IT and OT Continuity Planning for UK Manufacturing: A Practical Guide

A practical guide to maintaining and recovering production when failures across IT systems, operational technology or critical dependencies disrupt UK manufacturing.

KANJ Advisory Team
Explore
IT and OT Continuity Planning for UK Manufacturing: A Practical Guide

Research commissioned by Fluke Corporation estimated that unplanned downtime could be costing UK manufacturing as much as £736 million a week. The study, reported in October 2025, found that 68 per cent of UK manufacturing respondents had experienced unplanned downtime during the previous year.

The scale of loss will vary considerably between manufacturers, but the underlying point is clear. When digital systems support physical production, disruption can quickly affect output, quality, dispatch and customer commitments.

In many office-based organisations, temporary workarounds may allow some activity to continue during an IT outage. Manufacturing has fewer such options. People may still be present and machinery may still be available, but production can stop because schedules, specifications, machine settings, quality records or stock information cannot be accessed.

An effective manufacturing continuity plan therefore needs to go beyond explaining how technology will be restored. It should also consider how the business will maintain and recover production safely.

Start With Minimum Viable Production

Traditional continuity planning often begins with a list of systems. Manufacturing continuity is more useful when it begins with the products and orders that matter most.

The central question is:

What is the smallest combination of people, machinery, information, systems and suppliers needed to complete and dispatch priority orders safely and to the required quality standard?

This can be thought of as the organisation’s minimum viable production capability.

Defining it requires decisions about which product lines should be prioritised, which customers or contracts carry the greatest consequences and what level of output could be maintained during disruption.

For one manufacturer, the priority might be continuing a high-volume production line. For another, it may be completing a small number of regulated or contractually important orders. The answer should reflect commercial commitments and production realities rather than being determined solely by the perceived importance of individual systems.

Once minimum viable production has been defined, the organisation can identify everything needed to support it. That may include production schedules, materials, machine settings, engineering drawings, quality records, stock information and safe restart procedures.

This creates a continuity plan based on production capability rather than a generic inventory of technology.

Map the Complete Production Dependency

Manufacturing operations depend on a mixture of information technology, operational technology, physical equipment, people and external services.

Enterprise Resource Planning and Manufacturing Execution Systems may coordinate orders, materials and production. Programmable Logic Controllers and industrial control systems may operate equipment. Cloud platforms may store specifications or production information. Suppliers may provide raw materials, maintenance, specialist tooling or remote technical support.

Understanding how those elements interact can be more valuable than considering each one separately.

Mapping individual assets is useful, but mapping the production sequence provides additional context. A system may appear less critical when viewed alone while remaining essential to a particular stage of production.

For example, restoring an ERP platform may not allow production to resume if machine configuration data remains unavailable. Production may restart but finished goods may be unable to leave the site if label printing, quality records or dispatch documentation cannot be produced.

The plan should therefore reflect which dependencies are needed at each stage, from receiving an order through to producing, approving and dispatching the finished product.

Set Recovery Priorities Around Production

Recovery Time Objectives define how quickly a service should be restored. Recovery Point Objectives define how much data loss the organisation can tolerate.

Both are important, but they are most useful when they reflect what production can absorb.

A generic priority list might classify the ERP system as critical and a document platform as secondary. Operational analysis may reveal that production can continue temporarily without full ERP access but cannot safely proceed without current drawings or quality specifications held elsewhere.

Recovery priorities should therefore follow the sequence in which the business needs to resume activity.

Leadership, production, engineering, quality and IT can work together to agree which products should be recovered first, how long each production stage can remain unavailable and which temporary procedures are safe and workable.

They should also consider when partial production becomes less viable than waiting for full recovery and who has the authority to approve a restart.

This helps prevent technical recovery from becoming disconnected from operational need.

Design IT and OT Recovery Differently, but Test Them Together

Office IT and operational technology often have different technical requirements.

OT environments may include older operating systems, specialist protocols and equipment that cannot be patched, rebooted or replaced on normal IT schedules. A control system connected to live machinery may also require carefully managed shutdown and restart procedures.

OT recovery therefore benefits from its own technical instructions, rollback arrangements, testing constraints and production ownership.

That does not mean it should be planned in isolation.

A production line may depend on both OT controls and information supplied by ERP, MES, quality or warehouse systems. Restoring one environment without the other may provide limited operational benefit.

IT and OT recovery can be designed separately where their technical requirements differ, while being exercised together wherever production depends on both.

Network segmentation is also important. Separating OT from wider corporate systems can restrict the movement of ransomware or another cyber incident. It can provide greater control over remote access and reduce the likelihood that a compromise of an office device reaches equipment supporting live production.

Segmentation does not remove the need for continuity planning, but it can reduce the number of systems affected by the same event.

Plan for Safe Degraded Operation

A continuity plan should identify which activities can continue without normal systems and under what conditions.

Manual workarounds can help maintain production, but they may also introduce quality, safety and traceability risks. Manual records can support continuity, provided they capture the necessary information, can later be reconciled and remain consistent with the organisation’s quality processes.

It is therefore helpful for the plan to define which processes can operate manually, who can authorise the workaround and how quality and traceability will be maintained.

The organisation should also understand how much work a temporary process can support and when degraded operation should stop.

This is particularly important in regulated or safety-sensitive production environments. Maintaining output is unlikely to represent a successful continuity response if the organisation cannot later demonstrate what was produced, which materials were used or whether the correct checks were completed.

Understand the Real Supplier Buffer

A supplier outage does not need to affect the manufacturer’s own systems to interrupt production.

Raw-material suppliers, logistics providers, cloud platforms, maintenance partners and equipment manufacturers can all become critical dependencies. The time available to respond may range from hours to months, depending on stock levels, lead times and the availability of approved alternatives.

Rather than relying on a general statement about supply-chain resilience, manufacturers can establish their actual operational buffer.

For each critical supplier, it is useful to understand:

·       how long production can continue without its service or material;

·       which products and customers would be affected first;

·       whether an alternative supplier has already been approved;

·       whether specifications, data or tooling can be transferred;

·       whether a substitution would introduce quality or regulatory issues;

·       what evidence exists of the supplier’s own continuity arrangements.

Longstanding supplier relationships remain valuable, but continuity planning also benefits from a clear understanding of what would happen if an important supplier became unavailable.

Protect the Information Needed to Restart

Backups are essential, but the existence of a backup does not by itself prove that production can recover.

Manufacturers can gain greater confidence by establishing whether critical production information can be restored within the required timeframe and whether that information can be trusted following a cyber incident.

This includes more than office files. Machine configurations, product specifications, engineering drawings, quality records, production schedules and stock information may all be essential to a safe restart.

Copies should be protected from the same incident that affects the live environment. Restoration should also be tested rather than assumed.

Following ransomware or another compromise, the fastest available backup may not necessarily be the correct recovery point. The organisation may first need to establish when the compromise began and whether restored systems, accounts and data are safe to use.

The plan should therefore consider both the availability and integrity of production information.

Define Who Can Stop and Restart Production

During a significant incident, restoring technology is only part of the response. Someone needs to decide whether production can continue, whether a workaround is acceptable and when normal operations can safely resume.

Clarifying those responsibilities in advance can reduce uncertainty during an incident.

The plan should identify who can declare a continuity incident, stop an affected process, approve manual workarounds and prioritise customers and orders. It should also establish how technical recovery will be coordinated with production, quality and safety requirements.

Technical teams can confirm that systems are available. Production, quality and operational leaders can then determine whether the business is ready to use them.

Test the Decisions as Well as the Technology

A backup restoration test provides evidence that data can be recovered. It does not necessarily show that the business can maintain or restart production.

Manufacturing continuity exercises are more valuable when they include a realistic operational scenario.

For example:

The main site has lost access to its ERP and production scheduling systems following a cyber incident. The recovery team cannot yet confirm whether the latest data is trustworthy. A priority customer order is due to dispatch the following morning.

The exercise could explore whether the production team can identify what should be manufactured, access current specifications, verify materials and maintain quality records.

It should also test who decides whether production continues, which customers need to be contacted and what evidence will be required before normal operations restart.

This examines the organisation’s judgement, communication and operational workarounds alongside its technical recovery.

Exercises can be scheduled around maintenance and production constraints, while the scenario itself reflects the pressure and uncertainty of a real event.

Review the Plan When Production Changes

An annual review is a sensible minimum, but manufacturing environments can change significantly within 12 months.

It may also be appropriate to review the plan when a production line or site is introduced, a business is acquired, core systems change or a critical supplier is replaced. Changes to machinery, products, remote access or regulatory obligations may also alter the organisation’s recovery priorities.

Incidents and exercises should provide another reason to revisit the plan, particularly when they reveal assumptions that no longer reflect how production operates.

A Practical Way to Review Manufacturing Continuity

Six questions can help a manufacturing leadership team assess whether its continuity arrangements reflect the realities of production:

1.     What is our minimum viable production capability?

2.     Which combination of people, systems, machinery, information and suppliers supports it?

3.     In what sequence would those dependencies need to be recovered?

4.     How would we maintain safety, quality and traceability during disruption?

5.     Who can approve degraded operation and the eventual production restart?

6.     When did we last test the complete process?

Where a continuity plan explains how systems will be restored but says less about maintaining safe production in the meantime, that is likely to be the most valuable area for further development.

Kanj Technologies helps manufacturers identify their minimum viable production capability and understand the combination of IT, OT, information, people and suppliers required to support it.

This allows recovery arrangements to reflect how production actually operates rather than being adapted from a generic office-based template.

The objective is not simply to restore technology. It is to maintain and recover the organisation’s ability to produce, approve and deliver.

 

Keep exploring

Related blogs

let's collaborate

Need IT That Reduces Risk and Stands Up to Regulation?

Let's strengthen reliability and optimise your IT for efficiency.