One in Three Manufacturers Hit, and the Line Stops

New Make UK research puts the figure at 30% in twelve months. For manufacturers the distinguishing feature is not data loss. It is that downtime has an immediate, measurable cost.

Manufacturers affected
30% in 12 months
JLR economic impact
£1.9bn estimated
Suppliers affected
~5,000 organisations
Source
Make UK, August 2026

The new numbers

Make UK published research on 10 August 2026 finding that 30% of UK manufacturers experienced a cyber incident in the past twelve months, either directly or through their supply chain. The survey covered 132 UK manufacturers, and the most common consequences where there was an impact were production downtime and increased operational costs.

Among firms hit through a supplier rather than directly, the most common effects were delays to customer deliveries and reduced production capacity, both at 31%, with roughly a quarter reporting supplier delivery delays or shortages of components and materials.

A separate ESET survey in 2026 put the figure higher still, finding 78% of UK manufacturers had experienced an incident, with 95% of those reporting direct business impact.

Why manufacturing is different

In most sectors a cyber incident is a data problem. You lose information, you notify people, you deal with the consequences over months.

In manufacturing it is an availability problem, and the clock starts immediately. A locked planning system is a halted line. A halted line is a missed order. A missed order is a supplier relationship, and for a tier-two or tier-three supplier that relationship may be most of the business.

The Jaguar Land Rover incident made the point at a scale nobody could ignore. The Cyber Monitoring Centre categorised it as a Category 3 systemic event, estimating a £1.9 billion impact across the UK economy and effects across more than 5,000 organisations. Production halted for around five weeks across UK plants including Solihull, Halewood and Wolverhampton. Ciaran Martin, chair of the CMC technical committee and former NCSC chief executive, described it as by some distance the most financially damaging cyber event to hit the UK.

The bit that should concern West Midlands suppliers

JLR is the headline, but 5,000 organisations is the story. The government put £1.5 billion behind supplier support because the shutdown threatened firms that had done nothing wrong and had no way to influence the outcome.

If you sit in an automotive, aerospace, rail or defence supply chain, you are part of somebody else's attack surface whether or not you have thought about it that way. And increasingly your customers know it, which is why security requirements are being pushed down contracts to tier two and tier three.

That is where most of our manufacturing work now originates. Not from a firm worrying about hackers, but from a firm holding a customer requirement document and a deadline.

What actually gets exploited

The realistic path is not an attacker reaching your PLCs from the internet. It is:

  • A phished credential on an office laptop.
  • That laptop can reach far more of the network than anyone intended, because segmentation was never really finished.
  • Vendor remote access that has been permanently enabled and unmonitored since installation, because someone needed it once.
  • Backups on the same domain as everything else, encrypted along with it.

None of that is exotic. All of it is testable.

Testing manufacturing properly

A word on method, because this is where providers get it wrong. We do not scan operational technology. Conventional scanning knocks over legacy control systems, and stopping your line to prove it could be stopped is not a useful engagement.

What we assess is the IT side and the boundary: external infrastructure, the corporate network, whether an office device can reach the plant floor, how vendor access is controlled, and whether the backups would survive the thing they exist for. That is infrastructure and network testing, scoped conservatively and agreed in writing before anyone touches anything.

Anyone offering to scan your PLCs should worry you.

The practical order

  1. Send us the customer requirement if you have one. These documents are usually vaguer than they look and often ask for less than firms fear. Reading it is free.
  2. Cyber Essentials. Frequently the actual answer to what a customer is asking for. See Cyber Essentials certification.
  3. Segmentation testing between the office network and production.
  4. Audit vendor remote access. Who has it, whether it is still needed, whether anyone would notice it being used.
  5. Restore a backup and time it. That number is your real recovery position.

We are based in Albrighton and work across the West Midlands, Shropshire and Staffordshire with no travel charge, which on a three-day internal test is a meaningful difference. More on our manufacturing page and West Midlands coverage.

Common questions

Will testing stop our production line?

No, because we do not scan operational technology. We assess the IT estate and the IT/OT boundary, agree rules of engagement in writing beforehand, and exclude anything fragile. External and application testing has no operational impact at all.

We are a small supplier. Why would anyone attack us?

They are not attacking you specifically. You are being scanned along with everything else exposed to the internet, and separately your customer is asking because their auditor asked them. Neither depends on your size or significance.

Our systems are not connected to the internet.

Some of them are, or you would not have email. And the realistic path is not the internet reaching your plant floor directly. It is a compromised office laptop that can reach the plant floor because nothing meaningful separates them.

Our IT company handles security. Is that enough?

It may well be. Independent testing exists to verify what your provider tells you, which is what your customer is asking for, and it is not a criticism of them. We write findings so they can act on them directly.

What did the JLR attack actually cost?

The Cyber Monitoring Centre estimated £1.9 billion across the UK economy, with effects reaching around 5,000 organisations and production halted for roughly five weeks. The UK government provided £1.5 billion in support to protect suppliers.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.