In September 2025, British luxury carmaker Jaguar Land Rover (JLR) was hit by a serious cyber attack. The company shut down its core IT systems and suspended production at three factories. Initially expected to resume on September 24, the outage was extended to October 1 or later. 33,000 employees were left idle, tens of thousands of suppliers faced severe cash flow pressure, and the UK government announced a £1.5 billion loan guarantee to stabilize the supply chain.

This raises a critical question: why would a single cyber attack bring production to a halt for as long as three weeks?

Why Did JLR Need Three Weeks to Resume?

The prolonged downtime was not due to inefficiency within the IT team, but rather to governance and compliance processes that dictate the pace of recovery:

  1. Proactive system shutdown: Core systems must be shut down to contain the attack and prevent further spread.
  2. Forensics and compliance checks: Before restoration, digital forensics must verify data integrity and meet legal obligations.
  3. Phased restoration: Recovery requires staged reactivation of core, auxiliary, and external systems to avoid cascading failures.
  4. Supply chain synchronization: Production cannot resume unless parts suppliers, logistics, and dealers restart in tandem.
  5. Trust rebuilding: Stakeholders—employees, customers, and regulators—must be reassured that systems are secure, which often takes longer than technical repair.

These steps define the minimum timeline for recovery. Three weeks was not accidental, but the fastest achievable under these constraints.

Author

DQS Hong Kong

DQS Hong Kong specialises in certification auditing and training services across core disciplines including Information Security (ISO 27001), Quality Management (ISO 9001), and the Automotive Industry (IATF 16949). Our auditors bring deep sector-specific expertise, working closely with clients' operational realities to deliver actionable management insights and lasting commercial value — well beyond the boundaries of compliance alone.

Loading...

You Might Also Enjoy These Reads

Discover more articles that dive deep into related themes and ideas.
Blog
Loading...

What Commercial Value Does ISO 27001 Certification Bring to Hong Kong Businesses?

Blog
Loading...

EU AI Act: what your organisation needs to know in 2026

Blog
Loading...

AWS and Azure Are ISO 27001 Certified — But That Doesn't Mean Your Company Is