Nearly One in Three UK Manufacturers Hit by a Cyber Attack, Survey Finds
A new survey paints a stark picture of hacking risk across British industry, and reveals that half of affected companies had no plan ready when trouble arrived.

Key points
- Almost 30% of UK manufacturers reported a cyber attack on their own business or a supplier in their supply chain during the past year.
- Only half of the companies surveyed had a formal incident response plan, meaning a ready-made playbook for what to do when an attack hits.
- Jaguar Land Rover, Britain's largest automotive employer, suffered an attack nearly a year ago that halted production for several weeks.
- The survey highlights that attacks on suppliers, not just direct targets, are a growing route into otherwise well-defended businesses.
Nearly one in three British manufacturers has been hit by a cyber attack in the past year, either directly or through a supplier they depend on. That finding, surfaced by a survey reported by The Guardian Technology, is a sharp reminder that factories and production lines are not immune to the kind of digital disruption that usually makes headlines at banks and hospitals.
Why do manufacturers make attractive targets?
Production lines cannot pause without costing serious money. That pressure gives criminals a powerful bargaining chip.
When a factory's systems go down, every idle hour has a price tag. Criminals know this, which is why manufacturers are increasingly in the crosshairs of ransomware gangs, groups that use malicious software to lock a company's computers and demand payment to restore access. The urgency to restart production can push companies toward paying quickly rather than recovering slowly.
The survey also flags supply-chain attacks, where criminals break into a smaller, less-defended supplier first and use that access as a stepping stone into a larger manufacturer's network. One weak link can compromise an entire production ecosystem.
What happened at Jaguar Land Rover?
JLR, Britain's biggest automotive employer, was knocked offline by an attack almost a year ago that forced it to suspend production for weeks. The incident illustrated exactly how physical and digital operations are now intertwined: a problem in a server room translated directly into empty assembly lines and delayed vehicle deliveries.
Full details of how the attackers got in have not been confirmed publicly. Whether stronger identity controls, such as multi-factor authentication, which requires a second check beyond a password before anyone can log in remotely, would have changed the outcome remains an open question, though weak or stolen login credentials are the most common entry point in incidents of this type.
Should companies be worried, and what should they do?
Yes, but worry without preparation is useless. The survey's most alarming detail is not the attack rate; it is that half of affected manufacturers had no incident response plan in place.
A plan does not need to be elaborate. At minimum it should name who calls whom, which systems get isolated first, and how the business communicates with customers and regulators while recovery is underway. Companies that rehearse this before an attack lands recover faster and spend less.
For ordinary workers, the most practical step is straightforward: treat unexpected emails asking you to click a link or enter a password with real suspicion. A large share of industrial breaches begin with a single employee opening a convincing fake message, a technique known as phishing. Awareness of that risk, across every level of a workforce, costs nothing and stops a lot.
Common questions
Does this affect me as a customer or consumer?
Possibly. If a manufacturer that makes goods you buy is forced to pause production, you may see delays or shortages. If personal data, such as order or warranty records, sits in their systems, a breach could expose it.
What is a supply-chain attack?
It is when criminals target a smaller supplier to reach a bigger company. The big company trusts its supplier's systems, so attackers use that trusted connection as a back door.



