
Article adapted from the original column written by Guillaume Chéreau and published in JDN (in French).
Mass cybercrime continues to weaken critical supply chains: despite the progress made in cybersecurity, cyber resilience remains insufficient and is now emerging as a strategic and economic imperative.
The continuous rise of the cybercriminal threat regularly results in new waves of attacks, particularly by ransomware. The incidents that have occurred in recent weeks are a reminder that their consequences are no longer limited to the information systems of the organizations affected.
Today, a cyberattack can bring production to a lasting halt, disrupt a critical service or weaken an entire value chain. Impacts are measured as much in weeks of downtime, supply disruptions or temporary job losses as in financial losses.
At the same time, the regulatory framework continues to be strengthened. This evolution invites us to question the actual maturity level of organizations in cyber resilience. Three recent cyberattacks, occurring in very different sectors, help measure its limits.
Three cyberattacks that illustrate the current limits of cyber resilience
Jaguar Land Rover: a cyberattack that destabilizes an entire industrial supply chain
The ransomware attack against Jaguar Land Rover in late August 2025, claimed by the Scattered Lapsus$ Hunters group, illustrates the scale that the consequences of a cyber incident can now reach in the industrial sector.
The British manufacturer saw its production sites completely shut down between late August and early October 2025. Direct operating losses are estimated at £1.5 billion.
But it is above all the propagation of the effects of this attack that leaves a mark. The interruption of production at Jaguar Land Rover created difficulties for its entire subcontractor network. Around 700 British companies, representing nearly 150,000 jobs, suffered the consequences of this production halt. Some of them were already weakened even before this cyberattack.
Faced with this nationwide crisis, the British government announced in late September that it would guarantee a £1.5 billion loan to support Jaguar Land Rover and its partners and prevent bankruptcies. The manufacturer finally announced, on 7 October 2025, a restart of its production sites from mid-October, more than six weeks after the start of the attack.
According to the Cyber Monitoring Centre, the total economic cost of this incident is estimated at £1.9 billion, or approximately €2.1 billion. More than 5,000 entities were reportedly affected, directly or indirectly. Most of the losses reportedly stem from the halt of production activities, both at Jaguar Land Rover and across all its suppliers.
Collins Aerospace: very different disruptions depending on the operators’ level of preparation
The incident affecting Collins Aerospace, a subsidiary of RTX (formerly Raytheon), is another notable example from 2025. From 20 September onwards, a ransomware attack claimed by the Everest group rendered the MUSE system unavailable, which is used for passenger check-in at several European airports.
Because it is essential to passenger check-in, this system illustrates the risk of dependence on a single supplier when it comes to delivering a critical service.
Beyond the cyberattack itself, one element deserves particular attention: not all airports using MUSE experienced the same consequences.
Some, such as Dublin airport, experienced limited disruptions. Others, like Brussels airport, faced significant difficulties for several weeks.
The available hindsight does not yet allow this difference in impact to be precisely explained. On the other hand, it highlights, at the very least, different levels of preparation and maturity in cyber resilience between operators belonging to the same sector of activity.
Even if this incident ultimately translated into limited disruptions across European air transport, it is a weak signal that deserves to be taken into account. It is a reminder that the consequences of a software supply chain compromise can vary significantly depending on each organization’s ability to continue its activities despite the unavailability of a critical service.
Asahi: when a cyberattack threatens the supply of a national market
The Japanese group Asahi, which accounts for approximately 40% of Japan’s beer market, was hit by a ransomware attack on 29 September 2025. Claimed by the Qilin group, this attack did not directly interrupt the production lines.
However, it paralyzed the system used to manage orders and product shipments across the entire distribution network.
Deprived of these tools, the group’s employees had to fall back on fully manual procedures, using paper, pencil and fax to handle shipments. This degraded arrangement significantly reduced the company’s distribution capacity for several weeks.
Asahi announced in a statement that it had restored normal production and distribution capacity by late October 2025.
This case highlights a particular risk: when an actor holds a dominant position in its market, the paralysis of its information system can trigger a nationwide supply disruption. In Asahi’s case, the consequences could have been far more serious if the products concerned had been essential consumer goods or belonged to the healthcare sector.
Cyber resilience remains a major undertaking for organizations
These three incidents, occurring in just a few weeks, are a reminder of the consequences a cyberattack can have well beyond the information system of the organization directly affected.
Since the attack against Colonial Pipeline by the DarkSide group in May 2021, no event has illustrated with such force the economic repercussions a cyber crisis can cause, particularly in the case of Jaguar Land Rover.
Eight years after the WannaCry and NotPetya attacks, which marked the emergence of mass cybercrime, the finding remains the same: the maturity of businesses and public actors alike remains insufficient in cyber resilience.
Protection, detection and incident response programs have nevertheless developed significantly over recent years.
On the other hand, the capabilities to absorb a shock and quickly return to normal operations remain too rarely deployed within organizations.
This weakness appears at a time when regulatory requirements are evolving. The European DORA and NIS2 directives now place digital operational resilience among the obligations of the organizations concerned.
Beyond mere compliance, cyber resilience is progressively becoming a strategic and economic issue. It conditions both digital trust and organizations’ ability to remain competitive in a lastingly unstable environment.
This evolution is fully consistent with the direction taken by ANSSI (French National Cybersecurity Agency), which has placed cyber resilience at the core of its 2025-2027 strategic plan in response to this mass threat.
On that basis, 2025-2030 will be the five-year period dedicated to cyber resilience.
FAQ – cyber resilience
Read the article
OpenAI - Hugging Face : when the person who triggers the incident becomes the narrator of the crisis
25 August 2026Read the article
Publication of the ReCyF framework: ANSSI is concretely preparing organizations for the NIS2 era
6 July 2026Read the article