Manufacturing is being transformed by new technologies. While these technologies are not all digital, theyare mostly digitally enabled, i.e., their use is made possible only by dependable electronic sensors, actuators, andother digital devices. Thus, without cyber security, no smart industry. It is against this background that we investigatecyber security practices in Swedish manufacturing. Through a sector-wide survey performed in collaboration the withAssociation of Swedish Engineering Industries, cyber risk perception, existing risk controls, and scope for improvements are mapped. The results are based on 649 questionnaire responses received (a response rate of17%.). Overall, risk perception is relatively low, with only some 15--20% responding that risks are high or very high.About 80% have incurred no incidents in the past year. Business interruption is a much bigger worry than data breach,in line with previous findings. Furthermore, the use of cyber risk controls in Swedish manufacturing industry is still inits infancy, with less than half of respondents having cyber security strategies or continuity plans, and even fewertraining their employees or conducting incident management exercises. The paper is concluded with the identificationof a few interesting follow-up questions for future work.