M&S Cyber Incident: A Wake-Up Call for British Businesses

April 28, 2025

The Impact of a Major Retail Security Breach

The recent cyber incident at Marks & Spencer has sent shockwaves through the British retail sector.

The high street stalwart has been forced to take significant reactive measures, including:

  • Taking critical systems offline
  • Suspending Click & Collect orders until further notice
  • Disabling contactless payments across their 1,000+ UK stores
  • Warning customers of potential delays to home deliveries

While M&S hasn't explicitly confirmed whether ransomware is involved in this incident, their public statements contain telling details. The retailer's announcement that they needed to "move processes offline to protect colleagues, partners, suppliers, and business" is consistent with standard ransomware response protocols and highlights the devastating impact such security breaches can have on operations and customer experience.


What We Know So Far

The incident began last weekend, with M&S taking the commendable approach of providing regular updates to customers via their website and social media channels. Their communication strategy has been praised for its transparency, with the company acknowledging the challenges while reassuring customers that in-store operations continue, albeit with limitations.

The fact that contactless payments specifically have been affected is particularly noteworthy. This suggests the incident may have compromised or forced the shutdown of payment processing systems, while chip and PIN transactions appear to remain functional.


The Broader Context for UK Businesses

This incident does not exist in isolation. Recent data suggests cybercriminals are targeting UK organisations at an unprecedented rate. The retail sector, with its vast customer databases and complex payment systems, presents a particularly attractive target for malicious actors.


Proactive Security in an Era of Escalating Threats

At AltiaCyber, we've been helping organisations secure their digital future since 2013, and incidents like the one affecting M&S reinforce what we've long advocated: a comprehensive cybersecurity strategy is no longer optional for businesses of any size.

The complexity of modern IT environments—spanning on-premises infrastructure, multiple cloud providers, and countless endpoints—demands robust security frameworks built on several key principles:

1. Zero Trust Architecture

Traditional security perimeters are no longer sufficient. Zero Trust principles assume no user or system is trustworthy by default, requiring continuous verification regardless of location or network connection.

2. Comprehensive Threat Detection

Modern security solutions must provide visibility across your entire digital estate, detecting anomalous behaviour and potential threats before they escalate into major incidents.

3. Incident Response Readiness

As the M&S incident demonstrates, how an organisation responds to a security breach can significantly impact business continuity. Having tested incident response plans in place is crucial.

4. Regular Security Assessments

Identifying vulnerabilities before they can be exploited requires ongoing assessment of your security posture against evolving threats and attack vectors.


Learning from Others' Experiences

While details of the M&S incident continue to emerge, several lessons are already apparent:

  1. Digital dependencies are business-critical: The disruption to contactless payments and online order fulfillment demonstrates how deeply digital capabilities are embedded in modern retail operations.
  2. Transparent communication is essential: M&S's approach to customer communications during this incident has been widely praised, highlighting the importance of honest, regular updates during a crisis.
  3. Offline fallbacks remain valuable: The ability to continue operations, albeit in a limited capacity, by reverting to offline processes demonstrates the importance of maintaining business continuity plans.


Protecting Your Business

With cybercriminals increasingly targeting UK businesses at unprecedented rates, organisations must ask themselves: can we afford to wait until our systems are compromised?

At AltiaCyber, we implement robust security solutions built on Zero Trust principles, protecting businesses from evolving threats that can disrupt operations and damage customer trust. Our methodical approach helps businesses identify vulnerabilities and strengthen their security posture before they become headlines.


Take Action Today

Don't wait for a cyber incident to expose vulnerabilities in your security posture. Our team of cybersecurity experts can help you assess your current defences and develop a roadmap for strengthening your protection against emerging threats.

Book a complimentary 20-minute cybersecurity assessment call with our security experts. Email cyber@altia.tech to secure your slot.

July 24, 2025
New sophisticated phishing campaign uses legitimate Microsoft infrastructure to bypass traditional security controls
July 22, 2025
Microsoft warns of active exploitation as attackers bypass MFA and steal cryptographic keys from on-premises SharePoint servers
July 16, 2025
The latest Cyber Security Breaches Survey 2025, published by the Department for Science, Innovation and Technology and the Home Office, provides crucial insights into the current state of cyber security across UK businesses and charities. The findings reveal both progress and persistent challenges in the cyber security landscape.
July 15, 2025
In a sophisticated cyber operation dubbed "RedDirection," security researchers have uncovered one of the largest browser hijacking campaigns to date. Over 2.3 million Chrome and Edge users fell victim to malicious code hidden within seemingly innocent browser extensions – tools they trusted and used daily for productivity and entertainment.
July 9, 2025
The recent Qantas data breach affecting 5.7 million customers highlights critical cybersecurity vulnerabilities that could impact any organisation
By fahd.zafar July 2, 2025
New research reveals that over 25% of UK buildings have been cyber-attacked in the past year – and the threat is growing exponentially
By fahd.zafar June 24, 2025
The average employee manages over 80 passwords for work applications. Is it any wonder that "Password123!" remains one of the most common corporate passwords? Latest guidance on password managers and passkeys offer a timely reminder that the technology to solve our authentication challenges already exists – we just need to trust it.
By fahd.zafar June 20, 2025
The genetic testing company 23andMe has been handed a £2.31 million fine by the UK's Information Commissioner's Office (ICO) following a devastating data breach that exposed the personal information of seven million people worldwide. For cybersecurity professionals, this case offers sobering lessons about the catastrophic consequences of inadequate security practices.
By fahd.zafar June 18, 2025
Discover why sustainable cyber security depends on organisational culture, not just technology. Learn how to build security-minded cultures that empower people and reduce risk
May 7, 2025
The recent cyber attack on Co-op stores serves as a stark reminder of how digital disruptions can quickly cascade into real-world consequences. With stores facing empty shelves, payment system failures, and compromised customer data, this incident highlights the critical importance of robust cybersecurity measures for all businesses, regardless of industry.