Sector News > Manufacturing

Cyber attacks hitting output, costs and customer deliveries across UK manufacturing

Cyber attacks hitting output, costs and customer deliveries across UK manufacturing

By Manufacturing Writer • Posted in Manufacturing

  • 30% of manufacturers experienced a cyber incident in the past 12 months, either directly or through their supply chain.
  • Where cyber incidents had an impact, production downtime and increased operational costs were the most common consequences.
  • 31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries, while 31% reported reduced production capacity.
  • 67% of manufacturers have cyber insurance, but 17% do not and 16% are unsure whether they are covered.
  • 51% have incident response plans and 45% have assigned senior leadership responsibility for cyber security.

Nearly one in three UK manufacturers has been hit by a cyber incident directly or through its supply chain in the past year, with attacks increasingly disrupting production, increasing costs and delaying customer deliveries, new Make UK research shows.

Cyber security is no longer simply an IT issue for manufacturers, but a core production, supply chain and business continuity risk, according to the organisation's new report, Cyber Security in Manufacturing.

The research finds that 30% of UK manufacturers experienced a cyber incident over the past 12 months, either directly or through their supply chain. Where incidents had an impact, production downtime and increased operational costs were the most common consequences.

The findings highlight how digital disruption can rapidly become physical disruption in a modern factory. As manufacturers become increasingly reliant on connected machinery, robotics, enterprise systems, suppliers and remote access tools, cyber attacks can quickly affect uptime, safety, customer orders and wider supply chain resilience.

Recent high-profile incidents have demonstrated how quickly cyber disruption can move from IT systems to production lines and supply chains. Disruption affecting Jaguar Land Rover led to weeks of interrupted production across key UK manufacturing sites and wider impacts across suppliers, underlining the need for cyber resilience to be treated as a core operational risk.

Attacks on suppliers can also quickly put production and customer commitments under pressure. Among firms affected by a cyber attack on a supplier, the most common impacts were delays to customer deliveries (31%) and reduced production capacity (31%), while almost a quarter reported supplier delivery delays (23%) or shortages of components and materials (23%).

The report warns that cyber resilience must be treated as part of operational performance, alongside productivity, quality and health and safety. It calls for manufacturers to strengthen basic cyber hygiene, improve supplier assurance, protect operational technology and ensure cyber risk has clear senior ownership.

The research also reveals gaps in preparedness. While 67% of manufacturers have cyber insurance, 17% do not and 16% are unsure whether they are covered. Just over half (51%) have incident response plans, while 45% have assigned senior leadership responsibility for cyber security.

The findings come amid growing national concern about cyber risk. Government research has estimated the annual cost of significant cyber attacks to UK organisations at £14.7 billion, while the Government’s Cyber Resilience Pledge urges firms to take practical steps including board-level responsibility, use of NCSC tools and stronger supply chain security.

Nina Gryf, Innovation and Digitalisation Lead at Make UK, said:

“Cyber attacks are no longer abstract technical events for manufacturers. They are showing up on the factory floor through downtime, higher costs, delayed orders and pressure on supply chains. In a connected industrial economy, a digital weakness can quickly become a production problem.

“The message for manufacturers is clear: cyber resilience is business resilience. Firms do not need to do everything at once, but they do need clear leadership, basic controls, tested recovery plans and stronger assurance across their supply chains. The businesses that get this right will be better placed to keep production moving, protect customers and invest in digital technologies with confidence.”

Jonathon Ellison, Director of National Resilience at the National Cyber Security Centre, said:

“In today’s threat landscape, no manufacturer can afford to treat cyber security as anything other than a business-critical priority. The NCSC is working to help organisations of all sizes strengthen their cyber defences, from board-level governance and staff training through to free practical services such as Early Warning and Exercise in a Box.

“We encourage organisations across the sector to engage with this report and act on its recommendations. By sharing expertise, promoting good practice, and embedding initiatives such as Cyber Essentials across supply chains, we can build the strong foundations needed to withstand evolving cyber threats and create a more secure and resilient manufacturing industry.”

Make UK says manufacturers should prioritise practical steps including board-level ownership of cyber risk, employee training, incident response planning, patch management, supplier assurance and protection for operational technology systems.