A survey from MakeUK, the group that represents British manufacturers, found that 30% of factories in the UK were hit by a cyberattack, or by an attack on a company in their supply chain, over the past year. Only half of those companies had a plan for what to do when it happened.
That gap matters because manufacturing has quietly become the most attacked industry on the planet for ransomware, ahead of hospitals and energy firms. The logic is simple: a hospital can often keep running on paper records for a day, but a factory cannot. Every hour a production line sits idle costs real money, so criminals expect manufacturers to pay a ransom fast just to get the line moving again.
The UK already has a case study in what this looks like at scale. Jaguar Land Rover was forced to halt production across every factory, office, and dealership last September after hackers got into its systems. The independent Cyber Monitoring Centre estimated the total cost to the UK economy at a minimum of 1.9 billion pounds, likely the most expensive cyber incident Britain has ever recorded.
The damage was so severe that the government stepped in with a 1.5 billion pound loan guarantee, not to help JLR directly, but to stop its suppliers from collapsing and their workers from losing jobs. Reporting has pointed to Russian hackers as the source of the attack.
This is exactly why the MakeUK numbers on supply chains matter so much. Among manufacturers hit by an attack on their supply chain, about 30% reported delivery delays or had to cut output, and close to a quarter reported shortages of parts or materials from suppliers. You do not need to be hacked yourself to get hurt, a weak link two or three companies away can shut your line down just as effectively.
There is a newer wrinkle that makes this harder to ignore. In November, Anthropic disclosed that a state linked hacking group had hijacked its own AI coding tool, Claude Code, and used it to carry out 80 to 90 percent of a large espionage campaign with almost no human involvement, just a handful of decisions made by people at key moments. The skill and time it takes to run a serious attack is dropping fast, which means the pool of companies worth targeting is growing.
A mid-sized manufacturer that once assumed it was too small to be interesting to hackers no longer gets that excuse. None of this requires a large security team to address. A written response plan, the kind half of the surveyed manufacturers still do not have, is cheap compared to weeks of lost production.
Separating factory floor systems from office computers limits how far an intruder can travel once inside. Asking suppliers directly how they would handle an attack is no longer a courtesy question, it is basic due diligence. Cyber insurance premiums are also climbing, up roughly 6.5% globally this year according to Munich Re, and insurers increasingly price risk based on whether a company can show it has a plan at all.