Just Half of UK Manufacturers Have Internal Cyber Incident Response Process, Report Finds - ASIS International
ASIS InternationalArchived Aug 15, 2026✓ Full text saved
Just Half of UK Manufacturers Have Internal Cyber Incident Response Process, Report Finds ASIS International
Full text archived locally
✦ AI Summary· Claude Sonnet
Illustration by iStock; Security Management
MANUFACTURING
INFORMATION SECURITY
CYBERSECURITY
INCIDENT MANAGEMENT AND OPERATIONS
Just Half of UK Manufacturers Have Internal Cyber Incident Response Process, Report Finds
By Claire Meyer 12 August 2026
Today in Security
Many UK manufacturers are significantly strengthening their cyber defenses, but they remain exposed to disruption, according to a new report this week from Make UK, an organization representing 20,000 manufacturers.
The report, Cyber Security in Manufacturing, found that 30 percent of manufacturers faced a serious incident in the past year, either directly or through their supply chain. A third of those affected saw financial and business impact from those incidents, while two-thirds reported no impact due to effective mitigations or containment.
Nearly all (92 percent) of survey respondents said they have firewalls in place for cybersecurity, followed by malware protection (80 percent), secure configurations (67 percent), and access control (61 percent), although patch management lagged behind at only 36 percent.
Manufacturers have the biggest room for improvement around governance, though. Only 45 percent of respondents said they have a senior leader responsible for cybersecurity, and barely half reported having internal incident response and recovery practices.
Cybersecurity Governance and Incident Preparedness
We have internal incident response/recovery processes
51 percent
A senior leader is responsible for cybersecurity
45 percent
We have cybersecurity roles defined in policy
42 percent
Cybersecurity is regularly discussed at board or risk meetings
39 percent
We have a chief information security officer (CISO)
23 percent
None of the above
3 percent
Supply chain risk is a key element of the report. A cyber incident at one supplier can quickly affect many others, causing delays to customer deliveries (reported by 31 percent of affected manufacturers), reduced capacity (31 percent), and shortages of components or materials (23 percent).
Resilience is a critical commercial issue, too, with customers increasingly looking for proof that manufacturers can protect data and avoid disruption. A quarter of survey respondents for the report said that customers are requesting cybersecurity compliance, and 23 percent of manufacturers are asking suppliers for cybersecurity assurances.
“This demonstrates a growing awareness of third-party cyber risk and highlights how responsibility for cyber resilience is becoming embedded across supply chains,” the report said. “While most manufacturers have not yet introduced such requirements (71 percent), the findings suggest that cyber security is increasingly being treated as a shared responsibility rather than an issue confined within individual organizations.”
It’s not surprising that both customers and manufacturers are sensitive to cyber threats lately. Various studies posit that significant UK manufacturing cyber incidents cost more than £250,000 ($337,600) per attack, with major enterprise data breaches costing notably more. Make UK conservatively estimated that the direct financial impact on an affected manufacturer is approximately £28,000 ($37,800) per incident, driven by increased operational costs and production downtime.
Wider Business Impacts of Cyber Incidents
Increased operational costs
46 percent
Production downtime
46 percent
Disruption to supply chain
15 percent
Data loss or breach
15 percent
Ransom demand
15 percent
Lost output or reduced capacity
8 percent
Delays to customer orders
8 percent
“While manufacturers increasingly recognize the importance of cybersecurity, many still face practical barriers to improving their cyber resilience,” the report said. “These barriers can limit the adoption of cybersecurity products, services, standards, and insurance, leaving businesses more exposed to cyber threats.”
Manufacturers struggle to find solutions that align with the realities of their operating environments and requirements. Even when organizations invest in digital technologies, automation, and artificial intelligence to improve productivity and competitiveness, those same technologies can expand cyber risk exposure, creating a connected cycle of productivity and vulnerability, the report said.
“The challenge therefore is not choosing between digitalization and security but ensuring that cyber resilience is built into digital adoption programs from the outset,” Make UK noted.
Barriers to Improving Cyber Resilience
Unaware of available products
32 percent
Too expensive
32 percent
Not relevant to our business
23 percent
Lack of provider understanding of manufacturing
18 percent
Too complex
9 percent
Other
5 percent
MOST POPULAR ARTICLES
1. How Modern Video Technology Helps Close the Gap on Agricultural Crime
2. U.S. Federal Agencies Issue Rule on How Local Law Enforcement Can Take Down Drones
3. Securing the Harvest by Building Resilience in Modern Agriculture