As cyberattacks grow more disruptive and interconnected supply chains amplify their impact, organisations must rethink how they manage risk and resilience. Raghu Nandakumara explores whether government intervention is sustainable and why containment, visibility and control are now critical to limiting damage and protecting economic stability.

Following the cyber incident that disrupted Jaguar Land Rover and reverberated across its supply chain, the UK government stepped in to stabilise affected businesses with a £1.5 billion loan guarantee.
But are such bailouts sustainable in the face of rising cyberthreats? Raghu Nandakumara discusses the potential consequences of intervention and what organisations should be focusing on to improve their resilience.
Has the UK crossed a line by intervening in a major cyber incident or was it unavoidable?
I don’t see the intervention as crossing a line. It was an unavoidable move, made necessary by how deeply interconnected our economy has become. That £1.5 billion was not really a bailout of Jaguar Land Rover itself, but of the thousands of upstream suppliers who rely on its business to stay afloat.
It has a lot in common with the financial crash of 2008, when governments intervened to prevent a systemic collapse. The phrase ‘too big to fail’ sums up that crisis.
Now the issue is that some organisations are ‘too interconnected to fail’. A major cyber incident does not stay contained. It can quickly ripple out to impact regional employment, economic stability and public confidence.
The harder question is what happens next time. We cannot assume public money will always be there. At some stage, there must be a clearer view on when the government steps in and when it does not. Given how frequently these attacks are occurring, we may need those answers sooner than we think.
Why is attack disruption outweighing extortion and how does that change the risk landscape?
Attackers are focusing on disruption because it causes far more damage than ransom ever could. The profits from ransomware are limited, but the economic fallout from a major incident is significant. The JLR incident alone cost far more than the total ransom revenue typically generated in a year, so the incentive has shifted. If attackers can grind a company or an entire supply chain to a halt, they can have a much greater impact.
These outcomes are particularly attractive to nation-state actors, who are motivated more by economic and political destabilisation than profit.
We are also seeing fewer opportunistic ‘spray and pray’ attacks and more targeted efforts against organisations at the centre of complex supply chains.
This significantly changes the risk landscape. Cyber-risk is no longer just about data loss or ransom payments. It is now a question of economic resilience and national stability.
If another bailout becomes necessary, what happens next?
It is a matter of when, not if, we see another cyberattack on the scale of JLR. If another bailout is required, it is likely to come with far stricter conditions.
The Treasury does not have unlimited resources and stepping in once risks setting a precedent that it will intervene repeatedly. That is not sustainable if incidents become more frequent and more disruptive.
This is likely to prompt a rethink of the obligations placed on organisations affected by cyberattacks, particularly those at the centre of major supply chains. We may see more prescriptive guidelines on liability for downstream impacts and clearer frameworks for managing losses across suppliers, contractors and local economies.
For the government, the goal will be to reduce uncertainty and avoid a situation where public funds repeatedly absorb private-sector risk. In practice, this means tighter expectations around incident reporting, clearer accountability across supply chains and higher standards of resilience.
If a cyberattack on one organisation can trigger national consequences, it is reasonable to expect a higher level of preparedness and transparency.
So, if prevention cannot be guaranteed, what should organisations focus on instead?
It is impossible to prevent every attack in highly interconnected environments, so the focus must shift to containment. The real test is not whether an attacker gains access, but how quickly the damage can be limited.
What matters now is reducing disruption. How long were operations affected? How much financial loss occurred? How many suppliers and customers were impacted? Keeping these impacts to a minimum is how success will be judged by ministers, boards and the public.
Containment determines whether an incident remains localised or spreads across operations, suppliers and regions. This depends on two key factors. First, organisations must be able to detect threats early, which requires strong visibility across networks, systems and dependencies.
Second, organisations need the controls to prevent attacks spreading, using approaches such as segmentation and Zero Trust.
Those that can limit lateral movement, protect critical services and contain disruption are best positioned to withstand modern cyberthreats and avoid the need for government intervention.


