Nearly One in Three UK Manufacturers Hit by a Cyber Attack, Survey Finds

A new survey reveals that nearly a third of British manufacturers were hit last year, and half had no plan ready when trouble arrived.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
An industrial manufacturing facility floor with modern machinery, overlaid with digital security warning graphics and attack indicator symbols appearing on the
Share

Key points

  • Almost 30% of UK manufacturers reported a cyber attack on their own business or a supplier in their supply chain during the past year.
  • Only half of the companies surveyed had a formal incident response plan, a ready-made playbook for what to do when an attack hits.
  • Jaguar Land Rover, Britain's largest automotive employer, suffered an attack almost a year ago that halted production for several weeks.
  • Attacks on suppliers, not just direct targets, are a growing route into otherwise well-defended businesses.

Nearly one in three British manufacturers has been hit by a cyber attack in the past year, directly or through a supplier they depend on. That finding, reported by The Guardian Technology, is a sharp reminder that factories and production lines aren't immune to the digital disruption that usually makes headlines at banks and hospitals.

Why do manufacturers make attractive targets?

Production lines can't pause without costing serious money, and that pressure gives criminals a powerful bargaining chip.

When a factory's systems go down, every idle hour has a price. Criminals know this, which is why manufacturers are increasingly in the crosshairs of ransomware gangs: groups that lock a company's computers with malicious software and demand payment to restore access. The urgency to restart production can push companies toward paying quickly rather than recovering slowly.

Supply-chain attacks compound the risk. Criminals break into a smaller, less-defended supplier first, then use that trusted connection as a stepping stone into a larger manufacturer's network. One weak link can compromise an entire production ecosystem. Our coverage of Accenture's $4.1 billion acquisition of OT security firms Dragos, runZero and NetRise on 18 June showed how seriously the industry is now pricing that exposure.

What happened at Jaguar Land Rover?

JLR, Britain's biggest automotive employer, was knocked offline by an attack almost a year ago that forced it to suspend production for weeks. The incident illustrated how physical and digital operations are now intertwined: a server-room problem translated directly into empty assembly lines and delayed deliveries.

How the attackers got in hasn't been confirmed publicly. Whether stronger identity controls, such as multi-factor authentication (a second check beyond a password before anyone can log in remotely), would have changed the outcome is an open question. Weak or stolen credentials are the most common entry point in incidents of this type.

Should companies be worried, and what should they do?

Yes, but worry without preparation is useless. The survey's most alarming detail isn't the attack rate. It's that half of affected manufacturers had no incident response plan in place.

A plan doesn't need to be elaborate. At minimum it should name who calls whom, which systems get isolated first, and how the business communicates with customers and regulators during recovery. Companies that rehearse this before an attack lands recover faster and spend less.

For ordinary workers, the most practical step is straightforward: treat unexpected emails asking you to click a link or enter a password with real suspicion. A large share of industrial breaches begin with a single employee opening a convincing fake message, a technique known as phishing. Awareness of that risk costs nothing and stops a lot.

Common questions

Does this affect me as a customer or consumer?

Possibly. If a manufacturer that makes goods you buy is forced to pause production, you may see delays or shortages. Personal data sitting in their systems, order records or warranty details, could be exposed in a breach.

What is a supply-chain attack?

It's when criminals target a smaller supplier to reach a bigger company. The big company trusts its supplier's systems, so attackers use that trusted connection as a back door.

© 2026 Threat Vectr