Report by Make UK
Cyber Security In Manufacturing
Key Findings
30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries.
46% of manufacturers experienced increase of operational cost and production downtime where incidents caused disruption.
31% of affected manufacturers experienced delays, 31% saw reduced capacity, and 23% faced component or material shortages following a supplier cyber incident.
51% of manufacturers have incident response plans.
45% of manufacturers have senior ownership and recovery testing.
10% of manufacturers experienced an incident with a direct financial impact and a further 20% reported successfully mitigating attacks before they caused business disruption.
23% of manufacturers report that they have asked suppliers to demonstrate cyber security compliance, closely mirroring the 25% that have been asked to provide similar assurance to their own customers.
Using the midpoint of each cost range to calculate a weighted average, the estimated direct financial impact of a cyber incident on an affected manufacturer is approximately £28,000 per incident.
More than one in five manufacturers (22.7%) believe available cybersecurity solutions are not relevant to their business, while 18.2% report that providers lack a sufficient understanding of manufacturing operations.
Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).
Patch management is used by only 36% of manufacturers.
Fewer than a quarter (23%) of manufacturers have a dedicated Chief Information Security Officer (CISCO).