Cybersecurity

The M&S Cyber Attack: Key Lessons in Cyber Resilience For Australian Businesses

More than a year on, the cyber attack on Marks & Spencer (M&S) remains one of the most significant incidents to hit a major UK business in recent years.

The attack emerged over the Easter weekend in April 2025, with M&S later confirming that threat actors had gained access through a third-party contractor using social engineering techniques. The retailer initially estimated that the incident would reduce group operating profit by approximately ÂŁ300 million (over $566 million AUD) before insurance, cost mitigation and other actions.

Although the incident occurred in the UK, the wider significance of the M&S incident extends far beyond the attack itself. It demonstrates how closely cyber security is connected to business continuity and customer trust, reinforcing why cyber resilience is a business priority, not simply an IT concern.

How Did the M&S Cyber Attack Affect the Wider Business?

The M&S cyber attack showed how quickly an IT incident can become a business-wide disruption, affecting operations, revenue, supply chains, employees and customers.

Business Operations

M&S had to take critical systems and processes offline while it contained the incident. Although physical stores remained open, the business couldn’t operate as usual, with disruption affecting online fulfilment, Click & Collect, in-store ordering and contactless payments.

Revenue and Customer Experience

M&S paused online orders for 46 days, preventing customers from purchasing through one of its key sales channels. In the first half of 2025/26, Fashion, Home & Beauty online sales fell by 42.9%, reflecting the pause in online trading and the gradual recovery that followed.

Supply Chain Disruption

Modern supply chains depend on connected systems for forecasting, ordering, inventory, warehousing and logistics. At M&S, disruption to these processes contributed to reduced product availability, additional waste and higher logistics costs.

Staff Productivity

Employees relied on manual processes to keep parts of the business moving. These workarounds added pressure and reduced productivity across operational teams.

Reputation and Trust

M&S apologised for the disruption and kept customers updated as services were restored. Although it did not report a measurable loss of customer confidence, the incident demonstrated the reputational risk involved. 

Why Does Supply Chain Risk Matter More Than Ever?

The M&S incident highlighted why businesses need to look at their entire technology ecosystem, not just the systems they manage internally. Modern businesses rely on cloud platforms, software providers, managed service providers, payment systems and logistics partners to operate.

Third parties can hold sensitive data, manage critical infrastructure and have trusted access to business systems, meaning an incident affecting one provider can quickly spread to the organisations it supports.

The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 identifies effectively managing third-party risk as one of four priority actions for Australian businesses. Building resilience requires organisations to understand both their own risk and the exposure created by their wider supply chain. 

What Can the M&S Incident Teach Business Leaders?

For Australian business leaders, the M&S incident offers practical lessons in strengthening an organisation’s ability to respond, recover and continue operating. 

Lesson 1: Cyber Resilience Is a Leadership Issue

Cyber security has traditionally been viewed as IT’s responsibility, but incidents like the M&S attack show why this mindset must change. Cyber incidents have business-wide consequences, making resilience a leadership issue. Leaders need to understand the organisation’s exposure and ensure teams have clear responsibilities, resources and authority to act quickly.

Lesson 2: Understand Your Third-Party Dependencies

Organisations inherit cyber risk through every supplier, partner and provider they rely on. Leaders should identify which third parties are critical, what access they hold and how their loss would affect operations, alongside alternative providers and practical workarounds.

Lesson 3: Plan for Recovery, Not Only Prevention

No organisation can eliminate every cyber risk, the Australian Bureau of Statistics found that 21% of Australian businesses experienced a cyber security incident during 2024–25. Organisations must therefore be prepared to contain an incident, maintain critical services and recover quickly. A strong plan should define who makes critical decisions, which services are restored first and how employees and customers will be informed.

Lesson 4: Build Multiple Layers of Protection

No single technology platform removes cyber risk. Instead, organisations need a layered approach combining people, processes, governance, technology and incident response. This is known as defence in depth. If one layer fails, the others can help contain the incident and limit its damage. 

Why This Matters for Australian Organisations

The scale and cost of cybercrime make the lessons from M&S equally relevant to Australian organisations. ASD’s Annual Cyber Threat Report 2024–25 recorded more than 84,700 cybercrime reports, equivalent to one every six minutes. The average reported cost for Australian businesses also rose by 50% to $80,850.

Against this backdrop, ASD recommends that businesses adopt an “assume compromise” mindset, recognising that incidents may occur and preparing to limit their impact.

Is Your Business Ready to Respond?

Cyber resilience is measured by how quickly an incident is detected, how effectively the business responds, whether it can continue operating and how quickly it recovers.

By reflecting on incidents like the M&S attack, businesses can strengthen their own preparedness. These lessons can prompt leaders to review their dependencies, challenge assumptions and test response plans before disruption occurs.

Ready to strengthen your organisation’s cyber resilience? Talk to Virtuoso about a practical plan to understand your risk, improve protection and prepare for disruption.

About the author
Markus McIver

Markus McIver

Markus has spent over two decades helping businesses get more from their technology. As Managing Director at Virtuoso, he leads a team obsessed with making IT a driver of growth rather than a source of friction, covering everything from cyber resilience and Microsoft cloud to co-managed IT partnerships.

Ready to simplify your IT?

Let’s discuss your goals and challenges - no obligation, just practical advice.

Book a Discovery Call