28/04/2025
In April 2025, Marks & Spencer (M&S), a prominent British retailer, experienced a significant cyberattack that disrupted its operations. The incident affected contactless payments, click-and-collect services, and led to the suspension of online orders in the UK and Ireland. While M&S assured customers that their data remained secure, the breach highlighted vulnerabilities in retail cybersecurity infrastructures.
Incident overview
The Marks & Spencer cybersecurity breach commenced over the Easter weekend, causing widespread service disruptions. M&S had to temporarily shut down its website and app, and some operations were moved offline to mitigate the effects. The company engaged the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to investigate the breach, suspecting potential foreign involvement.
Preventative measures and best practices
While M&S acted swiftly to address the breach, the incident underscores the importance of proactive cybersecurity measures. IT services companies can glean the following lessons
- Regular security audits: Conduct comprehensive assessments to identify and rectify vulnerabilities in systems and networks.
- Employee training: Implement ongoing cybersecurity awareness programs to educate staff about potential threats and safe practices.
- Multi-factor authentication (MFA): Enforce MFA across all access points to add an extra layer of security against unauthorised access.
- Incident response planning: Develop and regularly update a robust incident response plan to ensure swift action in the event of a breach.
- Third-party risk management: Vet and monitor third-party vendors to ensure they adhere to stringent cybersecurity standards.
- Data encryption: Ensure sensitive data is encrypted both at rest and in transit to protect against data breaches.
The Marks & Spencer cybersecurity breach serves as a stark reminder of the evolving threats facing the retail sector. By adopting comprehensive cybersecurity strategies and fostering a culture of vigilance, businesses can better protect themselves and their customers from potential violations.
Don’t wait for an incident to expose your vulnerabilities. Our expert IT services team specialises in proactive cybersecurity strategies, tailored to your business needs. Get in touch today and start a conversation to secure your business.