Make UK urges companies to treat cyber security as Board
level priority
Key findings:
- 30% of manufacturers experienced a cyber incident in the past
12 months, either directly or through their supply chain.
- Where cyber incidents had an impact, production downtime and
increased operational costs were the most common consequences.
- 31% of manufacturers affected by supplier cyber attacks
reported delays to customer deliveries, while 31% reported
reduced production capacity.
- 67% of manufacturers have cyber insurance, but 17% do not and
16% are unsure whether they are covered.
- 51% have incident response plans and 45% have assigned senior
leadership responsibility for cyber security.
New Make UK research shows nearly one in three manufacturers have
been hit by cyber incidents directly or through their supply
chain, with disruption increasingly affecting production, costs
and customer delivery.
Cyber security is no longer just an IT issue for manufacturers
but a core production, supply chain and business continuity risk,
according to new research from Make UK.
The report, Cyber Security in Manufacturing, finds that 30% of UK
manufacturers experienced a cyber incident over the past 12
months, either directly or through their supply chain. Where
incidents had an impact, the most common consequences were
production downtime and increased operational costs.
The findings underline how digital disruption can rapidly become
physical disruption in a modern factory. As manufacturers become
more reliant on connected machinery, robotics, enterprise
systems, suppliers and remote access tools, cyber attacks can
quickly affect uptime, safety, customer orders and wider supply
chain resilience.
Recent high-profile incidents have shown how quickly cyber
disruption can move from IT systems to production lines and
supply chains. Disruption affecting Jaguar Land Rover led to
weeks of interrupted production across key UK manufacturing sites
and wider impacts across suppliers, underlining the need for
cyber resilience to be treated as a core operational risk.
Supplier attacks can quickly put production and customer
commitments under pressure. Among firms affected by a cyber
attack on a supplier, the most common impacts were delays to
customer deliveries (31%) and reduced production capacity (31%),
while almost a quarter reported supplier delivery delays (23%) or
shortages of components and materials (23%).
The report warns that cyber resilience must be treated as part of
operational performance, alongside productivity, quality and
health and safety. It calls for manufacturers to strengthen basic
cyber hygiene, improve supplier assurance, protect operational
technology and ensure cyber risk has clear senior ownership, with
nearly a third of firms either lacking cyber insurance or unsure
whether they are covered.
The findings come amid growing national concern about cyber risk.
Government research has estimated the annual cost of significant
cyber attacks to UK organisations at £14.7 billion, while the
Government's Cyber Resilience Pledge urges firms to take
practical steps including board-level responsibility, use of NCSC
tools and stronger supply chain security.
Nina Gryf, Innovation and Digitalisation Lead at Make UK,
said:
Cyber attacks are no longer abstract technical events for
manufacturers. They are showing up on the factory floor through
downtime, higher costs, delayed orders and pressure on supply
chains. In a connected industrial economy, a digital weakness can
quickly become a production problem.
The message for manufacturers is clear: cyber resilience is
business resilience. Firms do not need to do everything at once,
but they do need clear leadership, basic controls, tested
recovery plans and stronger assurance across their supply chains.
The businesses that get this right will be better placed to keep
production moving, protect customers and invest in digital
technologies with confidence.
Jonathon Ellison, Director of National Resilience at the
National Cyber Security Centre, said:
In today's threat landscape, no manufacturer can afford to treat
cyber security as anything other than a business-critical
priority. The NCSC is working to help organisations of all sizes
strengthen their cyber defences, from board-level governance and
staff training through to free practical services such as Early
Warning and Exercise in a Box.
We encourage organisations across the sector to engage with this
report and act on its recommendations. By sharing expertise,
promoting good practice, and embedding initiatives such as Cyber
Essentials across supply chains, we can build the strong
foundations needed to withstand evolving cyber threats and create
a more secure and resilient manufacturing industry.
Make UK says manufacturers should prioritise practical steps
including board-level ownership of cyber risk, employee training,
incident response planning, patch management, supplier assurance
and protection for operational technology systems.
ENDS
Notes to editors
- Make UK surveyed 132 UK manufacturers for its Cyber Security
in Manufacturing report.
- The report examines cyber risk, supply chain exposure,
operational impacts, governance, insurance and practical steps to
improve resilience.