Just Half of UK Manufacturers Have Internal Cyber Incident Response Process, Report Finds
Many UK manufacturers are significantly strengthening their cyber defenses, but they remain exposed to disruption, according to a new report this week from Make UK, an organization representing 20,000 manufacturers.
The report, Cyber Security in Manufacturing, found that 30 percent of manufacturers faced a serious incident in the past year, either directly or through their supply chain. A third of those affected saw financial and business impact from those incidents, while two-thirds reported no impact due to effective mitigations or containment.
Nearly all (92 percent) of survey respondents said they have firewalls in place for cybersecurity, followed by malware protection (80 percent), secure configurations (67 percent), and access control (61 percent), although patch management lagged behind at only 36 percent.
Manufacturers have the biggest room for improvement around governance, though. Only 45 percent of respondents said they have a senior leader responsible for cybersecurity, and barely half reported having internal incident response and recovery practices.
|
Cybersecurity Governance and Incident Preparedness |
|
|
We have internal incident response/recovery processes |
51 percent |
|
A senior leader is responsible for cybersecurity |
45 percent |
|
We have cybersecurity roles defined in policy |
42 percent |
|
Cybersecurity is regularly discussed at board or risk meetings |
39 percent |
|
We have a chief information security officer (CISO) |
23 percent |
|
None of the above |
3 percent |
Supply chain risk is a key element of the report. A cyber incident at one supplier can quickly affect many others, causing delays to customer deliveries (reported by 31 percent of affected manufacturers), reduced capacity (31 percent), and shortages of components or materials (23 percent).
Resilience is a critical commercial issue, too, with customers increasingly looking for proof that manufacturers can protect data and avoid disruption. A quarter of survey respondents for the report said that customers are requesting cybersecurity compliance, and 23 percent of manufacturers are asking suppliers for cybersecurity assurances.
“This demonstrates a growing awareness of third-party cyber risk and highlights how responsibility for cyber resilience is becoming embedded across supply chains,” the report said. “While most manufacturers have not yet introduced such requirements (71 percent), the findings suggest that cyber security is increasingly being treated as a shared responsibility rather than an issue confined within individual organizations.”
It’s not surprising that both customers and manufacturers are sensitive to cyber threats lately. Various studies posit that significant UK manufacturing cyber incidents cost more than £250,000 ($337,600) per attack, with major enterprise data breaches costing notably more. Make UK conservatively estimated that the direct financial impact on an affected manufacturer is approximately £28,000 ($37,800) per incident, driven by increased operational costs and production downtime.
|
Wider Business Impacts of Cyber Incidents |
|
|
Increased operational costs |
46 percent |
|
Production downtime |
46 percent |
|
Disruption to supply chain |
15 percent |
|
Data loss or breach |
15 percent |
|
Ransom demand |
15 percent |
|
Lost output or reduced capacity |
8 percent |
|
Delays to customer orders |
8 percent |
“While manufacturers increasingly recognize the importance of cybersecurity, many still face practical barriers to improving their cyber resilience,” the report said. “These barriers can limit the adoption of cybersecurity products, services, standards, and insurance, leaving businesses more exposed to cyber threats.”
Manufacturers struggle to find solutions that align with the realities of their operating environments and requirements. Even when organizations invest in digital technologies, automation, and artificial intelligence to improve productivity and competitiveness, those same technologies can expand cyber risk exposure, creating a connected cycle of productivity and vulnerability, the report said.
“The challenge therefore is not choosing between digitalization and security but ensuring that cyber resilience is built into digital adoption programs from the outset,” Make UK noted.
|
Barriers to Improving Cyber Resilience |
|
|
Unaware of available products |
32 percent |
|
Too expensive |
32 percent |
|
Not relevant to our business |
23 percent |
|
Lack of provider understanding of manufacturing |
18 percent |
|
Too complex |
9 percent |
|
Other |
5 percent |









