Supply Chain and Cyber Risks Highlighted in Defence Exercise
New analysis of the Office for National Statistics (ONS) latest business survey, carried out by the home delivery specialist Parcelhero, reveals that fears over cyber-attacks disrupting supply chains vary sharply depending on the sector. Some parts of the economy that keep the nation stocked and running are far more worried than others. Retailers are considerably more worried than the transport and logistics firms that move their goods.
The analysis comes at a critical time. Cabinet Office minister Darren Jones told Parliament this month that the multi-day “Operation Albiston Shadow” exercise, planned for 2027, will test the country’s ability to respond to hybrid attacks, including cyber-attacks, sabotage and disinformation, alongside a wider NATO exercise.
As part of the same update, the Government confirmed it would proceed with a previously announced public awareness campaign encouraging households to prepare for disruptions to power, water, phone signal, or food supplies. It also newly added cyber-attack risks, including threats to water infrastructure and national data systems, to its National Risk Register.
“When Government is rehearsing its response to hybrid threats, it’s worth asking how ready the businesses behind Britain’s supply chains feel too – the ONS data gives a useful, if uneven, answer,” said Parcelhero’s Head of Consumer Research, David Jinks M.I.L.T.
“Across all UK businesses, 7.1 per cent currently say they’re concerned about a cyber-attack affecting their supply chains over the next 12 months. But that average hides some real differences by sector.
“Of the three sectors most central to getting goods onto shelves, wholesale & retail is the most concerned about cyber-attacks disrupting supply chains, with 11.7 per cent citing this worry — well above the all-business average. Manufacturing follows closely at nine per cent. In contrast, transport & storage, the sector that actually moves goods around the country and includes logistics, parcels, haulage and warehousing firms, reports the lowest concern of the three at just 3.3 per cent, below the national average.
Jinks said that the gap is worth paying attention to: “Retailers are clearly alert to the risk, which is no surprise, given they’re the point where a cyber incident becomes visible to customers first, as empty shelves or failed payments. But transport & storage sits in the middle of the chain connecting manufacturers to retailers, so companies in this sector need to have a greater focus on the impact of a cyber-attack on themselves or their partner companies.
“Britain doesn’t have to imagine what that looks like in practice. In April 2025, M&S and Co-op were both hit by ransomware attacks linked to the same threat actor, within days of each other. M&S lost contactless payments and click & collect over Easter weekend, then suspended online sales altogether for weeks and reverted to pen-and-paper stock tracking, leaving some shelves bare well into the summer. The Cyber Monitoring Centre put the combined financial impact at £270 million to £440 million, with M&S alone forecasting a hit of around £300 million to its annual profit and in-store sales down roughly 15 per cent in the first month.
“Co-op, targeted by the same attacker in much the same way, came through it comparatively lightly, with in-store sales down around 11 per cent over the same period. Co-op moved quickly to contain the breach and its systems were more segmented, limiting the damage, and it was already regularly rehearsing its crisis response.”