Cyber Attacks on UK Manufacturers: Why Supply-Chain Security Is a Business Risk
Nearly a third of UK manufacturers have experienced a cyber incident either directly or through their supply chain during the past year, according to new research reported this week.
Make UK’s findings indicate that 30% of manufacturers experienced an incident, with attacks contributing to lost production time, higher costs and disruption across connected suppliers. Yet only around half of manufacturers surveyed had a cyber-response plan in place.
The figures highlight an increasingly important business risk.
Modern manufacturers depend on connected factories, suppliers, logistics providers, cloud systems and external technology partners. That connectivity can improve productivity and visibility, but it also means a cyber incident affecting one organisation may disrupt several others.
Cybersecurity therefore needs to be considered not only as an IT issue, but as part of operational resilience and supply-chain risk management.
Why Manufacturing Is Particularly Exposed
Manufacturing businesses increasingly rely on interconnected systems to manage:
- Production
- Inventory
- Procurement
- Logistics
- Warehousing
- Customer orders
- Maintenance
- Supplier communications
- Financial operations
Operational technology may also be connected with wider corporate networks.
This connectivity can allow manufacturers to monitor production and improve efficiency, but it creates dependencies.
If a supplier, software provider or logistics partner loses access to critical systems, a manufacturer may experience disruption even when its own network has not been compromised.
Make UK’s survey found that among manufacturers affected by cyber incidents in their supply chains, around 30% reported delays to customer deliveries or reduced output. Almost a quarter experienced supplier delays or shortages of components or materials.
A Supplier Can Become a Cyber Risk
Businesses routinely assess suppliers for price, quality, delivery capability and financial stability.
Cybersecurity should increasingly form part of that assessment.
A supplier may have access to:
- Shared systems
- Customer information
- Production schedules
- Technical specifications
- Login credentials
- Remote-support tools
- File-transfer services
- Procurement platforms
Where access is poorly controlled, compromise of the supplier may create a route into the customer's environment.
The risk is not limited to direct network access.
A supplier may also be unable to deliver essential components because ransomware or another cyber incident has disrupted its operations.
The result can be a cyber incident that becomes a production and commercial problem for organisations elsewhere in the supply chain.
Cyber Incidents Can Stop Physical Production
The impact of a cyberattack is not necessarily limited to stolen information.
Manufacturing incidents can affect:
- Production lines
- Order processing
- Warehouse operations
- Supplier scheduling
- Customer deliveries
- Payroll
- Communications
- Access to technical systems
The 2025 cyber incident affecting Jaguar Land Rover demonstrated how severe this disruption can become. Production was halted for weeks, and the Cyber Monitoring Centre subsequently estimated that the wider economic impact reached at least £1.9 billion, largely because of lost output at JLR and its suppliers.
The lesson is not that every cyber incident will produce damage on that scale.
It is that digital resilience and operational resilience are increasingly connected.
Cybersecurity Due Diligence Should Extend to Suppliers
Manufacturers should understand which suppliers create the greatest operational or information-security dependency.
Relevant questions may include:
- What systems can the supplier access?
- What data does it hold?
- Is remote access required?
- How are privileged credentials controlled?
- Does the supplier use multi-factor authentication?
- How are vulnerabilities managed?
- Does it have an incident-response plan?
- How quickly must it notify customers of a breach?
- Are subcontractors used?
- What business-continuity arrangements are in place?
The depth of assessment should reflect the supplier's role.
A contractor with no system access does not necessarily require the same scrutiny as a technology provider with privileged access to production infrastructure.
Limit Third-Party Access
Where external access is necessary, it should be controlled carefully.
Businesses should consider:
- Limiting permissions to what is required
- Using individual rather than shared accounts
- Applying multi-factor authentication
- Reviewing dormant access
- Restricting privileged accounts
- Monitoring remote sessions
- Removing access promptly when contracts end
- Separating critical operational systems where appropriate
Supplier access should not remain active indefinitely simply because it was required during an earlier project.
Periodic reviews may identify accounts, connections or permissions that are no longer necessary.
Prepare for Supplier Failure
Cyber resilience also means preparing for an incident affecting another company.
A manufacturer may need to consider:
- Which suppliers are operationally critical
- Whether alternative suppliers are available
- What inventory could support temporary disruption
- How long production can continue without a particular system or component
- Whether manual processes are possible
- How customers will be informed
- Which contracts contain cyber-notification requirements
- Who makes decisions during a disruption
A cyber-response plan should therefore consider more than an attack on the manufacturer's own systems.
It should also address significant disruption affecting critical third parties.
What Should a Cyber-Response Plan Cover?
Make UK’s finding that only around half of surveyed manufacturers had a response plan is particularly significant.
A practical response plan may define:
- Who has authority to activate the response.
- How affected systems will be isolated.
- Which technical specialists should be contacted.
- How evidence will be preserved.
- Which suppliers or customers need to be informed.
- How business-critical operations will continue.
- Who will coordinate legal, insurance and regulatory issues.
- How communications will be managed.
- How systems will be restored safely.
- How lessons from the incident will be implemented.
The plan should be tested rather than simply stored as a document.
An exercise may reveal unclear responsibilities or dependencies that are difficult to identify during routine operations.
Preserve Evidence During an Incident
Immediate containment is essential, but organisations should also consider evidence preservation.
Relevant material may include:
- System and security logs
- Suspicious emails
- Malware samples
- Account activity
- Authentication records
- Remote-access information
- Supplier communications
- Payment or extortion demands
- Relevant timestamps
Routine remediation can sometimes overwrite or remove useful information.
Where litigation, insurance claims, regulatory reporting or criminal investigation may follow, technical evidence should be preserved appropriately and legal advice obtained where necessary.
Avoid Assuming Who Caused the Attack
Cyber incidents can involve ransomware groups, credential theft, compromised suppliers, insiders or other threat actors.
Early indicators do not always establish attribution.
An IP address, user account, domain or piece of infrastructure may belong to an intermediary or compromised third party rather than the individual responsible.
Businesses should therefore distinguish confirmed technical findings from assumptions.
The immediate priorities are containment, evidence preservation, business continuity and understanding the scope of compromise.
Cyber Security Services
Conflict International provides Cyber Security Services to businesses seeking to understand cyber risk, strengthen resilience and respond to suspected incidents.
Depending on the circumstances, our work may include:
- Cyber risk assessments
- Vulnerability and exposure reviews
- Incident-response support
- Digital evidence preservation
- Security testing
- Review of third-party cyber exposure
- Technical investigation of suspected compromise
- Support with business-continuity planning
Cybersecurity measures cannot guarantee that an organisation will never experience an attack.
The objective is to reduce preventable exposure, identify weaknesses early and improve the organisation's ability to respond when an incident occurs.
Discuss Manufacturing or Supply-Chain Cyber Risk
If your organisation depends on connected production systems, critical suppliers or external technology providers, Conflict International can assess where cyber dependencies may create operational risk.
Where an incident has already occurred, early technical containment and evidence preservation may also help establish what happened and support subsequent decision-making.
Complete the enquiry form below to discuss your requirements.