In September 2025, a cyberattack forced Jaguar Land Rover to take its internal IT networks offline. Global production lines came to a complete standstill. Thousands of workers were told to stay home. The disruption lasted weeks, not days, and rippled through thousands of connected suppliers across the UK. The financial impact ran an estimated 50 million pounds per week at the height of the shutdown, and by the end of the fiscal year in March 2026, JLR’s annual revenue had dropped nearly 21 percent. The UK’s Cyber Monitoring Centre put the total economic damage across the broader supply chain at 1.9 billion pounds.

JLR is not a 100-person manufacturer, but the failure that turned a cyberattack into a company threatening event was not exotic. It was the absence of a plan for what happens when the primary way of doing business simply stops working, for weeks, with no clear path to an alternative. That same failure, at a much smaller scale, is what turns a broken CNC machine, a key supplier going dark, or a ransomware attack into a permanent closure for smaller manufacturers who never built a real business continuity plan in the first place.

This article is about what a genuine business continuity plan for manufacturing actually contains, using a realistic 100-employee manufacturer as the working example throughout. This is deliberately broader than IT disaster recovery or cybersecurity incident response, both of which are necessary pieces of the plan but not the whole plan. A real BCP covers what keeps the entire business running, not just what keeps the servers running.

29%
of all global ransomware cases in Q1 2024 targeted manufacturing, nearly double the year prior
66%
of organizations report supply chain disruption as a major component of their risk profile
75%
of businesses have no active plans to build, update, or test their continuity team
$1.9M
average per-day downtime cost for a manufacturer during a ransomware related outage

Business continuity plan, disaster recovery, and incident response are not the same thing

These three terms get used interchangeably, and the confusion is exactly why so many manufacturers think they have a real plan when they actually have one piece of one.

A business continuity plan (BCP) is the master document covering how the entire business keeps operating during any kind of disruption: a cyberattack, a supplier failure, a key employee leaving suddenly, a fire, a utility outage, or an equipment breakdown. It answers the question “how do we keep making and shipping product, getting paid, and communicating with customers and vendors, no matter what caused the disruption.”

Disaster recovery (DR) is the specific technical plan for restoring IT systems and data after a disruption. It is a critical component inside a BCP, not a substitute for one. A manufacturer can have excellent backups and still shut down permanently if it has no plan for what happens when a key supplier disappears or the building itself becomes unusable. See the difference between having backups and having real disaster recovery for the IT-specific piece of this puzzle.

Incident response (IR) is the specific, tactical plan for the first hours of a cybersecurity event: who gets notified, who isolates affected systems, who calls breach counsel. It is also a component inside the BCP, focused narrowly on security incidents rather than every category of disruption. See what incident response actually looks like when it is done right for that piece specifically.

A real BCP contains both of these as sub-plans, plus several categories of continuity that have nothing to do with IT at all. Those non-IT categories are where most manufacturing BCPs, when they exist at all, are thinnest.

What a real BCP for a 100-person manufacturer actually contains

Picture a realistic profile: a precision machining or electronics assembly manufacturer in Orange County or the Inland Empire, roughly 100 employees across two shifts, serving a mix of commercial and defense adjacent customers, running on a mix of CNC equipment, an ERP system, and a handful of specialized software tools tied to specific customer contracts. Here is what a genuinely complete BCP for that business covers, category by category.

1. Risk assessment and business impact analysis

Before writing a single procedure, the plan needs a documented list of what could actually disrupt this specific business: a key supplier failure, a fire or flood at the facility, a cyberattack, a prolonged power outage, the sudden departure of a critical employee, a critical piece of equipment failing, or a customer contract requirement changing overnight. For each risk, the plan states the realistic likelihood, the financial and operational impact if it happens, and the maximum tolerable downtime before the damage becomes severe or unrecoverable. This is not a generic checklist. It is specific to this manufacturer’s actual customers, equipment, and supply chain.

2. Supply chain continuity

This is the category most 100-person manufacturers skip entirely, and it is often the one that matters most. A real plan does not just list Tier 1 suppliers. It maps Tier 2 and Tier 3 as well, since the actual bottleneck is often a small, specialized component maker several layers deep in the supply chain that nobody at the manufacturer has ever directly contacted. For any component with high impact and high supply risk, the plan identifies at least one alternative supplier, with a relationship already established before a crisis, not researched for the first time during one. Building that relationship in advance, sharing forecasts, and understanding a backup supplier’s own continuity posture are what separate a plan that works from a list of vendor names nobody has actually called.

3. Facility and equipment continuity

The plan documents what happens if the primary facility becomes unusable, whether from fire, flood, extended utility outage, or structural damage: is there an alternate facility identified, a relationship with another manufacturer who could absorb overflow production, or a documented plan to lease emergency space and equipment. For critical machinery, the plan includes preventive maintenance schedules to reduce the likelihood of failure in the first place, along with a documented process for rapid repair, backup equipment, or outsourcing specific production steps if a critical machine goes down and cannot be repaired quickly.

4. Workforce continuity

A 100-person manufacturer typically has a small number of people whose knowledge is not documented anywhere except in their own head: the one person who knows how to run a specific piece of legacy equipment, the office manager who has the only copy of certain customer relationships, the shift supervisor who is the sole point of contact for a key account. The plan identifies these single points of failure explicitly and requires cross-training or documentation specifically to close them. It also documents succession for key roles and a communication plan for reaching employees during a disruption, including who has authority to make emergency decisions if leadership is unreachable.

5. IT and cybersecurity continuity

This is where the disaster recovery and incident response plans plug in as sub-components. The BCP references, at minimum, off-site backups that can be accessed and restored rapidly if critical systems, including the ERP platform that tracks production, inventory, and shipping, become unavailable, and a documented incident response process for cyberattacks specifically. Given that manufacturing accounted for 29 percent of all global ransomware cases in early 2024, nearly double the year before, this is not a low-probability category to leave thin.

6. Communication and customer continuity

The plan documents exactly who contacts customers, vendors, insurers, and employees during a disruption, with pre-drafted communication templates so nobody is composing an explanation from scratch under pressure. For defense adjacent manufacturers specifically, this includes a plan for notifying primes of any disruption affecting a contracted delivery schedule, since a supplier that goes dark without communication risks losing the relationship even after operations resume.

7. Financial continuity

The plan documents available cash reserves, lines of credit, and insurance coverage specifically relevant to a prolonged disruption, including business interruption insurance and, increasingly, cyber insurance with terms the business has actually reviewed rather than assumed. It also documents the realistic cash flow impact of the maximum tolerable downtime identified in the risk assessment, so leadership knows in advance how long the business can absorb a disruption before it becomes an existential problem rather than an operational one.

Red flag: If your business continuity plan is entirely focused on IT systems and backups, with no documented alternative suppliers, no identified backup facility, and no plan for the specific employees whose knowledge exists only in their own heads, it is a disaster recovery plan wearing a BCP label. JLR’s IT systems were the trigger, but the reason the disruption lasted weeks and cascaded through thousands of connected companies was the absence of continuity planning at every other layer of the business.

Generic checklist vs a real, working plan

Category Generic checklist Real, working plan
Supply chain “Identify backup suppliers” as a bullet point Named alternate suppliers for high-risk components, with an existing relationship, mapped through Tier 2 and Tier 3
Facility “Consider alternate location” as a bullet point A specific arrangement with another manufacturer or a documented emergency leasing plan, agreed to in advance
Workforce No mention of single points of failure Named individuals whose knowledge is undocumented, with an active cross-training plan to close each gap
IT and cyber “We have backups” Tested, immutable backups with a defined recovery time, plus a rehearsed incident response plan
Communication No plan; improvised if something happens Pre-drafted templates for customers, vendors, primes, and employees
Testing Written once, never revisited Tabletop exercise at least annually, updated after any real disruption or major operational change

Why testing is the step almost everyone skips

A written plan that has never been rehearsed is a document, not a capability. A tabletop exercise, walking leadership and key staff through a realistic scenario, a key supplier suddenly closing, a ransomware attack encrypting the ERP system, a fire damaging the primary facility, is where the gaps in a written plan actually surface, while nobody’s real production schedule is at stake. Seventy five percent of businesses currently have no active plans to build, update, or test their continuity team, which means the plan most manufacturers have on file, if they have one at all, has never been checked against a realistic scenario since the day it was written.

Key takeaway: A real business continuity plan for a 100-person manufacturer covers supply chain, facility, workforce, IT, communication, and financial continuity together, not IT recovery alone with everything else left to improvisation. JLR’s cyberattack became a 1.9 billion pound economic event not because the IT failure itself was unusual, but because nothing else in the business was built to keep functioning while IT was down.

The honest version

Most manufacturers in the 50 to 200 employee range either have no business continuity plan at all, or have a plan that is really just an IT disaster recovery document with a different cover page. The gap is rarely intentional. Building a genuine BCP touches procurement, HR, finance, operations, and IT all at once, and none of those departments individually owns the responsibility to pull it together. That gap is exactly where JLR’s disruption, and countless smaller versions of it at manufacturers nobody has heard of, actually originates: not from a single point of failure, but from the absence of a plan for what happens to everything else while that one point of failure is being fixed.

Building the plan does not require a large budget or a dedicated compliance department. It requires someone to actually sit down with operations, procurement, HR, and IT together, document the real risks specific to this business, and write down the specific alternate suppliers, facilities, and cross-trained employees that turn a disruption into a bad week instead of a company ending event. Then it requires testing that plan at least once a year, so the day it is actually needed is not the first time anyone has looked at it since it was written.

Find out where your manufacturer’s continuity plan actually has gaps.

Intelecis helps Orange County and Inland Empire manufacturers build the IT and cybersecurity continuity pieces of a real business continuity plan, including tested backups, incident response, and network segmentation that limits how far a disruption spreads. NSA-Accredited, with documented experience across CMMC regulated and commercial manufacturing environments. Book a free security assessment and we will show you exactly where your current plan, if you have one, actually holds up.

Get Your Free Security Assessment →

📞 949-266-2088 · Fullerton, CA · NSA-Accredited · Serving OC since 2010

Related reading:
Cybersecurity Services for OC Businesses ·
Why Your Backup Is Not Your Disaster Recovery Plan ·
What Does Incident Response Actually Look Like When It’s Done Right? ·
Network Segmentation: The $50 Fix That Could Have Prevented a $500K Breach ·
Schedule Your Free Security Assessment