Well, what a month! UK retail is under attack with Marks and Spencer (M&S), Co-op and Harrods all suffering attacks. In this month's edition we look at:

In April 2025, UK retailers Marks & Spencer (M&S) and Co-op and followed by Harrods in early May experienced significant cyberattacks, disrupting operations and exposing vulnerabilities in their cybersecurity frameworks. All three cases have been claimed by the Scattered Spiders group deploying DragonForce ransomware. Hackers impersonated employees to deceive IT help desks into resetting passwords, granting unauthorised access to internal networks.
These attacks underscore the importance of robust cybersecurity frameworks, including adherence to standards like ISO 27001. The incidents reveal how social engineering tactics can bypass technical defences, emphasising the need for comprehensive security awareness and training. An appropriately designed scope of ISO 27001 and continued adherence to the cyber security controls will provide sufficient protection to make the hackers go elsewhere.
In the 2025 CISCO Cybersecurity Readiness Index (UK) it says only 4% of UK businesses reached the mature stage of readiness and alarmingly 70% are in the beginner (9%) and formative (61%) stages.
What does this say about all three companies attitude to cyber security? My opinion is that none of the companies are demonstrating to the public they had taken cyber threats seriously and probably had not invested sufficiently to prevent attacks. However, they are similar to most companies.
DM me with the word retail to discuss your cyber risks.
The British Library suffered a ransomware attack in 2023. NHS services, provided by Synnovis the supplier of pathology systems to Guy’s & St Thomas’ NHS Foundation Trust and King’s College NHS Foundation Trust, experienced cyberattacks in June 2024 disrupting critical operations and blood transfusions and blood tests.
All the organisations have recovered now though? The attacks were in 2023 and 2024. The answer is no!

The British Library has been praised for its response to the attack and its transparency into what happened. It is still recovering undertaking a recover and rebuild program for many of its systems that were outdated and out of support.
This is the latest update from the British Library website blog: Following the major cyber-attack in late 2023, 2024 saw us bring back interim versions of a number of our key services, including:
The damage caused in the attack was extensive, and our recovery continues to be underpinned by the need to rebuild our infrastructure safely and securely. Over the next year we’ll continue to restore systems and services.
By contrast 11 months after the Synnovis attack patients are still in the dark about what data was stolen, including information about their illnesses. The Qilin group published information on the dark web.
Synnovis has still not provided a detailed analysis of what data was published by Qilin. Data breach specialists CaseMatrix suggest more than 900,000 patients were impacted, with the published material including names, dates of birth, NHS numbers, and in some cases personal contact details. But the most sensitive information CaseMatrix identified included pathology and histology forms used to share patient details between medical departments and institutions. These forms often describe symptoms of intimate and private medical conditions.
Full recovery in both of these attacks is still some way off. The attack demonstrates that recovery from cyber-attacks is a complicated operation. The complexity is especially poignant when primary data and backup data is encrypted in the attack. Cyber security resilience is critical in surviving an attack.
Worried about your cyber security resilience DM me with the word resilience.
It’s 2025. Cyber attacks aren’t rare. They’re relentless. There is an attack on UK business every 45 seconds (NCSC)

🟦 Phishing and ransomware are no longer just threats — they’re business models.
🟦 Regulatory pressures aren’t slowing down — they’re stacking up.
🟦 AI is accelerating decision-making — but also amplifying risk at speed and scale.
If your organisation is still thinking in terms of cyber security as a box-ticking exercise, we need to talk. Because what you really need — now more than ever — is cyber resilience.
Cyber resilience is the ability to prepare for, respond to, and recover from cyber incidents.
It’s not just about stopping threats. It’s about bouncing back fast, keeping operations running, and protecting your reputation while under pressure.
In plain terms: Security helps you avoid the fire. Resilience ensures your business survives the fire.
And in today’s climate, fires happen — often. There is an attack on UK businesses and / or infrastructure every 45 seconds (NCSC)
Let’s get real. You’ve probably heard:
“We haven’t been hit yet. We’re fine.”
Until you’re not. And when that moment comes, it’s too late to start planning.
🟦 The average cost of recovery of a UK data breach in 2024? £3.4 million. Excluding lost sales, lost customers etc.
🟦 Downtime from ransomware? Days — sometimes months.
🟦 Regaining lost trust? Months… if ever.
But the real cost? Boardroom chaos. Customer churn. Contract loss.
Cyber resilience protects revenue continuity, brand trust, and investor confidence — the things that keep your business alive and growing.
Resilience doesn’t live in IT.
🟦 The CFO needs to know the financial exposure.
🟦 The COO must understand operational impacts.
🟦 The CEO should be asking: “What’s our recovery time — and who’s accountable?”
🟦 Every employee must know what to do when something goes wrong.
Your people are your frontline — or your liability.
That’s why resilience must be embedded, not bolted on. Through planning, testing, and culture. Through partnerships — not products.
If this all feels overwhelming, you’re not alone. Many scaling businesses realise too late they’ve outgrown their informal, ad-hoc approach.
Here’s what we tell clients:
🟦 Start with a business risk lens — not a tech one.
🟦 Run a readiness review — how fast can you detect, respond, and recover?
🟦 Map your crown jewels — know what data must be protected at all costs.
🟦 Drill your teams — tabletop exercises beat chaos every time.
🟦 Get external help — resilience isn’t DIY.
Cyber resilience is what turns a cyber event into a blip — not a headline.
You don’t need to do everything at once. But you do need to start.
Because in today’s threat landscape, the question isn’t if your business will face disruption.
It’s when. And how prepared you’ll be to survive it.
💬 If you’re wondering where the gaps are in your cyber security — let’s have a conversation. DM me the word resilience.
