IT support for manufacturing and engineering businesses

IT support for manufacturing has to start from two facts. The first is that a factory is not an office with machines in it. The second is what happened here in September 2025.

After the Jaguar Land Rover cyber attack stopped production for five weeks, three regional Chambers surveyed 84 local firms employing nearly 30,000 people between them.

77% reported a negative effect, 45% took a significant financial hit, 35% cut hours or stood staff down, and 14% made redundancies. 18% were not even in JLR’s supply chain, just caught in the knock-on.

None of those firms had been breached themselves.

Production planning, warehouse systems, machine controllers, quality records, finance and customer portals all have to work together, and a good proportion of the kit on the shop floor was installed before anyone worried about what it was connected to.

Computercentric has supported manufacturers and engineering businesses across the West Midlands for over 20 years, including Vesta Space in Aldridge and In-Comm Training, who train apprentices for engineering employers across the Midlands. This page covers what actually breaks in a manufacturing environment, what it costs, and what to do about it.

Talk to us about IT support for your manufacturing business. Call 01922 830000, WhatsApp or email.

Team of IT professionals providing reliable and tailored IT support for small businesses in Birmingham, ensuring smooth operations and robust cybersecurity.

What IT support for manufacturers should cover

Office IT support covers maybe half of what a manufacturing business needs. Proper manufacturing IT services should include:

  • Helpdesk support for office, shop floor and warehouse users
  • ERP, MRP and production system support, and liaison with your software vendor
  • Network design that separates production systems from the office network
  • Security for connected machines, controllers and older kit that cannot be patched
  • Cyber Essentials certification, increasingly demanded by customers and primes
  • Backup and disaster recovery covering production data, not just email
  • Resilient connectivity across offices, factory floor, warehouse and multiple sites
  • Microsoft 365 administration, email security and account protection
  • Hardware supply and leasing for office PCs, shop floor terminals and rugged devices
  • IT planning that fits capital cycles and production schedules

Why a factory is not an office with machines in it

The thing that catches out generalist IT providers is that a manufacturing business runs two technology estates with different rules, and they have quietly grown into each other.

Office IT is the bit everyone recognises. Email, finance, Microsoft 365, laptops. It gets patched on a Tuesday, rebooted at lunchtime, and if it goes down for an hour people are annoyed rather than idle.

Operational technology is everything that touches production. CNC controllers, PLCs, inspection systems, label printers, the press brake with a touchscreen, the laser cutter with an embedded PC. It does not get patched, it often cannot be rebooted without a setup engineer present, and when it stops, the line stops.

The machine that runs Windows 7

Almost every manufacturer we visit has at least one. A six-figure machine tool with a control PC running an operating system that stopped receiving security updates years ago, because the vendor never certified anything newer and requalifying it would mean days of downtime and a visit from the OEM.

This is not a local failing. BlackBerry’s manufacturing OT research found 86% of manufacturers running core functions on outdated or unsupported operating systems, with 57% still running Windows 7 somewhere in the estate. The same study found only 47% had network segmentation in place.

That second figure is the problem. The old machine is not the risk. The old machine connected to everything else is.

Replacing a working machine because its controller is old is rarely justifiable, and no finance director is going to sign it off. Isolated on its own network segment with tightly controlled access, a Windows 7 controller is a managed risk. Sitting on a flat network with the office laptops, a shared password and a route to the internet, it is the softest entry point in the building.

Windows 10 reached end of support on 14 October 2025, which quietly widened this problem. It is no longer just the machine controllers. Engineering workstations, barcode terminals, quality inspection PCs and vendor-supplied systems all need checking, and many older devices cannot meet the Windows 11 hardware requirements.

Flat networks and the quiet drift

The NCSC published guidance in September 2025 making the same point from the other direction. Systems that were once genuinely air-gapped now talk to enterprise IT, cloud platforms and remote vendor management tools, and almost nobody has an accurate picture of it.

Their phrase for what is missing is a definitive record: what is connected, to what, and what happens to the business if each part fails. In practice the documentation gap is the real problem. Temporary fixes become permanent, devices get swapped without records being updated, and a vendor’s remote support tunnel opened for a commissioning visit in 2019 is still open.

The first useful thing any IT provider can do for a manufacturer is find out what is actually on the network. It is rarely what the drawing says.

Who owns the machine

There is a third problem, and it is organisational rather than technical. Office IT belongs to whoever handles IT. The machine belongs to production, or engineering, or the vendor who installed it, so when a controller misbehaves it falls between two people who each reasonably think it is the other’s job.

That gap is where most manufacturing IT problems live. We work it explicitly: we handle the network, the security boundary and the IT side of the connection, and deal with the machine vendor directly when the fault sits inside their equipment.

Computercentric — Independent IT Consultancy
Birmingham & West Midlands
Birmingham City Centre Jewellery Quarter Aston Erdington Digbeth Bordesley Green Moseley Selly Oak Edgbaston Harborne Sutton Coldfield Lichfield Walsall Solihull Bournville Aldridge HQ
✕

Cyber security for manufacturers: what the numbers show

Manufacturing is among the most attacked sectors in the UK, for a simple reason: downtime costs so much per hour that manufacturers are more likely to pay quickly.

Make UK research published in August 2026 found 30% of UK manufacturers had suffered a cyber incident in the previous twelve months, directly or through their supply chain. Only 51% have an incident response plan. Among those hit by an attack on a supplier, 31% saw delays to customer deliveries, 31% reduced production capacity, and 23% ran short of components.

What the JLR incident should change

The September 2025 Chambers survey figures at the top of this page are worth taking to a board meeting, because they reframe the question. The risk is not only that you get attacked. It is that a customer does, and your working capital absorbs it.

Five questions follow from that, and none of them are really IT questions:

  • Can you operate, invoice and communicate if a major customer’s portal or EDI link disappears for a month?
  • Do you have cash-flow contingency for a 4 to 6-week customer shutdown?
  • Are production schedules, quality documents, CAD files, ERP data and customer contacts recoverable independently of any customer system?
  • Can key people work from alternative devices or locations if your own site is compromised?
  • Do your supplier contracts say anything about incident notification and recovery?

What did not happen shapes how much help to expect next time. The government announced a £1.5bn loan guarantee through UK Export Finance to support JLR’s liquidity and supply chain, but reporting in October and November 2025 said the facility had not been drawn down.

No dedicated local authority hardship fund materialised for affected firms in Walsall, Wolverhampton, Sandwell or Dudley.

Plan on the basis that recovery money arrives late, if at all.

The controls that actually matter here

All the standard advice applies, and none of it is specific to manufacturing: MFA everywhere, conditional access, email authentication, endpoint protection, patching within a fortnight, and removing access the day somebody leaves.

Four other controls matter considerably more in a factory than they do in an office:

  • Network segmentation between production and office systems, so a phishing email opened in accounts has no route through to a machine controller. This is the highest-value control available to most manufacturers, and on the figures above fewer than half have it.
  • Controlled remote access for machine vendors, replacing the standing tunnel that has been open since commissioning with access that is requested, time-limited, logged and closed behind them.
  • Backup that genuinely covers production: ERP databases, CAD and CAM files, machine programs, quality records and calibration data. We regularly find manufacturers with immaculate email backup and no copy anywhere of the programs that make their parts.
  • A recovery order built around how the business earns money rather than which system feels most important in the abstract. Work out which system has to be running before you can make and ship something, because that is not a decision anyone makes well at 6am with the line stopped.

Our guide to business continuity and disaster recovery covers the planning side, and cyber attacks to be aware of explains the common attack types in plain terms.

Local coverage

Manufacturing IT support across the West Midlands & Staffordshire

We support manufacturers and engineering firms in each of the areas below, from single-site workshops to multi-site operations running shifts, keeping the office, the shop floor and the ERP working together.

West Midlands

Birmingham

  • Managed IT support
  • Cybersecurity & EDR
  • Cloud & Microsoft 365
IT services in Birmingham →
West Midlands

Walsall

  • Managed IT support
  • Backup & disaster recovery
  • Proactive monitoring
IT services in Walsall →
West Midlands

Wolverhampton

  • Managed IT support
  • Cybersecurity & compliance
  • Network management
IT services in Wolverhampton →
West Midlands

Sutton Coldfield

  • Managed IT support
  • Microsoft 365 management
  • Business continuity
IT services in Sutton Coldfield →
Staffordshire

Lichfield

  • Managed IT support
  • Cybersecurity & EDR
  • Backup & recovery
IT services in Lichfield →
West Midlands

Aldridge

  • Managed IT support
  • Cloud services & hosting
  • IT consultancy
IT services in Aldridge →
West Midlands

Bournville

  • Managed IT support
  • Endpoint protection
  • Business continuity
IT services in Bournville →

Cyber Essentials and what your customers actually require

Cyber Essentials covers five controls: boundary firewalls, secure configuration, user access control, malware protection and security patching within 14 days. Nationally, more than 61,000 Cyber Essentials and Cyber Essentials Plus certificates were awarded in the year to June 2026.

For manufacturers, the driver is commercial rather than regulatory, and it varies sharply by who you supply.

In defence and aerospace, it is explicit. BAE Systems’ supplier requirements state that the supplier “shall hold, and continue to hold, a valid Cyber Essentials Certificate prior to contracting”. Defence Standard 05-138 requires annually renewed Cyber Essentials at very low risk level and Cyber Essentials Plus at low. Rolls-Royce recognises Cyber Essentials, ISO 27001, NIST 800-171 and the OT-specific IEC 62443 as routes to compliance.

In automotive, it is more nuanced and worth being accurate about. JLR’s supplier code of conduct requires suppliers handling its data to do so “responsibly and securely” in line with contractual and legal requirements. There is no published universal mandate that every tier two and tier three supplier must hold Cyber Essentials Plus, whatever you may have been told.

The requirement depends on your contract, the information you handle and the systems you connect to the customer.

The awkward part for manufacturers is scope. Cyber Essentials expects devices to be supported and patched, which collides directly with the machine controller the vendor will not update. That is solvable through segmentation and documented scope boundaries, but it needs someone who has handled it before rather than a first attempt at self-assessment two weeks before a customer audit.

There is a free local route many manufacturers miss. The Cyber Resilience Centre for the West Midlands offers core membership to regional SMEs at no cost, including a 30-minute review with their head of cyber and access to Police CyberAlarm for network monitoring.

A sensible starting point, though not a substitute for managed protection, tested recovery or monitoring.

ERP, MRP and the systems production runs on

The software that runs a factory is not interchangeable with standard business applications, and generalist providers often have not encountered any of it.

UK manufacturers in the £2m to £50m range typically shortlist Microsoft Dynamics 365 Business Central, Sage 200, Sage X3, Epicor Kinetic or EFACS, with smaller firms often running cloud MRP such as MRPeasy instead of a full ERP. Alongside that sit CAD and CAM tools, a quality system, and a stock module that may or may not talk to finance.

The licence is the visible cost and rarely the real one. Business Central Premium lists at £84.60 per full user per month, so fifteen users is around £15,000 a year before anyone has implemented anything. Partner estimates put a typical manufacturing SME implementation at £30,000 to £120,000 and upwards once migration, integrations, report rebuilding and training are counted.

Many of these systems still run on-premises or hosted with a SQL database behind them, which puts server management, transaction log backups, session stability and patch discipline in the IT provider’s domain.

Two failure patterns come up repeatedly:

  • The first is a database backup nobody has ever tested, which tends to be discovered at the worst possible moment.
  • The second is degraded performance on a terminal server or VPN that gets reported as “the ERP is slow”, sends everyone down a support route with the software vendor, and turns out to be a network or virtualisation problem all along.

Our guide to server virtualisation covers some of that ground, and where a real gap exists between systems, our bespoke application development team can build the integration rather than leaving someone re-keying between two screens.

Funding: Made Smarter and what it will pay for

Manufacturers across the West Midlands and Staffordshire can access Made Smarter Adoption, and a surprising number of local firms have never heard of it.

It combines fully funded digital transformation advice with match funding of up to £20,000, at 50%, towards eligible technology.

The delivery area covers Birmingham, Dudley, Sandwell, Walsall, Wolverhampton, Coventry, Solihull, Staffordshire, Stoke-on-Trent and Shropshire, delivered with WMG at Warwick and the Manufacturing Technology Centre. Eligibility is a manufacturing or engineering SME with 249 employees or fewer, turnover under £36m and a manufacturing premises in the region.

It funds industrial digital technology rather than IT generally. Eligible projects include:

  • ERP, MRP and MES systems, and production planning
  • Digital quality management and traceability
  • Connected machinery, sensors and production data dashboards
  • Automation, robotics and cobots
  • CAD and CAM integration and digital engineering workflows
  • The specialist implementation, integration and training tied to the funded technology

Cyber security qualifies where it forms part of a wider digital adoption project, rather than as a certification exercise on its own.

What it will not fund is routine IT: replacement laptops, standard Microsoft 365 licences with no transformation case, ordinary support contracts, and anything ordered before the grant is approved. That last one catches people out, so apply before you buy.

What downtime actually costs

Research published by IDS-INDATA in January 2026 put the annual cost of unplanned downtime across UK and European manufacturing at £124bn to £157bn, with cost per hour ranging from around £12,000 to £30,000 in food processing and packaging up to £1.6m to £2.0m in automotive.

The causes they identify are equipment failure, control system and software issues, outages and connectivity disruption, and IT/OT complexity. Three of those four sit in IT’s domain.

This is the argument for proactive monitoring rather than a contract that starts when you ring.

A failing disk in the ERP server, a switch running hot, a backup silently failing for eleven days: all detectable in advance, all cheaper to fix on a Tuesday than at 6am on Monday when the first shift cannot log in.

The difference is set out in our article on proactive versus reactive IT support.

Connectivity, the shop floor and multiple sites

Factory environments are hostile to networking in ways offices are not. Steel structures and racking block signal, dust and coolant kill unprotected equipment, and a mezzanine office often ends up connected by whatever cable was nearest at the time.

Getting this right means proper cabling and network design rather than extending the office WiFi and hoping, plus WiFi surveyed for the racking layout as it actually is.

Handheld scanners need coverage in the aisles, not at the door.

If your ERP is cloud-hosted, or you file dispatch notes and customs paperwork online, your broadband is production equipment. A leased line with a guaranteed fix time, or at minimum a business connection with 4G or 5G failover, is the difference between a wobble and a stoppage.

Multi-site manufacturers also need sites linked properly with consistent security policy, so a unit acquired three years ago is not still an unmanaged island.

IT support for manufacturers in Birmingham and the West Midlands

Manufacturing remains central to this region’s economy. Make UK’s 2025 regional outlook puts the sector at 279,000 jobs, 9% of the West Midlands workforce and 13.9% of output. Around Computercentric it is denser still: manufacturing accounted for 15.6% of employment in South Staffordshire in 2022 and generated 27.1% of local GVA.

The local base is a practical engineering economy rather than a collection of household names.

From Aldridge and Darlaston through Bloxwich, Wolverhampton, Sandwell and Dudley, it is fabricated metals, machining, tooling, castings, fasteners, plastics and construction products.

The Black Country Enterprise Zone covers 120 hectares across Wolverhampton North, Darlaston and DY5 in Dudley. Just beyond Wolverhampton, i54 South Staffordshire and Four Ashes bring together JLR’s engine plant, Moog Aerospace and Gestamp in one corridor.

Most firms in that supply chain are small or medium-sized, with one production site, a lean management team and limited in-house IT. Make UK notes that businesses under 250 employees account for 99% of the region’s manufacturing business population.

Computercentric is based in Aldridge, near Walsall, in the middle of it. Most support runs remotely, and when a site needs an engineer for cabling, a WiFi survey, a network fault or a machine move, we attend without the travel surcharges that come with providers based further out.

Vesta Space shows the shape of the work. We have supported this Aldridge furniture manufacturer since it started in 2017, covering IT support, hosted telephony, connectivity, Microsoft 365, anti-ransomware protection, a managed firewall with backup, and the physical network and WiFi across their site.

We provide IT support for manufacturing companies in Birmingham, Walsall, Wolverhampton, Aldridge, Sutton Coldfield, Lichfield and Bournville.

Frequently asked questions about IT support for manufacturing

What does IT support for a manufacturing business include?

Beyond standard helpdesk and Microsoft 365 management, manufacturing IT support should cover your ERP or MRP system, network segmentation between production and office systems, security for connected machines and controllers, backup that includes production data and machine programs, resilient connectivity across the site, and Cyber Essentials support.

The distinguishing feature is that it deals with the shop floor, not just the offices.

How much does IT support cost for a manufacturer?

UK benchmarks put basic reactive support at £30 to £50 per user per month, proactive managed services at £50 to £80, and a security-led service with stronger EDR, email security and documented recovery at £80 to £120. Shift-based or multi-site manufacturers needing genuine 24-hour cover sit above that.

Manufacturing usually needs a hybrid model rather than pure per-user pricing, because shared shop floor terminals, on-premise ERP servers and factory firewalls are charged per device, per server and per site. Out-of-hours cover is normally a separate line.

Can you support our ERP or MRP system?

We support the environment your ERP runs in: servers, databases, backups, connectivity, terminal or remote access, Microsoft 365 integration and user permissions. That covers the majority of what goes wrong with Business Central, Sage 200, Epicor and similar systems.

When a fault genuinely sits inside the application, we deal with the software vendor directly rather than leaving your production manager running two support conversations at once.

We have machines running old operating systems. What can we do?

Isolate rather than replace. A controller on an unsupported operating system can be managed safely on its own network segment with strict controls on what it reaches and what reaches it, no internet route, and vendor access granted when needed rather than left open.

You are not unusual here. Research suggests 86% of manufacturers run core functions on outdated systems, but fewer than half have segmentation in place. The gap between those two figures is where the risk sits.

Do manufacturers need Cyber Essentials?

It depends on who you supply. In defence and aerospace it is often contractual: BAE Systems requires a valid Cyber Essentials certificate before contracting, and Defence Standard 05-138 requires Cyber Essentials Plus at low risk level.

In automotive there is no published universal mandate, so the requirement comes from your specific customer contract and the data you handle. Either way, the five controls prevent most common attacks, so certification tends to close real gaps rather than just producing a certificate.

Is there funding available for manufacturing technology?

Yes. Made Smarter Adoption offers eligible manufacturing and engineering SMEs across the West Midlands and Staffordshire fully funded digital transformation advice plus up to £20,000 in match funding towards industrial digital technology, including ERP, production data systems, automation and connected equipment.

It will not fund routine IT or anything purchased before approval, so apply before you order.

How do we protect ourselves against a supply chain attack?

You cannot stop a customer being attacked, so the aim is limiting what it does to you. Know which systems depend on external portals and connections, have a way to keep operating and recording work if a customer’s ordering system disappears for a fortnight, keep your own data recoverable independently, and review what access your suppliers and vendors hold to your network.

The JLR incident hurt suppliers who had done nothing wrong, mostly through frozen systems and cash flow rather than breaches of their own.

Can you support shift patterns and out-of-hours production?

Yes, and the detail matters more than the headline. A contract that says “24/7 support available” is worth little unless it defines what counts as a production-impacting P1 incident, whether that includes ERP unavailable, network down, despatch stopped or printing stopped, what the response target actually means, and which systems are excluded.

We scope support hours around your production calendar, including early starts, weekend running and shutdown windows for infrastructure changes. Monitoring runs continuously regardless of hours.

Talk to us about IT support for your manufacturing business

If nobody can tell you exactly what is connected to your production network, if your backup covers email but not machine programs, or if a customer has just sent a security questionnaire you cannot honestly complete, those are normal findings. They are what happens when the factory grows faster than the documentation, and they are fixable for less than one shift of unplanned downtime costs.

Start with a review. We will look at your network, your production and office systems, your backup position and your security posture, and give you a straight assessment of the gaps and what closing them costs.

Call us on 01922 830000 or contact us online. You can also see the other sectors we support, or read how to reduce IT costs if budget pressure is what is prompting the conversation.

Join our mailing list

If you’d like to receive useful information, news and advice to help you stay smart and ahead of the game when it comes to IT in business, then let us know below!  We won’t spam you, and you can opt-out any time.

Latest from Instagram