Microsoft 365 is secure. But is your tenant configured securely?
Cyber Security
Hannah Boswell
21 July 2026
Secure data optimisation & proactive backup
Proactive Licensing, Compliance & Asset Management
Agile, Modular, & Secure Cyber Security & Managed Siem
Manage & Transform Multi-Cloud, Hybrid & On-Premise
A year ago, Jaguar Land Rover's production lines at Solihull, Halewood and Wolverhampton fell silent. Not for a day or two, but for five weeks. Thirty thousand employees were told to stay home. Over 5,000 businesses in JLR's supply chain saw orders evaporate overnight. The Cyber Monitoring Centre later modelled the UK economic impact at £1.9 billion, making it the most costly cyber incident in British history.
Twelve months on, it's worth looking back not just at what happened, but at what would have needed to be in place to change the outcome. Because the uncomfortable truth is that none of the individual techniques used were particularly sophisticated. What made the attack so damaging was everything that happened, or didn't happen, in the hours and weeks that followed.
The attack didn't start with a technical exploit. It started with a phone call. Attackers ran a vishing campaign, placing calls that impersonated JLR's IT helpdesk, and convinced employees to hand over their login credentials. From there, the group logged in through legitimate remote access, escalated privileges, and moved laterally across JLR's network, reportedly abusing OAuth tokens to get around multi-factor authentication along the way.
By the time ransomware and destructive malware were deployed across ERP and production systems, the attackers had already reached deep into JLR's core infrastructure. The company's only option was to shut everything down globally, factory lines, dealer platforms, parts ordering, all of it, rather than risk containing a breach it couldn't fully see.
Three separate points in this timeline offered a chance to change what happened next.
The point of entry. The attack succeeded because a stolen set of credentials was treated as trustworthy. Once inside, static, long-lived access and a lack of policy-based controls meant the attackers could move around largely unchecked. Centralising credentials and issuing short-lived, automatically rotated access, rather than static passwords that work indefinitely once obtained, would have shrunk the window of opportunity considerably. This is precisely the gap that identity and secrets management is designed to close.
The dwell time. Vishing, VPN logins from a legitimate account, and lateral movement across the network don't always look like an attack in progress, particularly to a security team already managing thousands of daily alerts. This is where continuous, expert-led monitoring earns its keep. A managed detection and response service that correlates behaviour across the whole environment, rather than treating each alert in isolation, is built to catch exactly this kind of slow, quiet escalation before it reaches core production systems.
The recovery. This is arguably where the greatest opportunity was lost. Five weeks without a single vehicle rolling off the line suggests recovery plans that either didn't exist for a scenario this severe, or had never been tested at this scale. Modern cyber recovery services are built around a different assumption: that backups alone aren't enough, and that recovery only counts if it's been tested, validated, and can be triggered with confidence. Reducing a recovery window from weeks to minutes isn't a stretch target. It's what properly tested, isolated recovery environments are designed to achieve.
The JLR incident pushed cyber resilience further up the boardroom agenda across UK manufacturing, and rightly so. Manufacturing has now been the most targeted sector for cyberattacks for four years running. But a year on, many of the same structural gaps remain across the industry: legacy systems that can't be patched without a production outage, flat networks with limited segmentation between IT and OT, and recovery plans that look reassuring on paper but have never been tested against a real, systemic incident.
If there's one lesson worth taking from the anniversary of JLR's attack, it's this: prevention and recovery aren't a choice between one or the other. The organisations that come through an incident like this fastest are the ones that have invested in both, reducing the likelihood of a breach reaching production systems, and making sure that if it does, recovery is measured in minutes, not weeks.
If you want a wider view of what other major UK breaches from the same period revealed, our piece on what companies can learn from 2025's biggest data breaches covers M&S, EasyJet, JLR and the NHS in more detail.
Our free Industrial Threat Insight Report is a practical, OT-focused cyber risk assessment built specifically for manufacturing and industrial organisations. It's designed to surface exactly the kind of gaps that turned a single stolen credential into a five-week production shutdown, before you have to find them the hard way.
21 July 2026
Blog
08 June 2026
Blog
02 June 2026