30% of UK manufacturers suffered a cyber incident. What happens if you’re next?
New research from Make UK found that 30% of UK manufacturers experienced a cyber incident in the last 12 months, either directly or through their supply chain. Only around half have an incident response plan in place.
That’s the bit that should probably get more attention.
You can’t guarantee you’ll never suffer a cyber attack.
You can decide how prepared you’ll be if one happens.
Cybersecurity becomes a business problem very quickly
If an attack takes systems offline, it’s no longer just an IT issue.
Production can stop.
Orders can be delayed.
Staff can’t access systems.
Customers start asking questions.
Costs start rising.
Make UK found that production downtime and increased operating costs were among the most common impacts when incidents caused disruption. And of manufacturers affected by supplier cyber attacks, 31% reported delays to customer deliveries.
That’s where cybersecurity becomes a lot more tangible.
It’s not just about protecting data.
It’s about keeping the business running.
Would you know what to do tomorrow morning?
Imagine you arrive at work and staff can’t log in.
Email isn’t working.
Your ERP system is unavailable.
Files can’t be accessed.
Someone has a suspicious message on their screen.
What happens next?
Who takes control?
Who calls IT?
Which systems need recovering first?
Can you contact customers if email is down?
Do your backups actually work?
Those aren’t questions you want to be answering for the first time while an incident is happening.
Your suppliers are part of the problem too
The attack doesn’t necessarily have to happen to you.
A supplier, software provider or logistics partner suffering a cyber incident can quickly become your problem.
If one of your critical suppliers disappeared tomorrow, how long could you keep operating?
That’s increasingly part of the cybersecurity conversation, particularly in manufacturing where systems and supply chains are so interconnected.
And it’s one of the reasons the Government is increasingly encouraging organisations to strengthen cybersecurity throughout their supply chains, including through Cyber Essentials
So where do you actually start?
This is where cybersecurity can become unnecessarily complicated.
There are hundreds of products, frameworks and acronyms, and it’s very easy to end up buying another security tool without really knowing whether the basics are covered.
For most businesses, a much better starting point is Cyber Essentials.
Cyber Essentials is the Government-recommended minimum standard of cyber security for organisations of all sizes. It’s built around five technical controls designed to protect businesses against common internet-based cyber threats.
In practical terms, it forces you to look properly at things like:
- how your network is protected
- how devices are configured
- who has access to what
- whether software and operating systems are being updated
- how malware is being prevented
Which sounds fairly basic.
That’s because it is.
But basic security done properly prevents an awful lot of problems.
And then there’s Cyber Essentials Plus
Cyber Essentials is based on an assessment of the controls you have in place.
Cyber Essentials Plus goes a step further.
It covers the same core controls, but includes a technical audit to verify that those controls are actually working as they should.
For manufacturers, that’s particularly valuable.
Because there’s a big difference between saying:
“We think our security is configured correctly.”
and:
“It’s been independently tested and verified.”
That assurance can also matter when customers, larger organisations or supply-chain partners start asking what you’re doing to protect their data and systems.
Don’t wait until something happens
The Make UK figures aren’t really a reason to panic.
They’re a reason to check whether you’ve actually got the basics right.
Do you know what you’d do during an incident?
Are your systems properly protected?
Are updates being installed?
Are user accounts and permissions controlled?
Could you demonstrate that to a customer if they asked?
If the answer to some of those is “not sure”, Cyber Essentials is a sensible place to start.
And if you want the additional assurance that those controls have been technically verified, Cyber Essentials Plus is the next step.
At Network, we can help businesses understand what’s required, identify the gaps and get the right security controls in place before going through Cyber Essentials or Cyber Essentials Plus certification.
Because the best time to discover a weakness in your cybersecurity isn’t after production has stopped.
It’s before someone gets the chance to exploit it.
Source: Make UK, Cyber Security in Manufacturing, August 2026.





