Survey: A Third of UK Manufacturers Hit by Cyber-Attacks in the Past Year
A survey by lobby group MakeUK found that 30% of British manufacturers suffered a cyber-incident in the past year, though only half have a response plan in place. The report comes nearly a year after a major attack disrupted carmaker JLR.

A new survey shows that nearly a third of British manufacturing companies have experienced a cyber-attack in the past twelve months, either directly or through a supply chain partner. The research, conducted by manufacturers' lobby group MakeUK, underscores the growing scale of digital threats facing the sector.
The survey found that 30% of respondents had suffered a cyber-incident, often resulting in lost production time and higher costs. Yet only half of the companies surveyed said they had a formal plan in place to respond to such an attack.
A growing threat
The risk of cyber-attacks has increased in recent years as hackers, frequently linked to hostile states, have grown both more numerous and more skilled at breaching corporate defences. Large companies report facing near-constant attempts to access their systems, while the UK government estimates that cybercrime costs the national economy £14.7bn annually. The rise of generative AI, some versions of which have proven capable of autonomously hacking other businesses, has added further urgency to efforts to strengthen defences.
Manufacturers have increasingly connected their factories to gain faster insight into operations, but this greater connectivity also means that once attackers breach a system, the potential for damage is far larger. This was demonstrated by carmaker JLR, which was forced to shut down systems across all its factories, offices and retail sites after discovering intruders on the last day of August last year.
The independent Cyber Monitoring Centre estimated that the JLR attack cost the UK economy at least £1.9bn, likely making it the most expensive cyber incident in British history, largely due to lost output at JLR and its suppliers. The New York Times reported in June that UK law enforcement had concluded Russian hackers were responsible.
Other major attacks reported in recent years include two FTSE 100 manufacturers, valve maker IMI and components maker Smiths Group, which disclosed incidents within days of each other in early 2025. In retail, Marks & Spencer, the Co-op and Harrods all suffered costly breaches last year.
Jonathon Ellison, director of national resilience at the National Cyber Security Centre (NCSC), which was involved in responding to the JLR attack, said that in today's environment no manufacturer can treat cybersecurity as anything less than a business-critical priority, adding that the NCSC is working to help organisations of all sizes strengthen their defences.
Among the 123 surveyed manufacturers affected by an attack on their supply chain, about 30% reported delivery delays to customers or reduced output, while nearly a quarter said they faced supplier delays or shortages of components and materials.


