How to survive a cyber attack

25 Sep 2025 · 16 min · 5 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

How ransomware/cyberattacks disrupt UK businesses, using Jaguar Land Rover’s August 31 shutdown as the main case; why attacks spread across supply chains; what government and companies can do to survive.

Guests and backgrounds

Paul Kelso, Sky News business correspondent. James Hatch, Chief Digital Officer at BAE Systems; security/cyber leadership experience in defense and government-adjacent contexts.

Key claims

Attacks are often financially motivated (ransom/theft) and increasingly use dark-web tools and credential probing rather than random malware. Once encrypted, connected systems can’t operate, so manufacturing halts. Paying ransoms can make targets more likely; resilience comes from backups, incident planning, and board-level exercises.

Notable examples

JLR systems down (UK Midlands/Merseyside and Slovakia/India/Brazil), dealer registration and diagnostics disabled; Co-op (about £80m profit hit, £200m revenue loss), Marks & Spencer (about £300m), disrupted airports, and the British Library hack.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Impact of Cyber Attacks on Jaguar Land Rover

0:31 to 2:20

Discussion on the effects of the cyber attack on Jaguar Land Rover and other British companies.

“Despite some systems coming back online, production at Jaguar Land Rover remains at a standstill after a cyber attack a month ago.”

Understanding Cybersecurity Vulnerabilities

2:20 to 6:26

Exploration of how modern manufacturing is affected by cyber attacks and the complexities of supply chains.

“But first, Paul Kelso, our business correspondent.”

Government's Role in Cybersecurity

6:26 to 9:46

Discussion on the government's involvement in cybersecurity and the need for better protections.

“the government would buy the parts, the sunroofs and the wheels and the air conditioning units and the suspension arms that JLR aren't using and then sell them to JLR when it's back up and running.”

Motivations Behind Cyber Attacks

9:46 to 14:03

Insights into why companies are targeted for cyber attacks and methods used by attackers.

“What if this happened to the Ministry of defence.”

Preparing for Cyber Attacks

14:03 to 16:44

Learn how to effectively prepare your organization for potential cyber threats.

“Expecting to be attacked, I think, is realistic.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00How does a banana trigger a CIA-backed coup? Do AirPods herald the arrival of a new global order? What do LED lights say about the future of humanity? I'm Ed Conway, and in each episode of my new podcast, Stuff Matters, I take an object, crack it open, and reveal the world-shaping forces hidden inside. This is economics told through the things we think we understand. Search Stuff Matters on your podcast app to listen and follow. Coming up on the Sky News Daily, Despite some systems coming back online, production at Jaguar Land Rover remains at a standstill after a cyber attack a month ago. As another name is added to the list of British companies brought to their knees by hackers, is there anything that can be done?

0:49How does a banana trigger a CIA-backed coup? Do AirPods herald the arrival of a new global order? What do LED lights say about the future of humanity? I'm Ed Conway and in each episode of my new podcast Stuff Matters I take an object, crack it open and reveal the world-shaping forces hidden inside. This is economics told through the things we think we understand. Search Stuff Matters on your podcast app to listen and follow.

1:21At last a moment of respite for the tens of thousands of employees directly affected by the Jaguar Land Rover cyber attack, an attack that's meant no cars have been produced by JLR since August. The company has announced some of its systems are working again. Good news. But we are still days, if not weeks, from seeing Range Rovers rolling off the production line. Not such good news. And it comes at what cost? Well, already, you are likely to be into the hundreds of millions of pounds. This is very worrying to literally anyone and everyone on working in business right now in the UK. Because it's not just JLR.

2:00The co-op has lost millions. Marks and Spencer had six weeks of chaos. Airports up and down the country have seen people jetting to nowhere. And those are just a fraction of the British institutions and businesses who've had their security breached. Well, in a bit, I've got one cyber expert to explain how these attacks happen, why and what can be done. But first, Paul Kelso, our business correspondent. Paul, JLR, Jaguar Land Rover, Their problems must have started, what, a month ago now? August the 31st, their systems were infiltrated somehow. September the 1st, they announced that they made the decision to shut down everything.

2:36That means assembly lines in the UK, Midlands and Merseyside, but also Slovakia, India, Brazil, possibly China as well. And everything was knocked out, not just the systems that helped them make the cars, but the systems that allowed dealers to register cars. even the individual diagnostics machines that a mechanic would connect to your Range Rover if you had one to work out if a spark plug needed changing. All down. And it's going to last at least a month. They've already said they'll be closed till at least October the 1st. But that is not the same as saying when they'll be able to resume. And at this stage, it is very unclear when this enormously important company to the UK will be back in operation.

3:15I mean, it's a huge business, JLR, but these are huge problems. What do we understand is the cost to them? It's tens of millions of pounds a week in lost revenue. You can't order a new car, which means they can't make a new car and can't sell that car. They've been unable to register the cars, new cars that have been built and are sitting there in car parks around their factories because they haven't been able to use their systems with the DVLA. But it's enormously expensive and it's not just costing them bottom line down the supply chain. there's much more damage that might yet be reaped as this drags on.

3:52What I've never been able to wrap my head around is how a cyber attack would halt manufacturing. I can see why it might knock out IT systems and things like that, but I don't understand why the robots are not putting cars together. It's because you can't have one without the other. Modern supply chains are pretty amazing. I've never seriously pondered buying a Range Rover or Land Rover Discovery. If you go onto that website and play the game of what if, and you can select the colour, you can select different wheels, different levels of specification. There's a level of personalisation of a vehicle.

4:23That order then gets fed onto a production line and no two vehicles are necessarily the same. You've chosen the colour, you've got different specifications. That is all done just in time. If you've ordered the sunroof and you've got a sunroof supplier down the road, and I was in one this week in the West Midlands, you're delivering that sunroof just in time for it to go into that vehicle, which has ordered the sunroof because the one next to it might not have. And so you have this incredible complexity, which when it works, works well for the customer, works amazingly well for a very profitable company, but it's all digital at the end of the day.

4:56And what's so debilitating here is because of if this is a ransomware attack, and we don't know, but that's the implication, everything in JLR systems that's been infected and connected is encrypted and they can't use. So that's why everything stops. The government is suggesting that it might be prepared to step in and help out JLR. Yeah, this is very interesting. This week we saw the business sector and the industry sector in the West Midlands starting to listen to the supply chain, particularly, and the company about what's going on. It's the supply chain that is the issue. So JLR employs 33 ,000 people in the UK, hugely profitable, owned by a mega company, Tata, the Indian conglomerate.

5:38While its workers twiddle their thumbs, JLR, frankly, can afford to pay them. but everything is not built by JLR. There's a huge supply chain, hundreds of companies, at least 100 ,000 workers employed in them, perhaps more. Some of them are very big multinationals in their own right but some of them aren't. They only exist because they're selling a part to JLR in this very complex supply chain and they are already having to lay people off because if JLR aren't making cars they're not buying these parts. Essentially it faces the prospect of thousands of people losing their jobs in the West Midlands.

6:11So the question is what the government can do. Should they be bailing out JLR? That's not on the table. There's been suggestions that a furlough scheme, as in COVID, should be introduced. The unions want that. I understand that's been ruled out. So we're looking at some more bespoke possibilities. One floated is that the government would buy the parts, the sunroofs and the wheels and the air conditioning units and the suspension arms that JLR aren't using and then sell them to JLR when it's back up and running. But there's no guarantee they'll want those parts. There isn't an easy fix. And there will be an argument.

6:44Why are we spending taxpayers' money, everybody knows times are tight, on supporting this enormous company? The truth is, when they restart, they will need this supply chain. It's not just JLR that benefits from it. And a long-term impact and a loss of companies in this supply and would be really damaging to the West Midlands. Any number of MPs will tell you this is incredibly serious. So it's right the government looks at it. There's not an easy answer. And it hasn't just been Jaguar Land Rover that's been targeted. Any number of British institutions have by one presumes disparate groups. I mean, it feels a bit like an epidemic.

7:19It does. And what's striking is these are the ones we know about. We know about them because they're so high profile. Jaguar Land Rover is the flagship of British manufacturing industries. hugely important. Remember, JLR is one of the main reasons we've got a trade deal with the US and the UK government worked so hard to protect that company. But it follows household high street names, Marks and Spencers and the co-op that suffered big attacks earlier this year. Co-op, that attack left them with an£80 million hit to their profits, more than£200 million in lost revenue. M &S already said theirs cost them£300 million.

7:55Again, presumed to be ransomware attacks. We saw airports disrupted over the weekend because of an attack on one of the component parts of the checking in the airport system across Europe and the British Library, a great cultural institution. Nearly two years ago, their systems were hacked and perhaps less high profile because fewer people use it and certainly you don't use it commercially. But it suggests a vulnerability across the board. You can bet the leadership of every organisation of any size and profile in the UK is thinking if they can get them, if they are vulnerable, what about us? So there will be a huge focus in boardrooms, more importantly in the cyber security operations, digital operations, about how do we stop us being next.

8:41Is there an argument that perhaps the government needs to be more proactive when it comes to cyber security? I mean, we've had the National Cyber Security Centre up and running for the best part of a decade, and I've never known as many attacks on corporate entities. There is a question about the resilience of the UK. I spoke to the industry minister earlier this week. He said he doesn't think the UK is particularly vulnerable. Everyone is vulnerable to these kind of attacks. And the National Cyber Security Agency does offer a great deal of advice. There's a playbook for how to deal with these things.

9:12And there's lots of advice to try and protect yourself in the first place. Because what is absolutely evident from this is if these massive companies, these household names in British retail and industry are vulnerable, then everyone is vulnerable. And the point is, you need to keep them out in the first place, because once one of these malware attacks gets inside, you are in deep, deep trouble, and there is not a quick fix. Perhaps the bigger question for government, and this has been raised by MPs and has been raised with me privately, is what about the UK government's own systems? What if this happened to HMRC?

9:51What if this happened to the Ministry of defence. There are ways of shutting down entire systems through only the smallest vulnerability what this malware is in. It can be devastating. So I think there is a question for government, but it's about perhaps more about state systems than it is about the commercial world. Okay, let's pick up on that with James Hatch, Chief Digital Officer at BAE Systems. James, do we know why our companies are being targeted in this way? There's a fairly small number of reasons why people would do it. It tends to be either political or economic, looking for money, or sometimes, and probably more so in terms of cyber hacking than in other forms of criminality, sometimes people just do it because they want to do it.

10:42But mostly, for most corporations, the economic factors will be the key ones to ransom or theft. If you're an organised crime group, it's a way of making money that's actually less likely for you to end up in jail than it would be for smuggling drugs or something. And also, as things have developed, the availability of tools and kits on the internet to be able to carry out some of these things has made it easier for a wider range of people to carry out this kind of attack. So how do these groups, or indeed these individuals, how do they get access to the systems in the first place? The main thing that's happened over probably the past five years or so is the shift from things being general viruses that propagate almost randomly to being targeted attacks and using either software they've written themselves or using kits that they've acquired through the dark web.

11:32Criminals can try and get a hold of credentials, probe for weaknesses in people's networks and so forth. It sounds a bit like a franchise model Someone comes up with this bright idea of how to get inside systems and then what, they license it onto other criminal groups? Absolutely. If you've found something that works, there's two ways of making money out of that. Either you can use it once yourself and then do that again and again. That's quite a lot of effort. If you've invented something that works really well, then you can sell it to somebody else or even sell on access. Get a toe in the door to a network and then sell that access onto other people.

12:03Once they have achieved access to company systems and multinational systems, what are they capable of doing? Well, this is part of the challenge because software has become such a key component in businesses. From the systems that run an organisation, pay its suppliers and all that kind of stuff, through to manufacturing and customer service, it's everywhere in an organisation. So that's why I think we're starting to see the level of impact of these events become more and more difficult. So how can companies best protect themselves? And when we look at firms that have fallen foul of a cyber attack, does it immediately follow that they haven't done enough to prevent it?

12:43What I've seen in terms of the work I've done with BA Systems for Customers is most organizations are trying to manage a couple of things in relation to their technology. They're trying to drive greater speed and efficiency from the application of digital technology, and they're trying to maintain security. And the first of those is got a continuing competitive pressure. You're always under pressure. You're always trying to do things cheaper. You're trying to do faster, trying to offer better services to customers. Whereas cybersecurity goes from being very theoretical to very real quite quickly.

13:11In the space of one meeting, a chief executive can go from thinking, this is a thing that people are asking me to spend money on, but I can't quite. It's not tangible and we seem to be all right, to, oh dear, the worst has happened and now I'm having to deal with it. Well, if it all boils down to money, I mean, aren't businesses nowadays then just best advised to, whilst turning a profit, put some of that money away for the rainy day when one of these cyber attacks happens? And as soon as it happens, just pay up. I think the question of ransom is really difficult. There's a trade-off between the short-term and long-term for organisations and for society as a whole.

13:46In the short-term, it's really paying the ransom and getting back what you've lost can be very attractive, but you're going to make yourself more obvious as a target that way and also encourage the wider attacks. The impact, even if you have a well-managed incident, can be quite significant. Expecting to be attacked, I think, is realistic. Being ready to deal with an attack when it arises, but that doesn't have to just be hoarding money. I've done exercises with the boards of organizations where you step through what you would do, what an attack might look like, just to kind of take that challenge of understanding something that's a bit intangible and make it real for people.

14:23And one of the reasons you make that preparation is so that you have arrangements that can minimize the impact when it happens, so that you can have backups, that you can know what you're going to do. You have decided whether you're going to have insurance or not. You've just got a policy about whether you pay the ransom and that you have arrangements in place to be able to carry on operating as a business, even when you're under attack. If the company is being placed under attack by what one presumes to be a state entity, how do you respond to that? Is there a different approach to that where it's simply entirely motivated by money?

14:57Yes, in a couple of different ways. I mean, the defence sector and the government sector operates slightly differently from most commercial organisations. If you're being attacked by a nation state in order to get national secrets, then the government has an interest in that and you're not operating entirely on your own. So working with government agencies in order to be able to support cybersecurity is important in our sectors. And in that kind of situation, you're going to have to recognize that the level of attacks are going to be more heavily resourced. But that's why we have things like security clearances and standards and high levels of control around classified material.

15:34Our business correspondent Paul Kelso made the point that this focus on the commercial entities ignores the fact that, look, if these hackers got inside government, I mean, the damage could be, well, what could the damage be? So the impact could be very considerable. But that is something that the government is on. They set up the National Cyber Security Centre nearly 10 years ago. There is a strong established cyber security capability within UK government and they are continuously working and monitoring on this. And in fact, in a way that I'm encouraging commercial organisations to have that at the centre of what they're doing.

16:08Let's just turn back to the corporate to conclude. I mean, is this just the cost of doing business in an increasingly interconnected 21st century that cyber attacks, whilst not necessarily inevitable, are just going to be highly likely if you're operating at the scale of the companies that have been in the news recently? I think you have to be realistic that if you're connected to the internet, which you're a corporation, you're going to be. If you're using digital technology, if you've got a wide supply chain, if you're connected to a lot of people, then you just have to have clarity of how you're going to manage that at the centre of your business strategy.

16:44Yes, it's a cost of doing business, but if you do it right, not a big extra cost. But if you try and run everything digitally, connect everything to everything, and then try and stick security on afterwards, that is really expensive. So my main piece of advice would be to think about it early. Make sure that you've got it built into the way you handle your technology and how you manage your suppliers and how you manage people. And build it in and be ready for the worst when it happens so that you can live through it. Thanks to James, to Paul and to you for listening. The Daily's back tomorrow.

17:16Bye for now. How does a banana trigger a CIA-backed coup? Do AirPods herald the arrival of a new global order? What do LED lights say about the future of humanity? I'm Ed Conway, and in each episode of my new podcast, Stuff Matters, I take an object, crack it open, and reveal the world-shaping forces hidden inside. This is economics told through the things we think we understand. Search Stuff Matters on your podcast app to listen and follow.

From the publisher
Despite Jaguar Land Rover announcing some of its systems are back online, not a single car has rolled off the production line since the end of August. And there's still no date set for the factories to reopen. All because of a cyber attack, costing hundreds of millions of pounds and threatening thousands of jobs.

JLR is just the latest British company harassed by hackers – with Marks & Spencer, Harrods and Co-op all suffering major (and expensive) outages in recent months. Airports and national institutions have also been attacked.

It all raises serious questions about the UK's vulnerability to cyber terrorists. Who has been targeting these companies and why? What can companies do to defend themselves? Are we heading for a cyber attack pandemic? And what can your business do to prepare for the inevitable?

Niall is joined by James Hatch, chief digital officer at BAE Systems, and Sky's business correspondent Paul Kelso.

Producer: Soila Apparicio 
Editor: Mike Bovill 

More from This Is Why

All 332 episodes
How to survive a cyber attackThis Is Why · 16 min
Listen in VO