The recent cyber attack on Jaguar Land Rover (JLR) is one of the biggest industrial incidents of recent years. One fragile link caused production to remain completely stationary and economic damage amounted to billions. It is a lesson for any organisation that wants to prevent a cyber attack and improve its information security.
Preventing cyberattack starts with chain insight
Many organisations focus on firewalls and patches, but real digital resilience requires direction on the entire supply chain: suppliers, integrations, (cloud) platforms and operational technology (OT). Those who want to prevent hacking will ensure that detection, segmentation and response capacity are not only in IT, but also in OT.
What went wrong?
The cyber attack on Jaguar Land Rover was estimated to start at the end of August 2025, after which the car manufacturer decided on 1 September to stop production and IT systems worldwide to prevent further damage.
Important observations:
The attackers entered the core network of JLR .com including systems that control production planning, part logistics and vehicle registration. There was insufficient network segmentation.
JLR's factory in Halewood (Merseyside) signaled the attack First, the entire operation was quickly shut down.
The company later announced that “some data” It remained unclear whether customers' or suppliers' data were taken, or exactly what dates. The Guardian
The complexity of the digital infrastructure proved to be an obstacle to recovery: JLR had a connected — which prevented it from being possible to quickly isolate only part of the hacked system.
The supply chain was hit hard: JLR relied on more than 700 suppliers, small and medium-sized companies that supply luxury car spare parts. Interruption has continued to affect often smaller suppliers with narrow margins which are standstill in major difficulties arrived.
JLR had no choice but to use its systems completely offline (a) a challenging choice, but necessary according to the company.
The shutdown extended from days to weeks. Initially, a short interruption was expected, but production was later suspended until at least 24 September and possibly longer.Financial and operational impact greatly increased.
This combination of deep network penetration, insufficient segmentation between production, IT and the supply chain, the need for a complete shutdown and a complex supplier network left JLR unable to carry out its core activities for weeks.
It became clear that the attack was not only an IT problem, but an operational disaster with severe consequences throughout the chain.
Improving information security: Practical steps
1. Periodic mapping of chain risks
Perform risk analyses with suppliers and critical partners. Validere with audits, pen tests and assurance reports.
2. Network segmentation between IT and OT
Ensure strict network separation, minimize lateral movement and limit privileges to the necessary (least privilege).
3. Practice Incident Response
Test scenario performance indicators for production failure and data loss. Set up clear communication lines for internal teams and chain partners.
4. Enhance monitoring and detection
Implement continuous detection for abnormal behaviour, including outgoing traffic, privilege escalations and unusual logins.
From damage to strategy
The JLR incident shows that you can potentially prevent a cyber attack and minimise the damage by combining technology, policy and human behaviour. Anyone who wants to improve their information security looks far beyond compliance and builds on structural digital resilience from a directive perspective. Compliance must never be seen as a goal alone.


