Cyber Prep Gap Leaves UK Factories Vulnerable
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.
The UK's manufacturing sector is navigating a paradox: a growing awareness of cyber threats alongside persistent gaps in preparedness. A new report from Make UK, published on August 10, paints a picture of an industry where nearly a third of firms have faced a cyber incident in the past year, yet many still lack the most basic safeguards.
The report, titled "Cyber Security in Manufacturing," draws on data from Make UK's Cyber Resilience 2026 survey and other industry and government sources to assess the sector's readiness against digital threats. The findings underscore a critical disconnect between the rising operational and financial costs of cyber incidents and the uneven state of cyber resilience across the sector.
Incidents Hit Production and Deliveries
The operational toll of cyber incidents is clear. According to the report, 31% of affected businesses experienced reduced production capacity and operational delays. Additionally, 23% faced component or material shortages, and 31% reported delays in delivering products to customers.
These disruptions translate directly into financial losses, but the report doesn't quantify the exact monetary impact. Instead, it emphasizes that cyber incidents are no longer just an IT problem—they are a commercial one, affecting the ability to meet customer expectations and maintain supply chain integrity.
Preparedness Remains Uneven
While awareness is growing, preparedness is starkly uneven. The report notes that 51% of respondents have a formal cyber incident response plan, and 45% have designated senior leadership responsibility for cybersecurity. However, this also means that nearly half of UK manufacturers lack either of these baseline safeguards.
Fewer than a quarter of surveyed businesses (23%) employ a dedicated Chief Information Security Officer (CISO). This governance gap comes at a time when cyber readiness has shifted from a backend IT concern to a primary commercial factor, with commercial partners and customers increasingly demanding proof of robust data protection and supply chain integrity before entering contracts.
Despite these demands, almost a third of manufacturers either operate without cyber insurance or are unsure if their current coverage applies to cyber disruption.
Claroty Exec Comments on the Gap
Andrew Lintell, general manager for EMEA at Claroty, commented on the report's findings. He referenced the 2025 Jaguar Land Rover cyber-attack as "a watershed moment for industrial sectors," yet noted that many organizations still haven't taken the action that's desperately needed to boost their security.
"The reality is the industrial control systems, sensors and connected machinery on the factory floor that most IT centric security tools were never built to see. You can't defend or manage, what you can't see, and that's still the norm on most factory floors."
— Andrew Lintell, general manager for EMEA at Claroty
Lintell highlighted the tangible consequences: "In manufacturing, that chaos shows up as halted production lines and missed shipments, not just IT tickets, creating huge financial implications very quickly."
Board-Level Priority Needed
Make UK's report concludes that defensive postures must move beyond passive compliance. It calls on manufacturers to treat cybersecurity as a board-level priority, strengthen basic cyber hygiene, improve supplier assurance, and ensure recovery plans are tested before disruption hits.
The trade association sets out several core actions for manufacturing firms seeking to strengthen their defensive posture:
- Formalize and regularly stress-test an incident response plan so the organization is prepared before disruption hits
- Implement mandatory workforce cybersecurity awareness training to close internal skills and hygiene gaps
- Elevate third-party supplier assurance protocols to mitigate risks originating within the wider supply chain
- Review and audit insurance policies to verify adequate financial protection against business interruption and operational delays
Why It Matters for UK Manufacturing
The gaps highlighted in the report carry significant implications for the manufacturing sector. As cyber incidents become more frequent and costly, the lack of preparedness could lead to more disruptions that ripple through supply chains, affecting not just individual firms but the broader economy. The report suggests that manufacturers that fail to address these vulnerabilities may struggle to win contracts as customers increasingly vet cybersecurity postures.
For now, the onus is on manufacturers to close the gap between awareness and action. The findings indicate that while progress is being made, the sector still has a long way to go in embedding cyber resilience into its operational fabric.
Sources
- Infosecurity Magazine Original source
Continue Reading
Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Gray to White: A Hacker's Redemption Arc
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Rogue AI Response Gaps Threaten Enterprises
Most security leaders are confident they can detect rogue AI agents — but few can act fast enough.