Skip to main content
CybersecurityIncident Response

UK Manufacturers Lag in Cyber Incident Response Planning

UK factory floor with industrial equipment, workers, and integrated computer screens.

“You can't defend or manage, what you can't see, and that's still the norm on most factory floors,” said Andrew Lintell, general manager for EMEA at Claroty.

Incidents, operational impact and measured costs

Make UK’s report, Cyber Security in Manufacturing, published on August 10, finds that almost a third of UK manufacturers (30%) experienced a cyber incident over the past year, either directly or through their supply chain. The report ties those incidents to concrete operational harms: 31% of affected businesses reported reduced production capacity and operational delays, 23% suffered component or material shortages, and 31% of manufacturers hit by cyber-attacks reported delays in delivering products to customers. Make UK draws these conclusions from its Cyber Resilience 2026 survey alongside broader industry and government data.

Preparedness and governance shortfalls

Awareness of cyber risk is increasing across the sector, but readiness remains uneven. Only 51% of surveyed firms confirmed they have a formal cyber incident response plan in place; 45% report designated senior leadership responsibility for cybersecurity. Fewer than a quarter (23%) employ a dedicated chief information security officer (CISO). Make UK frames those figures as evidence that “baseline safeguards” are missing for a sizable share of manufacturers just as cyber readiness has become a primary commercial factor rather than a backend IT concern.

Commercial pressure, supplier assurance and insurance gaps

The report warns that commercial relationships are changing: customers and partners are increasingly demanding proof of robust data protection, continuous uptime and supply chain integrity before entering contracts. Despite that market pressure, Make UK finds nearly a third of manufacturers either operate without cyber insurance or are unsure whether their current coverage applies to cyber disruption, leaving firms exposed to the operational delays and financial impacts the survey documents.

Factory-floor visibility: Claroty’s warning and the Jaguar Land Rover reference

Andrew Lintell, reflecting on the industry's posture, said the 2025 Jaguar Land Rover cyber-attack is “held as a watershed moment for industrial sectors,” but added that many organisations still have not taken necessary action. He highlighted a persistent visibility problem: “The reality is the industrial control systems, sensors and connected machinery on the factory floor that most IT centric security tools were never built to see.” The report links that visibility gap to the real-world outcomes manufacturers are already experiencing — halted production lines, missed shipments and quickly mounting financial consequences.

Make UK’s core actions for manufacturers

  • Formalize and regularly stress-test an incident response plan so the organization is prepared before disruption hits
  • Implement mandatory workforce cybersecurity awareness training to close internal skills and hygiene gaps
  • Elevate third-party supplier assurance protocols to mitigate risks originating within the wider supply chain
  • Review and audit insurance policies to verify adequate financial protection against business interruption and operational delays

What this means for technologists, procurement leaders, and insurers

Technologists and security teams will be pressed to improve visibility of industrial control systems, sensors and connected machinery on the factory floor and to adopt the report’s recommendation to formalize and stress-test incident response plans.

Procurement and commercial leaders should expect customers and partners to require demonstrable proof of data protection, continuous uptime and supply chain integrity, and the report urges elevating supplier assurance protocols in response.

Insurers and risk managers face a dual challenge identified by Make UK: nearly a third of manufacturers lack clear cyber coverage or are uncertain about its applicability, and the report recommends firms review and audit policies to ensure financial protection against business interruption and operational delays.

Make UK’s findings draw a clear line between growing commercial expectations and persistent security gaps: more firms report having plans and leaders responsible for cyber, but critical roles, visibility and insurance remain incomplete across the sector. The trade association’s prescription is explicit — move cybersecurity to the board room, shore up basic hygiene, test recovery, and tighten supplier and insurance controls — and the unanswered question is whether a sector that has already felt tangible operational pain will accelerate those changes in time to prevent the next disruption.

https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/