A Make UK study found that 30% of UK manufacturers suffered a cyber incident in the past year, either directly or through their supply chain, underscoring continued exposure across the sector. The report said cyber resilience remains uneven: only about half of manufacturers have an incident response plan, many lack clear senior ownership for cybersecurity, and some do not have a dedicated CISO. Nearly a third also either lack cyber insurance or are unsure whether they are covered.
The findings warned that attacks on manufacturers can quickly escalate from IT disruption to operational and financial damage, including reduced production capacity, delayed operations, shortages of components or materials, and missed customer deliveries. Make UK and Converged Solutions Group urged firms to raise cybersecurity to board level, strengthen supplier assurance, improve cyber hygiene, test recovery plans, and review insurance coverage, citing the Jaguar Land Rover attack as an example of how a single incident can trigger production stoppages and downstream effects across thousands of organizations.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
On August 10, Make UK published its "Cyber Security in Manufacturing" report, drawing on its Cyber Resilience 2026 survey and other industry and government data. The report said 30% of UK manufacturers experienced a cyber incident in the past year and found major gaps in incident response planning, leadership ownership, and cyber insurance coverage.
A cyber attack on Jaguar Land Rover in September 2025 forced the company to halt production for weeks, becoming a prominent example of cyber risk in manufacturing. The incident was later cited as a watershed event for the sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.