The State of Play: 30% Hit, Half Unprepared
New data from Make UK paints a stark picture. Nearly a third of British manufacturers — 30% to be precise — suffered a cyber incident in the last year, either directly or via their supply chain. Yet only half have a formal cyber incident response plan in place.
The trade association’s report, Cyber Security in Manufacturing, published August 10, draws on its Cyber Resilience 2026 survey and government data. It’s not a pretty read.
Operational Chaos: The Real Cost of an Attack
Cyber attacks aren’t just IT headaches. They halt production lines, delay shipments, and break supply chains.
- 31% of affected firms saw reduced production capacity or operational delays
- 23% faced component or material shortages
- 31% reported delays delivering products to customers
That’s financial pain, not just technical disruption. In manufacturing, a stalled line means missed orders and lost revenue — fast.
Governance Gaps: Leadership and CISO Roles Missing
While 51% have a formal incident response plan, that leaves 49% without one. Similarly, only 45% have designated senior leadership responsibility for cybersecurity. Fewer than a quarter — 23% — employ a dedicated CISO.
Andrew Lintell, general manager for EMEA at Claroty, calls the 2025 Jaguar Land Rover attack a “watershed moment” — but notes many firms still haven’t acted.
“The reality is the industrial control systems, sensors and connected machinery on the factory floor that most IT centric security tools were never built to see,” he says. “You can’t defend or manage, what you can’t see.”
Commercial Pressure: Customers Demand Cyber Proof
Cyber readiness is now a commercial factor. Partners and customers increasingly require proof of data protection, uptime, and supply chain integrity before signing contracts. Yet nearly a third of manufacturers either lack cyber insurance or don’t know if their coverage applies to disruption.
That’s a risky position when one incident can bring operations to a standstill.
Make UK’s Recommendations: Move Beyond Compliance
The report urges manufacturers to treat cybersecurity as a board-level priority — not a backend IT concern. Key actions include:
- Formalize and stress-test incident response plans regularly
- Implement mandatory cybersecurity awareness training for all staff
- Strengthen supplier assurance protocols
- Review insurance policies to ensure coverage for business interruption
Passive compliance isn’t enough. Firms need tested recovery plans and proactive governance.
For more on building resilience, see our guide on manufacturing cybersecurity best practices and industrial cyber risk management strategies.