UK Manufacturers’ Cyber Resilience: A Troubling Landscape
A recent report from Make UK has revealed a troubling statistic: nearly one-third of manufacturers in the United Kingdom—30%—experienced a cyber incident in the past year, either directly or via their supply chains. This alarming statistic is coupled with the findings that the sector’s overall cyber resilience maturity remains worryingly inadequate.
The report, aptly titled Cyber Security in Manufacturing, was published on August 10 and draws upon data from Make UK’s own Cyber Resilience 2026 survey, in addition to broader industry and government statistics. Its aim is to evaluate the readiness of the manufacturing sector in the face of escalating digital threats.
One of the key takeaways from this report is the significant operational and financial implications of cyber incidents. A striking 31% of businesses impacted reported reduced production capacity and operational delays, while another 23% struggled with component or material shortages. Furthermore, 31% of manufacturers affected by cyber-attacks noted significant setbacks in their ability to deliver products to customers.
Evolving Risks and Uneven Preparedness
Despite an increase in awareness regarding cyber risks within the sector, the report highlights a concerning disparity in preparedness levels among UK manufacturers. While a majority seem to have implemented basic cyber hygiene measures, critical structural gaps continue to threaten the integrity of their operations.
For instance, the report noted that although 51% of respondents have a formal cyber incident response plan in place, and 45% have designated senior leaders responsible for cybersecurity, this still leaves nearly half of all UK manufacturers lacking these essential safeguards. Furthermore, fewer than 25% of surveyed businesses employ a dedicated Chief Information Security Officer (CISO), a crucial role in today’s risk-laden landscape.
This governance gap coincides with a broader shift in how businesses view cyber readiness; it has evolved from merely an IT concern to a primary commercial consideration. Manufacturers are now facing increasing demands from commercial partners and customers for robust data protection, continuous operational uptime, and integrity across their supply chains before entering into contractual agreements.
However, a notable concern arises: almost a third of manufacturers either lack cyber insurance or are uncertain whether their existing coverage protects against cyber disruptions.
Andrew Lintell, the general manager for EMEA at Claroty, shared insights regarding these findings. He noted the significance of the 2025 Jaguar Land Rover cyber-attack as a critical turning point for many industrial sectors. Yet, he expressed disappointment that numerous organizations continue to remain idle in bolstering their cybersecurity measures. “The reality is the industrial control systems, sensors, and connected machinery on the factory floor… You can’t defend or manage what you can’t see, and that’s still the norm on most factory floors,” he stated.
He further elaborated on the tangible consequences of inadequate cybersecurity: “In manufacturing, that chaos shows up as halted production lines and missed shipments, not just IT tickets, creating huge financial implications very quickly.”
Recommendations for Enhanced Cyber Resilience
In light of these sobering findings, the report from Make UK outlines several essential recommendations for improving cyber resilience in the manufacturing sector. It emphasizes that defensive strategies must evolve beyond mere compliance measures.
Manufacturers are encouraged to adopt a board-level focus on cybersecurity, reinforcing basic cyber hygiene practices while enhancing supplier assurance. Additionally, the report stresses the importance of ensuring that recovery plans are proactively tested before any disruptions occur.
To help manufacturing firms fortify their defenses, Make UK has proposed several core actions:
- Formalize and regularly test incident response plans to ensure organizational readiness prior to facing disruptions.
- Implement mandatory cybersecurity awareness training for the workforce to close internal skill gaps and improve hygiene practices.
- Elevate third-party supplier assurance protocols to mitigate risks that may arise from the broader supply chain.
- Review and audit insurance policies to confirm adequate financial protection against potential business interruptions and operational delays.
By taking these proactive measures, UK manufacturers can begin to bridge the cyber resilience gap and protect themselves against the ever-evolving landscape of cyber threats. In a world where digital vulnerabilities can lead to substantial operational setbacks, the importance of cybersecurity can’t be overstated. The path ahead involves diligence, commitment, and a transformative approach to safeguarding the future of manufacturing in the UK.
