@ra6bit You should report it even if you think it'll have no effect. Worst case scenario is they don't do anything about it but at least there's now a datapoint. Best case scenario is they do something about it. But if you don't report it, it becomes a self-fulfilling prophecy and nothing will ever get done.
Plus they do seem to care about tracking. See:
For those who haven't been following JLR in detail, key chain of events:
1) JLR outsource key IT and infosec functions to TCS, approved by 1x director and 2x NEDs on both JLR and TCS boards
2) JLR transfer staff by TUPE to TCS
3) TCS lay off transferred UK staff, including cyber risk and governance and cyber monitoring
4) record profits for a decade
5) got hacked
6) company stops functioning
7) get government to bail out their key suppliers (in progress)