Jaguar Land Rover: Only Half of UK Manufacturers Have a Cyber Incident Response Plan

Jaguar Land Rover: Only Half of UK Manufacturers Have a Cyber Incident Response Plan

UK Manufacturing Sector Faces Growing Cyber Threats as Resilience Gaps Persist

A new report by Make UK, the UK’s manufacturing trade association, reveals that nearly one-third (30%) of UK manufacturers experienced a cyber incident in the past year either directly or through their supply chain. Published on August 10, the Cyber Security in Manufacturing report combines data from Make UK’s Cyber Resilience 2026 survey with broader industry and government insights, exposing critical vulnerabilities in the sector’s digital defenses.

Operational and Financial Fallout from Cyber Incidents

Cyberattacks on manufacturers have tangible consequences, disrupting production and supply chains. Among affected businesses:

  • 31% reported reduced production capacity or operational delays.
  • 23% faced component or material shortages.
  • 31% experienced delays in customer deliveries, underscoring the sector’s reliance on uninterrupted operations.

Uneven Preparedness Despite Rising Awareness

While cybersecurity awareness is growing, the report highlights stark gaps in readiness. Key findings include:

  • 51% of manufacturers have a formal cyber incident response plan, leaving nearly half without one.
  • 45% have designated senior leadership responsible for cybersecurity meaning over half lack clear accountability.
  • Only 23% employ a dedicated Chief Information Security Officer (CISO), a critical role in managing modern threats.

The report warns that cybersecurity has evolved from an IT issue to a commercial imperative, with partners and customers increasingly demanding proof of robust data protection, uptime, and supply chain integrity before signing contracts. Yet, nearly a third of manufacturers either lack cyber insurance or are unsure if their coverage applies to cyber disruptions.

Industrial Control Systems Remain a Blind Spot

Andrew Lintell, EMEA General Manager at Claroty, noted that despite high-profile incidents like the 2025 Jaguar Land Rover cyberattack serving as wake-up calls, many manufacturers still fail to address core vulnerabilities. A major challenge lies in industrial control systems (ICS), sensors, and connected machinery, which traditional IT security tools often overlook.

"You can’t defend what you can’t see and that’s still the norm on most factory floors," Lintell said. "In manufacturing, cyberattacks don’t just create IT tickets; they halt production lines and delay shipments, leading to rapid financial losses."

Recommendations for Strengthening Defenses

Make UK’s report urges manufacturers to move beyond passive compliance and adopt proactive measures, including:

  • Elevating cybersecurity as a board-level priority.
  • Strengthening basic cyber hygiene (e.g., patch management, access controls).
  • Improving supplier assurance to mitigate third-party risks.
  • Testing recovery plans before disruptions occur.

The findings underscore the urgent need for the sector to close governance gaps and enhance visibility into industrial systems to prevent costly operational and financial setbacks.

Source: https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/

Jaguar cybersecurity rating report: https://www.rankiteo.com/company/jaguar

"id": "JAG1786436773",
"linkid": "jaguar",
"type": "Cyber Attack",
"date": "8/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing',
                        'location': 'United Kingdom',
                        'name': 'UK Manufacturing Sector (General)',
                        'type': 'Industry Sector'},
                       {'industry': 'Automotive Manufacturing',
                        'location': 'United Kingdom',
                        'name': 'Jaguar Land Rover',
                        'type': 'Company'}],
 'date_publicly_disclosed': '2024-08-10',
 'description': 'A report by Make UK reveals that nearly one-third (30%) of UK '
                'manufacturers experienced a cyber incident in the past year '
                'either directly or through their supply chain. The report '
                'highlights operational disruptions, financial fallout, and '
                "critical vulnerabilities in the sector's digital defenses, "
                'including gaps in incident response plans, leadership '
                'accountability, and industrial control system security.',
 'impact': {'operational_impact': ['Reduced production capacity',
                                   'Operational delays',
                                   'Component or material shortages',
                                   'Delays in customer deliveries'],
            'systems_affected': ['Production Systems', 'Supply Chain Systems']},
 'lessons_learned': 'Cybersecurity has evolved from an IT issue to a '
                    'commercial imperative. Manufacturers must prioritize '
                    'cybersecurity at the board level, strengthen basic cyber '
                    'hygiene, improve supplier assurance, and enhance '
                    'visibility into industrial systems to prevent operational '
                    'and financial setbacks.',
 'post_incident_analysis': {'corrective_actions': ['Adopt proactive '
                                                   'cybersecurity measures',
                                                   'Improve governance and '
                                                   'accountability',
                                                   'Enhance visibility into '
                                                   'ICS and connected '
                                                   'machinery',
                                                   'Strengthen supplier '
                                                   'cybersecurity '
                                                   'requirements'],
                            'root_causes': ['Lack of formal incident response '
                                            'plans',
                                            'Insufficient leadership '
                                            'accountability',
                                            'Poor visibility into industrial '
                                            'control systems',
                                            'Third-party risks',
                                            'Inadequate basic cyber hygiene']},
 'recommendations': ['Elevate cybersecurity as a board-level priority',
                     'Strengthen basic cyber hygiene (e.g., patch management, '
                     'access controls)',
                     'Improve supplier assurance to mitigate third-party risks',
                     'Test recovery plans before disruptions occur',
                     'Employ a dedicated Chief Information Security Officer '
                     '(CISO)',
                     'Enhance visibility into industrial control systems '
                     '(ICS)'],
 'references': [{'date_accessed': '2024-08-10',
                 'source': 'Make UK Cyber Security in Manufacturing Report'},
                {'date_accessed': '2024-08-10',
                 'source': 'Claroty (Andrew Lintell, EMEA General Manager)'}],
 'response': {'incident_response_plan_activated': '51% of manufacturers have a '
                                                  'formal cyber incident '
                                                  'response plan'},
 'title': 'UK Manufacturing Sector Cyber Threats and Resilience Gaps',
 'type': ['Cyberattack', 'Supply Chain Attack'],
 'vulnerability_exploited': ['Industrial Control Systems (ICS)',
                             'Third-Party Risks',
                             'Lack of Basic Cyber Hygiene']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.