Become a member
Take advantage of exclusive member benefits, world class events, networking and specialist support
29 September 2026
As with the wider world, the manufacturing sector is going through rapid and major change.
Factories are becoming more connected, more automated, and more data-driven in industry 4.0.
While bringing benefits such as increased efficiency and production, this increased technological reliance also introduces bigger cyber risks.
Read on as we highlight the bearing that manufacturing cybersecurity compliance will have on the tech-focused future.
Manufacturers are coming under pressure to meet strict regulatory demands.
This can be seen in the introduction of NIS2, which is directly impacting UK manufacturers with links to European supply chains.
Extending beyond traditional digital security, NIS2 requires manufacturers to take measures for protection against cyberthreats and the maintenance of operational resilience.
It demands the protection of Information Technology (IT) and Operational Technology (OT systems), management of risks, and reporting of breaches.
While UK manufacturing companies fall outside the scope of NIS2, customers may expect the fulfilment of similar standards, such as those set under the Cyber Security and Resilience (Network and Information Systems) Bill.
The fulfilment of the UK government-backed Cyber Essentials and Cyber Essentials Plus will be key to winning a variety of manufacturing contracts over the coming years.
Organisations can have more confidence in suppliers who have implemented the technical controls for protection against cyber attacks under such schemes.
Rules have also been set for the sale of internet-connected products under the Product Security and Telecommunication Infrastructure (PSTI) Act.
These include measures for basic digital security, such as the setting of unique passwords, and processes for reporting vulnerabilities.
Manufacturers must take direct responsibility, considering such aspects of security at the design stage.
The importance of managing cybersecurity compliance has been reflected in a recent MAKE UK report, with these key findings:
30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
Production downtime and increased operational costs were the most common impacts where incidents caused disruption.
31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries
Only around half have incident response plans in place.
In basic terms cyber attacks put a stop to production, resulting in customer dissatisfaction and financial costs.
There’s a clear need to prioritise cyber resilience alongside productivity, quality, and health and safety.
From factory machines to robots and controllers, such manufacturing technologies have traditionally been operated in separation.
However, we’re seeing all new levels of connection in the modern factory.
This is encompassing old machines, with outdated software vulnerable to cyber attacks.
With the range of manufacturing cybersecurity requirements, companies are being forced to take measures such as replacing such legacy equipment and using production monitoring systems.
It’s bound to be a continuing shift, as new threats and regulations are introduced.
While manufacturers generally recognise the need for improved cyber resilience, there are barriers such as cost, skills gaps, and confusion over which standards to follow.
MAKE UK has advised a number of practical steps for the protection of people, production, and supply chains.
These include:
Treating cyber resilience as a production priority, not just an IT issue
Mapping the vital systems and suppliers for factory operation
Testing responses and the ability to recover from cyber attacks.
Steps for improved manufacturing cybersecurity compliance will also lead to benefits such as improved reliability and efficiency.
There’s cause for optimism, with the rise of UK factories that are “secure by design”.
This will mean the integration of secure features into products and processes, with vulnerable legacy machines being isolated or replaced.
Manufacturing cybersecurity compliance must be prioritised at all levels, with the setting of clear responsibilities and reporting processes.
The integration of AI and machine learning will also be key for increased production line visibility and security responses.
Such measures will help in shaping the smart and secure factories of the future.