Cookie Consent by Free Privacy Policy Generator

UK manufacturers report 30% hit by cyber attacks as supply chain risk grows

The Guardian reports that nearly a third of British manufacturers have been hit by a cyber attack on them or a company in their supply chain over the past year, according to a new survey. The findings come almost a year after JLR, Britain's largest automotive employer, was forced to halt production for weeks following an attack. The survey highlights that large companies describe being under constant threat, yet only half have a response plan in place. The research underscores the scale of cyber risk facing UK manufacturing, a sector that remains a significant target for ransomware groups and supply chain attackers.

Why this matters for UK organisations

For UK manufacturers, this is not just about direct attacks on their own networks. Supply chain compromises can disrupt production, delay deliveries, and create contractual and reputational risk even when the breach happens elsewhere. Manufacturing environments often involve a mix of IT and operational technology systems, third-party logistics providers, component suppliers, and managed service providers, all of which create potential entry points for attackers. The fact that only half of organisations have a response plan in place suggests many are still treating cyber incidents as an IT problem rather than an operational and business continuity risk that requires board-level ownership and cross-functional planning. The JLR incident demonstrated how a cyber attack can halt production across multiple sites, affecting thousands of employees and disrupting supply chains for weeks. This is not a theoretical risk, it is a recurring operational reality for UK manufacturing.

What to review

Organisations should review whether they have an incident response plan that is tested, documented, and owned at the right level. This means ensuring that senior leadership, operations teams, IT, and security all understand their roles during an incident. Consider whether third-party suppliers are assessed for cyber resilience as part of procurement and contract management processes. Review whether operational technology environments are segmented from corporate IT networks, whether remote access to OT systems is controlled and monitored, and whether there is visibility into who can access critical production systems. For organisations without a response plan, this is a priority to address. For those with a plan, consider whether it has been tested in the last 12 months, whether it covers supply chain disruption scenarios, and whether the plan includes clear decision-making authority and communication protocols.

Source: The Guardian

News and blog posts
Today's brief highlights the operational reality of supply chain risk across...
The Guardian reports that nearly a third of British manufacturers have been hit...
Infosecurity Magazine reports that a supply chain attack targeting WordPress...
Dark Reading reports that cyber attacks targeting water systems have widened...