By Lindsey Munson, managing editor, The American Mold Builder

Advancements in artificial intelligence (AI), digital systems and connected technologies are creating new opportunities across the molding industry to improve productivity, streamline workflows and gain greater visibility into operations. At the same time, these technologies present challenges surrounding cybersecurity, data protection, employee training and long-term technology strategies. For mold shops, understanding where to begin and how to build a solid digital platform is becoming increasingly important.
To explore this topic, The American Mold Builder magazine brought together three industry professionals with unique expertise and experience. Roger Bassous, president of R.E.R. Software, Inc., shared his perspective from decades of experience developing software solutions that help manufacturers improve planning, production tracking and operational visibility. Kristopher Chandler, partner at Benesch Friedlander Coplan & Aronoff LLP, provided insight into the legal, risk management and cybersecurity considerations. Kyle Klouda, president of MSI Mold Builders, offered the viewpoint of inside a mold builder’s shop applying technology in a real-world manufacturing setting.
For small- to medium-sized shops, what does digital readiness look like today, and where should businesses begin?
Bassous: Mold shops vary widely in their level of digital readiness, and in how far they have progressed along their digital transformation journey – with many still in the early stages. Digital readiness falls into two key areas: hardware and software. From a hardware perspective, the first step is to establish a reliable technology infrastructure. This includes networking machines and connecting the PCs, tablets and other devices used throughout the shop floor. From a software perspective, the process begins by identifying where digital solutions can deliver the greatest business value.
Whether the priority is quoting, planning, production tracking or operational oversight, it is important to clearly define the process the company wants to improve and the data it wants to capture or make more accessible. Once those objectives are established, the next step is to evaluate software providers (or internal efforts) and select the solution best aligned with the company’s operational needs, business goals and long-term digital strategy.
Chandler: Digital readiness does not necessarily mean adopting every new technology at once. It means having the systems, data practices and internal discipline to use technology in a way that improves the business without creating unnecessary risk. In practical terms, that includes knowing what digital assets the company has, where critical customer and design data resides, who has access to it, how that access is controlled and how the business would continue operating if a system went down.
Companies should begin with the basics: map the most important business processes and data flows. For example, how does a customer CAD file enter the organization, where is it stored, who can view or modify it, how is it shared with vendors or subcontractors and when is it archived or deleted? That exercise often reveals immediate opportunities to improve efficiency and security at the same time. Many organizations rely on software platforms, cloud storage, ERP systems, machine monitoring tools and outside IT providers. Before adopting new tools, companies should understand who owns the data, how the data may be used, whether the vendor can use it to train AI systems, what security commitments the vendor is making and what happens if the relationship ends.
The best starting point is not usually a major technology overhaul. It is in building a practical digital foundation: create inventory systems, classify sensitive data, tighten access controls, back up critical information and make sure new technology decisions are being made with input from operations, IT, management and legal or contractual advisors where appropriate.
Klouda: For most mold shops, digital readiness isn’t about having every new piece of technology. It’s about being able to find information quickly, know where a job is at and make decisions based on data instead of chasing employees down for answers. A good starting point is looking at how information moves through the shop. From quoting and design to machining, EDM, assembly and sampling, there usually are a few places where information gets stuck or entered multiple times. Fixing those bottlenecks often provides more value than buying new software.
Mold shops get the biggest wins by improving their existing systems, digitizing paperwork where it makes sense and creating better visibility into what’s happening on the floor. Start with the basics and build from there.
From a broader perspective, where can AI provide the greatest value for mold shops, and where should they proceed with caution?
Bassous: The most accessible AI opportunities for mold builders today include data analysis, search, marketing and proposal development. AI can accelerate quoting by reviewing past estimates, identifying similar jobs and potentially automating much of the process. It also can generate marketing images and content while helping employees strengthen proposal-writing skills.
However, companies must consider internal and customer data-privacy requirements before using cloud-based AI tools, as submitted information may be retained or used for model training. AI results should be carefully reviewed, with human oversight before any output is accepted or applied.
Chandler: AI can provide real value to mold builders by helping employees to make better, faster decisions from information the shop already has. Near-term opportunities include quoting support, project scheduling, predictive maintenance, quality analysis, document review, customer communications, inventory planning and identifying patterns in job performance. AI also helps organize institutional knowledge, preserving expertise from veteran employees. One of the most promising applications is analyzing operational data to identify trends behind rework, delays, machine downtime and quoting variance. In that sense, AI is less about replacing skilled employees and more about giving them better information.
Shops should proceed with caution when AI tools touch customer’s confidential information, proprietary designs, trade secrets, pricing models or employee data. Public AI tools are not simply productivity applications – data retention practices, usage rights and terms of use matter. Uploading customer or proprietary information without understanding how it will be used can create contractual, confidentiality and intellectual property risks. Accuracy also requires attention. AI can generate confident but incorrect results, making human oversight essential. Organizations should establish clear policies for AI use, limit sensitive data exposure and begin with lower-risk applications before expanding into more critical business functions.
Klouda: Right now, AI is most valuable when it helps employees work smarter, not when it tries to replace them. Mold building is a highly skilled trade, and AI isn’t going to replace experienced mold designers, programmers or moldmakers anytime soon. The biggest opportunities are with things like quoting, searching historical job data, helping with design reviews, CAM programming assistance, scheduling and finding patterns in shop data. These are areas where employees spend a lot of time digging through information, and AI can speed that up.
The area where shops need to be careful is treating AI output as fact. AI can be a great assistant, but it doesn’t inherently understand tooling, shutoffs, cooling layouts, steel selection or customer requirements the way experienced people do. It should help support decisions, not make critical engineering decisions on its own.
For a company beginning its digital transformation, what is one practical step it can take to improve efficiency, data management or technology adoption?
Bassous: One practical step a mold shop can take today is to measure machine utilization. By identifying idle time, bottlenecks and unrealized machining capacity, a shop can improve scheduling, increase throughput and generate more value from equipment it already owns. This also creates a strong data foundation for future digital transformation efforts.
Chandler: One practical step is to create a simple data and systems inventory. It does not need to be complicated. A shop can start by listing its key systems, what each system is used for, what types of data are stored there, who has access, whether the system is cloud-based or on premises and whether the information is backed up. That inventory creates immediate value because it gives management a clearer picture of the business’s digital operations. It can reveal duplicate tools, inconsistent storage practices, outdated permissions or critical information that only one person can access. It also becomes a foundation for better cybersecurity, vendor management, insurance applications and future technology adoption.
From a legal and risk-management standpoint, this exercise especially is useful because it connects business operations to contractual obligations. Many shops receive customer data under purchase orders, nondisclosure agreements or supplier terms that impose confidentiality, security or data-handling requirements. A shop cannot reliably meet those obligations unless it knows where the data is and who can access it.
Klouda: One of the best things a mold shop can do is create a technology roadmap. Start by evaluating how the business manages data, communicates and uses technology across the organization. Identify the biggest gaps, then prioritize the improvements that will have the greatest impact. It also helps to get an outside perspective. That doesn’t have to mean hiring an expensive consultant. Invite an AMBA member that the company respects to spend a day in the shop and provide honest feedback. Even the solution providers making cold calls can be a valuable resource – they’re often willing to point out opportunities for improvement.
The key is to understand where the shop is today so it can build a realistic plan for the future.
What cybersecurity risks are commonly underestimated by mold builders?
Bassous: Most ransomware incidents and intellectual property losses result from inadequate IT security and insufficient employee training. Limiting administrative access and controlling software installations can significantly reduce the risk of malware from infected downloads. Because phishing attacks increasingly are sophisticated, all employees should be trained to avoid suspicious links and independently verify sensitive requests. For example, confirming wire instructions directly with a vendor rather than relying on email alone.
Chandler: One risk mold builders often underestimate is the sensitivity and value of the data they hold. Many shops understand that they need to protect financial information or payroll data, but they may give less attention to some aspects of customer files, technical drawings, specifications, prototypes, production data, pricing information and communications about future product plans. That information can be highly valuable to customers and competitors, and it may be protected by contractual confidentiality obligations. This is important because a cyber incident at a mold shop may not just be an internal IT problem. It can become a customer relationship issue, a contractual issue and potentially an intellectual property issue. If a shop loses access to files due to ransomware, production can stop. If customer design files are accessed or exfiltrated, the impact may extend beyond the shop’s own operations.
Another commonly underestimated risk is employee access. Many incidents do not start with highly sophisticated attacks. They start with compromised credentials, phishing emails, weak passwords, shared accounts or former employees retaining access longer than they should. For a smaller shop, these issues can feel administrative, but they often are central to real-world cybersecurity risk and contractual and legal exposure.
Klouda: The biggest risk many shops underestimate is the value of their CAD files and design data. Most companies think cybersecurity starts and ends with ransomware, but customer models, tool designs, CAM files, quotes and engineering data are some of the most valuable assets a mold shop has. If those files get into the wrong hands, the damage may not be obvious right away, but it can have a long-term impact on the shop and the customer. The challenge is that these files move around a lot. They’re shared with customers, programmers, vendors and remote employees. Every handoff introduces some level of risk. That’s why protecting intellectual property has to be treated with the same importance as keeping servers and workstations running.
If every mold shop could implement just one cybersecurity best practice this year, which practice would provide the greatest impact, and why?
Bassous: If every mold shop could implement one cybersecurity best practice this year, it should be maintaining secure, regularly tested backups of critical business and production data.
Mold builders rely on valuable CAD files, customer information, machine programs, quotations and operational records. A ransomware attack, hardware failure or accidental deletion can bring production to a halt if that information cannot be recovered quickly. Backups should be automated, stored separately from the main network and tested regularly to confirm that the data actually can be restored. This relatively straightforward step significantly can reduce downtime, protect intellectual property and help a shop recover more quickly from a cyber incident.
Chandler: If one cybersecurity measure had to be prioritized, implementing multifactor authentication would be the recommendation, especially for email, remote access, cloud storage, ERP systems and any system containing customer or business-critical data. Multifactor authentication is not perfect, but it is one of the most practical and effective steps a shop can take to reduce the risk that a stolen password becomes a full compromise. Email is important because it often is the gateway to the rest of the business. If an attacker gains access to an email account, they may be able to impersonate employees, redirect payments, access customer files, reset passwords or gather information for a more targeted attack. Adding multifactor authentication creates an additional barrier that can prevent many credential-based attacks from succeeding.
The key is to implement it thoughtfully. Multifactor authentication should apply to leadership, finance, engineering, project management and anyone with access to sensitive customer or operational data. It also should be paired with basic access reviews so the shop can confirm that employees and vendors only have the access they need.
Klouda: If only one cybersecurity measure could be implemented, it should be multifactor authentication (MFA) across the entire business. Most of the attacks the industry hears about start with a compromised password. MFA adds another layer of protection that can stop attackers even if they already have someone’s login credentials. Priority should be given to Microsoft 365, email, VPN access and remote-access tools, as these systems often serve as the entry point into a company’s network. There are a lot of important cybersecurity controls, but MFA provides companies one of the biggest security improvements for the least amount of effort and cost.
Organizations will need to carefully monitor their current and future compliance obligations as they build their AI infrastructures and increase their reliance on AI tools
What role do employees, training and culture play in protecting a company’s digital systems and data?
Bassous: Employees play the most critical role in cybersecurity. Training them to understand malware and data-privacy risks is the simplest first step, while bulletin-board notices and recurring reminders help keep security top of mind.
Chandler: Employees are essential. Cybersecurity is not just an IT function; it is an operational discipline. A shop can buy good technology and remain vulnerable if employees do not know how to recognize suspicious emails, handle customer files, use approved tools or report concerns quickly. Training should be practical and specific to the shop’s work. Employees should understand why customer data, quotes, specifications and production data matter. They should know when it is acceptable to use personal devices, external drives, cloud-sharing tools or AI applications, and when it is not.
In addition, employees should know how to report a suspected phishing email, lost device or accidental disclosure without fear that they will be blamed for speaking up.
Culture matters because people often avoid reporting mistakes if they think they will be punished. That delay can turn a manageable incident into a serious one. A strong cybersecurity culture encourages employees to pause before clicking, verify unusual requests, question unexpected payment or file-transfer instructions and escalate concerns quickly. Management sets the tone. If leadership treats cybersecurity as a business priority tied to customer trust, quality and continuity, employees are more likely to take it seriously.
For mold builders, that framing is important. Protecting digital systems and data is part of protecting the shop’s reputation and the customer relationships that sustain
the business.
Klouda: The reality is that employees either are the strongest defense or the biggest vulnerability. Most cybersecurity incidents don’t happen because a firewall failed. They happen because someone clicked a malicious link, responded to a phishing email or shared information with the wrong person. That’s why training is critical. Employees don’t need to become cybersecurity experts, but they should know how to recognize suspicious emails, handle customer data properly and report something that doesn’t look right. Creating a good security culture is just as important. When employees feel comfortable asking questions or reporting mistakes without getting blamed, issues get identified much earlier and usually are much easier to contain.
Looking ahead, how are AI, cybersecurity and digital technologies expected to reshape the industry over the next three to five years? what steps should be taken now to prepare?
Bassous: If AI reaches artificial general intelligence, its global impact will be profound. Even without AGI, current AI can and will be used for data analysis, quoting, CAD/CAM, better decision-making and automating routine tasks. The best preparation is to centralize and digitize as much business data as possible so it can deliver value now and support future capabilities.
Cybersecurity equally is important, and achieving CMMC Level 2 or higher will place manufacturers in a strong position. For mold builders outside the defense supply chain, the NIST Cybersecurity Framework 2.0 provides a practical foundation for assessing and improving cybersecurity risk management.
Chandler: Over the next three to five years, digital capabilities are expected to become increasingly tied to competitiveness. Customers will continue to expect faster communication, better visibility, stronger data protection and more sophisticated use of technology throughout the supply chain. AI and data analytics likely will play a larger role in quoting, scheduling, quality control, maintenance and knowledge management.
At the same time, cybersecurity expectations will rise. Customers increasingly may ask suppliers to demonstrate that they have basic controls in place, such as access management, incident response procedures, employee training, backup and secure handling of confidential information. Cybersecurity may become not only a risk-management issue, but also a business development issue.
Over the next few years, those closely monitoring the regulatory environment expect significant state and federal laws and regulations to be implemented governing AI development and deployment. Organizations will need to monitor their current and future compliance obligations as they build their AI infrastructures and increase their reliance on AI tools. Partnering with legal professionals will be important to ensure organizations understand what obligations and exposure are arising from AI usage.
Mold builders should prepare by building a scalable foundation now. That means organizing data, modernizing outdated systems where appropriate, documenting key processes, reviewing vendor and software contracts, adopting reasonable cybersecurity controls and developing clear internal policies for AI use.
Shops do not need to solve everything at once, but they should avoid drifting into digital transformation without governance. The most successful shops will be those that treat technology as part of their overall business strategy.
AI, cybersecurity and digital tools should support craftsmanship, customer service, quality and efficiency. They should not be adopted just because they are new. A thoughtful approach will help mold builders use these technologies to strengthen their operations while protecting the customer trust and proprietary know-how that are central to the industry, all while navigating compliance obligations and legal exposure.
Klouda: Over the next few years, data will become one of the biggest competitive advantages a mold shop can have. AI will continue improving and will be a daily tool for things like quoting, project planning, design review, knowledge sharing and finding information buried in years of historical job data. Shops that can effectively organize and use their data will benefit the most.
At the same time, cybersecurity is going to become increasingly important. As more equipment, software and vendors become connected – the attack surface grows. The best thing shops can do today is get their data organized, strengthen basic cybersecurity practices, clean up access permissions, implement MFA and start testing AI in focused areas where it can deliver real value.
The shops that take those steps will be in a much better position five years from now than the shops that wait.
More information: www.beneschlaw.com, www.msimoldbuilders.com and www.RERSoftware.com


