Nearly a third of British manufacturers were hit by a cyber-attack, either directly or through their supply chain, in the past 12 months, according to a new survey from MakeUK. Only half had a plan in place to respond.
Government data shows only a quarter of all UK businesses have a formal incident response plan, rising to 57% for medium-sized organisations and 76% for large ones.
Nearly a third of manufacturers were hit in the past year
MakeUK’s survey found that 30% of manufacturers experienced a cyber incident in the past 12 months, either directly or through a supplier. Where the incident had an impact, production downtime and higher operating costs were the most common results. Of those affected by an attack on a supplier, 31% reported delayed customer deliveries and 31% reported reduced production capacity. The UK government estimates cybercrime costs the economy £14.7 billion a year, and manufacturing is a consistent target because connected factories give an attacker more places to cause damage once they are inside.
Only half of manufacturers have a response plan, and most other UK businesses have even less
MakeUK found 51% of manufacturers have a formal incident response plan and 45% have assigned senior leadership responsibility for cyber security. That sounds low until it is compared with the wider picture. The government’s Cyber Security Breaches Survey 2025/26 found only 25% of all UK businesses have a formal incident response plan, and only 15% review the cyber security risks posed by their immediate suppliers.
In Dr Logic’s experience, this gap is rarely about budget. It is about incident response never becoming anyone’s clear, named responsibility until something has already gone wrong.
Connected systems mean one weak link now spreads further
Manufacturers have connected their factories to get faster insight into production, but that same connectivity means an attacker who gets in through one weak link, often a supplier, can reach much more of the business than they could a decade ago. The same logic applies outside manufacturing. A creative agency running client files through shared cloud storage, connected SaaS tools and third-party contractors has the same structural exposure: a single compromised supplier account can reach far more of the business than it could when systems were separate.
Cyber Essentials certification specifically requires a documented process for handling an incident, which is exactly the gap both surveys are describing.
The JLR attack remains the clearest warning of what this costs
Jaguar Land Rover’s cyber-attack in autumn 2025 forced a production halt lasting weeks and, according to the independent Cyber Monitoring Centre, cost the UK economy at least £1.9 billion, probably the most expensive cyber incident in British history. We covered the details in Jaguar Land Rover Cyber-Attack: Lessons in Cyber Resilience for UK Businesses. It was not an isolated case. Two FTSE 100 manufacturers, IMI and Smiths Group, reported attacks within days of each other in early 2025, and Marks & Spencer, the Co-op and Harrods all suffered costly breaches in the same year. Jonathon Ellison, the National Cyber Security Centre’s director of national resilience, has said no manufacturer can now afford to treat cyber security as anything less than a business-critical priority.
What this means if you are not a manufacturer
The specific numbers in MakeUK’s survey are about manufacturing, but the underlying lesson is not sector-specific. Any business that depends on suppliers, cloud platforms or outsourced IT has the same exposure to a weak link elsewhere in the chain. Dr Logic recommends starting with three things regardless of sector: a written incident response plan naming who does what in the first hours of an attack, a documented review of the cyber security standards your key suppliers hold, and a named person accountable for cyber security rather than leaving it as an unassigned responsibility.



















































