**UK’s Cybersecurity in Manufacturing Report: Recovery Planning Takes Centre Stage**
A new report from Make UK highlights a critical shift in how manufacturers should approach cybersecurity. Moving beyond a narrow focus on IT defenses, the report argues that cyber resilience must be treated as a core operational requirement for modern factories. With enterprise systems now tightly integrated with operational technology (OT), robotics, suppliers, and logistics platforms, a cyber incident can disrupt everything from production schedules to customer deliveries.
The data reveals a mixed picture: while 70% of manufacturers reported no operational disruption from cyber incidents in the past year, and 20% contained attacks before they caused downtime, 10% still experienced incidents with financial or business impacts. These outcomes underscore the need for robust recovery planning, supplier risk management, and clear ownership of OT risks.
**Cybersecurity Reaches the Factory Floor**
Unlike organizations focused primarily on data, manufacturers face unique risks because cyber events can affect systems that control production, monitor equipment, manage orders, and coordinate logistics. The report identifies ERP and manufacturing execution systems as prime ransomware targets and warns of the dual risks of intellectual property theft and compromised safety. If a cyber event or unauthorized configuration change could create a hazardous situation, it must be treated as both a safety and cybersecurity issue.
This demands cross-functional governance. Engineering, maintenance, production, IT, health and safety, procurement, and senior leadership must all play a role. The report emphasizes the need for clear approval routes for changes, defined supplier system access, and established escalation paths, along with processes to assess production and safety impacts during an incident.
Core security controls are widely adopted—92% use firewalls, 80% employ malware protection, and 67% follow secure configuration practices. However, patch management remains a weak spot at only 36%, and the long lifecycle of industrial equipment connected to newer business platforms, cloud services, and remote monitoring tools increases exposure. Organizations must identify critical equipment and platforms, clarify decision-making authority, and map dependencies across machinery, service providers, and the supply chain.
**Supplier Incidents Have Ripple Effects**
The report also highlights how supplier-related cyber incidents extend impact beyond the directly breached company. While 67% of manufacturers saw no financial effect from supplier incidents in the past year, 10% experienced financial or business impacts and 20% avoided disruption through mitigations. For affected companies, common consequences included delays to customer deliveries, reduced production capacity, component shortages, and logistics disruptions.
Supplier assurance is becoming a two-way street. Although most manufacturers have not yet formally requested cybersecurity evidence from suppliers, 25% have received customer requests to demonstrate their own cybersecurity compliance. Make UK recommends mapping supplier dependencies and assessing their ability to disrupt operations, rather than relying on standardized questionnaires or contractual models.
Two high-profile examples illustrate the reach of digital disruption: Marks & Spencer faced around £131 million in costs following a cyber incident that shut down online clothing and home orders for 46 days, while Stryker Medical navigated a global network incident affecting production, shipping, and distribution, with NHS partners helping to manage UK supply risk.
**Downtime Drives Costs**
The financial impact of a cyber incident is significant, with Make UK estimating an average cost of about £28,000 per affected manufacturer—though the report calls this figure conservative. Costs ranged widely: 36% of affected firms reported expenses up to £10,000, while similar proportions faced costs between £25,001 and £50,000. The most frequently cited business effects were increased operational costs and production downtime, each reported by 46% of affected companies, followed by supply chain disruption, data loss, and ransom demands at 15% each.
These results show that cyber recovery cannot be separated from continuity planning. Restoring endpoints is not enough; manufacturers must test the full return of production schedules, order management, logistics coordination, and customer commitments.
**Governance and Testing Remain Uneven**
Progress on preventative controls outpaces formal preparedness. While over half of respondents have internal incident response processes, a named senior leader responsible for cybersecurity, defined cyber roles in policy, or regular board-level discussions, gaps remain. Only 23% have a dedicated CISO, and 11% reported no preparedness arrangements at all. Confidence in readiness also outpaces evidence, with 38% describing themselves as very confident and 10% extremely confident, while 36% are only moderately confident.
Affordability and lack of awareness are the top barriers to improvement, followed by perceived misalignment between available products and manufacturing needs and limited provider understanding of operational environments. Make UK directs organizations to NCSC resources including the Board Toolkit, Cyber Security Code of Practice, Early Warning service, and Exercise in a Box, and encourages industrial control system teams to engage with the ICS Community of Interest.
Above all, the report urges manufacturers to move beyond documentation and regularly test how production, orders, logistics, and customer relationships recover after an incident.
—
### **FAQ**
**Q: Why does manufacturing cybersecurity extend beyond the IT department?**
A: Because cyber incidents can disrupt production systems, equipment safety, order management, and logistics—impacting the ability to meet customer commitments. Ownership must span engineering, operations, safety, procurement, and leadership.
**Q: What operational systems are most at risk?**
A: ERP and manufacturing execution systems are key targets for ransomware, while intellectual property theft and safety-critical OT disruptions are major concerns.
**Q: How significant is the supplier risk in manufacturing cyber incidents?**
A: Supplier incidents can cause production delays, capacity loss, and component shortages for affected manufacturers, even if many report no direct financial impact.
**Q: What are the most common cybersecurity controls in manufacturing?**
A: Firewalls (92%), malware protection (80%), secure configuration (67%), and access control (61%) are widely used, but patch management remains limited at 36%.
**Q: What barriers prevent better cybersecurity in manufacturing?**
A: The leading barriers are affordability and lack of awareness, followed by products that do not fit manufacturing-specific needs and limited provider understanding of operational environments.
**Q: How can manufacturers improve their cyber resilience?**
A: By mapping systems and supplier dependencies, defining governance and escalation processes, testing recovery of production and logistics, and using NCSC and industry resources for guidance.
—
### **Conclusion**
Make UK’s report makes it clear that cybersecurity in manufacturing is no longer just an IT issue—it is an operational resilience issue. As factories become more connected, the consequences of cyber incidents ripple through production, safety, and customer commitments. While preventative controls are steadily improving, recovery planning, supplier risk management, and governance still require urgent attention. Manufacturers must adopt a holistic, cross-functional approach, regularly test their ability to recover operations, and leverage trusted frameworks and industry guidance to build true cyber resilience. The goal is not just to prevent attacks, but to ensure that production can continue—or quickly recover—when they occur.



