Cyber incidents hit three in ten manufacturers

Cyber incidents hit three in ten manufacturers

Cyber incidents affected three in ten UK manufacturers last year. Make UK found production downtime, higher costs, and supplier disruption among the consequences, while only around half of manufacturers currently maintain an incident-response plan.


Three in ten UK manufacturers experienced a cyber incident directly or through their supply chain during the past year, with attacks contributing to production downtime, higher costs, and delays to customer deliveries.

Research from Make UK found that cyber risk is increasingly translating into operational disruption rather than remaining confined to information-technology systems.

Production stoppages and increased operating costs were among the most common consequences reported where an incident disrupted a manufacturer. The findings indicate that the financial effect of an attack can continue well beyond the initial effort to secure affected systems.

Supplier exposure is a substantial part of the problem. Among manufacturers affected by a cyberattack involving a supplier, 31% reported delays to deliveries to their own customers.

That gives cyber incidents a route through industrial supply chains. A disruption at one component producer, logistics provider, software supplier, or outsourced service business can interrupt production schedules and commercial commitments elsewhere, even where the customer’s own systems remain secure.

Preparedness remains uneven. Only around half of manufacturers have an incident-response plan, while almost a third either do not have cyber insurance or are unsure whether they are covered.

Make UK is calling for manufacturers to treat cybersecurity as a board-level issue, strengthen basic controls, increase supplier assurance, and test recovery arrangements before an attack occurs.

Manufacturing is particularly exposed to the connection between digital systems and physical operations. Modern factories depend on enterprise software, connected equipment, production scheduling, remote access, logistics platforms, supplier data, and increasingly automated machinery.

Disruption to one of those systems can prevent machinery or people from operating effectively even where the attack itself does not physically damage production equipment. Lost access to scheduling, inventory, engineering data, or maintenance systems can be enough to reduce output.

Cyber resilience therefore increasingly overlaps with business continuity. A company may be able to restore corporate email or office applications relatively quickly while still facing lost production because specialist equipment, plant networks, or supplier interfaces require different recovery processes.

Manufacturers running tightly scheduled production lines can have limited scope to absorb delays without affecting customers. Where components are delivered on a just-in-time basis, a disruption lasting hours rather than days may already be enough to create bottlenecks further along the chain.

Supplier dependence makes that resilience harder to control. Manufacturers can maintain strong protections over their own networks but still rely on logistics providers, component suppliers, outsourced technology services, maintenance contractors, and other partners with different levels of cyber maturity.

Supplier assessment therefore has to consider operational dependence as well as the sensitivity of information being shared. A business handling little confidential data can still represent a substantial cyber risk if its services are critical to production.

The findings also expose the limitations of treating insurance as a substitute for recovery capability. Cyber cover can reduce the financial effect of some incidents, but it cannot restore production capacity, recreate missed delivery windows, or immediately replace a critical supplier.

Incident-response planning has a similar operational dimension. Manufacturers need to establish who can authorise shutdowns, how teams communicate if core networks fail, which suppliers must be contacted, how customers are informed, and how production can restart safely.

Testing those decisions can expose dependencies that are not obvious in a written policy. Recovery arrangements that work for office systems may be unsuitable for production environments where specialist machinery, safety controls, and older technology are involved.

Cybersecurity is also becoming part of commercial assurance between companies. Large manufacturers and regulated customers increasingly need confidence that suppliers can protect information and continue delivering after disruption.

Smaller businesses in critical supply chains may therefore face greater scrutiny over access controls, backups, staff training, recovery planning, and the technology providers they use. That shifts cyber resilience from an internal technical matter into a factor affecting supplier selection and contract management.

The challenge is becoming more acute as manufacturers increase the amount of connected technology used across factories, engineering, logistics, and administration. Those investments can improve productivity and visibility, but every additional connection creates another dependency that needs to be managed.

Make UK’s figures show that this is already an operating issue rather than a hypothetical technology risk. With 30% of manufacturers reporting direct or supply chain incidents and only around half maintaining response plans, the gap between digital dependence and recovery readiness remains substantial across the sector.



  • Nichols buys VITHIT in €75m expansion

    Nichols buys VITHIT in €75m expansion

    Nichols is buying VITHIT to broaden its drinks portfolio significantly. The €75m cash-funded acquisition adds a profitable functional-drinks brand with UK, Irish, and international distribution, and is expected to enhance earnings immediately.


  • Cyber incidents hit three in ten manufacturers

    Cyber incidents hit three in ten manufacturers

    Cyber incidents affected three in ten UK manufacturers last year. Make UK found production downtime, higher costs, and supplier disruption among the consequences, while only around half of manufacturers currently maintain an incident-response plan.


  • Permanent hiring stabilises after 45-month decline

    Permanent hiring stabilises after 45-month decline

    Permanent hiring stabilised after forty-five months of sustained national decline. Temporary billings continued to rise, short-term vacancies increased for the first time in two years, and pay growth strengthened despite continued weakness in overall labour demand.