
A cyberattack that stops production costs far more than the ransom. Jaguar Land Rover lost roughly five weeks of output, an estimated £1.9 billion to the UK economy, and pulled about 5,000 suppliers down with it. For a mid-market plant the math has the same shape: manufacturing cyberattack downtime equals cost per hour multiplied by days-to-restore — and days-to-restore is the only variable you control.
JLR is the clearest public example of that shape. The attack began 31 August 2025. JLR paused production on 1 September 2025. By 22 September all production had been stopped for about three weeks, and the restart slipped again to 1 October 2025. Three UK plants — Solihull, Wolverhampton and Halewood — sat idle roughly five weeks before a phased restart in October. The Cyber Monitoring Centre put the eventual damage to the British economy at about £1.9 billion, the most damaging cyberattack in British history. Roughly 5,000 associated businesses were affected, from tier-one suppliers down to dealerships, and the UK government issued an emergency £1.5 billion loan guarantee to keep that supplier base alive.
Two caveats before any of that reaches your plant. First, JLR never confirmed ransomware — reporting noted the attack’s characteristics were consistent with it, which is not the same as a confirmed strain. Second, JLR is a large-enterprise cautionary case, not a scale model. You will never post a £1.9 billion number. The structure of that loss transfers; the magnitude does not.
What does manufacturing cyberattack downtime actually cost?
Two numbers. The first is your hourly cost of a stopped line: contribution margin per unit times units per hour, plus the fixed costs that keep burning while nothing ships — payroll, leases, utilities, depreciation. Most finance teams can produce that in an afternoon; it is the same arithmetic used to justify capital equipment.
The second is the one almost nobody has measured: how many days it takes to get back to shipping. That is where the cost is actually decided, and it is the number an IT program can move.
| Cost line | What drives it | Clock it runs on | Can you control it? |
|---|---|---|---|
| Lost output | Units not built times contribution margin | Every hour the line is stopped | Only by restoring sooner |
| Fixed costs still burning | Payroll, leases, utilities, depreciation | Every hour, whether or not you ship | No |
| Recovery labour and overtime | Internal staff, outside responders, catch-up shifts | Days to weeks after restore | Partly, with a rehearsed plan |
| Expedite and penalty costs | Air freight, line-down charges, missed delivery terms | Triggered by contract dates, not hours | Partly, by communicating early |
| Lost or reallocated orders | Customers dual-sourcing while you are dark | Months, long after restart | Rarely |
| Supplier and dealer fallout | Your stoppage idles their revenue too | Weeks, and it lands on your relationships | No |
| Ransom, if one is paid | A single negotiated figure | One time | Yes, and it still does not restart the line |
| Forensics, legal and notification | Incident response, counsel, regulator and customer notice | Weeks to months | Partly, with evidence already in place |
The bottom four rows are the ones that surprise people, because downtime does not stay inside your fence line. The SMMT reported that JLR’s five-week halt helped drive UK car production down 27% in September 2025, to just over 51,000 vehicles — the worst September since 1952. One manufacturer’s stoppage moved a national statistic. At your scale the same effect shows up as a tier-two supplier furloughing a shift because your purchase orders stopped.
Why is the ransom the smallest line item?
Because paying does not restart production. A decryption key, when it works at all, decrypts at disk speed across thousands of machines, frequently corrupts some of what it touches, and leaves you with the question you had before you paid: which systems are clean enough to trust? The ransom is a one-time, negotiable figure. Weighed against weeks of stopped production, it is rarely the largest number on the page.
An attacker also does not need to touch a controller to stop a plant. Identity, virtualization, ERP and file services are enough on their own, and that is where these incidents almost always land — we cover that mechanism in how manufacturing ransomware shuts down production without touching a PLC, including Dragos’s Q2 2026 count of 1,140 ransomware incidents against industrial organisations, of which manufacturing absorbed 747 — roughly 65%. Halcyon’s September 2026 automotive ransomware research cited JLR’s £1.9 billion for the same reason we do: it is the best-documented public measure of what a stopped line costs.
We have sat in the first 48 hours of these events. The hours do not go into negotiation. They go into deciding what is clean, finding a restore point that predates the intrusion, and discovering which system has to come back before the next one will start — which is exactly how days of downtime accumulate. If you are in that window now, start with what to do after a ransomware attack.
How long does manufacturing cyberattack downtime really last?
Longer than the RTO in your plan. That is not a criticism of the plan — it is what happens when targets written per system meet an event that hits every system at once. JLR is instructive because it was not an organisation short of resources: production paused 1 September, the restart was pushed to 1 October, and the return was phased rather than a switch being thrown. Manufacturing cyberattack downtime is measured in days and weeks, not hours.
| System tier | Typical stated RTO | What actually stretches it |
|---|---|---|
| Identity (Active Directory / Entra ID) | Hours | Nothing else can be trusted until identity is rebuilt from a known-good state, so it is serial, not parallel |
| Virtualization hosts | Hours to one day | Hosts get reimaged and patched before any VM is allowed to land on them |
| ERP and order management | One to two days | Data consistency and reconciliation, not restore speed — you must know which transactions survived |
| File, quality and engineering data | One to three days | Volume. The restore rate is bandwidth-bound and does not care about your target |
| Line-adjacent workstations and historians | Days | Per-machine rebuilds plus OEM software reinstalls that depend on the vendor’s calendar |
If the difference between a backup, a disaster recovery plan and business continuity is still fuzzy internally, fix that first — we define all three in backup vs disaster recovery vs business continuity. It matters here because backups shorten data loss, while only continuity planning shortens the outage itself.
What does business-interruption insurance actually cover?
In general shape, a cyber business-interruption policy reimburses lost income and extra expense from a covered event. That is real money — and it is also the part most owners assume is fully handled. Four features routinely surprise people:
- Sublimits. The business-interruption section commonly carries its own limit, well below the policy’s headline number.
- A waiting period. Coverage typically starts only after a stated waiting period, often measured in hours. Losses inside that window are yours.
- Proof of loss. You must document the loss to the insurer’s satisfaction — production records, order history, an outage timeline. Reconstructing that from systems that were themselves encrypted is its own project.
- Vendor outages are usually separate. If the attack hit your supplier or your ERP host rather than you, that generally falls under contingent business interruption, distinct cover you may or may not have bought.
QOS MSP is not an insurance broker and gives no coverage advice. What your policy pays, what triggers it, and how long your waiting period runs are questions for your broker and your counsel — take this list to them as questions, not answers. What we supply is the technical side they will ask for: control evidence, logs, and the restoration timeline that documents your outage hour by hour. Insurers increasingly require specific controls before they will write the policy at all, which we cover in cyber insurance requirements for small business.
How do you shrink manufacturing cyberattack downtime?
You attack days-to-restore, because it is the only term in the equation you own. Every hour of manufacturing cyberattack downtime you remove comes out of that term. The levers, in the order they pay off:
- Tested restores, not backups that merely exist. The single biggest lever on manufacturing cyberattack downtime. An untested backup is a hypothesis; we restore to scratch hardware on a schedule and time it, because a measured restore rate is the only one you can plan around.
- Immutable or offline copies. If an attacker who owns your domain can also delete your backups, you do not have backups — you have a shared folder.
- A documented restoration order. Identity, then virtualization, then ERP, then line-adjacent systems. Written down beforehand, because the order is not obvious at 2 a.m. and each mistake costs about a day.
- Known-good gold images. Rebuilding a workstation from a current image takes minutes; rebuilding from memory and a vendor download page takes hours, times every machine.
- Pre-agreed OEM and vendor escalation paths. Named contacts and contract terms for the machine builders whose software must be reinstalled. Discovering the support process mid-outage adds days that have nothing to do with IT.
- Tabletop exercises. One a year, with operations and finance in the room, not just IT. The exercise usually finds a dependency the diagram missed.
- RTO and RPO agreed per system, not one blanket number. A four-hour target on everything is a budget request. Four hours on identity and two days on engineering archives is a plan.
Segmentation belongs one step earlier on the same list: it cuts downtime by shrinking how much has to be restored at all. That architecture is its own subject, covered in IT/OT network segmentation for manufacturers.
When do you NOT need a full DR site?
Most of the time. A warm second site or standby cloud capacity is real money every month, and it is the wrong first purchase for a plant that has never timed a restore. If your hourly cost of a stopped line is modest and your customers tolerate a two-day recovery, tested backups with immutable copies and a written restoration order buy more reduction in manufacturing cyberattack downtime per dollar than a replica site will.
Buy the replica when the arithmetic says so: when one day of downtime costs more than a year of standby infrastructure, when a customer contract carries a line-down penalty that starts inside 24 hours, or when an OEM or regulator requires a demonstrated failover. Run that calculation before anyone quotes you a second data centre — us included.
What QOS MSP owns — and what it does not
QOS has delivered IT since 2007, nearly two decades, and continuity is the part of managed services judged on one bad day rather than 364 good ones. BCDR is included in your plan at every tier — designing the continuity approach, agreeing RTO and RPO per system, configuring and administering it, testing restores, and running the recovery. The redundant systems continuity runs on — a second site, standby cloud capacity, backup storage — are billed separately, because we administer that infrastructure rather than resell it to you.
What we are not matters just as much. We are not an insurance broker and give no coverage advice. We are not a digital forensics or ransom-negotiation firm; when an incident needs one, we work alongside them. And we never program PLCs or touch OEM machine software — that stays with your controls engineers and machine builders, and an MSP claiming otherwise is describing a liability, not a service.
Within that lane, manufacturing cyberattack downtime is the one number we will put a stopwatch on. If you want your plant’s days-to-restore measured rather than assumed, that work sits inside infrastructure management services and security administration. Talk to us and we will start with a timed restore test — usually the cheapest bad news a manufacturer ever buys.
Frequently asked questions
How much does manufacturing cyberattack downtime cost per hour?
There is no universal figure: it is contribution margin per unit times units per hour, plus the fixed costs that keep running while nothing ships. Multiply that hourly number by days-to-restore, not hours, because downtime is counted in days. For scale, Jaguar Land Rover’s roughly five-week 2025 shutdown was estimated at about 1.9 billion pounds of damage to the UK economy, but that is a large-enterprise figure and does not scale down to a mid-market plant.
How long does it take to recover production after a cyberattack?
Days to weeks, not hours. Jaguar Land Rover paused production on 1 September 2025 and was offline roughly five weeks across its Solihull, Wolverhampton and Halewood plants before a phased restart in October. Recovery is serial: identity must be rebuilt from a known-good state before virtualization, then ERP, then line-adjacent systems. Stated recovery time objectives assume one system failed, not all at once, which is why real downtime overruns the plan.
Does cyber insurance cover lost production from a cyberattack?
A cyber business-interruption policy generally reimburses lost income and extra expense from a covered event, but these policies commonly carry their own sublimit, a waiting period often measured in hours before coverage starts, and proof-of-loss documentation requirements. A vendor or supplier outage usually needs separate contingent business-interruption cover. QOS MSP is not an insurance broker and gives no coverage advice: take those four points to your broker and your counsel.
Did Jaguar Land Rover confirm the 2025 attack was ransomware?
No. JLR did not confirm ransomware. Reporting noted the attack’s characteristics were consistent with ransomware, which is not the same as a confirmed strain or a confirmed extortion demand. What is documented is the operational impact: production paused on 1 September 2025, roughly five weeks offline, an estimated 1.9 billion pounds of damage to the UK economy, about 5,000 associated businesses affected, and an emergency 1.5 billion pound government loan guarantee.
Can attackers stop a production line without touching machine controls?
Yes, and that is the normal case. Encrypting identity, virtualization, ERP and file services halts shipping even when no controller is touched. Dragos counted 1,140 ransomware incidents against industrial organisations in Q2 2026, and manufacturing absorbed 747 of them, roughly 65 percent. That is why downtime is an IT recovery problem, not a controls problem.
What is the fastest way to shorten manufacturing cyberattack downtime?
Time an actual restore. Most plants learn their real recovery rate only during an incident, when it turns out to be days rather than the hours the plan promised. Restore to scratch hardware on a schedule, keep immutable or offline copies an attacker cannot delete, and write the restoration order down in advance: identity, then virtualization, then ERP, then line-adjacent systems. Those three steps cut downtime more than any product purchase.