Nearly one-third of British manufacturing firms, 30%, reported experiencing a cyberattack or a supply chain-related cyber incident in the past 12 months, according to a survey by MakeUK, a lobby group for British manufacturers. This figure underscores a rising cybersecurity risk for companies within the sector. The findings emerge almost a year after a cyberattack on JLR, Britain's largest automotive employer, which led to a weeks-long halt in production.
The MakeUK report found that these cyber incidents frequently resulted in lost production time and increased operational costs for manufacturers. Despite the clear impact, only half of the surveyed companies had a response plan in place to address a cyberattack. This preparedness gap is particularly concerning given the increasing sophistication and frequency of attacks by hackers, some of whom are backed by hostile states.
The UK government estimates that cybercrime costs the national economy £14.7 billion annually. The emergence of generative AI systems, capable of autonomous hacking, has added urgency to efforts to improve cybersecurity defenses. Manufacturers have increasingly connected their factory operations to enhance productivity and gain real-time insights. However, this expanded connectivity also broadens the potential scope of harm once attackers breach a system.
The JLR cyberattack, which began around August 31, 2025, forced the company to shut down systems across its factories, offices, and retail operations. Production at JLR was paused on September 1, 2025, and continued for three weeks, with staff instructed to stay home. The independent Cyber Monitoring Centre estimated the JLR hack cost the UK economy at least £1.9 billion, primarily due to lost output, making it one of the most expensive cyber incidents in British history. Initial reports suggested a "loose collective" of hackers took credit, but authorities later determined Russian hackers carried out the attack. The attack on JLR, which employs 34,000 workers and supports an additional 120,000 jobs in its supply chain, caused approximately $2.5 billion in economic damage. The British government provided JLR with a £1.5 billion support package following the incident.
The JLR incident was not isolated. Other major attacks publicly reported in recent years include those on FTSE 100 manufacturers IMI and Smiths Group in early 2025. In the retail sector, Marks & Spencer, the Co-op, and Harrods also experienced costly breaches last year. Jonathon Ellison, director of national resilience at the National Cyber Security Centre (NCSC), which assisted with the JLR response, stated that cybersecurity must be a business-critical priority for manufacturers.
A broader UK government survey, the Cyber Security Breaches Survey 2025/2026, indicated that 43% of all UK businesses, approximately 612,000 organizations, reported a cyber breach or attack in the preceding 12 months. This figure remained stable from the previous year. Larger businesses faced a higher incidence of attacks, with 69% of large businesses and 65% of medium businesses reporting breaches, compared to 42% of micro and 46% of small businesses. The proportion of businesses reporting lost revenue or share value due to cyber incidents more than doubled from 2% to 5%. Reputational damage reports also rose from 1% to 3%.
Phishing attacks remain the most common type of breach, affecting 38% of businesses and rated as the most disruptive by 69% of those impacted. Qualitative interviews within the government survey highlighted a perception that phishing attacks have become easier for attackers to execute and are increasing in sophistication. While ransomware attacks declined to 1% of survey participants, down from 3% in the two preceding years, the overall threat landscape remains dynamic.
The government's survey noted that despite publicity surrounding high-profile incidents, there has not been a sustained, economy-wide improvement in cyber resilience. A "resilience gap" persists between larger and smaller organizations. New risks associated with AI adoption are emerging more quickly than security practices can adapt. Only 24% of UK businesses using AI have practices in place to manage the associated cyber risk.
