Cyber Security

Cyber crises are now an EHS readiness issue

By Steph Miller-Harris, Incident & Crisis Management Solutions Specialist, EcoOnline

Over recent years, the conversation about workplace risk has been shaped by a familiar cast of hazards: slips and falls, chemical exposure, lone workers in isolated environments, and the toll of occupational stress. These are the threats that built the EHS (environment, health, and safety) profession, and rightly so, as they still unnecessarily claim lives and livelihoods every year. 

But when more than 1,300 UK workers were asked to identify the greatest threat to their organisation’s operational continuity, the top answer was not a serious workplace injury. Nor was it fire, a physical security breach, or an environmental incident. 42% pointed to a cyberattack or data breach, putting it above every traditional safety hazard on the list – driven not by fear of an attack happening, but by fear of the disruption it would cause. The finding comes from EcoOnline’s 2026 Workplace Safety Report, which surveyed over 5,900 workers across North America, the Nordics, and the UK and Ireland.  

You can see why. In autumn 2025, a cyberattack halted Jaguar Land Rover’s UK production for around five weeks. Machinery hadn’t broken; the digital systems running it had been pulled offline, which was enough to bring everything to a stop. Something in a server room emptied the factory floor, and for the thousands of workers and suppliers in the supply chain, it didn’t matter whether it was a cyber problem or a physical one – it was both. And JLR wasn’t an outlier. In fact, manufacturing was the most-targeted sector for cyberattacks in 2025 and cyberattacks with physical consequences rose 146% in a year.  

On its own, this might be read as part of a wider cultural anxiety about digital security. But the pattern holds everywhere. Workers ranking cyber incidents as the threat they worry about the most is a readiness question rather than a prevention one, and it changes what organisations need to plan for.  

The limits of siloed thinking 

Health and safety has historically defined itself by the physical hazards it manages. These remain critically important: 44% of UK workers handle chemicals at work, nearly a third of lone workers experienced an accident while working alone in 2025, and stress continues to drive the majority of work-related illness.  

None of that is going away; what is changing is where the boundaries of risk sit. 

A cyberattack does not limit its consequences to the server room. When plant management systems go offline, workers operating machinery lose the digital oversight that helps keep them safe. When vehicle navigation and tracking systems are compromised, drivers and dispatchers lose the visibility needed to manage journeys, deliveries and lone workers. When phone systems or internal communications networks fail, teams can struggle to share urgent instructions, escalate incidents and confirm that people are safe and accounted for. The attack may begin with data or digital infrastructure, but its consequences can quickly reach people, physical operations, and the surrounding community. 

A preparedness gap that demands attention 

What makes this convergence a matter of urgency is not simply the elevated perception of cyber risk among workers. It is what the data reveals about readiness. 

Among UK and Ireland workers, just 30% said they were aware their employer had a crisis plan and understood it well, the lowest result of any region surveyed. That means seven in ten workers enter each working day without meaningful knowledge of how their organisation would respond to a major operational disruption.  

The organisational picture is no more reassuring. The UK government’s own Cyber Security Breaches Survey found that just a quarter of businesses have a formal incident response plan in place, and that the share of smaller firms with business continuity plans covering cyber risk has fallen. A response plan might not stop an attack from landing but it decides how fast an organisation can get resume normal operation if it does. In the event of an attack, that gap is a structural vulnerability. 

This is, fundamentally, a health and safety issue. Crisis preparedness, business continuity and workforce protection have long sat within the EHS mandate. The emergence of cyber-physical risk does not transfer that responsibility elsewhere. It expands it. 

Preparing for when cyber defences fail 

Cybersecurity strategies understandably focus on keeping attackers out. Organisations invest in technical controls, staff awareness, monitoring, and detection because prevention remains the first line of defence. 

But no organisation can assume every attack will be prevented, especially with AI increasing the scale and sophistication of attacks. 

Once a cyber incident interrupts operations, removes access to trusted information, or creates uncertainty about whether work can continue safely, it becomes more than a technical problem. The organisation must establish what has happened, which people and processes are affected, what can continue, what must stop, and how employees and other stakeholders should be informed. 

That requires a documented and exercised crisis management process bringing together cybersecurity, IT, operations, EHS, communications, HR, legal, and leadership. Roles, escalation thresholds, decision-making authority, alternative communication routes, and contingency processes should all be agreed before an attack occurs. 

Plans must also account for safety-critical dependencies. Can workers still be accounted for? Can teams access essential chemical and safety information? Can high-risk work still be approved? Can remote and lone workers receive instructions? 

Regular exercises help organisations test these assumptions, expose gaps, and build confidence before a real incident places the plan under pressure. 

Coordinating crisis response in real time 

Strong processes come first, but the right technology can help organisations put them into action quickly. 

During a major cyber incident, information may arrive from multiple teams and locations, often incomplete or changing rapidly. Without a clear structure, decisions become fragmented, actions are duplicated, and important updates are lost across emails, messages, and spreadsheets. 

Digital crisis management software gives response teams a shared environment in which to build a common operating picture, record decisions, assign actions, maintain updates, and coordinate communications. 

Its role is not to investigate malware or restore compromised systems. That remains the work of cybersecurity and IT specialists. Its value lies in helping the wider crisis team manage the consequences, keep customers informed, protect workers, safeguard brand and reputation, maintain essential services, and coordinate recovery. 

Some 72% of UK workers said more digital EHS tools would make them feel safer, up from 67% in 2025. But technology earns trust when it strengthens trained people and tested processes, not when it replaces them. 

Recovery also needs to be planned. Restoring a system does not automatically mean operations can resume safely. Organisations need clear restart criteria, confidence that safeguards and information are reliable, and a structured review of what the incident revealed. 

Connected resilience in practice 

Addressing this does not require EHS to become a cybersecurity function. It requires EHS to be part of operational readiness planning, ensuring that incident response and business continuity plans account for the consequences when cyber disruption reaches workers, customers, sites, and physical operations. 

In practice, readiness depends on connecting the people, plans, live information, communications, actions, and decisions that shape an effective response. When a cyberattack affects operations, teams need a shared operational picture showing what is happening, who and what may be exposed, which actions are underway, and where further decisions are required. 

This is also where a connected view across safety and sustainability operations becomes valuable. Visibility into worker status, site conditions, chemical hazards, critical tasks, assets, and environmental controls can help crisis leaders understand how disruption in one system may create risks elsewhere. 

The value is not in any individual capability but in the connection between them: spotting patterns across risk domains that siloed systems miss and coordinating a response before fragmentation makes things worse. With unplanned downtime in manufacturing estimated to cost as much as $260,000 an hour, the cost of fragmented visibility is no longer theoretical. 

A professional mandate that is expanding 

Health and safety professionals have always evolved in response to the risks their organisations face. The expansion of chemical safety regulation, the growth of lone worker protection, the integration of mental health into occupational risk frameworks – each of these represented a broadening of the mandate in response to evidence that the boundaries of harm had shifted. 

The evidence now points somewhere new. Workers already understand that the line between cyber risk and physical safety is not real. The organisations that will manage operational risk most effectively in the years ahead are those whose EHS functions understand it too – and are structured, resourced, and equipped to act on that understanding. The workforce has redefined the risk landscape. The profession’s task now is to meet it there.

Related Articles

Back to top button