Cyber Essentials

Make UK’s new survey puts numbers on what the Jaguar Land Rover attack made visible: manufacturing supply chains carry cyber risk in both directions, and the smaller firms in the chain carry more of it than they think. Jonathan Krause, founder of Forensic Control and a former Metropolitan Police cybercrime investigator, on what the figures mean for suppliers.
By Jonathan Krause | Founder, Forensic Control | 11 August 2026
Make UK, the manufacturers’ organisation, published survey findings on Monday showing that 30% of UK manufacturers experienced a cyber incident in the past 12 months, either directly or through their supply chain. Just 51% have a formal cyber security incident response plan in place, a gap that matters beyond the factory gate, because the Jaguar Land Rover (JLR) attack showed what it costs when preparation is thin.
Among the manufacturers reporting incidents, 31% suffered reduced production capacity or operational delays, 31% saw customer deliveries delayed, and 23% experienced component or material shortages caused by an attack somewhere upstream. The survey of 123 firms counted incidents arriving both directly and through the contract chain.
What I find most telling is how unevenly the exposure is spread. The primes have security teams and retainers in place; it is the smaller firms further down the chain that will be asked, often at short notice, to evidence controls they have not previously documented.
The attack on JLR began in late August 2025 and halted production for around five weeks from 1 September. The Cyber Monitoring Centre (CMC), the independent body that categorises major UK cyber events, put the most likely cost at £1.9bn, spread across roughly 5,000 affected organisations. Ciaran Martin, chair of the CMC’s technical committee, called it “by some distance, the single most financially damaging cyber event ever to hit the UK.”
Most of that £1.9bn did not sit on JLR’s own balance sheet. It spread through suppliers who suffered no attack on their own systems, only a customer that could not build cars. What struck me, watching it unfold, was how little of the bill related to the intrusion itself; for a supplier on thin margins, five weeks without orders is a financing problem long before it is a security one.
In the public sector, the question is already explicit: suppliers to the Ministry of Defence and the wider public sector are asked to demonstrate certification before new contracts are awarded. Supplier questionnaires there ask for Cyber Essentials certification as a baseline, and the scheme’s five controls map closely onto the entry routes used in the attacks the survey describes. It would surprise me if private primes, having just absorbed a £1.9bn lesson in supplier fragility, settled for less.
Cyber Essentials Plus adds hands-on technical verification to the base scheme’s self-assessment: an assessor tests a sample of your devices and runs vulnerability scanning against your systems, rather than taking the questionnaire answers on trust. For a supplier trying to stay on an approved list, that distinction matters, because independently verified evidence is what a prime’s procurement and insurance teams can accept without argument.
The same assurance pattern has already moved through the defence and public sector supply chains we support, and I wrote in April about the Cyber Resilience Pledge asking public sector suppliers for exactly this evidence.
The first hour of preparation is free. Confirm multi-factor authentication (MFA) is enabled for every user on Microsoft 365 or Google Workspace, and on your accounting platform (Sage, Xero or QuickBooks), not only for administrators. Open your incident response plan, if you have one, and check three fields: the out-of-hours contact list, the date of last review, and who it names as able to authorise taking systems offline. Then pull your insurance schedule and confirm whether cyber cover is included and what its notification requirements say.
The public record offers a controlled experiment in why this matters to a board. When attackers reached the Co-op in April 2025, its team spotted the intrusion in progress and disconnected systems before ransomware could be deployed; even the attackers conceded that “they yanked their own plug”, and shelves were recovering within days. Marks & Spencer, hit in the same wave, was still disrupted weeks later, with online orders suspended and a cost the company put at around £300m. The difference was less about budget than about a decision someone was prepared, and authorised, to take quickly.
If no plan exists, the National Cyber Security Centre’s (NCSC) Exercise in a Box service is free and the starter scenarios take less than an hour with your existing team.
If you supply a larger manufacturer and no security questionnaire has reached you yet, the sensible assumption is that one arrives before your next contract renewal. Our free Quick Check tool shows where you stand against the five Cyber Essentials controls in around ten minutes; the number to call with the results is in the box above.
A workable plan names the people who lead the response and their deputies, with out-of-hours contact details for your IT provider, insurer and bank. It states who can authorise disconnecting systems, and how staff report a suspected incident. The National Cyber Security Centre publishes free templates and rehearsal exercises. Plans that have not been rehearsed tend to fail first on contact details and decision authority.
No. Cyber Essentials certifies five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. It is designed to prevent the most common attacks rather than to manage the aftermath of one. Incident response planning sits alongside certification, and the strongest supplier submissions include both: a current certificate and a dated, rehearsed response plan.
The Cyber Monitoring Centre estimated the most likely cost of the 2025 Jaguar Land Rover attack at £1.9bn, making it the most financially damaging cyber event recorded in the UK. Around 5,000 organisations were affected, most of them suppliers.
Cyber Essentials demonstrates that five baseline technical controls are in place, and Cyber Essentials Plus adds independent hands-on verification, the level many procurement teams now specify. Beyond certification, keep an up-to-date asset list, evidence of multi-factor authentication and patching, and a named security contact, because these are what supplier questionnaires ask for most often.
There is no legal requirement, but Make UK’s August 2026 survey found nearly a third of UK manufacturers either have no cyber insurance or are unsure whether their cover would respond. Check whether cyber events are covered, what the notification requirements are, and whether the insurer expects controls such as multi-factor authentication, since a lapsed control can complicate a claim.
Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.