One in three UK manufacturers suffered cyber-attacks in past year

Almost one in three (30%) of UK manufacturers have been hit by cyber-incidents either directly or via their supply chains in the past 12 months, according to a new survey by Make UK, the organisation that represents UK manufacturers. Production downtime and increased operational costs were the most common consequences, with 31% of manufacturers that were affected by supplier cyberattacks reporting delays to customer deliveries, 31% experiencing reduced production capacity, 23% reporting delays to supplier deliveries, with a similar number facing shortages of components and materials.
The report, Cyber Security in Manufacturing, states that cybersecurity is no longer just an IT issue for manufacturers, but a core production, supply chain and business continuity risk.
The findings underline how digital disruption in a modern factory can rapidly become physical disruption. As manufacturers become more reliant on connected machinery, robotics, enterprise systems, suppliers and remote access tools, cyberattacks can quickly affect uptime, safety, customer orders and wider supply chain resilience.
Recent high-profile incidents have shown how quickly cyber-disruption can move from IT systems to production lines and supply chains. Disruption affecting Jaguar Land Rover led to weeks of interrupted production across key UK manufacturing sites and wider impacts across suppliers, underlining the need for cyber-resilience to be treated as a core operational risk, says the report.
It warns that cyber-resilience must be treated as part of operational performance, alongside productivity, quality, and health and safety, and calls for manufacturers to strengthen cyber-hygiene, improve supplier assurance, protect operational technology, and ensure that cyber-risk has clear “ownership” at a senior level.
Of the 132 manufacturers surveyed, 51% say they have incident response plans and 45% have senior leaders with an assigned responsibility for cyber-security. Two thirds (67%) have cyber-insurance, but 17% do not – and 16% are not sure whether they are covered.
Make UK says manufacturers should prioritise practical steps including board-level ownership of cyber-risk, employee training, incident response planning, patch management, supplier assurance and protection for operational technology systems.
“Cyberattacks are no longer abstract technical events for manufacturers,” says Make UK’s innovation and digitalisation lead, Nina Gryf. “They are showing up on the factory floor through downtime, higher costs, delayed orders and pressure on supply chains. In a connected industrial economy, a digital weakness can quickly become a production problem.
“The message for manufacturers is clear: cyber resilience is business resilience,” she adds. “Firms do not need to do everything at once, but they do need clear leadership, basic controls, tested recovery plans and stronger assurance across their supply chains. The businesses that get this right will be better placed to keep production moving, protect customers and invest in digital technologies with confidence.”
Make UK’s findings come amid growing national concern about cyber-risks. Government research has estimated the annual cost of significant cyberattacks to UK organisations at £14.7bn. The Government’s Cyber Resilience Pledge urges firms to take practical steps including board-level responsibility, use of NCSC tools, and stronger supply chain security.
“In today’s threat landscape, no manufacturer can afford to treat cybersecurity as anything other than a business-critical priority,” warns Jonathon Ellison, director of national resilience at the National Cyber Security Centre. “The NCSC is working to help organisations of all sizes strengthen their cyber-defences, from board-level governance and staff training, through to free practical services such as Early Warning and Exercise in a Box.
“We encourage organisations across the sector to engage with this report and act on its recommendations,” he continues. “By sharing expertise, promoting good practice, and embedding initiatives such as Cyber Essentials across supply chains, we can build the strong foundations needed to withstand evolving cyber threats and create a more secure and resilient manufacturing industry.”

