What Happened
In September 2025, a ransomware attack forced Jaguar Land Rover to shut down its UK plants, halting production of about 1,000 luxury vehicles per day. This disruption affected over 5,000 downstream companies. The UK's Cyber Monitoring Centre estimated the financial impact at £1.9 billion, marking it as the most economically damaging cyberattack in UK history. The Bank of England noted the incident's role in slowing national growth. Following the attack, Jaguar Land Rover announced 4,000 job cuts, directly linking them to the attack's aftermath.
Timeline
September 2025: Initial breach and production halt across UK facilities
September, October 2025: Over 5,000 supplier and customer organizations experience disruption
Q4 2025: Bank of England reports measurable impact on national GDP growth
Early 2026: UK Cyber Monitoring Centre releases £1.9 billion damage assessment
Mid-2026: Jaguar Land Rover announces 4,000 job reductions tied to attack recovery costs
This incident occurred during a 40% surge in manufacturing ransomware attacks compared to the previous year, with half of all 2026 attacks carried out by groups that didn't exist two years earlier.
Which Controls Failed or Were Missing
While specific control gaps at Jaguar Land Rover aren't public, the attack's success suggests systemic failures common in manufacturing:
Inadequate network segmentation: Production systems were too accessible, allowing attackers to halt multiple facilities. Industrial control systems weren't isolated from IT networks.
Ineffective backup architecture: The decision to shut down rather than restore from backups suggests compromised backup integrity or insufficient testing.
Weak vendor access controls: Manufacturing environments often grant remote access to vendors. If a third-party connection was the initial vector, it indicates poor access governance.
Insufficient threat detection: The attack progressed to encrypt systems across multiple sites before containment, indicating gaps in security monitoring and incident response.
What the Relevant Standards Require
ISO 27036 (Information security for supplier relationships) requires organizations to:
- Establish security requirements for suppliers (Clause 6.2)
- Assess supplier security controls before contracts
- Monitor supplier compliance throughout the relationship
- Define incident notification and response obligations in agreements
For manufacturing, Clause 7.3 mandates determining security requirements for products and services supplied by external parties, including supply chain resilience.
SR 23-4 (Interagency Guidance on Third-Party Relationships) requires:
- Risk-based due diligence proportionate to third-party criticality
- Continuous Monitoring of Active Arrangements of third-party performance and risk
- Contingency plans for third-party failure
- Board and senior management oversight of third-party risk
The guidance states institutions should consider the potential for a third party's failure to affect multiple business lines, as seen when Jaguar Land Rover's shutdown impacted 5,000 organizations.
EBA Guidelines on Sound Management of Third-Party Risk require:
- Identification and classification of critical third parties
- Contractual provisions ensuring business continuity
- Regular testing of exit strategies and alternatives
The £1.9 billion impact shows the consequences of not matching concentration risk assessment with substitutability planning.
Lessons and Action Items for Your Team
1. Reclassify your tier-one manufacturers as critical third parties
If a supplier's failure would halt your operations, they're critical under both EBA and SR 23-4. Don't let contract value alone determine criticality. The 5,000 companies affected by Jaguar Land Rover's shutdown likely hadn't classified them as a concentration risk because they weren't the cheapest or largest supplier, they were architecturally central.
Action: Run a substitutability assessment for every supplier whose failure would cause operational disruption lasting more than 48 hours. If you can't replace them in that window, they're critical.
2. Require and verify backup testing cadence
Your contracts should specify backup frequency, retention, and testing schedules. More importantly, you need evidence of successful restoration tests.
Action: Add this clause to your Right to Audit provisions: "Provider shall conduct quarterly restoration tests of production-critical systems and provide test reports within 15 days of completion." For tier-one suppliers, request observer access to annual disaster recovery exercises.
3. Build notification timelines into every manufacturing contract
The longer you wait to learn about a supplier's incident, the less time you have to activate your own contingency plans.
Action: Require notification within four hours of any incident affecting production capacity, with status updates every 12 hours until restoration. This isn't punitive, it's operational necessity. Map this to ISO 27036 Clause 8.2 (incident management requirements).
4. Pressure-test your own concentration risk
If Jaguar Land Rover's disruption affected 5,000 companies, ask yourself: which of your suppliers could do the same to your organization?
Action: Document your top ten provider concentration risks and assign ownership for maintaining active contingency arrangements. This should include pre-negotiated agreements with alternative suppliers, even if you never activate them. The cost of maintaining a warm standby relationship is trivial compared to £1.9 billion in economic damage.
5. Implement tiered access controls for supplier connections
Manufacturing environments often grant broad network access to equipment vendors and system integrators. Every open connection is a potential initial access vector.
Action: Enforce zero-trust principles for all third-party remote access. Require multi-factor authentication, restrict access to specific systems rather than network segments, and log all supplier sessions. Review access permissions quarterly and revoke immediately upon contract termination.
The Jaguar Land Rover incident isn't just a cautionary tale, it's a template. When your tier-one supplier goes dark, you need answers in hours, not days. Your contracts, monitoring architecture, and contingency plans should reflect that timeline.





