Summary
- Made Smarter Yorkshire has launched a £400,000 cyber programme for SME manufacturers with Sheffield Hallam University.
- Support ranges from introductory awareness training through Cyber Essentials, Cyber Essentials Plus, and preparation for ISO 27001.
- The pilot links cyber resilience directly to industrial digitisation, where connected production systems raise the operational cost of security failures.
Small and medium-sized manufacturers across Yorkshire will be offered fully funded cybersecurity support through a £400,000 government-backed pilot, as industrial digitisation leaves more production systems exposed to disruption that can move rapidly from an IT incident onto the factory floor. Made Smarter Yorkshire is delivering the programme with Sheffield Hallam University, with training due to begin in September.
The initiative is structured in four levels, beginning with basic cyber awareness before moving through Cyber Essentials, Cyber Essentials Plus, and preparation for ISO 27001. The introductory stage will be available to SME manufacturers without prior registration for the wider Made Smarter programme, while businesses seeking the more advanced support will need to join it.
Rather than depending entirely on external consultants, the pilot will also create Cyber Security Champions inside participating manufacturers. Its introductory 2.5-hour online session will cover phishing, weak passwords, cloud security, and safer working practices before participants develop an action plan for their own organisation.
The advanced stages move from awareness into formal controls. Cyber Essentials focuses on a defined set of baseline technical measures, Cyber Essentials Plus adds independent technical verification, and the ISO 27001 programme will help manufacturers identify security gaps and develop the management systems needed to work towards certification.
Manufacturing incidents quickly reach production
The programme arrives as factories connect more machinery, operational technology, cloud services, supplier systems, and business software to the same digital estate. Those connections can improve visibility and productivity, but they also create paths through which a compromised account or poorly secured system can interrupt physical production.
Make UK’s latest manufacturing cybersecurity research found that 30% of manufacturers had experienced a cyber incident during the previous year, either directly or through their supply chain. Where incidents caused disruption, production downtime and higher operating costs were among the most common consequences, while supplier attacks also created delays to customer deliveries.
Those findings explain why cybersecurity is becoming part of a programme originally designed around technology adoption. Government and industry policy has encouraged smaller manufacturers to use automation, connected machinery, data platforms, cloud services, and digital production tools, but the return from those systems deteriorates quickly when a security failure stops the operation.
The pressure is particularly acute for SMEs because formal security programmes compete with machinery, energy, staffing, compliance, and working-capital demands. A large industrial group may employ dedicated security engineers, while a smaller manufacturer can depend on a small IT team, an external provider, or people whose main job lies elsewhere.
A staged route may lower the adoption barrier
The structure of the Yorkshire programme avoids assuming that every manufacturer should begin with ISO 27001. A company taking its first formal steps can start with awareness and an action plan, while businesses facing customer requirements or more demanding supply chains can progress towards independently verified controls.
Cyber Essentials is deliberately narrower than ISO 27001, concentrating on a baseline intended to reduce exposure to common attacks. Cyber Essentials Plus verifies implementation technically, whereas ISO 27001 requires a wider management framework around information-security risks, responsibilities, monitoring, and improvement.
That progression may fit manufacturers better than treating security certification as a single project. It gives smaller businesses somewhere to begin while allowing companies with larger customers or regulated supply chains to build evidence that their controls are becoming more mature.
Certification cannot guarantee that an organisation will avoid an attack, but it can provide a common procurement baseline and force internal security practices to become more explicit. In sectors such as aerospace, defence, automotive, and infrastructure, customers increasingly want assurance that suppliers will not become an easy route into a wider operational network.
The programme will be delivered online, at Sheffield Hallam University, and, for some advanced support, at manufacturers’ premises. Participants can also connect into Made Smarter’s wider offer, including digital roadmaps, consultancy, leadership development, internships, and technology grants where available.
Made Smarter says the Yorkshire pilot could inform how cybersecurity support is delivered across its English programmes if the approach proves successful. The more revealing measure will be how many manufacturers progress beyond the introductory session and convert subsidised advice into durable technical and management changes inside production environments.












