Cyber security for manufacturers

The Jaguar Land Rover attack cost an estimated 1.9 billion pounds, and most of that bill fell on suppliers whose own systems were never breached. Forensic Control helps UK manufacturers evidence the security controls that primes now require, close the incident response gap, and keep their place on approved supplier lists.

Why manufacturing cyber risk flows through the supply chain

Manufacturing has become one of the most attacked sectors in the UK, and the risk does not stay where the breach happens. When attackers halted Jaguar Land Rover production for around five weeks in late 2025, the Cyber Monitoring Centre put the most likely cost at £1.9bn spread across roughly 5,000 organisations, most of them suppliers who suffered no intrusion of their own. For a supplier on thin margins, five weeks without orders is a financing problem long before it is a security one.

The wider picture matches. Survey findings from Make UK, the manufacturers organisation, show that 30% of UK manufacturers experienced a cyber incident in the past 12 months, directly or through their supply chain, while only 51% hold a formal cyber security incident response plan. Among firms reporting incidents, roughly a third suffered reduced production capacity or delayed customer deliveries, and nearly a quarter experienced component shortages caused by an attack somewhere upstream.

The consequence for suppliers is practical rather than abstract: primes that have just absorbed the cost of supplier fragility are tightening their assurance requirements. Supplier questionnaires increasingly ask for Cyber Essentials certification as a baseline, and firms that cannot evidence their controls risk losing their place on approved lists at renewal.

Forensic Control works with manufacturers to get ahead of that conversation: certification to the level primes specify, evidence packs their procurement teams can accept without argument, and an incident response capability for when something does go wrong.

Common security challenges for manufacturers

The gaps we see in manufacturing reflect a sector where production systems, legacy equipment and supply chain obligations meet, often without a dedicated security team in the middle.

Supplier questionnaires from primes

Automotive, aerospace and FMCG primes increasingly require Cyber Essentials from suppliers. Questionnaires often arrive at short notice, before contract renewal.

Production downtime risk

For a manufacturer, the cost of an incident is measured in halted lines and missed deliveries, not just IT recovery. Downtime is the real bill.

IT and OT convergence

Production systems that once ran in isolation now connect to corporate networks and the internet. Each connection is a route an attacker can use.

Legacy and unpatched systems

Equipment and control software often outlive vendor support. Ransomware groups now select victims by which devices are already exploitable.

The incident response gap

Only around half of UK manufacturers hold a formal incident response plan. Plans that exist often fail first on contact details and decision authority.

Cyber insurance conditions

Nearly a third of manufacturers have no cyber insurance or are unsure their cover would respond. Lapsed controls such as MFA can complicate a claim.

Meeting prime supplier assurance through Cyber Essentials Plus

For most manufacturing suppliers, Cyber Essentials is the certification supplier questionnaires name, and Cyber Essentials Plus is the level that ends the conversation. The independent technical audit, with an assessor testing a sample of your devices and running vulnerability scanning against your systems, produces evidence a prime procurement or insurance team can accept without argument. Self-assessed answers, taken on trust, increasingly cannot.

Forensic Control is an authorised IASME Certification Body, not a reseller. We have been delivering Cyber Essentials since 2017, and we work with manufacturers to certify on the timeline the contract allows:

  • Cyber Essentials (Basic). Self-assessment with expert review. Sufficient where the questionnaire asks only for baseline certification.
  • Cyber Essentials Plus. Independent technical audit with 12 months of vulnerability scanning included at no extra cost. The level primes increasingly specify.
  • Cyber Essentials Duo. Basic and Plus combined at a single price point. Often the right choice when the assurance requirement is expected to tighten at the next renewal.

The five Cyber Essentials controls map closely onto the entry routes used in the attacks now hitting the sector. Certification is not just a procurement checkbox: it closes the doors most attacks actually walk through.

From supplier questionnaire to accepted evidence

A typical engagement, from the questionnaire arriving to a renewal-ready evidence pack. We work to your contract timeline.

1
Questionnaire review
We review the security questionnaire or contract clause you have received to confirm exactly what level of certification and evidence the prime requires.
2
Scope and readiness check
We map which systems are in scope, including where production and office networks connect, and identify anything that would cause an assessment to fail.
3
Remediation support
Most failures trace to a small set of gaps: MFA not fully enforced, unsupported software still in use, admin access too widely held. We help you close them without disrupting production.
4
Certification
Cyber Essentials self-assessment with expert review, or the full Cyber Essentials Plus technical audit including vulnerability scanning, at the level your prime specifies.
5
Evidence pack for the prime
Certification documents, scope statement and technical summary formatted for the supplier questionnaire, reusable across multiple customers.
6
Incident response readiness
A working response plan with named decision-makers, out-of-hours contacts and rehearsed authority to disconnect systems, closing the gap half the sector still has.
Forensic Control logo

“Most of the Jaguar Land Rover bill did not sit on JLR's own balance sheet. It spread through suppliers who suffered no attack on their own systems, only a customer that could not build cars. The firms that come through that kind of event are the ones that could evidence their controls before anyone asked.”

Jonathan Krause
Founder & Head Assessor, Forensic Control. Former Metropolitan Police Hi-Tech Crime Unit

Frequently asked questions

Practical answers to the questions manufacturers ask us most often.
Do manufacturers need Cyber Essentials to keep supplying larger customers?
What did the Jaguar Land Rover cyber attack cost, and why does it matter to smaller suppliers?
Are our production systems and machinery in scope for Cyber Essentials?
What should a manufacturer's cyber security incident response plan include?
Does Cyber Essentials cover incident response?
How quickly can a manufacturer get certified ahead of a contract renewal?
Will our cyber insurance respond if we are hit?
We also supply the Ministry of Defence. Do different requirements apply?

Speak to a specialist about supplier assurance and certification

Whether a security questionnaire has just arrived, a contract renewal is approaching, or you want to close the incident response gap before anyone asks, we can help. Book a short call to talk through where you are and what you need.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.