What the Survey Reveals About UK Manufacturing Attacks
A new survey covered by the Guardian paints a troubling picture for the UK's industrial base: nearly a third of manufacturers were hit by a cyberattack in the past year. Even more concerning, only about half of the companies surveyed have a formal plan in place for how to respond when an attack happens. Big companies described being under constant threat, yet many are still operating without the basic playbooks that could limit damage and speed recovery.
This gap between exposure and preparedness is the real story here. It's one thing to acknowledge that attacks are frequent; it's another to actually build the processes, roles, and technical safeguards needed to respond quickly. Manufacturers that lack a response plan are effectively deciding how to react to a breach in the middle of a crisis, which is exactly when mistakes are most costly.
Why Manufacturers Are Prime Targets for Hackers
UK manufacturers cyberattack risk isn't rising by accident. Factories and industrial firms sit at an uncomfortable intersection: they hold valuable intellectual property, run complex supply chains with dozens of third-party vendors, and increasingly rely on connected operational technology that wasn't originally designed with cybersecurity in mind. Older industrial control systems, legacy software, and a patchwork of remote access tools used by contractors and engineers all widen the attack surface.
Manufacturers are also attractive targets because disruption has immediate, visible consequences. A ransomware attack that halts a production line doesn't just cost money in ransom payments; it stops shipments, breaks supply agreements, and can ripple out to every business downstream. That leverage makes manufacturers more likely to face pressure to pay quickly, which in turn makes them more attractive targets in the first place.
Attackers have also gotten better at bypassing the defenses companies assume will protect them. The D1R ransomware attack on ARM is a useful case study here: the group claiming responsibility managed to compromise a major UK-based technology company despite the presence of two-factor authentication, a control many businesses treat as sufficient on its own. That incident is a reminder that no single safeguard, however standard, guarantees protection. Layered defenses matter more than any one checkbox.
Closing the Gap: VPNs, Access Controls and Incident Response Basics
Much of the exposure described in the survey traces back to how remote access and internal networks are managed. Manufacturers often have engineers, contractors, and third-party maintenance teams connecting into internal systems from outside the building, sometimes using consumer-grade tools or outdated remote access software that hasn't been reviewed in years.
A properly configured VPN, paired with strict access controls, is one of the most straightforward ways to reduce this risk. VPNs encrypt traffic between remote users and internal systems, making it much harder for attackers to intercept credentials or session data on the way in. But a VPN alone isn't a silver bullet, as the ARM case shows. It needs to sit alongside strong authentication, network segmentation that limits how far an attacker can move if they do get in, and regular audits of who actually has access to what.
For manufacturers still relying on flat networks where a single compromised account can reach production systems, finance software, and customer data all at once, segmentation should be treated as a priority, not a nice-to-have. Combined with VPN-secured remote access, these are baseline hygiene measures now, not advanced defenses reserved for large enterprises.
Building a Response Plan Before You Need One
The survey's most actionable finding is arguably the simplest: only half of manufacturers have an incident response plan. That means the other half would be improvising during an actual breach, deciding in real time who to call, what systems to isolate, and how to communicate with customers and regulators.
A basic response plan doesn't need to be complicated. It should identify who is responsible for making decisions during an incident, list the technical steps for isolating affected systems, and include a communication plan for staff, customers, and, where relevant, regulators. Testing that plan periodically, even through a simple tabletop exercise, matters just as much as writing it down.
What This Means For You
If you work in manufacturing or run a business that depends on manufacturing partners, this survey is a signal to check your own exposure rather than assume it's someone else's problem. Ask whether remote access into your systems is secured with a VPN and strong authentication, whether your network is segmented so a single breach can't spread everywhere, and whether there's an actual written plan for what happens if an attacker gets in. The UK manufacturers cyberattack risk described in this survey isn't abstract; it's a reflection of gaps that exist in ordinary day-to-day IT decisions.
Key Takeaways
- Nearly a third of UK manufacturers were attacked in the past year, yet only half have a response plan.
- Manufacturers are attractive targets due to valuable IP, complex supply chains, and legacy operational technology.
- Standard defenses like two-factor authentication can be bypassed, as seen in the ARM breach, so layered security matters.
- VPN-secured remote access and network segmentation are baseline protections, not optional extras.
- A written, tested incident response plan should be a priority for any manufacturer that doesn't already have one.




