Key Takeaways
- Approximately 30 % of British manufacturers reported a cyber‑incident affecting them or a supplier in the last year, often resulting in lost production time and higher costs.
- Only half of the surveyed firms have an incident‑response plan, leaving many unprepared for attacks.
- The rise of state‑backed hackers and generative‑AI tools has intensified the threat landscape, with the UK economy losing an estimated £14.7 bn annually to cybercrime.
- The August 2024 cyber‑attack on Jaguar Land Rover (JLR) halted production for weeks and is estimated to have cost the UK economy at least £1.9 bn, likely the most expensive cyber incident in British history.
- Other notable breaches in 2024‑2025 hit FTSE 100 manufacturers IMI and Smiths Group, as well as retailers Marks & Spencer, the Co‑op, and Harrods.
- Experts, including the National Cyber Security Centre (NCSC), stress that cybersecurity must be treated as a business‑critical priority for all manufacturers.
Overview of the Survey Findings
MakeUK, the lobby group representing British manufacturers, conducted a survey that revealed nearly one‑third of respondents had experienced a cyber‑attack on their own operations or within their supply chain during the previous 12 months. The incidents frequently disrupted production schedules and increased operational costs, underscoring the tangible financial impact of cyber threats on the manufacturing sector. Despite the prevalence of attacks, only about 50 % of the surveyed companies reported having a formal incident‑response plan in place, indicating a significant gap in preparedness that could exacerbate the consequences of future breaches.
Escalating Threat Landscape
The report notes that cyber risks have risen sharply in recent years, driven by an increase in both the number and sophistication of attackers. Many of these threat actors are believed to be backed by hostile states, employing advanced tactics to infiltrate corporate networks. Large manufacturers describe facing near‑constant probing attempts, and the UK government estimates that cybercrime costs the national economy roughly £14.7 bn each year. The emergence of generative artificial intelligence systems—some capable of autonomously identifying and exploiting vulnerabilities—has added a new dimension to the threat, prompting urgent calls for organisations to upgrade their defensive capabilities.
Impact of Digital Connectivity on Risk
Manufacturers have increasingly connected their factories to improve productivity, gaining real‑time insight into operations and enabling tighter coordination across the supply chain. While this digital integration offers efficiency benefits, it also expands the attack surface: once a hacker gains entry, the interconnected nature of modern manufacturing systems allows the intrusion to spread rapidly, magnifying potential harm. This dynamic was illustrated starkly by the cyber‑incident that struck Jaguar Land Rover (JLR) in August 2024, where attackers were able to move laterally across factories, offices, and retail outlets, forcing a widespread shutdown.
The JLR Cyber‑Attack and Its Economic Consequences
On the final day of August 2024, JLR detected digital intruders within its IT environment, prompting the company to isolate and shut down systems across all its manufacturing sites, corporate offices, and retail operations. The disruption halted vehicle production for several weeks, affecting not only JLR but also its extensive network of suppliers. The independent Cyber Monitoring Centre later estimated that the attack cost the UK economy at least £1.9 bn, primarily due to lost output at JLR and downstream effects on its supply chain. This figure likely makes the JLR incident the most expensive cyber‑event ever recorded in Britain. Subsequent investigations by British law‑enforcement agencies pointed to Russian‑state‑backed hackers as the perpetrators, highlighting the geopolitical dimension of the threat.
Other High‑Profile Breaches in 2024‑2025
The JLR attack was not an isolated case. Early in 2025, two FTSE 100 manufacturers—valve specialist IMI and components maker Smiths Group—publicly disclosed cyber‑incidents that occurred within days of each other, underscoring the vulnerability of even large, well‑resourced firms. In the retail sector, Marks & Spencer, the Co‑op, and the luxury department store Harrods all reported costly breaches during the same period. These incidents collectively demonstrate that cyber threats cut across industries, affecting manufacturers, suppliers, and customer‑facing businesses alike, and often result in supply‑chain delays, component shortages, and reputational damage.
Supply‑Chain Specific Impacts
Among the manufacturers surveyed that had experienced a cyber‑attack on their supply chain, roughly 30 % of the 123 respondents reported delivery delays to customers or reductions in output. Almost a quarter indicated they had suffered supplier‑side delivery delays or shortages of essential components and materials. These findings illustrate how a breach at one node can ripple outward, disrupting production schedules, inflating inventory costs, and eroding customer confidence. The interconnected nature of modern manufacturing amplifies the potential for cascading failures when cyber defences are insufficient.
Expert Recommendations and Industry Response
Jonathon Ellison, director of national resilience at the National Cyber Security Centre (NCSC), emphasized that in the current threat environment, no manufacturer can afford to treat cybersecurity as anything less than a business‑critical priority. He noted that the NCSC is actively collaborating with organisations of all sizes to strengthen their cyber defences, offering guidance, threat intelligence, and incident‑response support. Industry leaders are increasingly adopting measures such as network segmentation, multi‑factor authentication, continuous monitoring, and employee cyber‑hygiene training to reduce exposure. However, the survey’s revelation that only half of manufacturers possess a formal response plan suggests that many still need to move from ad‑hoc reactions to structured, resilient cybersecurity strategies.
Conclusion: The Imperative for Proactive Defence
The data presented by MakeUK paints a clear picture: cyber threats are now a routine risk for British manufacturers, with significant financial and operational consequences when defences fail. The high‑profile JLR attack serves as a stark reminder of the potential scale of damage, while the broader array of incidents across sectors illustrates the pervasive nature of the risk. As attackers leverage state backing, advanced techniques, and AI‑driven tools, manufacturers must elevate cybersecurity from an IT concern to a core component of strategic planning. Investing in robust defences, developing and testing incident‑response protocols, and fostering supply‑chain transparency are essential steps to safeguard production continuity, protect economic value, and maintain trust in an increasingly digital industrial landscape.

