Cybersecurity has become an operational risk for manufacturers rather than a purely technical concern. A new report from Make UK, The Manufacturer's Organisation finds that nearly a third of manufacturers have now been hit by a cyber incident either directly or through their supply chains, exposing production lines, supplier networks, and business continuity to growing threats.
Cyber Resilience Gains Ground
The report highlights that incidents carry particular weight for manufacturers because they connect directly to physical production through operational technology, robotics, and connected machinery. When these systems are disrupted, the result is halted production lines, delayed orders, and frustrated customers.
Those effects don't stay contained to a single company. According to Steve Bradford, Senior Vice President and General Manager for EMEA at SailPoint, manufacturing has long been an attractive target because supply chains tend to be sprawling and complex, with legacy systems and scattered tooling giving attackers easy openings. He notes that compromising just one supplier's credentials can be enough to disrupt an entire supply and demand network.
Digital Systems Introduce New Vulnerabilities
Manufacturing used to run largely in isolation. Today, factory floors are wired into business systems, cloud platforms, supplier networks, and remote monitoring tools, and each connection adds another potential point of entry for attackers.
Of the 30% of manufacturers affected by cyber incidents over the past year, two-thirds managed to mitigate the damage, while the remaining third faced serious financial and operational fallout. Among companies hit by attacks on their suppliers, 31% reported delayed customer deliveries and reduced output, 23% saw material shortages and supplier delays, and 8% experienced logistics disruption and higher costs.
There is a silver lining: cyber assurance is climbing the corporate agenda. Nearly a quarter of manufacturers now ask suppliers to prove their cyber compliance, and a similar share have themselves been asked by customers to do the same. Still, the report finds that 71% of manufacturers have no such requirements in place at all.
"Critical infrastructure, including manufacturing, has long been favoured by cybercriminals."— Steve Bradford, SVP & GM EMEA, SailPoint
Financial Impact Extends Beyond Ransom
The true cost of an attack goes well beyond any ransom demand. Among impacted companies, 46% pointed to rising operational costs and production downtime as the most common consequence. Supply chain disruption, ransom demands, and data breaches were cited by 15%, while a further 8% reported reduced output and delayed orders.
On the barriers side, cost and lack of awareness of available solutions were cited by 31.8% of respondents as the main obstacle to improving resilience. Over one in seven felt existing solutions weren't relevant to their business, and 18.2% said providers simply don't understand how manufacturers operate.
