
Supply chain cyber risk is not just a problem for large manufacturers. It is now a practical business continuity issue for any UK organisation that relies on cloud apps, outsourced IT, logistics partners, finance platforms, software suppliers or connected equipment.
On 10 August 2026, The Guardian reported on Make UK survey findings that nearly a third of British manufacturers had been hit by a cyber attack either directly or through a company in their supply chain during the past 12 months. The report said 30% of manufacturers had experienced a cyber incident, many seeing lost production time and increased costs, while only half had a response plan in place.
That should land with SMEs as well as factories. A supplier outage can stop orders being processed, delay customer deliveries, break finance workflows, lock staff out of key systems, or expose shared data. You do not need to be the original target to feel the impact.
Why this matters now
The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a cyber breach or attack in the previous 12 months. It also found that phishing remained the most common type of breach or attack, affecting 38% of businesses.
The same survey shows the supplier gap clearly. Only 15% of businesses said they formally reviewed cyber risks from immediate suppliers, and only 6% reviewed their wider supply chain. Small businesses were better than micro businesses, but still only 22% had reviewed immediate supplier risk and 10% had reviewed wider supply chain risk.
The National Cyber Security Centre’s supply chain guidance is blunt about why this matters: suppliers often hold access, systems, services or data that your organisation depends on. If a weak link is exploited, the disruption can move quickly from their environment into your working day.
What SMEs should check first
- Know your critical suppliers: list the services you cannot operate without, including Microsoft 365, payment systems, CRM, hosting, phone systems, remote access tools, finance software, payroll, logistics and specialist production systems.
- Check account security: require multi-factor authentication for supplier portals, shared systems and admin accounts. If a supplier platform does not support MFA, treat that as a real risk, not just an inconvenience.
- Limit supplier access: give third parties the minimum access they need, review it regularly, and remove access quickly when contracts, staff or projects change.
- Ask for evidence: Cyber Essentials, Cyber Essentials Plus, security questionnaires, backup policies and incident response processes are all useful signals. The aim is proportionate assurance, not paperwork for its own sake.
- Test the outage scenario: decide what happens if a supplier is unavailable for a day, a week, or longer. Who calls customers? Which process becomes manual? What data would you need locally?
- Keep independent backups: where the data is business-critical, make sure you are not relying only on the supplier’s platform to recover it.
Incident response has to include suppliers
A lot of cyber plans focus on the company’s own laptops, servers and Microsoft 365 tenant. That is necessary, but incomplete. The first call during an incident may need to be to a software vendor, fulfilment partner, outsourced IT provider, payment provider, insurer, solicitor or regulator.
The NCSC’s Exercise in a Box includes a supply chain ransomware scenario designed to help organisations practise this before it happens. It suggests allowing 90 to 120 minutes and involving senior decision-makers, technical staff and communications support. That is a sensible model for SMEs too: keep the exercise short, practical and focused on who does what.
The practical takeaway
Supply chain security does not mean turning every supplier review into an enterprise procurement project. It means knowing which relationships matter most, asking sensible security questions, reducing unnecessary access, and making sure the business can still operate when someone else’s systems go down.
For BM Technologies clients, the most useful starting point is a simple supplier risk review: critical systems, access levels, MFA, backup position, contracts, support contacts and outage workarounds. Done properly, it becomes part of business continuity, not just cyber security.
Sources
- The Guardian: UK manufacturers face rising hacking risk as survey shows 30% were hit last year, 10 August 2026.
- GOV.UK: Cyber Security Breaches Survey 2025/2026, published 30 April 2026.
- NCSC: Supply chain security guidance, reviewed 22 October 2025.
- NCSC Exercise in a Box: Supply chain ransomware attack exercise.
- GOV.UK: UK leads global fight to stop ransomware attacks on supply chains, 24 October 2025.
