In 2025, Jaguar Land Rover (JLR) experienced one of the most disruptive cyber incidents in recent UK business history. The company was forced to shut down critical IT systems and pause production across multiple global facilities, demonstrating how a single cyberattack can ripple far beyond one organisation. Public reporting on the Jaguar Land Rover cyberattack highlighted the scale of the disruption and its impact on operations, staff, and suppliers alike.
For small and medium-sized businesses, the incident serves as a stark reminder that supply chain security is no longer optional, even if your own systems are not directly targeted.
What Happened to Jaguar Land Rover?
On 31 August 2025, JLR detected a serious cyberattack and took the decision to proactively shut down large parts of its IT infrastructure to contain the incident. This led to extended production stoppages at UK plants in Solihull, Wolverhampton and Halewood, as well as facilities overseas. According to reporting by Computer Weekly, the disruption contributed to a quarterly loss of around £485 million, underlining the financial consequences of large-scale cyber incidents (Computer Weekly coverage).
Further investigation confirmed that employee data had been accessed during the breach, adding a data protection dimension to what initially appeared to be an operational incident, as reported by The Record (employee data exposure).
A Supply Chain Shockwave
The most significant lesson from the JLR incident is how deeply cyber disruption can affect an entire supply ecosystem.
Manufacturers, logistics partners, and component suppliers were unable to operate normally because orders could not be processed or delivered. As detailed in an industry analysis by Acronis, production dependencies meant delays cascaded rapidly across the automotive supply chain (manufacturing impact analysis).
For many smaller suppliers, this sudden halt created severe cash-flow pressure. Business rescue specialists warned that some firms reliant on JLR contracts faced serious financial risk due to prolonged disruption (impact on suppliers).
The scale of the incident was significant enough to prompt government-level intervention to stabilise the company and its supply chain, underlining the wider economic impact of cyber events (SecurityWeek reporting).
Key Lessons for SMEs on Supply Chain Security
1. Supply Chain Cyber Risk Is Your Risk
Even if your business was not directly attacked, dependency on a larger partner can bring operations to a standstill. SMEs need visibility into:
- Which suppliers are business-critical
- How digitally dependent those relationships are
- What contingency plans exist if systems go offline
Cyber security must be considered as part of supplier risk, not just internal IT.
2. Incident Response Must Include Supplier Failure
JLR’s rapid decision to isolate systems limited further internal damage, a move often cited as good practice in manufacturing cyber resilience (manufacturing response analysis). However, many SMEs lack documented or tested response plans that account for supplier outages.
Running tabletop exercises that include third-party disruption scenarios can dramatically improve preparedness.
3. Identity and Access Controls Matter Across the Supply Chain
Many supply chain attacks begin with compromised credentials or poorly managed third-party access. Shared accounts, excessive permissions, and weak authentication increase risk particularly where suppliers access internal systems.
Strong identity management and regular access reviews are essential to reducing exposure.
4. Data Resilience Is Business Resilience
When systems go down, operations stop. The JLR incident shows how quickly production and revenue can be impacted. Businesses should ensure backups, recovery plans, and continuity measures are tested, not just documented.
This is a core part of effective cyber security strategy, not an optional extra.
5. Minimum Security Standards Protect Everyone
Setting baseline security expectations for suppliers such as regular patching, vulnerability management, and incident notification timelines helps reduce weak links. Frameworks like Cyber Essentials can be useful starting points.
Why Supply Chain Security Is Now a Leadership Issue
Cybersecurity incidents like the JLR attack demonstrate that cyber risk is no longer just an IT concern. It is a business continuity and governance issue that affects revenue, reputation, and long-term resilience. As highlighted by Cybersecurity Dive, the financial and operational impact of the incident extended well beyond technology teams (earnings impact analysis).
For SMEs, this means cyber security must be embedded into supplier management, contracts, and operational planning.
How Marshall Helps Businesses Reduce Supply Chain Cyber Risk
At Marshall, we help organisations understand and reduce cyber risk across both their internal systems and their wider supply chain. Through structured assessments, vulnerability management, and ongoing cyber security services, we help businesses identify weak points before they lead to disruption.
Our approach focuses on practical, proportionate security helping SMEs build resilience without unnecessary complexity.
Concerned about how a cyber incident could affect your suppliers or customers?
Book a meeting with an expert, call 0203 384 9832 or email enquiries@marshallinfotech.com.
Let’s build cyber resilience that protects your business and the partners you rely on.

