Nearly a third of UK manufacturers hit by cyber-attacks, survey finds

A new survey shows 30% of British manufacturers suffered a cyber-attack on themselves or a supplier in the past year, yet only half have a formal plan to respond when one strikes.

AI2Day Newsdesk3 min read
A close-up, sharply lit photograph of two printed pages lying side by side on a dark desk, one page covered in dense text and tables with several entries circle
Share

Key points

  • Nearly one in three British manufacturers (30%) reported a cyber-attack on their business or a company in their supply chain in the past year.
  • Only half of those affected companies had a formal incident-response plan, meaning a written playbook for what to do when an attack happens.
  • The findings arrive roughly one year after JLR (Jaguar Land Rover), Britain's largest automotive employer, was forced to halt production for several weeks following a significant cyber-attack.
  • Large manufacturers described themselves as being under constant threat, yet preparedness still lags well behind the level of risk.

British factories are under mounting pressure from hackers, and the numbers show many are not ready for it. A new survey reveals that almost one third of UK manufacturers experienced a cyber-attack against their own systems or against a company they rely on in their supply chain, meaning the network of suppliers that feed parts, software or services into a finished product.

That supply-chain angle matters. A manufacturer can invest heavily in its own security, then still get hurt because a smaller supplier with weaker defences gets compromised first. Hackers have learned that smaller companies are often an easier door into bigger ones.

Why does this affect ordinary people?

When a factory goes down, goods stop moving. Shelves go short, delivery times stretch, and prices can rise. The JLR attack, which first reported by The Guardian forced one of Britain's biggest employers to suspend production for weeks, showed how quickly a single breach can ripple through jobs, dealerships and customers.

Half of surveyed companies admitted they have no incident-response plan. That is the equivalent of a shop owner who knows flooding is likely but has never once thought about where the mop is.

What should businesses do right now?

Security experts consistently recommend the same starting points: map every supplier you depend on, ask them directly what security measures they run, and write down, even briefly, what your team will do in the first 24 hours after an attack is discovered.

Training staff to recognise phishing emails, fake messages designed to steal passwords or trick employees into handing over access, remains one of the most cost-effective defences a small or medium-sized firm can take.

The survey results are a timely nudge. Manufacturers that have not reviewed their exposure since the JLR incident are working from an outdated picture of their own risk.

What happens next?

The UK government has signalled tighter cyber-security requirements for critical industries, including manufacturing, as part of broader national resilience efforts. Specific rules and timelines are still being shaped, but the direction of travel is clear: regulators want documented plans, not good intentions.

For now, the practical gap between the scale of the threat and how prepared companies actually are remains wide.

Common questions

Does this only affect large factories?

No. Supply-chain attacks specifically target smaller suppliers because they are easier to breach, then use them as a stepping stone into larger companies. Any business that sells parts or services to a bigger manufacturer is a potential target.

What is an incident-response plan and do I need one?

It is a short written document that says who calls whom, what systems to shut down first, and how to notify customers if your business is hit. Any company that stores customer data or runs networked machinery benefits from having one, even a basic two-page version.

© 2026 AI2Day