Jaguar Land Rover stopped for five weeks and nothing was missing

On 31 August 2025 Jaguar Land Rover detected abnormal behaviour on IT systems at its Halewood plant. The next morning, staff at Halewood, Solihull and Wolverhampton were told to stay home. Production stopped across JLR’s UK operations for roughly five weeks.

No component was short. No ship was late. No supplier had failed. The company shut its own lines down to contain an intrusion, and roughly 5,000 businesses in its supply chain discovered their revenue depended on a security decision they had no part in making.

The Cyber Monitoring Centre estimated the cost across the UK economy at £1.9bn — the most economically damaging cyber incident in the country’s history. The damage showed up in the numbers well into the next year: third-quarter figures published in January 2026 showed wholesale volumes of 59,200 vehicles, down 43.3% year on year, and retail sales of 79,600, down 25.1%.

Your buffers do not cover this

Every resilience playbook written since 2020 aims at the same target: the thing that does not arrive. Dual sourcing, safety stock, nearshoring, supplier scorecards. All of it assumes disruption enters through the goods.

JLR’s disruption entered through the network, and none of those defences engage. Safety stock is worthless when the plant that would consume it is dark. A second supplier does not help when the buyer cannot raise a purchase order. The failure was not upstream or downstream. It was in the middle, and it propagated in both directions at once.

Note the inversion. Conventional third-party risk asks what happens when a small vendor is compromised and the damage climbs to the multinational. JLR ran the other way: a large hub went down and its downtime functioned as an attack on 5,000 spokes. Suppliers on tight margins and short cash runways faced existential risk after a few weeks without orders — punished for someone else’s breach, with no visibility and no vote.

Nor was it isolated. Weeks later, attackers compromised Collins Aerospace’s MUSE software and European airports descended into chaos, with the same shape: one supplier of a digital service, many operators unable to function. Marks & Spencer, hit in the same wave of UK retail attacks, watched pre-tax profit fall from £391.9m to £3.4m in the six months to 27 September.

The dependency nobody mapped

The Cyber Monitoring Centre’s guidance to boards for 2026 is worth reading as a supply chain document rather than an IT one. Identify the digital assets genuinely required to deliver business value. Challenge systems-compromise scenarios rather than assuming recovery. Put recovery plans in place that contain losses when key systems fail, and understand the dependencies between IT and OT.

That last point has form. Colonial Pipeline’s operational technology was inoperable in 2021 because of the impact on its IT systems — the fuel could have moved, and the billing could not.

The CMC also makes a point that belongs on every supplier’s risk register: a high proportion of revenue reliant on a single ultimate customer increases the potential impact when that customer stops operating. Most tier-two suppliers know their customer concentration as a commercial fact. Few have priced it as a cyber exposure.

What follows from this

Large buyers will push cyber requirements down their supply chains, and smaller suppliers will need to demonstrate baseline controls to keep contracts. That is coming regardless.

The harder question is the one JLR poses to everyone downstream of a big customer: how many weeks of that customer’s silence can you survive, and have you ever asked them what their recovery time objective is? You cannot audit your way out of their risk. You can know your number.

Explore More Insights

Discover more supply chain knowledge, tools and analysis.

Scroll to Top