Home » UK Manufacturers Face Growing Cyber Supply Chain Risk

UK Manufacturers Face Growing Cyber Supply Chain Risk

by Kylie Bower


Nearly a third of UK manufacturers say they or a company in their supply chain experienced a cyber incident in the past year, while only half have a response plan in place.

The new findings put supplier exposure alongside direct attacks as a manufacturing risk. A compromised supplier can interrupt production even when the manufacturer itself is not the initial target.

Supply-chain incidents are disrupting production

The Guardian reported that a Make UK survey found 30% of manufacturers had experienced a cyber incident either directly or through their supply chain during the previous 12 months. Among manufacturers affected through their supply chains, about 30% reported delayed customer deliveries or cuts to output, while almost a quarter reported supplier delays or shortages of components and materials.

The UK government’s Cyber Security Breaches Survey provides a broader benchmark. It found 43% of UK businesses identified a breach or attack in the past year, while only 25% had a formal incident-response plan. Those figures cover businesses across the economy and are not a direct manufacturing comparison.

Jaguar Land Rover shows how quickly a cyber incident can move from IT disruption into production. JLR shut down global systems after discovering an attack in late August 2025 and began a phased manufacturing restart on October 8. Production returned to normal levels by mid-November, and JLR recorded £196 million in cyber-related costs in its second fiscal quarter.

The Cyber Monitoring Centre separately estimated the wider UK financial impact at £1.9 billion across more than 5,000 organizations, including disruption to JLR’s multi-tier manufacturing supply chain and downstream businesses.

For manufacturers, supply-chain breaches require more than vendor questionnaires. Teams need to know which suppliers can reach production-critical systems, which dependencies could stop output, and how quickly alternatives could be activated.

Response plans need to cover the factory floor

The UK’s Cyber Resilience Pledge makes board responsibility and stronger supply-chain security core commitments. Its requirements include auditing Cyber Essentials coverage across supply chains and taking a risk-based approach to supplier requirements.

For manufacturers, that means mapping supplier access, testing escalation paths, and making sure incident-response plans cover production recovery as well as data and systems.

Security teams should also verify where operational technology connects to enterprise networks and which third parties can reach those environments. A factory restart can involve production scheduling, logistics, supplier systems, and the controlled return of equipment, not just restoring files.

The practical question is straightforward: Which supplier or system failure could stop production, and has the response plan actually been tested against that scenario?

Also read: Researchers found 77 counterfeit Open VSX extensions that collected developer and CI/CD data, exposing another route for supply-chain compromise.



Source link

Related Posts

Leave a Comment