Marks & Spencer Cyber Attack: Experts Weigh In on Retailer's Recovery Efforts

As Marks & Spencer works to recover from the recent cyber attack, experts are hailing the retailer's decision to take its time in getting systems back online as "vital" to ensuring security and preventing future incidents. The attack, which occurred over the Easter weekend, resulted in customer personal data being stolen and empty shelves across the UK. With the disruption expected to last until July, cyber security experts warn that rushing to bring systems back online without proper integrity checks could risk further compromise.

Key Takeaways:

  • The extended disruption to Marks & Spencer following the cyber attack is "appropriate" and "necessary" to ensure proper recovery, cyber security experts have said.
  • The attack, which was caused by human error, has resulted in customer personal data being stolen and empty shelves across the UK.
  • Experts warn that rushing to bring systems back online without proper integrity checks could risk further compromise.
  • Marks & Spencer's recovery efforts must prioritize a secure and complete recovery over a rapid one, with a focus on restoring core systems and recovering critical data.
  • Effective incident response plans, regular testing, and collaboration with cyber security experts are critical to minimising disruption.
  • A proactive approach to cyber security, including threat detection, security-by-design principles, and employee awareness, is the best defence against increasingly sophisticated attacks.
  • Business continuity and incident response planning are key to ensuring a co-ordinated and resilient strategy in the recovery process.
  • Recovery efforts must consider all aspects of security, particularly the integrity of backups and the organisation's ability to restore critical systems even in worst-case scenarios.

Statistics:

  • The cyber attack is expected to cost Marks & Spencer around £300 million.
  • The disruption is expected to last until July.
  • The attack resulted in customer personal data being stolen, including names, email addresses, postal addresses, and dates of birth.
  • Marks & Spencer has halted orders on its website and seen empty shelves across the UK.
  • The recovery process involves restoring core systems and recovering critical data, with a focus on security and integrity.

Sources:

  • ANS (digital firm) - "M&S appears to be taking the appropriate and necessary steps following the cyber attack, with a likely focus on restoring core systems and recovering critical data."
  • NCC Group (cyber security firm) - "Many people underestimate the full scope of a cyber attack and the time it takes to restore systems to usual functionality, recovery can often take months."
  • M&S (Marks & Spencer) - "Human error" caused the cyber attack.