Summary
- Make UK says 30% of manufacturers experienced a cyber incident directly or through their supply chain during the previous year.
- Production downtime and increased operating costs were the most common consequences where attacks caused disruption.
- Only around half of respondents had incident-response plans, while almost a third lacked cyber insurance or were unsure whether they were covered.
Cyber incidents are reaching the production line rather than remaining confined to corporate IT, with new UK manufacturing research linking attacks to downtime, higher operating costs, supplier disruption, and delayed customer deliveries.
Make UK says 30% of manufacturers experienced a cyber incident during the previous year, either directly or through their supply chain. Where an event caused disruption, production downtime and increased operational costs were the most commonly reported consequences.
The effects also travelled through suppliers. Among manufacturers affected by cyberattacks on suppliers, 31% reported delays to customer deliveries, connecting third-party cyber exposure directly to contractual and operational performance.
The findings show why manufacturing risk cannot be divided neatly between IT security and factory operations. Enterprise resource planning, identity systems, production scheduling, logistics, supplier portals, engineering data, and industrial systems may be technically distinct, but production depends on them operating together.
A cyber incident does not therefore need to manipulate machinery directly to stop a factory. Loss of authentication, production schedules, parts information, network availability, or supplier connectivity may be enough to make continued operation unsafe, inefficient, or commercially impractical.
Make UK’s research also exposes gaps in preparation. Only around half of manufacturers said they had an incident-response plan, while almost a third either did not have cyber insurance or did not know whether they were covered.
Those gaps become more important once disruption leaves the technology estate. Restarting manufacturing can require production lines to be brought back in sequence, supplier schedules to be rebuilt, safety and quality checks to be repeated, and customers to be given revised delivery commitments.
Financial pressure can also move down the supply chain rapidly. A smaller manufacturer that depends on one large customer may continue paying staff and suppliers while orders are delayed, production is suspended, or invoices cannot be processed further upstream.
Insurance can transfer part of that loss, but uncertainty over whether cover exists suggests that some manufacturers may not have mapped cyber interruption against the policies intended to protect revenue and operations. Business interruption, supplier failure, incident-response expenditure, and contractual losses can fall under different conditions and exclusions.
The sector’s wider investment priorities reflect growing recognition of the risk. Make UK’s 2026 executive research found manufacturers increasing expenditure on cyber resilience alongside automation, digital technology, and other transformation programmes.
That creates its own dependency. Greater use of connected manufacturing systems, cloud platforms, automation, and digital supply-chain tooling can improve efficiency while making technology availability more closely tied to physical output.
The new findings do not suggest every cyber incident stopped production, nor do they identify a single attack type responsible for the sector’s exposure. They do show that cyber risk is already appearing in the operational measures manufacturers use to judge performance — whether production runs, what it costs, whether suppliers can deliver, and whether customers receive their goods on time.



