On 10 August 2026, a new survey from the manufacturers’ organisation Make UK laid bare an uncomfortable truth for British industry: nearly a third of the country’s manufacturers — 30% — have suffered a cyber-incident in the past year, either directly or through a partner in their supply chain. The finding, drawn from a poll of 123 manufacturing firms, lands at a moment when the sector is still absorbing the shock of the Jaguar Land Rover attack, an incident the Cyber Monitoring Centre estimates cost the UK economy at least £1.9bn and which is now widely regarded as the most expensive cyber event in British history.
For a UK small or medium-sized business, the headline number matters less than the shape of the risk beneath it. Manufacturing does not sit in isolation; it is a web of suppliers, sub-contractors, logistics partners and component makers, each connected to the next by orders, data feeds and increasingly by live systems integration. That interconnection is exactly what makes the sector productive — and exactly what an attacker exploits. When a single link in the chain is breached, the disruption does not stay put. Make UK found that among firms hit through their supply chain, around 30% reported delivery delays or cuts to output, and almost a quarter reported supplier delivery delays or shortages of components and materials. Perhaps most striking of all, only half of the affected manufacturers had a formal incident response plan in place. This article sets out what the survey found, why the threat is escalating, and what a proportionate response looks like for an SME that cannot afford a dedicated security team.
What the Make UK survey actually found
The survey, reported by the Guardian on 10 August 2026, canvassed 123 manufacturers and found that 30% had experienced a cyber-incident over the previous twelve months. Crucially, that figure counts incidents suffered either directly or through the supply chain — a deliberate framing that reflects how modern industrial risk actually travels. A manufacturer may run an impeccable security programme and still be knocked offline because a supplier it depends on, or a customer it integrates with, was the one that fell. In an economy built on just-in-time delivery and tightly coupled production schedules, someone else’s breach becomes your outage.
The operational consequences were concrete. Among those hit through the supply chain, roughly 30% reported delivery delays or reductions in output, and almost a quarter reported that their suppliers had suffered delivery delays or shortages of components and materials. For a manufacturer, those are not abstract IT problems; they are missed shipments, idle production lines, penalty clauses and customers who quietly begin looking elsewhere. A cyber-incident in this sector is measured not only in recovery costs but in the compounding commercial damage of not being able to make and move product.
The single most revealing statistic, however, is about preparedness rather than impact. Only half of the affected manufacturers had a formal incident response plan in place when the incident struck. That means a substantial share of firms were improvising their way through the most stressful operational event a business can face — deciding in the moment who to call, whether to pay, how to communicate with customers, and how to bring systems back safely — with no agreed plan to fall back on. The gap between the businesses that recover quickly and those that do not is very often decided long before the attack, in whether that plan exists and has been rehearsed.
The central lesson of the Make UK survey is that a manufacturer’s risk is no longer bounded by its own perimeter. You can patch every server, train every employee and still be brought down because a supplier, sub-contractor or logistics partner was compromised and the disruption cascaded into your production schedule. That is what “supply-chain risk” means in practice: your exposure is the sum of your own security and the security of every organisation you depend on to make and ship product. The right response is not fatalism but planning — knowing your critical suppliers, understanding how a failure at each would hit you, and having a rehearsed response ready before you need it.
The JLR attack: the shadow over the whole sector
No manufacturer reads a survey like this without thinking of Jaguar Land Rover. The attack, discovered at the end of August last year, shut down systems across all of JLR’s factories, offices and retail operations — a near-total operational stop at one of Britain’s flagship industrial employers. The Cyber Monitoring Centre subsequently estimated that the incident cost the UK economy at least £1.9bn, a figure that makes it, in all likelihood, the most expensive cyber-attack in British history. That estimate is a floor, not a ceiling, and it captures the ripple effect across suppliers, dealers and the wider economy, not merely JLR’s own bill.
In June 2026, the New York Times reported that British law enforcement had reportedly concluded Russian hackers were behind the attack. Whatever the ultimate attribution, the operational facts are what should concentrate the minds of smaller manufacturers: a single intrusion was able to halt production, back-office functions and sales simultaneously, across an entire enterprise, for a sustained period. If an organisation of JLR’s scale and resources can be brought to a standstill, the notion that a smaller firm is somehow beneath an attacker’s notice does not survive contact with the evidence. Attackers increasingly go after the manufacturers precisely because production downtime is so expensive that the pressure to pay is intense.
The JLR case also illustrates why the supply-chain framing matters so much. A large manufacturer sits at the centre of a constellation of smaller suppliers, many of them exactly the kind of UK SME that reads a newsroom like this one. When the anchor firm stops, those suppliers feel it immediately — orders freeze, invoices go unpaid, and cash flow tightens for businesses that had nothing to do with the original breach. Conversely, a compromise that begins at a small supplier can be the route into a much larger target. Supply-chain risk runs in both directions, and every firm in the chain is both a potential victim and a potential vector.
How the story unfolded: a timeline
The current alarm did not arrive out of nowhere. It is the product of a run of incidents and assessments over the past year that together reframed cybersecurity as a core industrial risk rather than a back-office IT concern. The sequence below sets the Make UK survey in that context.
Why the attack surface keeps widening
One of the survey’s most important background findings is structural rather than statistical: the increased connectivity that manufacturers have adopted to raise productivity has, at the same time, widened the attack surface. Once an intruder breaches a single link in the chain, that same connectivity gives them room to move. The very integrations that let a factory schedule production against live supplier data, monitor equipment remotely, and coordinate logistics in real time also create more doors, more trust relationships and more paths for an attacker to travel once inside.
This is the central tension of modern manufacturing. Digitisation delivers real, measurable gains — less downtime, tighter inventory, faster response to demand — and no serious business is going to unplug to be safe. But every new connection is also a new dependency and a new potential point of failure. The chart below is an illustrative threat model of the kinds of connected capability a modern manufacturing environment typically relies on, and therefore the breadth of what an attacker who breaches one link may be able to reach. The percentages are indicative, intended to convey relative exposure rather than a measured audit.
Read that chart as a map of blast radius. The more of these systems sit flat on one network, sharing credentials and trust, the further an intruder travels from a single foothold. The most damaging detail is the last bar: when backup and recovery systems are reachable from the same network an attacker compromises, the one control most businesses assume will save them can be encrypted or deleted alongside everything else. Segmentation — keeping operational technology, office IT and backups in separate, guarded zones — is what shrinks that radius, turning a catastrophic breach into a contained one.
Nearly a third: putting the headline number in perspective
The 30% figure deserves to be sat with rather than skimmed past. It means that in a typical room of ten manufacturers, three have been through a cyber-incident in the last year alone — not over a decade, not as a distant hypothetical, but within the last twelve months. And because the count includes supply-chain incidents, the true reach of disruption is wider still: for every firm that was itself breached, others felt the consequences downstream without appearing in the “directly attacked” column.
For an SME, the lesson embedded in that number is about probability, not certainty. A 30% annual incident rate across the sector does not mean any individual firm will definitely be hit this year, but it does mean that treating an incident as a remote, once-in-a-career event is no longer defensible. The businesses that come through best are those that have internalised the odds and prepared accordingly: baseline defences in place, critical suppliers mapped, and a response plan written down and rehearsed. That preparation is what turns a 30% probability from an existential threat into a manageable operational risk.
Where manufacturing SMEs are most exposed
The Make UK finding that only half of affected firms had a response plan points to a wider pattern: the gaps that hurt most in an industrial cyber-incident are rarely exotic. They are the familiar fundamentals, left undone because they never felt urgent until the day they did. The checklist below is ordered by priority. A well-run manufacturer should be able to answer each line with evidence; hesitation on the high-priority items is itself a signal of where the real exposure lies.
Notice that none of these controls requires a large in-house security team. They require discipline, documentation and a partner who keeps them current. This is precisely the ground that a scheme like Cyber Essentials is designed to cover: a government-backed baseline of five technical controls — firewalls, secure configuration, access control, malware protection and patch management — that closes the most common routes an attacker uses. For a manufacturer in someone else’s supply chain, certification is increasingly not just good practice but a condition of winning and keeping contracts.
What a manufacturing cyber-incident can cost, by business size
The financial exposure of an industrial cyber-incident scales with the complexity of the estate and, above all, with how long production stays down. The bands below are indicative rather than precise, intended to help SME leaders frame a proportionate conversation about investment in prevention and recovery. All figures are illustrative and in pounds sterling, and exclude the harder-to-quantify costs of lost contracts and reputational damage.
| Business size | Typical profile | What a serious incident disrupts | Indicative cost if poorly prepared |
|---|---|---|---|
| Micro (1–9 staff) | Specialist supplier or sub-contractor | A single production line, order processing, a handful of key customer relationships | £10,000–£40,000 |
| Small (10–49 staff) | Component maker or light manufacturer | Multiple lines, ERP and stock systems, contractual delivery commitments | £40,000–£200,000 |
| Medium (50–249 staff) | Multi-site or tier-one supplier | Connected OT across sites, regulated data, penalty-bearing supply contracts | £200,000–£1m+ |
| Any size in a critical chain | Sole-source or safety-critical supplier | Downstream customers halted, personal data under UK GDPR, ICO obligations | Recovery cost plus contractual and regulatory liabilities |
The largest single variable in every row is not the size of the firm but the quality of preparation and the speed of recovery. A manufacturer with segmented systems, tested immutable backups and a rehearsed response plan can absorb an incident that would be existential for one without them. The JLR figure of £1.9bn is a reminder that industrial downtime compounds fast — and that the economics of prevention are almost always favourable against the economics of a prolonged stoppage.
Reactive versus proactive: two ways to hold the risk
Reactive posture
Where many manufacturing SMEs sit today
- Treat cybersecurity as an IT cost centre rather than a business-critical, board-level risk
- Have no written incident response plan — the gap half of affected firms discovered mid-crisis
- Run operational technology, office IT and backups flat on one network with shared trust
- Assume suppliers are secure without ever asking, mapping the chain, or writing it into contracts
- Learn about relevant threats from the news rather than from a partner watching on their behalf
- Carry the full commercial and regulatory liability without the visibility to manage it
Proactive posture
Where Cloudswitched takes you
- Establish a government-backed baseline with Cyber Essentials and keep the five controls current
- Hold a written, rehearsed incident response plan with clear roles and communications
- Segment OT from office IT and isolate tamper-resistant, regularly test-restored backups
- Map critical suppliers, understand each failure’s impact, and set security terms in contracts
- Receive proactive notification and plain-English impact assessments when a threat lands
- Keep a virtual CIO view of cyber and supply-chain risk so accountability stays inside the business
The gauge above reflects a common reality rather than a measured average: many manufacturing SMEs sit in the low-to-middle range on readiness, strong on making product but weak on the security fundamentals that keep them making it under pressure. The Make UK finding that only half of affected firms had a response plan is a real-world echo of that score. Moving the needle does not require becoming a security specialist. It requires putting the baseline in place, writing the plan down, testing the backups, and knowing who to call before the crisis arrives.
You do not need a security team to make meaningful progress in a single afternoon. Do three things. First, confirm you have a written incident response plan — who decides, who communicates, who restores — and if you do not, draft even a one-page version today. Second, verify that at least one recent backup is genuinely offline or immutable and has actually been test-restored, not just assumed to work. Third, list your three most critical suppliers and ask what would happen to your production if each went dark for a week. Those three steps address exactly the gaps the Make UK survey exposed, and none of them requires new technology — only decisions.
Why the NCSC is calling this business-critical
The National Cyber Security Centre’s director of national resilience, Jonathon Ellison, framed the survey’s message in unambiguous terms: no manufacturer can afford to treat cybersecurity as anything other than a business-critical priority. That language is deliberate. It moves the subject out of the server room and into the boardroom, placing it alongside supply security, health and safety, and financial control as a risk the leadership of a business owns rather than delegates.
The reasoning behind that framing is the same thread running through this whole story. When a cyber-incident can halt production, break delivery commitments and cascade through a supply chain, it is no longer a technical inconvenience — it is a threat to the firm’s ability to trade. And with generative AI systems now reportedly being used to autonomously hack into businesses, the effort required to mount a credible attack is falling even as the potential rewards for hitting a manufacturer rise. The combination of a lower barrier to entry and a higher-value target is precisely why the baseline defences can no longer be optional.
For UK SMEs the practical takeaway is proportion, not panic. You cannot eliminate the risk, and you do not need to match the security budget of a multinational. What you can do is close the common, well-understood gaps that attackers rely on, put the fundamentals beyond doubt, and ensure that accountability for cyber and supply-chain risk sits with someone in the business who is watching for exactly this kind of news. That is the difference between being a passive statistic in next year’s survey and an informed operator who has already acted.
The Make UK findings at a glance
| Detail | What we know |
|---|---|
| Source | Make UK survey of 123 UK manufacturers, reported by the Guardian on 10 August 2026 |
| Headline finding | 30% suffered a cyber-incident — directly or via the supply chain — in the past 12 months |
| Preparedness | Only half of affected manufacturers had a formal incident response plan in place |
| Output impact | Around 30% of supply-chain-hit firms reported delivery delays or cuts to output |
| Supplier impact | Almost a quarter reported supplier delivery delays or component and material shortages |
| Economic backdrop | UK government estimates cybercrime costs the economy £14.7bn a year |
| Benchmark incident | The JLR attack, estimated by the Cyber Monitoring Centre at a minimum £1.9bn cost |
| JLR scope | Systems shut across all JLR factories, offices and retail operations; discovered end of August 2025 |
| Attribution | Per the New York Times (June 2026), UK law enforcement reportedly concluded Russian hackers were behind it |
| Emerging factor | Generative AI reportedly used to autonomously hack businesses, lowering the barrier to attack |
| Structural cause | Increased factory connectivity widened the attack surface once one link is breached |
| Official view | NCSC’s Jonathon Ellison: cybersecurity must be treated as a business-critical priority |
| Core lesson | Your risk is the sum of your own security and every supplier you depend on to make and ship |
Related reading from the Cloudswitched newsroom
This survey sits within a run of stories we have covered on the fragility of the connected systems UK SMEs depend on — and the way risk now travels through suppliers rather than stopping at the perimeter. If your production, data or connectivity relies on third parties, the same supply-chain logic applies. See our analysis of the N-central zero-day and how an attack on a managed-service tool cascades to downstream customers, the data-handling lessons of the UKGI data breach, and the operational fallout of the GitHub outage that stalled development teams. On the connectivity that underpins modern manufacturing, read our pieces on the Brawband broadband outage and the full-fibre installation damage that can sever a site in an instant — both reinforcing the same message: the suppliers and infrastructure behind your business are now part of your security and resilience picture.
Turn the survey’s warning into a plan you can prove
Cloudswitched helps UK manufacturers and their suppliers put a government-backed baseline in place with Cyber Essentials — firewalls, secure configuration, access control, malware protection and patch management — and builds the rehearsed response plan that half of affected firms were missing. If this story has left you unsure where you stand, we will help you find out and close the gaps.
Talk to us about Cyber Essentials CertificationFrequently asked questions
Do not be a statistic in next year’s survey
Nearly a third of UK manufacturers were hit this year, and only half of those affected had a plan. Cloudswitched helps you put a Cyber Essentials baseline, a rehearsed response plan and resilient backups in place — so that when supply-chain risk lands, you are the firm that keeps making and shipping product. Let us show you what good looks like.
Talk to us about Cyber Essentials Certification


