X
Phone and laptop in modern office
News
News

Get help with cybersecurity

I

A Shock Call for UK Retail: Cyberattacks on the Rise

05 May 2025

 

Cyberattacks are on the up. Over the past few weeks, the UK retail sector has faced a disturbing trend: a series of damaging cybersecurity breaches affecting major high street names – Marks & Spencer, The Co-Op, and most recently, Harrods. According to reporting by The Register, this pattern points toward a potentially coordinated cyber assault targeting British retail giants. The fallout has been significant. For M&S, the breach reportedly disrupted major parts of their operations – from online shopping platforms to even contactless payments in-store. The full financial cost remains unknown, but it’s safe to say the damage runs well into the millions.

This wave of attacks serves as a stark reminder that cybersecurity is not just an IT concern – it’s a business continuity issue. It affects your brand, your operations, and your customers. But it also raises a few pressing questions: Why are these attacks happening? How are the attackers getting in? And what can businesses do to protect themselves? And even at a SME level, if you’re thinking it doesn’t really matter as you’re too small to be a problem, imagine what 2 weeks lost revenue in the height of your season will do to you.

The Motivation Behind Cyberattacks

When people hear about cybersecurity breaches, the first question that often arises is: What’s in it for the attacker? There’s no one-size-fits-all answer. In some high-profile cases, the motive may be terrorism or state-sponsored disruption. Crippling another country’s banking system, communications infrastructure, or defense capabilities can be an act of cyber warfare – a modern battlefield tactic.

However, most attacks on commercial entities are financially motivated. One of the most common methods is ransomware – where attackers encrypt a business’s data or shut down key systems, and then demand a payment in exchange for unlocking them. For organisations like M&S or Harrods, every minute of downtime can translate into lost revenue, customer dissatisfaction, and reputational harm – making them prime targets. Then, there’s also the “script kiddie” category – less skilled individuals using pre-written code to exploit known vulnerabilities. While their tools may be less sophisticated, the damage can still be significant, especially if they stumble upon poorly secured systems.

How Attackers Breach Systems

Understanding how these attacks occur is key to building better defenses. Most cyber intrusions exploit basic vulnerabilities:

  • Unpatched Systems: Many businesses run outdated software or fail to install security patches promptly. Attackers exploit known bugs that could have been easily fixed.
  • Default Passwords and Weak Credentials: It’s shocking how many systems are still protected with “admin/admin” or similarly weak combinations. Attackers use automated tools to find and break into such accounts.
  • Phishing Attacks: Employees are often the weakest link. A convincing phishing email can trick someone into handing over credentials or clicking a malicious link that installs malware.
  • Zero-Day Exploits: These are vulnerabilities that have only just been discovered and have no available fix yet. Hackers can take advantage of these gaps in the window before vendors release a patch.

As for the recent UK retail breaches, the exact point of entry hasn’t been made public. But whether it was a phishing email, a legacy application vulnerability, or a compromised third-party vendor, it highlights just how complex and fragile modern digital systems can be.

Balancing Cybersecurity with Usability

Implementing cybersecurity controls isn’t just about piling on every security measure available – it’s about making smart choices that don’t paralyze the organisation. Take Multi-Factor Authentication (MFA), for example. While it’s one of the most effective tools for preventing unauthorized access, applying it too aggressively (e.g., requiring it for every single document access) can grind productivity to a halt. It’s all about balance. Businesses need to assess their risk exposure and tailor their controls accordingly. That means using frameworks like those published by the National Cyber Security Centre (NCSC), and adapting them in a way that fits the organisation’s size, industry, and operating style.

There’s a well-known quote from cybersecurity expert Gene Spafford that sums this up perfectly: “The only truly secure system is one that is powered off, cast in a block of concrete, and sealed in a lead-lined room with armed guards – and even then, I have my doubts.” This quote highlights a crucial truth: no system connected to the outside world is 100% secure. Risk is always present – the goal has to be to manage it, not eliminate it entirely.

Planning for the Worst

If the worst does happen – and in today’s climate, it’s a matter of when, not if – your response can be the difference between a temporary setback and a full-blown crisis. That’s why incident response planning is essential. It’s not enough to hope your defenses hold; you must have contingency plans for when they don’t.

Key steps include:

  • User Education: Phishing attacks rely on your users doing things – giving away password, access, etc. Educating them to better understand how to avoid them is a key part of your mitigation strategy.
  • Regular Backups: Maintain secure, encrypted backups of critical data and systems. Test them regularly to ensure they can be restored in an emergency.
  • Disaster Recovery Plans: Know exactly what steps to take to resume operations. This includes fallback systems, manual processes, and clear lines of communication.
  • Business Continuity Plans: Go beyond IT. Think about how to maintain customer service, supply chain operations, and financial systems in the event of a major disruption.

By having robust plans in place, businesses can turn a potential disaster into a manageable situation.

The Legacy Systems Debate

Looking ahead, one of the biggest cybersecurity challenges many organisations face lies not in new technologies, but in legacy systems. These are the mainframes and software platforms – often written in COBOL – that power sectors like banking, insurance, and large retail chains. Despite their age, these systems are remarkably stable. In fact, one study estimates that 43% of international banking systems still run on COBOL. But there’s a problem: the number of developers with the skills to maintain these systems is shrinking fast. As these systems age, they become harder to secure and even harder to modernize. So, what’s the solution? Should businesses overhaul these systems entirely, at great cost and risk? Or continue to patch and maintain them with dwindling expertise? There’s no simple answer, but it’s a conversation that every organisation still relying on legacy infrastructure must begin now.

Final Thoughts: It’s Time to Take Cyber Risk Seriously

Cybersecurity can no longer be treated as an afterthought – and that includes SMEs too. The recent breaches at M&S, The Co-Op, and Harrods show just how disruptive and costly an attack can be. And plenty of SMEs are getting hit, they just don’t get reported in the media. Whether it’s ransomware, phishing, or a zero-day exploit, businesses must treat cyber resilience as a strategic priority. If you’re unsure how your systems would hold up under attack – or what steps you’d take if your operations went offline – now is the time to ask those questions. Because by the time you need a plan, it’s already too late.

If you’d like us to look at your organisation’s preparedness and help you build a cyber-resilient future, get in touch today.