Navigation

Cybersecurity: The Cost of Complacency

Software, Media & Technology

Whilst the importance of businesses building strong cyber security systems to support their tech stacks is hardly a new concept, the M&S attack (and subsequent valuation drop) does serve as a timely reminder of its importance. Any potential investor or acquiror is going to drill into your IT systems during a transaction – so now might be a good time to consider an audit.

The main obstacle businesses face is the general consensus that either you won’t be a target to attackers due to your size, or that a scenario is so unlikely that it is not worth preparing for. When your business relies on technology to run, the most dangerous attitude that you can have as a business owner is that cyber integrity is not a top priority. We receive an array of questions during IT diligence calls, including ‘what is your disaster recovery plan for if AWS goes down?’ – something that would generally be considered a world ending event.

The bottom line? You need to be prepared.

Businesses need to engage with initiatives like the government-backed Cyber Essentials certification scheme to help protect their systems against common cyber threats. Whilst the main barrier to engaging in these schemes is constraints of resources and the complexity of the guidance, it is a worthwhile investment of your time to and budget to adopt these essential suggestions. Firstly, you will reap the returns of this from an investor or acquiror when you decide to exit, but with less downtime and less spent on recover from an incident, the upside may come much sooner. The Times has even reported that implementing the recommended Cyber Essentials protections reduces the likelihood of a cyber insurance claim by 92%.

Change is being put on the agenda from above. Regulatory bodies continue to push for enhanced disclosure of cyber incidents to prevent systemic risks, and the UK government has been proactive in addressing cybersecurity threats. The Cyber Security and Resilience (CS&R) Bill announced last year aims to introduce stricter regulations to guide and protect British firms; the likely provisions of which will require players to allocate greater resources to protect their digital assets through increased investment in their cybersecurity infrastructure and supply chain security.

Recent cyberattacks on supermarkets like Marks & Spencer and The Co-operative Group have exposed critical weaknesses in the UK’s cybersecurity infrastructure. The orchestrated attack on M&S disrupted online orders, payment systems, and recruitment processes and over the weeks following the attack, M&S shares dropped by almost 7%. This resulted in a £750m drop in the company’s market cap. Share value has increased since the low during mid-May, but it is anticipated that the disruption will have a £300m negative impact on FY26 profitability, which highlights the potentially devastating consequences for victims of cyberattacks. The National Cyber Security Centre (NCSC) has called this incident a “wake-up call” for businesses across the country.

Even in large businesses, the main threat to cyber integrity is the attitudes of management, and how a crisis is handled. The Co-op took a ‘pull the plug’ approach, with management taking the difficult decision to shut off systems as soon as the attackers were detected. This reduced the overall downtime as the attackers were halted in their tracks. On the other hand, M&S kept its systems running even after the ransomware group was detected in its network, allowing it to tunnel further and steal more data.

The repercussions the two retailers faced were vastly different. Yes, both suffered significant disruption to procurement and were left with empty shelves, but The Co-op has recovered much better than M&S. The difference between these outcomes? – The Coop appreciated the significance of an attack and took an early sacrifice to stop it in its tracks.

Looking ahead:

SMEs remain susceptible to hackers as data has become gold. Smaller players are likely to have fewer protections in place than large corporates due to having fewer resources, which makes a successful attack more likely.

If a full IT audit is not on the cards right now due to budget constraints, there are small changes you can add to your current strategy to help safeguard your business and all the work you have poured into it.

  1. Be proactive:

Technology leaders are calling for their customers to engage in cyber defence, with Microsoft calling for traditional passwords to be replaced by passkeys. But as cyber criminals have grown more sophisticated and leverage artificial intelligence to enhance their attacks, even multi-factor authentication systems are being bypassed. Dynamic cyber security strategies should be in place for all businesses –not just a checklist attitude.

  1. Utilise Artificial Intelligence:

Cybersecurity firms continue to deploy AI-powered solutions to detect and neutralise threats in real time, and at a more accessible price point than even a few years ago. These could be the right option for you and may be more cost effective than increasing your cybersecurity headcount. For example, the Internet of Things “IOT” is a powerful tool used across the supply chains of many players – but the more devices you operate in your network, the more vulnerable you are. AI solutions can automatically isolate compromised devices, which can promptly halt an attack in its tracks and prevents it from spreading across a network.

  1. Train your staff:

Not just your management. Most workers use technology in some form and the UK suffers from a large cyber skills gap -the UK Cybersecurity Council has found that 90% of organisations have skills gaps within their teams, including in incident response. Cyber awareness workshops are a relatively low-cost investment that enables all members of staff to know how to conduct themselves safely with technology and identify threats and sophisticated phishing attempts. Regular peer ‘check ins’ across teams can increase accountability of each member of staff and encourage the use of multi-factor authentication or passkeys, and other safe technology practices. The crucial point here is that everyone in your business needs to be actively guarding against cyber threats.

Small steps taken consistently can have a real impact, so take a look at the National Cybersecuity Centre’s Small Business Guide to see what you can do to get started to improve your position. After all – prevention is always better than cure.

By Annabel Whelan on 30/05/2025