New research from Make UK, the manufacturers' organisation, has exposed a dangerous readiness gap across Britain's industrial base: only half of UK manufacturers have a cyber incident response plan in place, even as 30% report experiencing a cyber incident in the recent period surveyed. That combination — high attack frequency paired with low preparedness — is exactly the profile we see in organizations that suffer the longest outages, the highest ransom payments, and the most severe regulatory fallout when an intrusion lands.
For defenders, this isn't an abstract statistic. Manufacturing is now one of the most consistently targeted sectors globally. Ransomware crews and their initial access brokers have learned that operational technology (OT) environments and just-in-time production schedules create maximum pressure to pay. Every day of halted production can cost a mid-size manufacturer six to seven figures. An organization without a tested IR plan doesn't get to negotiate from a position of strength — it improvises under fire, and improvisation during a ransomware event is how recoverable incidents become existential ones.
If your organization — manufacturing or otherwise — falls into the 50% without a documented, tested response plan, this is your forcing function. Below is a practitioner's breakdown of why this gap persists, what the threat landscape looks like for industrial organizations in 2026, and the concrete steps to build genuine response capability.
Why Manufacturing Is a Prime Target
The findings align with what we observe across IR engagements in the industrial sector. Several structural factors make manufacturers disproportionately attractive and disproportionately vulnerable:
- IT/OT convergence without segmentation. Legacy programmable logic controllers (PLCs), HMIs, and SCADA systems designed for availability — not security — increasingly sit on networks reachable from corporate IT. Flat network architectures turn a phished workstation into a plant-wide outage.
- Low tolerance for downtime. Threat actors deliberately time attacks against production-critical windows. A manufacturer facing contractual delivery penalties will pay faster than almost any other victim profile.
- Legacy and unpatchable assets. Many production environments run Windows systems past end-of-life or vendor-locked firmware that can't be patched without scheduled maintenance windows measured in months.
- Third-party and supply-chain exposure. Manufacturers depend on deep vendor ecosystems — ERP providers, logistics platforms, machine OEMs with remote maintenance access. Each is an ingress point, as multiple supply-chain intrusions over the past two years have demonstrated.
- Under-resourced security teams. Unlike financial services, many mid-market manufacturers have no dedicated SOC, no 24/7 monitoring, and security responsibilities distributed across an already-thin IT team.
The 30% incident figure should be read in that context: attacks aren't hypothetical, and they're not slowing down. The absence of a response plan doesn't reduce the probability of an incident — it only guarantees a worse outcome when one occurs.
What an Incident Response Plan Actually Buys You
From the IR side of the table, the difference between organizations with and without a plan is stark and measurable:
Organizations with a tested plan contain incidents in hours to days. They know who has authority to isolate a production segment, they've pre-staged forensic tooling, their backups are segmented and tested, and their legal/comms/cyber-insurance call trees are exercised. Recovery follows a runbook, not panic.
Organizations without a plan lose the first 48–72 hours to paralysis: Who decides to shut down the line? Can we disconnect the ERP without corrupting inventory data? Who calls the insurer before the ransom clock expires — and did we just void coverage by engaging the attacker first? Do we have backups that predate the initial compromise, or has the detonation already poisoned them? These questions get answered either in a tabletop exercise or during a live breach. The latter is catastrophically expensive.
Documented, exercised IR plans also directly reduce regulatory exposure under frameworks increasingly applied to UK industry, and they materially affect cyber insurance premiums and claims outcomes — insurers now routinely deny or reduce payouts where basic preparedness controls were absent.
Executive Takeaways
For security leaders and executives looking to move from the unprepared 50% to the resilient half, these are the actions that matter most, in priority order:
-
Build the plan, then test it — a document nobody has read is not a plan. Develop an incident response plan aligned to NIST SP 800-61 (Incident Handling Guide) covering the full lifecycle: preparation, detection and analysis, containment, eradication, recovery, and post-incident review. Then run at least two tabletop exercises per year — including one ransomware scenario and one OT/ICS scenario — with executives, legal, comms, and plant operations in the room. Exercises expose decision-authority gaps that no document review will.
-
Segment IT from OT — this is the single highest-value technical control. Map the data flows between corporate networks and production systems, then enforce separation with firewalls, unidirectional gateways where feasible, and jump hosts with MFA for any remote access into OT zones. Ransomware that cannot traverse from IT to OT is a bad week; ransomware that can is a bad quarter. Follow IEC 62443 zone-and-conduit principles and the guidance in the UK NCSC's collection for the manufacturing and industrial sectors.
-
Establish 24/7 detection capability — in-house or outsourced. Most manufacturing intrusions begin with standard tradecraft: phishing-delivered initial access, credential theft, and lateral movement — all detectable with managed detection and response (MDR) coverage. If a 50-person IT department can't staff a SOC, retain an MDR provider and ensure OT-adjacent systems are in telemetry scope. Mean time to detect is the variable that determines whether an incident becomes a headline.
-
Fix your backup architecture before you need it. Maintain offline or immutable (object-lock) backups with at least one copy logically or physically air-gapped from production. Critically: test restoration quarterly against real recovery-time objectives. In our engagements, unrecoverable or untested backups — not the ransom itself — are the most common driver of payment decisions.
-
Pre-stage your response relationships. Retain a DFIR firm before an incident (retainer SLAs beat cold calls at 3 a.m.), confirm your cyber insurance carrier's breach coach and panel-vendor requirements, and establish contact protocols with relevant authorities — for UK organizations, that includes the NCSC, Action Fraud, and the ICO where personal data is implicated. Contractual and regulatory notification clocks start at discovery, not at your convenience.
-
Extend readiness to the supply chain. Require incident notification clauses and minimum security baselines (aligned to Cyber Essentials at minimum, IEC 62443 or NIST CSF for critical suppliers) in vendor contracts. Audit remote maintenance access paths into your environment — OEM VPN accounts with standing credentials are a recurring initial-access vector in industrial intrusions.
The Bottom Line
The Make UK findings are a warning delivered early enough to act on. Thirty percent of manufacturers have already been hit; the probability that any given industrial organization faces a serious incident in the next 24 months is high and rising. The organizations that survive those incidents intact aren't lucky — they're prepared. They decided who makes the shutdown call before ransomware made it urgent, they segmented their networks before an intruder tested them, and they rehearsed their response before it was real.
If your organization is in the half without a plan, the remediation is straightforward: start now, start with the tabletop, and build from there. An imperfect plan exercised twice a year beats a perfect plan written during a breach every time.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.