
New
Make UK research shows nearly one in three manufacturers have been hit by cyber incidents directly or through their supply chain, with disruption increasingly affecting production, costs and customer delivery.
Cyber security is no longer just an IT issue for manufacturers but a core production, supply chain and business continuity risk, according to new research from Make UK.
The report, Cyber Security in Manufacturing, finds that 30% of UK manufacturers experienced a cyber incident over the past 12 months, either directly or through their supply chain. Where incidents had an impact, the most common consequences were production downtime and increased operational costs.
The findings underline how digital disruption can rapidly become physical disruption in a modern factory. As manufacturers become more reliant on connected machinery, robotics, enterprise systems, suppliers and remote access tools, cyber-attacks can quickly affect uptime, safety, customer orders and wider supply chain resilience.
Recent high-profile incidents have shown how quickly cyber disruption can move from IT systems to production lines and supply chains. Disruption affecting Jaguar Land Rover led to weeks of interrupted production across key UK manufacturing sites and wider impacts across suppliers, underlining the need for cyber resilience to be treated as a core operational risk.
Supplier attacks can quickly put production and customer commitments under pressure. Among firms affected by a cyber attack on a supplier, the most common impacts were delays to customer deliveries (31%) and reduced production capacity (31%), while almost a quarter reported supplier delivery delays (23%) or shortages of components and materials (23%).
The report warns that cyber resilience must be treated as part of operational performance, alongside productivity, quality and health and safety. It calls for manufacturers to strengthen basic cyber hygiene, improve supplier assurance, protect operational technology and ensure cyber risk has clear senior ownership, with nearly a third of firms either lacking cyber insurance or unsure whether they are covered.
The findings come amid growing national concern about cyber risk. Government research has estimated the annual cost of significant cyber attacks to UK organisations at £14.7 billion, while the Government’s Cyber Resilience Pledge urges firms to take practical steps including board-level responsibility, use of NCSC tools and stronger supply chain security.
Nina Gryf, Innovation and Digitalisation Lead at Make UK, said: “Cyber attacks are no longer abstract technical events for manufacturers. They are showing up on the factory floor through downtime, higher costs, delayed orders and pressure on supply chains. In a connected industrial economy, a digital weakness can quickly become a production problem.
“The message for manufacturers is clear: cyber resilience is business resilience. Firms do not need to do everything at once, but they do need clear leadership, basic controls, tested recovery plans and stronger assurance across their supply chains. The businesses that get this right will be better placed to keep production moving, protect customers and invest in digital technologies with confidence.”
Jonathon Ellison, director of National Resilience at the National Cyber Security Centre, said: “In today’s threat landscape, no manufacturer can afford to treat cyber security as anything other than a business-critical priority. The NCSC is working to help organisations of all sizes strengthen their cyber defences, from board-level governance and staff training through to free practical services such as Early Warning and Exercise in a Box.
“We encourage organisations across the sector to engage with this report and act on its recommendations. By sharing expertise, promoting good practice, and embedding initiatives such as Cyber Essentials across supply chains, we can build the strong foundations needed to withstand evolving cyber threats and create a more secure and resilient manufacturing industry.”
Make UK says manufacturers should prioritise practical steps including board-level ownership of cyber risk, employee training, incident response planning, patch management, supplier assurance and protection for operational technology systems.