New research has highlighted the growing impact of cyber incidents on the UK’s manufacturing sector, with almost one in three manufacturers reporting that they have been affected either directly or through their supply chain during the past 12 months.
The survey, conducted by industry body Make UK, found that 30% of manufacturers had experienced a cyber incident, demonstrating how cyber risk is increasingly capable of affecting not only individual organisations but the wider networks of suppliers and customers on which modern manufacturing depends.
The findings also reveal a significant gap in preparedness. Just 51% of respondents reported having a formal cyber incident response plan, while 45% had designated responsibility for cyber security at senior leadership level.
Cyber incidents are disrupting business operations
The research demonstrates that the consequences of a cyber incident can extend considerably further than the immediate compromise of IT systems or data.
Production downtime and increased operational costs were among the most common consequences reported.
The impact was also evident across supply chains. Among manufacturers affected by a cyber incident involving a supplier, 31% reported delays to customer deliveries and 31% experienced reduced production capacity. Almost a quarter reported delays to supplier deliveries or shortages of components and materials.
These findings illustrate the interconnected nature of cyber risk within manufacturing. An incident affecting one organisation can create disruption across multiple businesses, even when those organisations have not themselves been directly compromised.
Recent incidents demonstrate the potential scale of disruption
The findings follow a series of significant cyber incidents affecting major UK organisations.
In 2025, Jaguar Land Rover was forced to suspend production following a cyber attack that affected its factories and wider operations. The Cyber Monitoring Centre subsequently estimated the incident had cost the UK economy at least £1.9 billion, with much of the impact resulting from lost output across JLR and its supply chain.
Other major UK businesses have also experienced significant cyber incidents in recent years, demonstrating that organisations across manufacturing, retail and other sectors continue to face a persistent threat.
For manufacturers in particular, increasing connectivity between corporate IT, production environments, suppliers and digital services creates dependencies that can amplify the operational consequences of an incident.
NCSC warns organisations to prepare for serious disruption
The Make UK findings arrive shortly after the National Cyber Security Centre (NCSC) published new guidance for organisations preparing for and recovering from highly disruptive cyber attacks.
Published on 28 July 2026, the guidance defines a highly disruptive attack as one that disrupts, disables or damages critical systems or services to the point that an organisation cannot operate normally.
The NCSC warns that recovery can take weeks or even months and that the consequences can extend beyond technology to affect customers, services, supply chains, finances and organisational reputation.
The guidance focuses on three stages of recovery: the immediate response, recovery towards minimum viable operations, and the longer-term rebuilding of the organisation.
It also warns organisations that recovery from a serious incident frequently takes longer than leadership teams initially expect. Businesses may need to operate with limited or unavailable IT services for weeks while systems, processes and services are progressively restored.
Cyber security is increasingly an operational issue
The latest findings reinforce a broader shift in the way organisations need to consider cyber risk.
Cyber incidents are not solely an IT or information security problem. When an attack prevents production, interrupts deliveries, affects suppliers or makes critical systems unavailable, the consequences quickly become an operational and commercial issue.
Jonathon Ellison, Director of National Resilience at the NCSC, said that manufacturers could no longer afford to regard cyber security as anything other than a business-critical priority.
For organisations, this places greater importance on understanding which systems and suppliers are essential to operations, having a tested incident response plan and establishing how critical services can continue if technology becomes unavailable.
The Make UK research suggests that while awareness of cyber risk is increasing, significant gaps remain between recognising the threat and being prepared to respond when an incident occurs.
With 30% of manufacturers affected directly or through their supply chains during the past year, the potential operational consequences of cyber incidents are becoming increasingly difficult for UK businesses to overlook.
References
- The Guardian, UK manufacturers face rising hacking risk as survey shows 30% were hit last year, 10 August 2026. Reports on the Make UK research, including the proportion of manufacturers affected, operational impacts and the estimated £1.9 billion economic impact of the JLR cyber incident.
Read the Guardian article - National Cyber Security Centre (NCSC), What to do when cyber attacks disrupt your organisation, 28 July 2026. NCSC guidance covering highly disruptive cyber attacks and their potential impact on critical systems, customers, supply chains, finances and organisational reputation.
Read the NCSC guidance - National Cyber Security Centre (NCSC), Recovering from a highly disruptive cyber attack, 28 July 2026. Guidance for leaders and cyber teams covering immediate response, recovery to minimum viable operations and longer-term organisational rebuilding.
Read the NCSC recovery guidance - National Cyber Security Centre (NCSC), Recovery and ongoing investigations, 28 July 2026. Detailed guidance explaining that organisations may operate with limited or unavailable IT services for weeks and that full recovery from a disruptive cyber incident can take many months.
Read the NCSC recovery and investigation guidance







