Key Takeaways

  • Make UK found that 30% of British manufacturers experienced a cyber incident during the previous 12 months (source).
  • Only around half of affected manufacturers had an incident response team, increasing the risk of prolonged disruption.
  • Connected operational technology is turning cybersecurity into a production, supply-chain and board-level resilience issue.

Make UK has found that 30% of British manufacturers experienced a cyber incident in the past 12 months, underlining how digital threats are moving closer to the factory floor.

The finding matters because an attack on a manufacturer rarely stays confined to email accounts or office computers. Production equipment, industrial control systems, logistics platforms and supplier connections increasingly depend on shared digital infrastructure. Once attackers gain access, the resulting disruption can spread across operations, procurement and customer delivery schedules.

Earlier Make UK research found that production stoppages were the most common consequence of a cyber incident, reported by 65% of affected manufacturers. Reputational damage followed at 43% (source). Those outcomes illustrate why manufacturers increasingly need to treat cyber risk as part of business continuity rather than as a technical issue owned solely by an IT department.

The preparedness gap remains conspicuous. According to the latest survey, only around half of manufacturers that had experienced an attack had an incident response team in place. Without designated specialists, businesses can lose valuable time deciding who has authority to isolate systems, communicate with suppliers, investigate the intrusion and approve a return to production.

Restoring a manufacturing environment can be far more complicated than recovering conventional business software. A company might be able to rebuild a laptop quickly, but restarting production machinery requires attention to safety, equipment availability and the integrity of operational data. Systems may need to be checked before they are reconnected, particularly where compromised technology could affect physical processes.

Separate 2026 research from ESET points to an even broader level of exposure, although its methodology and definition of an incident differ from Make UK's. ESET found that 78% of UK manufacturers had experienced at least one cyber incident, while 95% reported some form of business disruption. Furthermore, 75% faced between one and seven days of downtime.

The financial impact in that research was also substantial. According to the data, 52% of incidents generated six-figure losses, while nearly one in five exceeded £1 million. These figures incorporate costs that extend well beyond technical remediation, such as lost output, delayed orders, specialist support and disruption among suppliers.

That helps explain why industry surveys can produce very different estimates. Make UK's 30% figure and ESET's 78% finding should not be treated as a direct contradiction without comparing survey populations, wording and incident definitions. One study may capture confirmed attacks reported through formal channels, while another can include a broader range of security events. Both point in the same direction: cyber disruption has become a routine operational concern.

High-profile incidents involving Jaguar Land Rover have added urgency to that discussion. A major manufacturer sits inside a dense network of component suppliers, logistics providers, dealerships and technology partners. Disruption at one point can ripple outward, including to smaller businesses that may have limited cash reserves or recovery resources.

Smaller manufacturers are not peripheral to the threat. They can hold commercially valuable data, operate equipment that cannot tolerate extended downtime or provide access into larger supply chains. Limited security staffing may also make containment and investigation harder. Why attack a heavily defended enterprise directly if a weaker supplier offers another route?

Artificial intelligence adds another wrinkle. Generative AI can help attackers produce more convincing phishing messages, accelerate reconnaissance and automate portions of an intrusion. It does not remove the need for technical skill, but it can reduce the effort needed to target employees and suppliers at scale.

Broader figures from the UK government provide useful context without capturing the full manufacturing impact. Its Cyber Security Breaches Survey 2025 put the average self-reported cost of cyber crime, excluding phishing, at £990 per business when zero-cost responses were included, rising to £1,970 when they were excluded. Factory downtime can make sector-specific losses far higher.

For manufacturers, practical priorities include separating corporate and operational networks, controlling remote access, monitoring unusual activity and maintaining reliable offline backups. Security-by-design can also help when production equipment is purchased or modernised. Tested response plans matter just as much, including clear decision rights and contact arrangements for suppliers, insurers and external specialists.

That said, resilience is not simply about blocking every intrusion. It is about knowing which production processes matter most, how long they can remain unavailable and how safely they can be restored. As British factories become more connected, that recovery question is moving steadily from the server room to the boardroom.