[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
CYBERATTACK

A cyberattack hits. Production stops for five weeks. The supply chain absorbs the shock

A cyberattack disclosed by Jaguar Land Rover in late August 2025 halted global manufacturing operations. Production remained stopped for five weeks. The Cyber Monitoring Centre later estimated £1.9 billion in economic impact and said more than 5,000 organisations were affected across JLR's supply chain and the wider economy.

What happened

The attack caused an IT shutdown and halted global manufacturing operations, including JLR's major UK plants. Dealer systems were intermittently unavailable, while suppliers faced cancelled or delayed orders and uncertainty about future demand.

Production stopped on 1 September and remained halted for five weeks. The disruption spread far beyond JLR because its manufacturing model depends on a tightly connected network of suppliers, logistics providers and technology systems.

The Cyber Monitoring Centre estimated the total economic damage at £1.9 billion, with more than 5,000 organisations affected. The precise attack vector was not publicly confirmed in the authoritative sources used for this page.

Incident at a glance

Production shutdown
Five weeks
Estimated economic impact
£1.9B
Organisations affected
5,000+
Incident disclosed
Late August 2025
UK plants affected
Solihull, Halewood, Wolverhampton
Attack vector
Not publicly confirmed

The root cause

A cyberattack creates the same operational problem as other third-party incidents: critical software and systems become unavailable. The cause differs from insolvency, acquisition or discontinuation, but the operational outcome is similar.

The JLR event showed how deeply one organisation's disruption can propagate through an integrated supply chain. Suppliers can stop even when they are not the direct target because shared portals, ordering systems and manufacturing connections are unavailable.

What would Proof of Recovery have changed?

  • Verified escrow and recovery evidence for critical supplier and manufacturing systems would provide a clean, tested baseline for isolated recovery.
  • Deployment runbooks would give operations teams executable procedures for restoring priority services outside compromised infrastructure.
  • Current SBOMs would help teams identify affected components and isolate risk more precisely.
  • Independent recovery evidence would not prevent the attack, but it could reduce uncertainty about which systems can be restored and how.

Thousands of organisations were affected because modern production depends on shared systems. The cyberattack reached the supply chain through operational dependency

The regulatory consequence

The JLR incident focused attention on supply-chain technology risk across the UK and EU. NIS2 extends cybersecurity obligations into supply chains, while DORA requires incident response and recovery testing for critical ICT dependencies. UK guidance also emphasises supply-chain cyber-risk management.

A cyberattack on your vendor could stop your operation tomorrow. Do you have verified recovery evidence?

Book a briefing