Retail Cybersecurity: Marks and Spencer Cyber Attack Analysis | TruePoint Systems

Retail Cybersecurity: Lessons from Global Cyber Attacks

Retailers already worried about security issues, and modern technology just watched on the news as Marks and Spencer saw around £500-£700 million ($650M) wiped from its market value within a week. It shows how a single breach can decimate even major legacy brands. 

With that in mind, what can normal businesses do? 

The Marks & Spencer cyber attack has reaffirmed that ransomware recovery is disastrous to any business, and every SMB in Texas should pay attention, as it’s not the type of problem that one can just “wait out”. Events like this are the new normal when it comes to retail cybersecurity. 

We’ve provided the following playbook to help you avoid falling victim to the same issue. Learn where M&S stumbled and where they managed to claw back a sense of normality, and implement controls that help you prevent the same kind of losses. 

The Marks & Spencer Cyber Attack in Real Time 

On April 21, malicious actors used social engineering to gain a foothold in M&S’s systems with stolen credentials. They detonated a ransomware payload in the network and affected dozens of internal systems. 

When they detected the breach, M&S idled the whole distribution center of Castle Donington, sending around 200 staff home due to a lack of work. The single point of failure led to many of these issues, including empty shelves across the network. 

This warehouse shutdown prevented the breach from worsening, but it was already too late. By day three, they had suspended the point-of-sale process and stopped systems across their entire store network, including: 

  • Contactless payments 
  • Gift-card redemption 
  • Click-and-Collect 
  • Online & mobile-app orders 
  • Loyalty rewards programs 
  • Returns 
  • Automated supply & stock systems 
  • Some warehouse operations 
  • Internal platforms 
  • Recruitment portals 

Marks & Spencer was quickly forced to block hundreds of its staff from its systems to prevent exacerbating the problem. When they could not solve the problem, some staff had to resort to using a pen and paper to record customer purchases as the issue continued into a second week. 

Not Just Any Breach – An M&S Breach 

M&S’s market capitalization slid down by over £700 million as investors reacted to the situation. Public disclosure and GDPR notifications then led to the company hiring an external incident response team, costing them several million pounds more. 

By day seventeen, at the time of writing, M&S had announced “steady progress” and a partial restoration but warned that full recovery could take months. 

During that time, some of the problems the company has acknowledged include: 

  • Issuing only limited data publicly and frustrating customers 
  • Using an over-centralized single point of failure in their systems 
  • Complete lack of an offline ordering method 
  • Locking remote staff out of systems and throttling the investigation 
  • A lack of clear decision authority 

Ripple Effects Every Retailer Must Plan For 

Point of sale stoppage during peak hours can bleed any large store of tens of thousands of dollars per day in lost sales. At the same time, delivery windows start slipping, and remote buyers tend to abandon carts in these situations, dropping both past and present purchases. 

We may even see insurance carriers raise premiums across the sector in the near future as the breach reveals systemic weaknesses for many other stores. It is also essential not to acquiesce to ransomware demands, as they can cost an organization millions of dollars

Retail-Specific Cybersecurity Gaps 

Following the breach, it is the perfect time to look at retail and work out how to ensure you are as secure as possible. As such, be aware of these potential issues that you might suffer from: 

  • Cardholder data in transit may still be a target for access 
  • Legacy systems still run Windows 7 and cannot use modern protections 
  • Always-on Wi-Fi on modern systems creates constant exposure potential 
  • Franchises create more vendors who each have unique security needs 

Combining this with the new Texas Data Privacy and Security Act, which could lead to significant fines for breaches, there is more pressure than ever to protect resident data that your system may contain. Failing to respond can lead to $7,500 fines per violation, and even small retailers could quickly end up racking up six-figure penalties. 

Security Moves to Avert Retail Chaos 

In addition to creating a robust security system, you need to have a plan for recovery and continuity. The nature of ransomware means that getting back on your feet will not always mean recovery of precisely what you had on your system at the time of the breach. 

As such, the following steps may be imperative: 

  • Map critical functions in your business 
  • Decide on a maximum tolerable downtime 
  • Plan for hot-swapping cloud infrastructure if the worst happens 
  • Create a system of using alternate fulfillment centers if yours fails 
  • Work with a legal specialist to prepare pre-approved press statements 
  • Pay for cyber liability insurance to offset potential ransoms 

You will likely need 24/7 security monitoring to ensure that such risks are much less likely to breach automated systems. Taking this step demands boots-on-the-ground cybersecurity professionals who treat the situation with the seriousness it deserves. 

Also, perform regular reviews to align your processes with the evolving threat landscape. Give your cybersecurity team everything they need to remain trained and up-to-speed on the latest threats, and run a ransomware readiness assessment at their earliest convenience. Your staff are the human firewall you will need to ensure that you are as safe as possible, and giving them the best chance of recognizing a breach is a significant factor in your safety moving forward. 

How TruePoint Systems Shields Texas Retail 

If you need more help, TruePoint Systems is an East-Texas-based security operations center that can offer boots-on-the-ground support within hours of hearing about a problem. Following an initial consultation, we can provide advisory and direct assistance in retail cybersecurity, depending on the exact nature of the issue. 

Remember, one Marks & Spencer cyber attack cost the company £500 million in value. What would a similar breach do for you? 

TruePoint Systems offers Texas-strong protection. We aim to slash your downtime and reduce the cost of any breach. So, get in contact today and book a consultation before you become the next headline. 

TruePoint Systems Professional Logo PNG

Managed IT services and cybersecurity provider delivering integrated support, security, and strategic technology planning for growing organizations.

Longview, TX

119 W. Tyler St., Suite 250

Longview, TX 75601

903.212.2523

Tyler, TX

1001 ESE Loop 323, Suite 485

Tyler, TX 75701

903.630.8416

© 2024 TruePoint Systems ALL RIGHTS RESERVED