
Almost a third of UK manufacturers experienced a cyber incident directly or through their supply chains over the past year, but only around half have an incident response plan in place.
The findings from Make UK’s latest research, reported by The Guardian, reveal a widening gap between how dependent manufacturers have become on connected systems and how prepared they are when those systems fail.
Production downtime and higher operational costs were the most common consequences of disruptive incidents. Among manufacturers affected by an attack on a supplier, 31% reported delays to customer deliveries, while almost a quarter experienced shortages or late deliveries of components and materials.
This reflects the structure of modern manufacturing. Production depends on closely connected systems for scheduling, inventory, logistics, payments and access to technical data. An attacker does not necessarily need to compromise industrial machinery to stop a factory. Disrupting an enterprise system or a critical supplier can be enough to make production unsafe, uneconomic or simply impossible.
The consequences were demonstrated by the 2025 attack on Jaguar Land Rover. JLR shut down its global systems, severely disrupting manufacturing and retail operations. The effects spread across its supplier network, prompting the government to provide a £1.5 billion loan guarantee intended to support companies affected by the shutdown.
Despite this exposure, supplier assurance remains limited. The government’s Cyber Security Breaches Survey 2025/2026 found that only 15% of UK businesses formally reviewed risks from their immediate suppliers, falling to 6% for the wider supply chain. Even among large businesses, fewer than half assessed their direct suppliers.
Closing this gap requires manufacturers to plan around operational consequences rather than treating incident response as an IT exercise. They need to identify which systems and suppliers could halt production, establish workable offline procedures and rehearse how critical operations would be restored. Procurement teams also need proportionate security requirements for suppliers, backed by evidence rather than self-assessment alone.
The National Cyber Security Centre recommends combining baseline controls with business impact assessments, clearly assigned responsibilities and exercises that test whether operations can continue when technology is unavailable. Its supply-chain guidance also encourages organisations to make Cyber Essentials a minimum requirement where appropriate.
Manufacturers cannot remove every dependency or prevent every incident. They can, however, make sure that a failure elsewhere does not automatically become a production crisis. At present, the sector’s reliance on connected operations appears to be growing faster than its ability to withstand their disruption.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543