Jaguar Land Rover (JLR) has just suffered a major cyber-attack that forced it to shut down IT systems and halt car production across the world. Thousands of employees and suppliers have been left in limbo.
For those of us in the Midlands, this isn’t an abstract headline. JLR is the cornerstone of the local economy, and its suppliers, ranging from Tier 1 engineering firms to small family-run specialists, are directly exposed. When JLR sneezes, the region catches a cold.
This isn’t the first time a cyber-attack has rippled through the supply chain. Earlier in 2025, Marks & Spencer (M&S) was paralysed by a ransomware attack, also linked to the group Scattered Spider. Their recovery took months and cost hundreds of millions. Suppliers bore a good proportion of the brunt in lost sales and delayed payments.
So, what should JLR’s suppliers be doing right now? Let’s compare the two cases, draw out the lessons, and set out practical steps – short-term and long-term – for protecting your company, your cash, and your people.
JLR’s Current Crisis
In early September 2025, JLR was hit by a cyber-attack that has disrupted production at plants in the UK, India, Brazil, and Slovakia. Systems were shut down as a precaution, which almost certainly prevented data theft, but the impact has been severe. Suppliers such as Evtec and WHS Plastics have already told staff to stay home. Industry reports suggest disruption could last well into October.
The attack has been linked to the same hacking groups – Scattered Spider, Lapsus$, ShinyHunters – that targeted M&S earlier this year. JLR’s swift reaction may limit the long-term damage, but the immediate pain for its supply chain is undeniable.
The M&S Cyber-attack: A Costly Precedent
M&S was hit in April 2025. Its online and in-store systems were crippled for weeks, costing an estimated £300 million in lost profits and wiping over £1 billion off its market value. Recovery was painfully slow: click-and-collect services weren’t fully restored until mid-August.
For suppliers, the consequences were stark. Orders were cancelled, payments delayed, and entire logistics chains thrown off balance. Many suppliers had no contingency plan and were left scrambling to cover wages and commitments.
The common thread with JLR? Both attacks exploited human weaknesses – social engineering and third-party vendor access. And in both cases, the shockwaves hit suppliers hard.
The Supply-Chain Ripple Effect
Cyber-attacks don’t just knock out the target company. They cascade through entire supply chains:
- Production halts: Suppliers dependent on JLR purchase orders suddenly face empty order books.
- Cash flow squeeze: Payments stall, but wages, rent, and tax bills don’t.
- Employment risk: Temporary layoffs or redundancies loom large if disruption drags on.
- Uncertainty: Nobody knows how long it will take to restore systems.
For directors of supplier businesses, this uncertainty is the hardest part. You don’t yet know if this will be a two-week blip or a three-month crisis. That makes clear, disciplined management essential.
What Suppliers Should Do
Short-Term Measures: Stabilise Now
- Preserve liquidity and staff morale
- Secure temporary funding lines, consider overdrafts or short-term credit to cover payroll and overheads.
- Communicate openly with staff; keeping people informed helps retain key skills and morale.
- Manage cash with discipline
- Run a rolling short-term cash flow forecast (daily or weekly) for at least 13 weeks. This is your radar.
- Engage early with lenders – banks and finance providers hate surprises. Proactive updates make it easier to negotiate support.
- Reschedule payments to HMRC and suppliers by agreement where possible. A managed deferral is always better than a default.
- Defer capital expenditure, special projects, and non-essential spending until the scale of JLR’s disruption becomes clearer.
- Stress-test your cash flow against best-, medium-, and worst-case scenarios. Know your break points before you hit them.
- Assess immediate exposure
- Map out where you rely on JLR systems – ordering, invoicing, logistics.
- Switch to manual or interim communication channels (phone, email, even fax if you must) to keep operations moving.
- Engage with insurers and financiers
- Notify cyber-insurance providers promptly; keep detailed records of losses.
- Tell your bank and creditors what’s happening. Openness now avoids difficult conversations later.
- Accelerate incident response planning
- Form a crisis team with finance, operations, IT, and HR leads.
- Use this as a live exercise: where are you most fragile, and what can be fixed quickly?
Mid-Term Actions: Build Resilience
- Strengthen cybersecurity culture
- Run phishing and social-engineering awareness refreshers for staff.
- Ensure multi-factor authentication (MFA) is standard for all privileged accounts.
- Tighten third-party access
- Introduce dual-approval workflows and call-back verification for critical instructions.
- Audit vendor permissions – remove anything unnecessary.
- Improve detection and readiness
- Invest in tools that flag unusual access behaviour.
- Run tabletop exercises simulating a supply-chain cyber-attack.
- Review operational continuity
- Develop manual workarounds for key systems.
- Create alternative logistics schedules to keep goods moving.
Long-Term Strategy: Reduce Dependency & Strengthen Foundations
- Diversify your customer base
- Explore supplying to other manufacturers, not just JLR.
- Consider aftermarket and export markets to spread risk.
- Make cyber resilience part of risk planning
- Budget for cybersecurity as you would for insurance or health and safety.
- Build financial reserves to cushion against future disruption.
- Collaborate across networks
- Share intelligence and best practice with peers, industry bodies, and regional forums.
- Push for better standards up and down the supply chain.
- Update contracts
- Build in cyber-incident clauses – covering notification, support, and liability.
- Make sure you’re aligned with any new supplier compliance regimes from JLR.
- Strengthen insurance
- Review your cyber insurance: does it cover supply-chain disruption, not just direct attacks?
- Stress-test cover gaps regularly.
Case Study: A Midlands Plastics Supplier in Limbo
Let’s imagine a Tier 1 plastics supplier based near Birmingham. They employ 220 staff and generate 80% of their turnover from JLR.
On 2 September, the JLR cyber-attack forces their biggest plant to stop production. Purchase orders dry up overnight. Trucks that were due to collect components are turned away. The supplier’s warehouse is full, but nothing is moving.
Week 1:
- Staff are still paid, but overtime is cut.
- The finance director sets up a 13-week rolling cash flow forecast to monitor the position daily.
- A meeting is held with the bank to agree a temporary extension to the overdraft.
- Payments to HMRC are rescheduled by agreement to free up immediate cash.
Week 2–3:
- Production lines stand idle. The company agrees temporary lay-offs with some shop-floor staff, maintaining a core workforce ready for restart.
- Capital expenditure projects – a new moulding machine and a building refurbishment – are deferred.
- The board holds weekly updates with lenders, keeping them informed so there are no surprises.
Week 4–6:
- JLR systems remain down. The supplier begins approaching other automotive OEMs about taking on emergency contracts.
- The directors meet with industry peers through a Midlands manufacturing forum to share updates and explore collaborative solutions.
- Stress tests of the cash flow show the company can survive up to 10 weeks without JLR orders, provided payment terms with suppliers continue to be managed.
What this case shows:
- Quick action to preserve cash buys breathing space.
- Honest communication with lenders and HMRC prevents panic.
- Deferment of non-essential spend preserves liquidity.
- Looking outward -at new customers and collaboration -lays the groundwork for long-term resilience.
In reality, many Midlands suppliers are in precisely this position right now. The directors who act fastest, with the clearest grasp of their cash position, will be the ones who come through intact.
Summary Table: Key Actions for Suppliers
| Time Horizon | Actions Summary |
|---|---|
| Immediate | Preserve cash, run 13-week rolling forecast, engage lenders early, reschedule HMRC/supplier payments, defer capex, keep staff informed |
| Near Term | Cyber-awareness training, MFA, tighten third-party access, invest in monitoring, incident drills |
| Long Term | Diversify customers, embed cyber risk planning, collaborate across networks, update contracts, strengthen insurance |
Conclusion: Turning Crisis into Catalyst
The JLR attack is a stark reminder that modern supply chains can be paralysed in hours, not because of physical issues, but because of invisible cyber threats. For suppliers in the Midlands, the uncertainty is daunting. But it also presents an opportunity.
By acting now -tightening cash, preserving staff, engaging lenders -you buy the breathing space to survive the immediate shock. By building resilience in the months ahead, you reduce vulnerability to the next crisis. And by diversifying customers and embedding cyber risk into your business model, you protect your company, your finances, and the livelihoods of your workforce for the long term.
When big brands are shaken, suppliers feel the aftershocks first. But with foresight, discipline, and strong management, you can not only weather the storm, you can emerge stronger.
For assistance on HR issues, we recommend Claire Lawton of Acorn Support, tel 01384 939495, with whom we have worked miracles in the past. If you would like some support from me, give me a call.
Paul Brindley, 07813102014