Skip to content

Illustration by iStock; Security Management

Just Half of UK Manufacturers Have Internal Cyber Incident Response Process, Report Finds

Many UK manufacturers are significantly strengthening their cyber defenses, but they remain exposed to disruption, according to a new report this week from Make UK, an organization representing 20,000 manufacturers.

The report, Cyber Security in Manufacturing, found that 30 percent of manufacturers faced a serious incident in the past year, either directly or through their supply chain. A third of those affected saw financial and business impact from those incidents, while two-thirds reported no impact due to effective mitigations or containment.

Nearly all (92 percent) of survey respondents said they have firewalls in place for cybersecurity, followed by malware protection (80 percent), secure configurations (67 percent), and access control (61 percent), although patch management lagged behind at only 36 percent.

Manufacturers have the biggest room for improvement around governance, though. Only 45 percent of respondents said they have a senior leader responsible for cybersecurity, and barely half reported having internal incident response and recovery practices.

Cybersecurity Governance and Incident Preparedness

We have internal incident response/recovery processes

51 percent

A senior leader is responsible for cybersecurity

45 percent

We have cybersecurity roles defined in policy

42 percent

Cybersecurity is regularly discussed at board or risk meetings

39 percent

We have a chief information security officer (CISO)

23 percent

None of the above

3 percent


Supply chain risk is a key element of the report. A cyber incident at one supplier can quickly affect many others, causing delays to customer deliveries (reported by 31 percent of affected manufacturers), reduced capacity (31 percent), and shortages of components or materials (23 percent).

Resilience is a critical commercial issue, too, with customers increasingly looking for proof that manufacturers can protect data and avoid disruption. A quarter of survey respondents for the report said that customers are requesting cybersecurity compliance, and 23 percent of manufacturers are asking suppliers for cybersecurity assurances.

“This demonstrates a growing awareness of third-party cyber risk and highlights how responsibility for cyber resilience is becoming embedded across supply chains,” the report said. “While most manufacturers have not yet introduced such requirements (71 percent), the findings suggest that cyber security is increasingly being treated as a shared responsibility rather than an issue confined within individual organizations.”

It’s not surprising that both customers and manufacturers are sensitive to cyber threats lately. Various studies posit that significant UK manufacturing cyber incidents cost more than £250,000 ($337,600) per attack, with major enterprise data breaches costing notably more. Make UK conservatively estimated that the direct financial impact on an affected manufacturer is approximately £28,000 ($37,800) per incident, driven by increased operational costs and production downtime.

Wider Business Impacts of Cyber Incidents

Increased operational costs

46 percent

Production downtime

46 percent

Disruption to supply chain

15 percent

Data loss or breach

15 percent

Ransom demand

15 percent

Lost output or reduced capacity

8 percent

Delays to customer orders

8 percent


“While manufacturers increasingly recognize the importance of cybersecurity, many still face practical barriers to improving their cyber resilience,” the report said. “These barriers can limit the adoption of cybersecurity products, services, standards, and insurance, leaving businesses more exposed to cyber threats.”

Manufacturers struggle to find solutions that align with the realities of their operating environments and requirements. Even when organizations invest in digital technologies, automation, and artificial intelligence to improve productivity and competitiveness, those same technologies can expand cyber risk exposure, creating a connected cycle of productivity and vulnerability, the report said.

“The challenge therefore is not choosing between digitalization and security but ensuring that cyber resilience is built into digital adoption programs from the outset,” Make UK noted.

Barriers to Improving Cyber Resilience

Unaware of available products

32 percent

Too expensive

32 percent

Not relevant to our business

23 percent

Lack of provider understanding of manufacturing

18 percent

Too complex

9 percent

Other

5 percent

 

arrow_upward