufficiently validated, finished goods inventory continues shrinking. The recovery response begins creating damage outside the actual exposure. Critical intervention exists between those two failures. It acts directly on the affected path while controlling what the intervention could damage around it. That is why collateral impact matters. The leader is not choosing between a perfect answer and a reckless answer. The leader is choosing among imperfect operating paths under time pressure. That is where discipline matters. Rene cannot make the decision using production pressure alone. Those responsibilities have to remain connected. The cybersecurity team cannot declare production trustworthy by itself. Production cannot declare affected systems clean. Quality cannot protect the organization if leadership treats release control as an obstacle. The plant manager should not be forced to carry a restart decision without the authority, evidence, and support required to make it responsibly. Operators should not be told to keep moving and then blamed later because records, instructions, or controls were unreliable. Justice matters inside this decision. Accountability has to follow authority, information, preparation, support, and control. If the organization gives a team an improvised process, weak information, unclear ownership, and no approved decision boundary, leadership cannot later pretend the resulting confusion was an operator discipline problem. That would be dishonest. The system created the condition. Leadership owns the decision standard. The team owns execution inside the standard it was actually given. That cost belongs to the people who created the operating condition. This is one reason direct intervention needs clear limits. The people executing the shutdown or restart need to know what has stopped. That is not the full critical intervention method. It is the recognition level boundary the listener needs to understand. Direct action without a defined boundary becomes another source of confusion. I have learned that a system coming back online and a system becoming trustworthy are not the same event. I have made versions of that mistake. Not in this exact ransomware scenario, but in the leadership pattern. You see movement return. You feel the pressure release a little. The team looks relieved, the objective suddenly feels reachable again. And you want to believe control returned with it. Sometimes it did. Sometimes the operation is moving because capable people are manually holding together a condition that has not actually recovered. Movement creates relief. Relief can make leaders stop asking whether control returned. That is the dangerous part. The question is not whether something works. The question is what operating responsibility the organization is now asking it to carry. A laptop can open a file. That does not mean the file should control a production release. A machine can accept a command. That does not mean the supporting data deserves decision authority. A system can display green. Green is a color. Trust is evidence. Now, ah, let me make that more precise. Trust is not one piece of evidence. It is the operating judgment that the required controls, dependencies, information, and responsibilities are working well enough to carry the consequence of production. That is a higher standard than the screen turned back on. This applies beyond ransomware. The visible technology may change. The leadership pattern stays similar. The team sees movement returning. Pressure builds to treat movement as recovery. The leader has to determine whether the path is trustworthy enough to support the objective. The better read is not, can the machine run? The better read is, can this production path create output we can verify, release, trace, and defend under the controls required for this operation? The better read is not, are the systems online? The better read is which services and dependencies have returned to a condition that supports trustworthy production. The better read is not how quickly can we return to the original schedule? The better read is what production capability can return without turning recovery pressure into a quality inventory, distribution, or customer failure. That changes the target. The leader stops chasing the appearance of normal operations. The leader begins protecting controlled operations. Critical intervention sits inside Deep In the decision execution and problem navigation module. CSA improves the initial read. Tactical resolution. Solution may contain the initial effect. Critical intervention becomes necessary when those controls cannot adequately protect the objective, and the affected production path must be acted on directly. Pro strengthens the collateral impact read. TMC protects communication, ownership, authority, and follow-through. But the primary tool here remains critical intervention. The problem cannot wait. Containment is no longer enough. The action point is sufficiently clear. The problem must be handled where it sits. Now think about your own operation. What production capability would your organization stop if the supporting information could no longer be trusted? Do not wait until the incident to discover five departments have five definitions of restored. Do not wait until the line is running to discover nobody owns the boundary between technically available and operationally trusted. Do not wait until pallets are staged to ask whether the organization can defend the records behind them. The practical field check is straightforward. First, name the objective. What are you protecting? Production volume may matter, but it may not be the complete objective. The objective may include product integrity, release confidence, traceability, customer availability, and controlled recovery. Second, identify what cannot currently be trusted. Do not stop at broad language such as the network is down or the system is affected. What operating capability has become unreliable? Third, separate physical capability from controlled capability. What can the equipment physically do? What can the organization responsibly verify? Where does the gap form between those two conditions? Fourth, compare the two consequence paths. What happens if production continues? What happens if production stops? Who carries each consequence? What risk spreads if the direct action is too broad or too narrow? Fifth, identify what evidence changes the decision. What supports a limited restart? What requires another stop? What justifies expanding production? What requires the organization to shift to a different problem navigation strategy, and that is recognition. The full critical intervention process goes deeper. It requires a disciplined read of the critical condition, action point, collateral impact, direct action, limits, ownership, communication, reassessment, and fallback. The takeaway for this briefing is simpler. Do not confuse availability with trust. Do not confuse movement with recovery. Do not keep stabilizing a production path that now requires direct action. Do not shut down unaffected capability simply because the pressure feels broad. Stop what cannot be trusted. Protect what remains reliable. Restore only what can be validated. Reassess before expanding the decision. A factory does not recover because its equipment begins moving again. It recovers when the organization can trust the path from authorization through production, verification, release, inventory, and customer delivery. The objective is not movement. The objective is controlled, defensible production. When you are ready to go deeper with critical intervention, go to www.direct action system.io slash course dash directory. Open the course directory, find the course tied to decision execution and problem navigation, and start there. That is where the deeper application belongs. Thanks for listening to the briefing.