<img alt="" src="https://www.instinct365intelligent.com/810470.png" style="display:none;">
  • IBM Select Partner 2025
  • ISO9001, 14001, 27001
  • Service Delivery Champion 2025
Crown Commercial Service Supplier IBM Platinum Partner
Celerity Logo
Solutions & Services
  • Data Resilience
    Data Resilience

    Secure data optimisation & proactive backup

  • Software
    Software

    Proactive Licensing, Compliance & Asset Management

  • Cyber Security
    Cyber Security

    Agile, Modular, & Secure Cyber Security & Managed Siem

  • Infrastructure
    Infrastructure

    Manage & Transform Multi-Cloud, Hybrid & On-Premise

Managed Backup Disaster and Cyber Recovery CopyAssure®
Software Licensing Management Managed Licence Compliance Software Asset Management Managed AI
Managed Siem MDR & MXDR Exposure Management Incident Response & Consultancy Secrets & Service Management
Infrastructure Advisory Infrastructure Transformation Managed Services FinOps as a Service Software Resell Hardware Resell
Client Outcomes Partners
Industries
Healthcare
Local Government
Financial Services
Retail
Manufacturing
Insights
All Resources
Technology Topics & Trends
About
Our Story
Our People
Accreditations
Corporate Social Responsibility
Careers
Contact
  • Contact
  • Sign In
×
  • Solutions & Services
  • Client Outcomes
  • Partners
  • Industries
  • Insights
  • About
Solutions & Services
  • Data Resilience

    • Managed Backup
    • Disaster and Cyber Recovery
    • CopyAssure®
  • Software

    • Software Licensing Management
    • Managed Licence Compliance
    • Software Asset Management
    • Managed AI
  • Cyber Security

    • Managed Siem
    • MDR & MXDR
    • Exposure Management
    • Incident Response & Consultancy
    • Secrets & Service Management
  • Infrastructure

    • Infrastructure Advisory
    • Infrastructure Transformation
    • Managed Services
    • FinOps as a Service
    • Software Resell
    • Hardware Resell
Industries
  • Healthcare
  • Local Government
  • Financial Services
  • Retail
  • Manufacturing
Insights
  • All Resources
  • Technology Topics & Trends
About
  • Our Story
  • Our People
  • Accreditations
  • Corporate Social Responsibility
  • Careers
  • Contact

Blog

Cyber Security

One Year on from the JLR Cyber Attack: what could have changed the outcome?

Holly Ellwood
Holly Ellwood

18 August 2026

Time to read

Loading read time...

Share this post

Table of contents

  • How the attack unfolded
  • Where the outcome could have changed
  • What's changed since, and what hasn't
  • Not sure where your own manufacturing environment stands?

 

Data Security LinkedIn Article Cover Image (1920 x 1080 px) (1)

A year ago, Jaguar Land Rover's production lines at Solihull, Halewood and Wolverhampton fell silent. Not for a day or two, but for five weeks. Thirty thousand employees were told to stay home. Over 5,000 businesses in JLR's supply chain saw orders evaporate overnight. The Cyber Monitoring Centre later modelled the UK economic impact at £1.9 billion, making it the most costly cyber incident in British history.

Twelve months on, it's worth looking back not just at what happened, but at what would have needed to be in place to change the outcome. Because the uncomfortable truth is that none of the individual techniques used were particularly sophisticated. What made the attack so damaging was everything that happened, or didn't happen, in the hours and weeks that followed.

 

How the attack unfolded

The attack didn't start with a technical exploit. It started with a phone call. Attackers ran a vishing campaign, placing calls that impersonated JLR's IT helpdesk, and convinced employees to hand over their login credentials. From there, the group logged in through legitimate remote access, escalated privileges, and moved laterally across JLR's network, reportedly abusing OAuth tokens to get around multi-factor authentication along the way.

By the time ransomware and destructive malware were deployed across ERP and production systems, the attackers had already reached deep into JLR's core infrastructure. The company's only option was to shut everything down globally, factory lines, dealer platforms, parts ordering, all of it, rather than risk containing a breach it couldn't fully see.

 

Where the outcome could have changed

Three separate points in this timeline offered a chance to change what happened next.

The point of entry. The attack succeeded because a stolen set of credentials was treated as trustworthy. Once inside, static, long-lived access and a lack of policy-based controls meant the attackers could move around largely unchecked. Centralising credentials and issuing short-lived, automatically rotated access, rather than static passwords that work indefinitely once obtained, would have shrunk the window of opportunity considerably. This is precisely the gap that identity and secrets management is designed to close.

The dwell time. Vishing, VPN logins from a legitimate account, and lateral movement across the network don't always look like an attack in progress, particularly to a security team already managing thousands of daily alerts. This is where continuous, expert-led monitoring earns its keep. A managed detection and response service that correlates behaviour across the whole environment, rather than treating each alert in isolation, is built to catch exactly this kind of slow, quiet escalation before it reaches core production systems.

The recovery. This is arguably where the greatest opportunity was lost. Five weeks without a single vehicle rolling off the line suggests recovery plans that either didn't exist for a scenario this severe, or had never been tested at this scale. Modern cyber recovery services are built around a different assumption: that backups alone aren't enough, and that recovery only counts if it's been tested, validated, and can be triggered with confidence. Reducing a recovery window from weeks to minutes isn't a stretch target. It's what properly tested, isolated recovery environments are designed to achieve.

 

What's changed since, and what hasn't

The JLR incident pushed cyber resilience further up the boardroom agenda across UK manufacturing, and rightly so. Manufacturing has now been the most targeted sector for cyberattacks for four years running. But a year on, many of the same structural gaps remain across the industry: legacy systems that can't be patched without a production outage, flat networks with limited segmentation between IT and OT, and recovery plans that look reassuring on paper but have never been tested against a real, systemic incident.

If there's one lesson worth taking from the anniversary of JLR's attack, it's this: prevention and recovery aren't a choice between one or the other. The organisations that come through an incident like this fastest are the ones that have invested in both, reducing the likelihood of a breach reaching production systems, and making sure that if it does, recovery is measured in minutes, not weeks.

If you want a wider view of what other major UK breaches from the same period revealed, our piece on what companies can learn from 2025's biggest data breaches covers M&S, EasyJet, JLR and the NHS in more detail.

 

Not sure where your own manufacturing environment stands?

Our free Industrial Threat Insight Report is a practical, OT-focused cyber risk assessment built specifically for manufacturing and industrial organisations. It's designed to surface exactly the kind of gaps that turned a single stolen credential into a five-week production shutdown, before you have to find them the hard way.

 Get your Industrial Threat Insight Report

Latest Cyber News

All Resources
Microsoft 365 is secure. But is your tenant configured securely?
Microsoft 365 is secure. But is your tenant configured securely?

Microsoft 365 is secure. But is your tenant configured securely?

Cyber Security
Hannah Boswell
Hannah Boswell

21 July 2026

Read blog article
Operational Technology Cyber Security Starts with Understanding
Operational Technology Cyber Security Starts with Understanding

Blog

Operational Technology Cyber Security Starts with Understanding

Cyber Security
Holly Ellwood
Holly Ellwood

08 June 2026

Read blog article
Strengthening your business with managed security solutions
Strengthening your business with managed security solutions

Blog

Strengthening your business with managed security solutions

Cyber Security
Tracy Ridgley
Tracy Ridgley

02 June 2026

Read blog article
Logo WHITE-cropped
phone 0845 565 2097
email info@celerity-uk.com
Vector
9001_Certification Badges_RGB_(0421)_4 14001 Certification Badges_RGB_(0421)_4 27001 Certification Badges_RGB_(0421)_4 cyberessentials_certification mark plus_colour

Transforming Technology. Empowering People.

QUICK LINKS
  • Technology Topics & Trends
  • Clients
  • Partners
  • Policies
  • Cyber Security Managed Services
  • Managed Cyber Security
  • Cyber Security Managed Service Provider
  • Managed Cyber Security Services
  • Cyber Security Risk Management
LATEST BLOGS
  • One Year on from the JLR Cyber Attack: what could have changed the outcome?
  • Celerity Announced as Sponsor of the 2026 Oxygen Awards
  • Breaking it down: IBM Cost of a Data Breach Report 2026

Ⓒ Celerity 2026 All Rights Reserved

Privacy

Terms

 

  • There are no suggestions because the search field is empty.