Cyber incidents disrupt UK manufacturing operations

Cyber incidents disrupt UK manufacturing operations

Cyber incidents now affect three in ten UK manufacturers annually. Make UK links attacks to production downtime, additional costs, supplier disruption, and delayed customer deliveries as identity exposure spreads across connected industrial operations.


Three in ten UK manufacturers experienced a cyber incident directly or through their supply chain during the past year, with new industry research showing that digital attacks are increasingly translating into production downtime, higher operating costs and delayed customer deliveries.

The findings from Make UK put the headline figure at 30%. Production downtime and increased operating costs were the most common effects where cyber incidents caused disruption, while 31% of manufacturers affected by supplier attacks reported delays to customer deliveries.

Preparedness remains uneven. Almost a third of manufacturers either do not hold cyber insurance or are unsure whether they are covered, and only around half have an incident response plan. That gap is increasingly difficult to separate from normal production risk as factories depend on connected business systems, production networks, remote maintenance, digital suppliers and cloud services.

A manufacturer does not have to be the original target for an attack to stop production. Compromise at a supplier can delay components or materials, while stolen credentials at a contractor or service provider can provide a route into systems further along the chain. Production schedules, warehouse operations, quality systems and customer deliveries can all be affected before the incident reaches machinery on the factory floor.

The number of identities requiring control is also expanding as businesses introduce autonomous software and AI-enabled services. Steve Bradford, Senior Vice President, EMEA Sales at SailPoint, said complex supply chains and ageing systems continue to create opportunities for attackers while machine identities are increasing the volume of access that organisations have to govern.

“Critical infrastructure – including the manufacturing sector – has long been favoured by cybercriminals. Supply chains are often complex and sprawling. Legacy infrastructure and ‘tool sprawl’ offer bad actors fertile ground. Hackers only need to compromise one supplier’s credentials to wreak untold havoc across the entire supply and demand network and cause long-term operational disruption.

AI agents have compounded this risk. British businesses are adding as many as 10,000 AI agents and machine identities on a monthly basis. Whilst these systems offer undeniable efficiencies, they also introduce a new class of insider risk; requiring broad access permissions and moving at machine speed.

Frontier AI is changing the ways that hackers identify and then exploit vulnerabilities. But it’s not just external AI-driven threats manufacturers should be considering. They need to secure their agentic workforce – ensuring access to systems is granted only when and where it’s appropriate, and aggressively revoked when not.”

The growth in machine identities changes the scale of identity management rather than the underlying security principle. Software agents, applications, APIs and automated services can require access to multiple systems, sometimes with permissions that allow them to read, modify or trigger operational data. Credentials that remain active unnecessarily give an attacker another path through the organisation, particularly when the system using them can operate at machine speed.

Manufacturing environments add further complexity because modern plants frequently combine newer digital platforms with equipment installed over several generations. Production machinery may remain mechanically productive for decades while its control interfaces, operating systems or remote-access arrangements become progressively harder to maintain. Replacing everything at once is neither practical nor economically sensible, leaving companies to secure mixed estates while keeping output moving.

Supply chain access creates a similar compromise. Equipment vendors and engineering contractors need legitimate routes into sites for maintenance, commissioning and fault diagnosis, particularly where specialist skills are not held permanently in-house. Those connections become a problem when credentials are shared, poorly monitored or left active long after the work that justified them has finished.

The operational consequences of a major manufacturing cyber incident were demonstrated by the 2025 attack on Jaguar Land Rover, which forced production stoppages and affected companies across its supplier network. The disruption showed how quickly an incident at one large manufacturer can spread into businesses whose immediate systems were never compromised but whose revenues depend on the affected production programme.

Make UK’s figures indicate that this type of dependency is no longer an exceptional boardroom scenario. When 31% of manufacturers affected by supplier cyber attacks report delayed customer deliveries, cyber resilience begins to resemble familiar disciplines such as supplier qualification, equipment maintenance and business continuity rather than a separate exercise owned exclusively by the IT department.

Incident response planning is central to that shift because prevention will never remove every route into a business. Companies need to know which production, logistics and commercial systems are essential, how those systems can be restored, which suppliers can interrupt operations and where alternative processes remain possible while digital services are unavailable.

The continued expansion of industrial connectivity makes that work more pressing. Automation, remote monitoring and AI can improve throughput, maintenance and decision-making, but each additional identity, application and supplier connection expands the environment that has to be controlled. The uncomfortable part of Make UK’s 30% figure is not that manufacturing has become unusually digital; it is that production systems are already digital enough for cyber failures to appear alongside conventional causes of lost output.


Stories for you


  • BMI Redland restarts Coventry clay-tile production

    BMI Redland restarts Coventry clay-tile production

    BMI Redland has restarted clay-tile production after major Coventry refurbishment. The £6.3 million programme upgraded kiln equipment, automation, material handling, gas, control, and hydraulic systems during a five-month planned maintenance programme.


  • Turntide scales UK axial-flux motor manufacturing

    Turntide scales UK axial-flux motor manufacturing

    Turntide plans to automate axial-flux motor production in Northumberland facilities. The £17 million Project SUPREME programme targets higher volumes, reduced production costs, and expanded validation capability, subject to final government approval.