A production director called me last week and asked, almost as an aside, who was actually meant to own cyber risk on his shop floor.
He wasn't panicking, not exactly. There was a flat, slightly embarrassed tone in his voice, like someone realising mid-sentence that the honest answer was nobody. IT handled laptops and email addresses. Nobody had ever formally handed him, or anyone else on his leadership team, responsibility for what happens if the line itself gets hit.
He's not unusual. Just under a third of UK manufacturers reported a cyber incident somewhere in their operation over the past year, either hitting them directly or arriving through a supplier, according to Make UK's Cyber Security in Manufacturing research, covered by The Manufacturer this month. Where it landed, the damage wasn't abstract either. Production downtime and higher running costs were the two most common outcomes.
And among firms hit through a supplier, roughly three in ten saw customer deliveries delayed, with production capacity reduced too. None of that shows up on a spreadsheet as an IT problem.
It shows up as a missed shipment, a client asking awkward questions, or a shift standing around because a machine that talks to three other systems has gone quiet. Make UK's innovation and digitalisation lead, Nina Gryf, made a similar point when the findings came out. Her point, roughly, is that these incidents no longer sit quietly inside an IT ticketing system.
They show up on the order book, in a shift schedule, and eventually in a boardroom conversation nobody had scheduled.
The National Cyber Security Centre's Jonathon Ellison went further, framing board-level ownership of cyber security as unavoidable for manufacturers now rather than optional. And that's where it gets useful for anyone doing the actual hiring. Only 45% of the manufacturers in Make UK's research had assigned senior leadership responsibility for cyber security. Just over half, 51%, had any kind of incident response plan in place at all.
Flip those numbers round and the real story appears. More than half of UK manufacturers have nobody clearly in charge if a serious incident hits tomorrow, and just under half have no plan for what happens next. That gap isn't a technology gap so much as a hiring gap.
On most shop floors, the person best placed to spot trouble early and pull the right people together fast isn't sitting in a distant IT function.
It's whoever already runs production day to day, the operations director, the technical manager, the plant manager who knows which machine talks to which supplier's system. Or which one, if it went dark, would actually stop the line. Cyber resilience, on a factory floor, is mostly an operations leadership problem wearing a technology costume.
Why is cyber risk suddenly an engineering leadership problem?
Because the attacks Make UK is describing rarely stay inside a laptop. They reach connected machinery, robotics, remote access tools and supplier systems, all of which live on the operational side of a manufacturing business rather than the corporate network.
The person who understands how those systems actually connect, and who can make a fast call when one stops behaving properly, is an operations or engineering leader, not a help desk.
Treating it purely as an IT question misses where the real exposure sits. But most job specs haven't caught up with that yet. I still see operations director and technical manager briefs built almost entirely around output, cost control and team management. Which matter, obviously.
Nobody's arguing they don't. But a brief that never asks how a candidate has handled a genuine operational disruption, cyber-related or otherwise, is only testing half the job. The other half is what happens on the worst Tuesday of the year, and whether the person in the room actually knows what to do.
Which raises the obvious next question of what to look for when hiring an engineering manager capable of doing both halves of the job well.
What should employers actually look for in an operations director now?
Beyond the usual throughput and cost metrics, ask how a candidate has handled a live operational disruption of any kind, not just a cyber one. Ask whether they treat supplier risk as part of their own remit, or somebody else's problem entirely. A candidate who has actually managed a shift through a system outage brings something a polished CV rarely shows on its own.
It's the kind of detail a proper assessment process surfaces, and a quick CV skim almost never will. None of this means panicking about robots taking over your security function. It means treating operational resilience as a genuine hiring criterion rather than something bolted onto a job description at the last minute. Some businesses will solve this by training up the leadership team they already have.
Others will realise, usually after a near miss, that the next operations director or technical manager hire needs to walk in already thinking this way.
A generalist recruiter can fill an operations director vacancy well enough on paper. Salary matched, references checked, box ticked. What's harder to spot from a CV alone is whether someone has actually run a shift through a genuine operational shock and come out the other side with the plant still running.
That's the kind of judgement a specialist engineering recruiter builds up over years of placing people into exactly these roles. Not a generalist agency working across a dozen unrelated sectors, filling an engineering vacancy the same way it fills a warehouse one. If you're hiring for operations, engineering or technical leadership in a manufacturing business, it's worth having this conversation before the brief goes out, not after.
We work across the division as engineering recruitment specialists, and we've written up more on what we actually look for in an operations director hire if you want the longer version before you brief anyone.
And if you're an operations or engineering leader curious what the market makes of this kind of judgement right now, our latest vacancies are worth a browse too.















