Marks & Spencer is still in ‘rebuild mode’ following the major cyber-attack that rocked the British high-street stalwart earlier this year, and will be for months to come, according to the retailer’s chairman, Archie Norman.
Speaking to MPs, Norman described the breach as an ‘out of body experience’, and said that it felt as if the hackers were ‘trying to destroy’ the business, adding “It is not an overstatement to describe [the attack] as traumatic.”
Dodging questions about ransom demands and communications with the hackers, Norman told the parliament’s business and trade subcommittee on economic security, arms and export controls, that investigations have pointed to the threat group DragonForce, whose motives were “undoubtedly, ransom or extortion”.
However, Norman told MPs that M&S had lost roughly £10 million in profit for every week it wasn’t able to trade online. That has resulted in £300 million less profit as a direct consequence of the incident, though the retailer is expected to claim more than a third back in insurance to offset some of this loss.
The chairman was adamant that Marks & Spencer’s had not ‘left the back door open’, having trebled the number of cyber staff and doubled security spending over the last few years, but acknowledged the global nature of the business had left it vulnerable to attack.
“Businesses such as ours have a vulnerability, which is that we have a very wide attack surface,” said Norman.
“We have 50,000 people working on our systems – colleagues in the stores; contractors working for us, some may be outsourced, some may be in India, so the attack surface is enormous and the attacker, potentially, has only to be lucky once, with one of those 50,000.
“In our case, the initial entry, on 17 April, occurred through what people now call social engineering… Part of the point of entry in our case also involved a third party. That is just a reminder that the attack surface is very hard to defend.”
M&S’ reliance on legacy technology was also a chink in the stores armour, said Norman, with the hybrid of old and new systems making it difficult to compartmentalise, and easier for attackers to move laterally. That complexity ultimately forced the company to take a large chunk of its systems offline.
“Ideally, you would have all your systems in order, but it is not possible as a retailer to have completely watertight compartments,” said the chairman.
Recommended reading
- Inside the Aftermath: What Really Happens When You Get Hacked
- M&S Targets August for Full Online Recovery
- Comment | Inside the Ongoing M&S Ransomware Crisis
Norman also said that while M&S had moved quickly to report the breach to the National Cyber Security Centre (NCSC), he claimed it had since become apparent that ‘quite a large number of serious cyber-attacks never get reported.’
The chairman said that he had ‘reason to believe’ that there have been two major cyber-attacks on large British companies in the last four months, both of which have gone unreported.
“We think that that is a big deficit in our knowledge as to what is happening,” said Norman.
“I don’t think it would be regulatory overkill to say that if you have a material attack…on a company of a certain size, you are required, within a time limit, to report it to the NCSC. That would enhance the central intelligence body in this area.
“It is not that there is nothing that government can do, that’s for sure.”
While current rules mean that firms must notify the Information Commissioner’s Office of any incident that has a substantial impact on the provision of services no later than 72 hours of becoming aware, there is currently no regulatory requirement to inform the NCSC of a breach.





