Cyber Attacks Are Now a Production Problem, Not an IT Problem
Three in ten UK manufacturers were hit by a cyber incident in the past twelve months, either directly or through their supply chain. That figure comes from Make UK's Cybersecurity in Manufacturing research, published in August 2026.
The headline number is not the interesting one. Breach statistics have been climbing for years and most people have stopped reacting to them. The interesting numbers are the ones underneath, because they describe where the damage actually landed.
Among manufacturers affected by an attack on a supplier, 31% reported delays to customer deliveries and 31% reported reduced production capacity. Around a quarter reported material shortages or supplier delivery delays. These are not IT metrics. They are the metrics your board already reviews every month.

The damage is measured in days of output
Cyber risk has traditionally been presented to manufacturing boards in the language of data: records exposed, systems encrypted, information lost. That framing has never landed particularly well in a business where value is created by things physically moving through a building.
The 2026 data reframes it. When a manufacturer is affected, the consequence shows up as a line that is not running, an order that does not ship, and a customer who now has a reason to look at alternatives.
The reference point everyone uses is Jaguar Land Rover. The September 2025 attack halted production for several weeks. The Cyber Monitoring Centre classified it as a systemic event and estimated a UK economic impact of around £1.9 billion, with effects reaching more than 5,000 organisations. Very few of those 5,000 were attacked. They simply supplied, or were supplied by, someone who was.
That is the shift worth internalising. Your exposure is no longer limited to your own network. It includes the resilience of every organisation you have given a connection, a login or a delivery dependency to.
The volume behind the headline
Separate research from SonicWall recorded 1.84 million ransomware events across 364 sensors in UK manufacturing environments between January and May 2026, with annualised intrusion activity running around 28% above the 2025 total.
Detected events are not successful breaches, and the number should be read with that in mind. What it does indicate is sustained, deliberate targeting rather than opportunistic background noise. Manufacturing is being selected, and the reason is not subtle. Downtime in a factory has an immediate, calculable cost, which makes the extortion maths straightforward for an attacker.
There is a second driver that gets less attention. As more plant becomes connected, the boundary between the office network and the production environment gets thinner. Operational technology that was once genuinely isolated is now reachable, often through a route nobody documented. In an attack, that is how an IT incident becomes a physical shutdown.
You are somebody else's supply chain risk
If you supply into aerospace, automotive, defence or any tier one programme, this cuts both ways.
Your primes are reading the same research. The security questionnaires arriving with contract renewals are getting longer and more specific, and the evidence being requested is moving from policy documents to demonstrable configuration. Cyber Essentials Plus (CE+), ISO 27001 and AS9100 clauses that were once a tick-box exercise are becoming a genuine qualification gate.
That is a commercial risk with an unusual property: it is entirely within your control, and the work required is finite. Most of what a prime wants evidenced sits in the foundational layer, not in advanced security tooling. Multi-factor authentication applied properly across every cloud service. Security updates applied inside a defined window. Administrative accounts separated from everyday accounts. A documented scope of what you actually run.
We assess a lot of manufacturers against exactly this list. Very few fail because they lack sophisticated defences. They fail because something basic was switched off by default, or was switched on once and quietly drifted.
The response that is not "buy more tools"
The instinctive reaction to a statistic like 30% is to procure something. That is usually the wrong first move, because it adds a layer to an estate nobody has measured yet.
A more useful sequence is to establish what you actually have, test it honestly against a recognised standard, fix the foundational gaps in priority order, and only then consider what genuinely needs to be added. In practice, that ordering saves money as often as it spends it, because the assessment routinely surfaces licences and services already paid for and never switched on.
There is also a governance question worth putting on the agenda directly. Make UK's framing is that cyber security has stopped being an IT issue for manufacturers and become a production, supply chain and business continuity risk. If that is true, and the delivery and capacity numbers suggest it is, then it belongs in the same board conversation as plant reliability and single-source supplier risk, with the same expectation of evidence.
Where this leaves you
The honest position for most manufacturers is that they do not know where their baseline sits. Not because anyone has been negligent, but because reactive IT has no natural prompt to look underneath. When nothing has visibly broken, there is nothing to investigate.
That is what the Foundation phase of our Kepler framework is built to address: a strong, secure starting point, with risk reduced, resilience improved and a defensible baseline you can hand to a prime without rehearsing. It is deliberately unglamorous work, and it is the work that decides whether an incident is an inconvenience or a shutdown.
If you would like an honest read on where your own foundations sit, our Kepler Compass session takes 45 minutes, costs nothing, and is genuinely useful whether or not you do anything with us afterwards.
One question to take back to your next management meeting: if your largest customer sent you a security questionnaire tomorrow, how much of it could you evidence rather than assert?
Sources: Make UK, Cybersecurity in Manufacturing (August 2026), reported by The Manufacturer; SonicWall and e2e-assure research reported by IT Europa.


Comments