Site navigation

How Have Cyber Experts Reacted to the M&S ‘Incident’?

Tom Quinn

,

M&S cyber incident
While Marks and Spencer’s wades through the fallout of a recent cyber incident, DIGIT has a round-up of the cyber-sector reaction to events so far.

Marks and Spencer has been praised for its ‘refreshing’ approach to dealing with a recent cyber-incident, with several figures from the cybersecurity industry pointing to the retailer’s transparency, swift communication, and proactive engagement with authorities and experts as a model response.

News broke yesterday that the high-street veteran had been hit by a cyber incident in recent days, prompting ‘minor, temporary changes’ to its store operations, with reports from customers over the weekend that contactless payment issues and order delays were causing long queues in some stores. 

Before news of the cyber incident could break of its own accord, however, M&S chief executive Stuart Machin took to social media to reassure customers that the situation was under control, with external cybersecurity experts brought in to support the investigation.

The lack of defensiveness, legalese, and the conciseness of M&S’s messaging surrounding the event has been applauded by security experts in the hours since, with comments on social media suggesting the chain’s upfront approach was a breath of fresh air.

“Great communication from Marks and Spencer, clear, concise, factual and owning it,” said Jude McCorry, CEO at the Cyber and Fraud Centre.

“They are the victims – no one knows what really happens, and hopefully, because they have been great at communicating so far, they might let us know what really happened so others can learn.”

Other high-profile figures in the security sector agreed, such as Santander’s global head of cybersecurity research, Daniel Cuthbert, who commented: “It is very refreshing to see a company taking an approach like this. Not trying to hide the breach or hide behind strong legal/PR massage messages.”

While M&S continues to manage the aftermath of the incident, and has yet to disclose specific details about what occurred, there was broad agreement among cybersecurity professionals that the company has handled the situation well so far.

“Some text book cyber crisis communications from Stuart Machin and the Marks and Spencer team,” said William Dixon, a cybersecurity expert with the Royal United Services Institute and former head for cybersecurity at the World Economic Forum, as well as head of intelligence with Barclays’ Chief Security Office.

Dixon went further, saying that M&S have taken ownership of the situation, displaying empathy and responsibility, being transparent with customers with known facts but avoiding speculation in a way that reassures without causing more alarm about the unknown.

Similar sentiments were spread across social media, with some taking Marks and Spencer’s handling of the episode as a potential blueprint in how firms could respond to similar events in future.

“Rather than focusing solely on the disruption, security professionals should view the M&S incident as a case study in incident response, communication strategy, and system architecture,” said Crystal David, a senior consultant with Deloitte’s Cyber Risk Advisory in South Africa.

Laying out the situation through a cybersecurity lens, David praised M&S’s granular control over its systems, saying this had allowed the company to make ‘selective operational adjustments’ and minimise impact to customers, while effective segmentation of its architecture meant that while contactless payment might have gone down, the store’s website and app remained operational.

Likewise, others applauded the company for its past prioritisation of its network and systems, something which may have mitigated the effect of current events.

“While we don’t yet have the full details of the M&S cyber incident, the company’s dedication to protecting the network highlights the critical importance of a modern network security strategy,” said Jamie Moles, Senior Technical Manager at ExtraHop.

“Incidents like this demonstrate how essential it is to have real-time visibility, threat detection and rapid response capabilities across all digital infrastructure. Network visibility can play a pivotal role, helping organisations detect anomalies early, isolate potential threats and maintain service continuity.”


Recommended reading


It wasn’t all admiration, however, with some cyber professionals voicing concerns over M&S’s speed to confirm the incident and the choice to so far leave lingering questions over the extent of the breach.

“This is a we had to tell you not we wanted to and is being driven by PR and damage limitation,” said Justin Bentley, cybersecurity manager with software firm DAI.

“It doesn’t tell us anything about the content, systems and the impact as to what went on and how it will affect us, their customers.”

A raft of other comments across social media asked how customers can know whether their data is safe, how effective it was to leave front-line staff to initially deal with issues at the tills before sending out an alert, and if expectations could have been managed more effectively once the message went out.  

Marks and Spencer’s has promised to update once more becomes clear, especially if it finds evidence of sensitive data being compromised, but the episode does raise some questions for other high-street retailers security considerations.

“It’s a great example of how to be calm and sincere in a crisis,” said Steve Holloway, fractional chief technology officer with Kyloe Partners.

“But I do wonder how much their IT budget has been impacted over the last few years, how much they’ve invested in cyber and how much tech debt they’re carrying. 

“Bricks and mortar retailers often don’t prioritise tech investment as they should. It’s all good to apologise and empathise, but a lot of cyber incidents could be avoided if the risk were managed effectively and funded accordingly.”

Given the generally positive reaction from both customers and cybersecurity veterans, many more retailers might now be dusting off their cyber response plans to take a leaf from the M&S catalogue. 

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data