Back to News

Nearly a Third of UK Manufacturers Hit by Cyber-Attacks as Supply Chain Risk Soars

Nearly a Third of UK Manufacturers Hit by Cyber-Attacks as Supply Chain Risk Soars

On 10 August 2026, a new survey from the manufacturers’ organisation Make UK laid bare an uncomfortable truth for British industry: nearly a third of the country’s manufacturers — 30% — have suffered a cyber-incident in the past year, either directly or through a partner in their supply chain. The finding, drawn from a poll of 123 manufacturing firms, lands at a moment when the sector is still absorbing the shock of the Jaguar Land Rover attack, an incident the Cyber Monitoring Centre estimates cost the UK economy at least £1.9bn and which is now widely regarded as the most expensive cyber event in British history.

For a UK small or medium-sized business, the headline number matters less than the shape of the risk beneath it. Manufacturing does not sit in isolation; it is a web of suppliers, sub-contractors, logistics partners and component makers, each connected to the next by orders, data feeds and increasingly by live systems integration. That interconnection is exactly what makes the sector productive — and exactly what an attacker exploits. When a single link in the chain is breached, the disruption does not stay put. Make UK found that among firms hit through their supply chain, around 30% reported delivery delays or cuts to output, and almost a quarter reported supplier delivery delays or shortages of components and materials. Perhaps most striking of all, only half of the affected manufacturers had a formal incident response plan in place. This article sets out what the survey found, why the threat is escalating, and what a proportionate response looks like for an SME that cannot afford a dedicated security team.

30%
Of UK manufacturers hit by a cyber-incident — directly or via a supply chain partner — in the past 12 months, per Make UK’s survey of 123 firms
£14.7bn
The UK government’s estimate of what cybercrime costs the British economy every year — a steady, structural drain, not a one-off
£1.9bn
The Cyber Monitoring Centre’s floor estimate for the economic cost of the JLR attack — likely the most expensive cyber incident in British history
50%
Only half of affected manufacturers had a formal incident response plan — meaning the other half met a live crisis with no rehearsed playbook

What the Make UK survey actually found

The survey, reported by the Guardian on 10 August 2026, canvassed 123 manufacturers and found that 30% had experienced a cyber-incident over the previous twelve months. Crucially, that figure counts incidents suffered either directly or through the supply chain — a deliberate framing that reflects how modern industrial risk actually travels. A manufacturer may run an impeccable security programme and still be knocked offline because a supplier it depends on, or a customer it integrates with, was the one that fell. In an economy built on just-in-time delivery and tightly coupled production schedules, someone else’s breach becomes your outage.

The operational consequences were concrete. Among those hit through the supply chain, roughly 30% reported delivery delays or reductions in output, and almost a quarter reported that their suppliers had suffered delivery delays or shortages of components and materials. For a manufacturer, those are not abstract IT problems; they are missed shipments, idle production lines, penalty clauses and customers who quietly begin looking elsewhere. A cyber-incident in this sector is measured not only in recovery costs but in the compounding commercial damage of not being able to make and move product.

The single most revealing statistic, however, is about preparedness rather than impact. Only half of the affected manufacturers had a formal incident response plan in place when the incident struck. That means a substantial share of firms were improvising their way through the most stressful operational event a business can face — deciding in the moment who to call, whether to pay, how to communicate with customers, and how to bring systems back safely — with no agreed plan to fall back on. The gap between the businesses that recover quickly and those that do not is very often decided long before the attack, in whether that plan exists and has been rehearsed.

Why this matters even if your own defences are strong

The central lesson of the Make UK survey is that a manufacturer’s risk is no longer bounded by its own perimeter. You can patch every server, train every employee and still be brought down because a supplier, sub-contractor or logistics partner was compromised and the disruption cascaded into your production schedule. That is what “supply-chain risk” means in practice: your exposure is the sum of your own security and the security of every organisation you depend on to make and ship product. The right response is not fatalism but planning — knowing your critical suppliers, understanding how a failure at each would hit you, and having a rehearsed response ready before you need it.

The JLR attack: the shadow over the whole sector

No manufacturer reads a survey like this without thinking of Jaguar Land Rover. The attack, discovered at the end of August last year, shut down systems across all of JLR’s factories, offices and retail operations — a near-total operational stop at one of Britain’s flagship industrial employers. The Cyber Monitoring Centre subsequently estimated that the incident cost the UK economy at least £1.9bn, a figure that makes it, in all likelihood, the most expensive cyber-attack in British history. That estimate is a floor, not a ceiling, and it captures the ripple effect across suppliers, dealers and the wider economy, not merely JLR’s own bill.

In June 2026, the New York Times reported that British law enforcement had reportedly concluded Russian hackers were behind the attack. Whatever the ultimate attribution, the operational facts are what should concentrate the minds of smaller manufacturers: a single intrusion was able to halt production, back-office functions and sales simultaneously, across an entire enterprise, for a sustained period. If an organisation of JLR’s scale and resources can be brought to a standstill, the notion that a smaller firm is somehow beneath an attacker’s notice does not survive contact with the evidence. Attackers increasingly go after the manufacturers precisely because production downtime is so expensive that the pressure to pay is intense.

The JLR case also illustrates why the supply-chain framing matters so much. A large manufacturer sits at the centre of a constellation of smaller suppliers, many of them exactly the kind of UK SME that reads a newsroom like this one. When the anchor firm stops, those suppliers feel it immediately — orders freeze, invoices go unpaid, and cash flow tightens for businesses that had nothing to do with the original breach. Conversely, a compromise that begins at a small supplier can be the route into a much larger target. Supply-chain risk runs in both directions, and every firm in the chain is both a potential victim and a potential vector.

How the story unfolded: a timeline

The current alarm did not arrive out of nowhere. It is the product of a run of incidents and assessments over the past year that together reframed cybersecurity as a core industrial risk rather than a back-office IT concern. The sequence below sets the Make UK survey in that context.

End of August 2025 — The JLR attack is discovered
A cyber-attack shuts down systems across all of Jaguar Land Rover’s factories, offices and retail operations, halting production at one of Britain’s largest manufacturers and sending shockwaves through its supplier base.
Autumn 2025 — The supply-chain fallout spreads
As JLR’s systems stay offline, the disruption cascades to the smaller suppliers and logistics partners that depend on its orders — a live demonstration that a single firm’s outage becomes an entire chain’s problem.
Early 2026 — The Cyber Monitoring Centre puts a number on it
The Cyber Monitoring Centre estimates the JLR attack cost the UK economy at least £1.9bn, framing it as very probably the most expensive cyber incident in British history — and a floor, not a ceiling.
June 2026 — A Russian link is reported
The New York Times reports that British law enforcement had reportedly concluded Russian hackers were behind the JLR attack, underlining that industrial targets are squarely in the sights of capable, well-resourced adversaries.
Through 2026 — AI raises the tempo of attacks
Generative AI systems are reportedly used to autonomously hack into businesses, lowering the effort and skill needed to mount an intrusion and adding fresh urgency to the case for stronger baseline defences.
10 August 2026 — Make UK publishes its survey
A poll of 123 manufacturers finds 30% suffered a cyber-incident in the past year, directly or via the supply chain, with delivery delays and output cuts widespread and only half of affected firms holding a formal response plan.
11 August 2026 — The SME question sharpens
With the NCSC calling cybersecurity a business-critical priority for every manufacturer, attention turns to the smaller suppliers in these chains — the firms with the most to lose and the fewest dedicated resources to defend themselves.

Why the attack surface keeps widening

One of the survey’s most important background findings is structural rather than statistical: the increased connectivity that manufacturers have adopted to raise productivity has, at the same time, widened the attack surface. Once an intruder breaches a single link in the chain, that same connectivity gives them room to move. The very integrations that let a factory schedule production against live supplier data, monitor equipment remotely, and coordinate logistics in real time also create more doors, more trust relationships and more paths for an attacker to travel once inside.

This is the central tension of modern manufacturing. Digitisation delivers real, measurable gains — less downtime, tighter inventory, faster response to demand — and no serious business is going to unplug to be safe. But every new connection is also a new dependency and a new potential point of failure. The chart below is an illustrative threat model of the kinds of connected capability a modern manufacturing environment typically relies on, and therefore the breadth of what an attacker who breaches one link may be able to reach. The percentages are indicative, intended to convey relative exposure rather than a measured audit.

Networked production & control systems (OT)
93%
Supplier & logistics data integrations
88%
Remote monitoring of plant & equipment
82%
ERP & order-management systems
79%
Email & office IT shared with the shop floor
74%
Third-party maintenance & vendor access
68%
Backup & recovery systems reachable from the network
61%

Read that chart as a map of blast radius. The more of these systems sit flat on one network, sharing credentials and trust, the further an intruder travels from a single foothold. The most damaging detail is the last bar: when backup and recovery systems are reachable from the same network an attacker compromises, the one control most businesses assume will save them can be encrypted or deleted alongside everything else. Segmentation — keeping operational technology, office IT and backups in separate, guarded zones — is what shrinks that radius, turning a catastrophic breach into a contained one.

Nearly a third: putting the headline number in perspective

The 30% figure deserves to be sat with rather than skimmed past. It means that in a typical room of ten manufacturers, three have been through a cyber-incident in the last year alone — not over a decade, not as a distant hypothetical, but within the last twelve months. And because the count includes supply-chain incidents, the true reach of disruption is wider still: for every firm that was itself breached, others felt the consequences downstream without appearing in the “directly attacked” column.

30%
Nearly a third of UK manufacturers suffered a cyber-incident — directly or through a supply chain partner — in the past 12 months, according to Make UK’s survey of 123 firms

For an SME, the lesson embedded in that number is about probability, not certainty. A 30% annual incident rate across the sector does not mean any individual firm will definitely be hit this year, but it does mean that treating an incident as a remote, once-in-a-career event is no longer defensible. The businesses that come through best are those that have internalised the odds and prepared accordingly: baseline defences in place, critical suppliers mapped, and a response plan written down and rehearsed. That preparation is what turns a 30% probability from an existential threat into a manageable operational risk.

Where manufacturing SMEs are most exposed

The Make UK finding that only half of affected firms had a response plan points to a wider pattern: the gaps that hurt most in an industrial cyber-incident are rarely exotic. They are the familiar fundamentals, left undone because they never felt urgent until the day they did. The checklist below is ordered by priority. A well-run manufacturer should be able to answer each line with evidence; hesitation on the high-priority items is itself a signal of where the real exposure lies.

The gaps that decide how a manufacturing incident plays out — ranked by priority
A written, rehearsed incident response plan — the control half of affected firms lacked High
Tamper-resistant, offline or immutable backups an attacker cannot reach from the network High
Operational technology segmented from office IT and from the internet High
Multi-factor authentication on remote access, email and administrative accounts High
A mapped view of critical suppliers and how a failure at each would hit production Mid
Prompt patching of internet-facing systems and known-exploited vulnerabilities Mid
Security requirements written into supplier and sub-contractor contracts Mid
Staff awareness of phishing and AI-assisted social engineering across the shop floor Low

Notice that none of these controls requires a large in-house security team. They require discipline, documentation and a partner who keeps them current. This is precisely the ground that a scheme like Cyber Essentials is designed to cover: a government-backed baseline of five technical controls — firewalls, secure configuration, access control, malware protection and patch management — that closes the most common routes an attacker uses. For a manufacturer in someone else’s supply chain, certification is increasingly not just good practice but a condition of winning and keeping contracts.

What a manufacturing cyber-incident can cost, by business size

The financial exposure of an industrial cyber-incident scales with the complexity of the estate and, above all, with how long production stays down. The bands below are indicative rather than precise, intended to help SME leaders frame a proportionate conversation about investment in prevention and recovery. All figures are illustrative and in pounds sterling, and exclude the harder-to-quantify costs of lost contracts and reputational damage.

Business size Typical profile What a serious incident disrupts Indicative cost if poorly prepared
Micro (1–9 staff) Specialist supplier or sub-contractor A single production line, order processing, a handful of key customer relationships £10,000–£40,000
Small (10–49 staff) Component maker or light manufacturer Multiple lines, ERP and stock systems, contractual delivery commitments £40,000–£200,000
Medium (50–249 staff) Multi-site or tier-one supplier Connected OT across sites, regulated data, penalty-bearing supply contracts £200,000–£1m+
Any size in a critical chain Sole-source or safety-critical supplier Downstream customers halted, personal data under UK GDPR, ICO obligations Recovery cost plus contractual and regulatory liabilities

The largest single variable in every row is not the size of the firm but the quality of preparation and the speed of recovery. A manufacturer with segmented systems, tested immutable backups and a rehearsed response plan can absorb an incident that would be existential for one without them. The JLR figure of £1.9bn is a reminder that industrial downtime compounds fast — and that the economics of prevention are almost always favourable against the economics of a prolonged stoppage.

Reactive versus proactive: two ways to hold the risk

Reactive posture

Where many manufacturing SMEs sit today

  • Treat cybersecurity as an IT cost centre rather than a business-critical, board-level risk
  • Have no written incident response plan — the gap half of affected firms discovered mid-crisis
  • Run operational technology, office IT and backups flat on one network with shared trust
  • Assume suppliers are secure without ever asking, mapping the chain, or writing it into contracts
  • Learn about relevant threats from the news rather than from a partner watching on their behalf
  • Carry the full commercial and regulatory liability without the visibility to manage it

Proactive posture

Where Cloudswitched takes you

  • Establish a government-backed baseline with Cyber Essentials and keep the five controls current
  • Hold a written, rehearsed incident response plan with clear roles and communications
  • Segment OT from office IT and isolate tamper-resistant, regularly test-restored backups
  • Map critical suppliers, understand each failure’s impact, and set security terms in contracts
  • Receive proactive notification and plain-English impact assessments when a threat lands
  • Keep a virtual CIO view of cyber and supply-chain risk so accountability stays inside the business
38
Typical manufacturing-SME cyber readiness score (illustrative, out of 100)

The gauge above reflects a common reality rather than a measured average: many manufacturing SMEs sit in the low-to-middle range on readiness, strong on making product but weak on the security fundamentals that keep them making it under pressure. The Make UK finding that only half of affected firms had a response plan is a real-world echo of that score. Moving the needle does not require becoming a security specialist. It requires putting the baseline in place, writing the plan down, testing the backups, and knowing who to call before the crisis arrives.

A practical first step this week

You do not need a security team to make meaningful progress in a single afternoon. Do three things. First, confirm you have a written incident response plan — who decides, who communicates, who restores — and if you do not, draft even a one-page version today. Second, verify that at least one recent backup is genuinely offline or immutable and has actually been test-restored, not just assumed to work. Third, list your three most critical suppliers and ask what would happen to your production if each went dark for a week. Those three steps address exactly the gaps the Make UK survey exposed, and none of them requires new technology — only decisions.

Why the NCSC is calling this business-critical

The National Cyber Security Centre’s director of national resilience, Jonathon Ellison, framed the survey’s message in unambiguous terms: no manufacturer can afford to treat cybersecurity as anything other than a business-critical priority. That language is deliberate. It moves the subject out of the server room and into the boardroom, placing it alongside supply security, health and safety, and financial control as a risk the leadership of a business owns rather than delegates.

The reasoning behind that framing is the same thread running through this whole story. When a cyber-incident can halt production, break delivery commitments and cascade through a supply chain, it is no longer a technical inconvenience — it is a threat to the firm’s ability to trade. And with generative AI systems now reportedly being used to autonomously hack into businesses, the effort required to mount a credible attack is falling even as the potential rewards for hitting a manufacturer rise. The combination of a lower barrier to entry and a higher-value target is precisely why the baseline defences can no longer be optional.

For UK SMEs the practical takeaway is proportion, not panic. You cannot eliminate the risk, and you do not need to match the security budget of a multinational. What you can do is close the common, well-understood gaps that attackers rely on, put the fundamentals beyond doubt, and ensure that accountability for cyber and supply-chain risk sits with someone in the business who is watching for exactly this kind of news. That is the difference between being a passive statistic in next year’s survey and an informed operator who has already acted.

The Make UK findings at a glance

Detail What we know
SourceMake UK survey of 123 UK manufacturers, reported by the Guardian on 10 August 2026
Headline finding30% suffered a cyber-incident — directly or via the supply chain — in the past 12 months
PreparednessOnly half of affected manufacturers had a formal incident response plan in place
Output impactAround 30% of supply-chain-hit firms reported delivery delays or cuts to output
Supplier impactAlmost a quarter reported supplier delivery delays or component and material shortages
Economic backdropUK government estimates cybercrime costs the economy £14.7bn a year
Benchmark incidentThe JLR attack, estimated by the Cyber Monitoring Centre at a minimum £1.9bn cost
JLR scopeSystems shut across all JLR factories, offices and retail operations; discovered end of August 2025
AttributionPer the New York Times (June 2026), UK law enforcement reportedly concluded Russian hackers were behind it
Emerging factorGenerative AI reportedly used to autonomously hack businesses, lowering the barrier to attack
Structural causeIncreased factory connectivity widened the attack surface once one link is breached
Official viewNCSC’s Jonathon Ellison: cybersecurity must be treated as a business-critical priority
Core lessonYour risk is the sum of your own security and every supplier you depend on to make and ship

Related reading from the Cloudswitched newsroom

This survey sits within a run of stories we have covered on the fragility of the connected systems UK SMEs depend on — and the way risk now travels through suppliers rather than stopping at the perimeter. If your production, data or connectivity relies on third parties, the same supply-chain logic applies. See our analysis of the N-central zero-day and how an attack on a managed-service tool cascades to downstream customers, the data-handling lessons of the UKGI data breach, and the operational fallout of the GitHub outage that stalled development teams. On the connectivity that underpins modern manufacturing, read our pieces on the Brawband broadband outage and the full-fibre installation damage that can sever a site in an instant — both reinforcing the same message: the suppliers and infrastructure behind your business are now part of your security and resilience picture.

Turn the survey’s warning into a plan you can prove

Cloudswitched helps UK manufacturers and their suppliers put a government-backed baseline in place with Cyber Essentials — firewalls, secure configuration, access control, malware protection and patch management — and builds the rehearsed response plan that half of affected firms were missing. If this story has left you unsure where you stand, we will help you find out and close the gaps.

Talk to us about Cyber Essentials Certification

Frequently asked questions

What did the Make UK survey actually find?
Make UK polled 123 UK manufacturers and found that 30% — nearly a third — had suffered a cyber-incident in the past twelve months, either directly or through a partner in their supply chain. Among those hit via the supply chain, around 30% reported delivery delays or cuts to output, and almost a quarter reported supplier delivery delays or shortages of components and materials. Perhaps most tellingly, only half of the affected firms had a formal incident response plan in place when the incident struck.
What does “supply-chain cyber risk” mean for a manufacturer?
It means your exposure is no longer bounded by your own defences. A manufacturer can run an impeccable security programme and still be knocked offline because a supplier, sub-contractor or logistics partner it depends on was breached, and the disruption cascaded into its production. In a just-in-time economy, someone else’s incident becomes your outage. It also runs the other way: a compromise that begins at a small supplier can be the route into a much larger target, which is why every firm in a chain is both a potential victim and a potential vector.
Why does the JLR attack matter to my small business?
The Jaguar Land Rover attack, discovered at the end of August 2025, shut down systems across all of its factories, offices and retail operations and is estimated by the Cyber Monitoring Centre to have cost the UK economy at least £1.9bn — probably the most expensive cyber incident in British history. It matters to SMEs for two reasons. First, if an organisation of that scale can be halted, the idea that a smaller firm is beneath an attacker’s notice does not hold. Second, when a large manufacturer stops, the smaller suppliers around it feel the financial shock immediately, whether or not they were the ones breached.
How much is cybercrime costing the UK?
The UK government estimates that cybercrime costs the economy £14.7bn a year. That figure represents a steady, structural drain rather than a series of isolated events, and it captures the cumulative toll of fraud, disruption, recovery costs and lost productivity across the economy. Set against a single incident like the JLR attack — estimated at a minimum of £1.9bn on its own — it underlines how quickly the numbers escalate when critical industrial operations are disrupted.
Why does only having a response plan matter so much?
Because the gap between firms that recover quickly and those that do not is very often decided before the attack, in whether a rehearsed plan exists. Make UK found only half of affected manufacturers had one, meaning the rest were improvising through the most stressful operational event a business can face — deciding in the moment who to call, whether to pay, how to communicate and how to restore safely. A written, tested plan removes that improvisation, shortens downtime and reduces the odds of a costly mistake made under pressure.
How is increased factory connectivity part of the problem?
Manufacturers have adopted greater connectivity — live supplier data feeds, remote equipment monitoring, integrated logistics — to raise productivity, and those gains are real. But the same integrations widen the attack surface: they create more doors, more trust relationships and more paths for an intruder to travel once inside. The answer is not to disconnect but to segment, keeping operational technology, office IT and backups in separate guarded zones so that a breach of one link cannot roam freely across the whole environment.
What is Cyber Essentials and why is it relevant here?
Cyber Essentials is a UK government-backed scheme that sets a baseline of five technical controls — firewalls, secure configuration, user access control, malware protection and security update management. Together they close the most common routes attackers use to get in. For a manufacturer in someone else’s supply chain, certification is increasingly a condition of winning and keeping contracts, because larger buyers want assurance that their suppliers will not be the weak link. It is a proportionate, achievable standard that directly addresses several of the gaps the Make UK survey exposed.
Are attackers really using AI to hack businesses now?
Generative AI systems have reportedly been used to autonomously hack into businesses, which matters because it lowers the effort and skill needed to mount a credible attack. When more capable tooling is available to more people, the volume of attempts rises and smaller, less-defended targets become more attractive. This does not call for panic, but it does raise the value of getting the fundamentals beyond doubt — patching, access control, multi-factor authentication and staff awareness — because those baseline defences blunt exactly the kind of opportunistic, automated intrusion that AI makes cheaper to attempt.
We are a small supplier, not a big manufacturer — are we still a target?
Yes, and often more so. Small suppliers can be the easiest way into a larger, better-defended customer, which makes them attractive to attackers seeking leverage. They are also the firms most exposed when an anchor customer is hit, because a frozen order book and unpaid invoices can threaten cash flow quickly. Being small is not protection; it usually means fewer dedicated resources to defend and recover. The good news is that the highest-value controls — a response plan, tested backups, segmentation, multi-factor authentication and a Cyber Essentials baseline — are all within reach of a small business with the right partner.
How can Cloudswitched help a manufacturing SME?
Cloudswitched helps UK manufacturers and their suppliers put the fundamentals beyond doubt. We guide firms through Cyber Essentials certification to establish a government-backed baseline, build and rehearse the incident response plan that half of affected firms were missing, and design segmented networks and isolated, test-restored backups so a breach of one system cannot take down the whole estate. Through a virtual CIO perspective we keep cyber and supply-chain risk visible and accountable inside your business. If this survey has left you unsure where you stand, we will help you assess your position and close the gaps.

Do not be a statistic in next year’s survey

Nearly a third of UK manufacturers were hit this year, and only half of those affected had a plan. Cloudswitched helps you put a Cyber Essentials baseline, a rehearsed response plan and resilient backups in place — so that when supply-chain risk lands, you are the firm that keeps making and shipping product. Let us show you what good looks like.

Talk to us about Cyber Essentials Certification
Tags:Cyber EssentialsIT SupportVirtual CIONetwork Admin
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services for UK businesses

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

26
  • Virtual CIO

The CIO's Guide to Disaster Recovery Planning

26 Sep, 2025

Read more
20
  • Database Reporting

MySQL Reporting and Analytics for Small Businesses

20 Mar, 2026

Read more
12
  • IT Support

How to Set Up IT for a New Business: A Complete Guide

12 Mar, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.