Get IT Security Right, Keep Business Moving: What M&S, Co-op, JLR and The Farmer's Dog Teach Every Business
All dispatches
Security22 Sept 202617 min read

Get IT Security Right, Keep Business Moving: What M&S, Co-op, JLR and The Farmer's Dog Teach Every Business

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

Four business stories about access, recovery, supply chains and money, and what they mean for your managed IT service.

Based on public information available on 22 September 2026. Confirmed findings, reported details and recommendations are distinguished throughout.

1. Marks & Spencer: when one intrusion becomes a business-wide crisis

Imagine having customers ready to buy, stock to sell and staff ready to work, but being unable to complete the transaction.

For Marks & Spencer, that became a prolonged commercial reality. Following its April 2025 cyberattack, online orders stopped on 25 April. A limited service returned on 10 June, roughly six and a half weeks later. Read the reopening report

The website was only the visible part. M&S disconnected warehouse-management systems during its response, affecting online fulfilment, click-and-collect and in-store ordering. Employees introduced manual processes to keep stock moving and shops trading. M&S half-year results

What went wrong with the IT?

The confirmed entry route involved impersonation. Chairman Archie Norman told Parliament that attackers entered on 17 April by posing as a real individual, using that person's details. A third party was involved.

The practical failure was that the access process did not distinguish the attacker from the legitimate person being impersonated. M&S has not publicly established that a senior administrator clicked a phishing email, that the first account controlled every system, or that a VPN was the entry route. M&S's parliamentary evidence, questions 168 and 171 to 174

That distinction matters. Businesses often concentrate on password strength while overlooking how passwords and authentication methods can be reset. A strong login can still be undermined by a weak recovery process.

The NCSC, the part of GCHQ responsible for national cyber security, issued recommendations to the wider sector while the retail incidents were unfolding, and the joint advisory on Scattered Spider that it co-authored with its Five Eyes partners specifically addresses helpdesk impersonation and the need to strengthen identity verification. This is a wider defensive lesson, not proof of every step in the M&S attack. NCSC: incidents impacting retailers, recommendations, Joint advisory on Scattered Spider, co-authored by the NCSC

The second problem was containing the consequences

Norman acknowledged that interconnected older and newer systems complicated separation. M&S also said more than half its systems remained unaffected and protected: some services stopped because the company deliberately disconnected them.

The criticism should therefore be precise. The architecture and dependencies made safe containment and recovery difficult; the evidence does not show that attackers encrypted everything. Parliamentary evidence, questions 168 and 176

Why rebuilding took so long

M&S confirmed that certain applications and file systems were unrecoverable and required rebuilding. M&S strategic report

BleepingComputer separately reported theft of the Active Directory database containing account information and password hashes. That was reported identity compromise, not confirmation that the entire directory was destroyed. Original investigation

In a Windows environment, Active Directory helps determine who can access what. Recovering that foundation requires trusted recovery data and careful isolation. Microsoft's recovery guidance explicitly addresses restoring from a trusted backup and recovering in isolation. Simply making a server start again is not enough to establish that it is safe. Microsoft's Active Directory recovery guidance

This does not prove M&S had no usable backups or disaster-recovery plan. Its pre-attack annual report described recovery plans. What the incident demonstrates is that documented preparedness did not prevent a lengthy interruption. M&S 2024 annual report

The cost of that interruption

M&S initially estimated a £300 million operating-profit impact before mitigation and insurance. Its subsequent annual accounts recorded £131.3 million in incident-response and recovery costs, alongside £100 million in insurance income. These measure different things and are not a simple additive total. Original estimate, 2026 financial statements

What your IT service should address

Ask for evidence of:

  • Independent identity verification before sensitive account resets.
  • Separate, restricted administrator accounts and controlled supplier access.
  • Separation between ordinary users, critical systems and backup administration.
  • Recovery tests that restore an actual business service, including its identity and application dependencies.

These principles follow the NCSC's guidance on limiting access, separating systems and keeping tested backups. NCSC: mitigating malware and ransomware attacks, NCSC: 10 Steps to Cyber Security

Our Not ready to talk yet? We also handle hardware, broadband, mobile and networking, not just security. Audits, monitoring and backup management with restore testing are part of our managed services; those are the starting points for agreeing the protection and recovery work your business needs.

Get IT security right: verify access, contain compromise and prove recovery.

Start with the free IT Health Check

2. Co-op: the account reset that ended with empty shelves

A customer walking into a convenience store does not see its ordering software, distribution systems or network controls.

They see whether the products they need are on the shelf.

During Co-op's 2025 cyber incident, empty shelves made an IT problem visible in everyday life. Stock shortages followed disruption to the systems supporting ordering and distribution. ITV's reporting on the impact

Here, the initial failure is on the public record

Co-op's technology chief, Rob Elsey, told Parliament that attackers impersonated an employee and answered security questions successfully enough to obtain an account reset.

He said:

> "They were able to impersonate a colleague"

Malicious use followed about an hour after the reset. Co-op's parliamentary evidence, question 197

The account-recovery process accepted someone who was not the account holder. That is a concrete security failure.

It is also the one the NCSC singled out. Its recommendations to the sector on 4 May 2025, while these incidents were unfolding, told organisations to "review helpdesk password reset processes, including how the helpdesk authenticates staff members' credentials before resetting passwords, especially those with escalated privileges", alongside comprehensive multi-factor authentication, a review of every Domain, Enterprise and Cloud Admin account, and monitoring for risky logins. NCSC: incidents impacting retailers, recommendations

For any business, this exposes a weakness in relying on information a person knows as proof of who they are. Information can be researched, stolen or obtained through another compromised account. A helpdesk needs a robust verification process, including a safe way to handle the difficult case where the genuine employee has lost access to their normal authentication device.

Phishing-resistant authentication helps protect sign-ins, but recovery procedures must be designed to preserve that protection. NCSC: multi-factor authentication for your corporate online services, Joint advisory on Scattered Spider, co-authored by the NCSC

Some defences worked, and that matters

Co-op said monitoring detected malicious activity quickly. Separation of systems helped protect online trading and payments. Its response prevented ransomware deployment, although member data was stolen.

The company isolated an affected network zone and rebuilt roughly 40 pieces of key system equipment. Distribution operations used manual processes, which significantly reduced efficiency. Parliamentary evidence, questions 192 to 199

This is not a story in which every security control failed. It shows why several layers of protection matter: an attacker got through one control, while others limited what happened next.

The remaining weakness was operational resilience

Co-op's fallback arrangements kept activity going, but could not preserve normal distribution efficiency. That is the business-continuity issue the shelves exposed.

A manual process can exist on paper and still be too slow for real demand. A useful exercise must test throughput: how many orders, deliveries or customer requests can the business actually complete without its usual systems?

On 14 May, Co-op announced that its ordering system was back online and said availability would improve as stores were replenished. Restoring software did not instantly refill shelves. Co-op recovery update

Its published 2025 results estimate a £285 million impact on sales. That figure concerns sales, not the amount stolen or a ransom payment. Co-op annual results

What your IT service should address

Your support agreement should answer three practical questions.

First, who may reset an account, and how is the request verified? Seniority and urgency should not allow someone to bypass the process.

Second, what happens after a suspicious event is detected? A monitoring alert needs an accountable responder, authority to act and an escalation route. That is what a security operations centre does, and we have explained the model in plain terms in What is a 24/7 SOC?

Third, what work can continue while systems are isolated? For a retailer or wholesaler, that means testing ordering, stock allocation and dispatch, not just whether a backup file can be opened.

The NCSC recommends planning and exercising the response to ransomware, including scenarios where systems and backups are unavailable. NCSC ransomware guidance

Monitoring of networks, servers and critical applications, alongside ongoing IT strategy, is part of what we provide as managed services. The commercial discussion should establish which services need protection and which fallback arrangements require additional design or testing.

Get IT security right: protect account recovery, act on alerts and test how the business keeps trading.

Book a Discovery Call

3. Jaguar Land Rover: when the computers stop, so does production

Picture a factory ready to work. People, equipment and components are available. The systems needed to coordinate production cannot safely operate.

Now imagine the consequences travelling outwards: to suppliers waiting for schedules, dealerships waiting for vehicles and smaller businesses waiting for income.

Jaguar Land Rover's cyber incident created that kind of interruption. Its 2026 annual report says production paused for five weeks, restarted on 8 October 2025 and returned to normal levels by mid-November. JLR annual report

What went wrong with its IT?

JLR confirmed that it proactively shut down systems in response to the incident. Its public statements establish the operational outcome, but do not provide a complete forensic account of the initial access route.

That means it would be misleading to blame a particular unpatched server, phishing email or missing backup as an established fact.

The substantiated weakness was the scale of business interruption associated with losing trusted access to its systems. Production could not continue normally while the environment was secured and restarted. JLR itself acknowledged the need for stronger digital resilience, describing its response as:

> "building back our systems stronger than before"

JLR's account of the incident and recovery

That is a resilience gap demonstrated by the outcome. It is not proof that every factory system was directly infected or that a single security product would have prevented the shutdown.

Why an apparently healthy machine may still be unable to produce

Consider a general manufacturing example. A machine might be functional, but its operators may still need order instructions, approved specifications, material records, quality checks and shipping information before they can complete a saleable product.

If those dependencies are unavailable or untrusted, restarting the machine does not restart the business.

This is why recovery should be planned around complete operations. A test that demonstrates "the server is running" may say little about whether an order can be manufactured, checked, dispatched and invoiced.

The NCSC's guidance recommends separating networks, protecting backups and preparing and rehearsing incident-response arrangements; its free Exercise in a Box lets a business rehearse exactly this kind of scenario. Applying those principles to manufacturing requires both IT and operational expertise. NCSC: incident management, NCSC: Exercise in a Box

The financial consequences crossed company boundaries

JLR reported £196 million in cyber-related costs in the quarter to September 2025. That was a specific quarterly charge, not the total economic loss caused by the incident. JLR quarterly results

The Cyber Monitoring Centre estimated the wider UK financial impact at £1.9 billion, affecting more than 5,000 organisations. Its estimate included disruption beyond JLR and was subject to modelling assumptions. CMC assessment

For a smaller supplier, this creates a second problem: excellent internal IT does not prevent a customer's outage from affecting orders and cash flow. Technology planning must connect with commercial continuity planning.

What your IT service should address

Start with one complete business process and map its dependencies.

For each critical service, agree:

  • How long the business can tolerate its absence.
  • How much recent information it could afford to lose.
  • Which systems must recover first.
  • Which suppliers or specialists must participate.
  • How a safe restart will be approved.

The first two measures are often called recovery time and recovery point objectives. Their value is commercial: they connect the price of protection with the consequences of interruption.

Backups also need protection from the same accounts and attack paths that could compromise live systems. The NCSC recommends separate offline backups, or cloud backups designed to resist ransomware, and regular restoration tests. NCSC backup and ransomware guidance, NCSC: principles for ransomware-resistant cloud backups For a Microsoft 365 business, our backup guide sets out exactly what Microsoft keeps by default and for how long, which is less than most people assume.

Our audit and IT strategy work is the starting point for identifying dependencies and prioritising improvements. Where specialist production systems are involved, the plan should explicitly include the equipment vendors and appropriate operational specialists.

Get IT security right: plan recovery around the work that earns revenue.

Book a Discovery Call

4. The Farmer's Dog: a loss that could empty a small business's reserves

Clarkson said hackers "broke into our accounting system and helped themselves to £27,000" at The Farmer's Dog. Read the report

The public account does not establish the exact access or payment mechanism. We therefore cannot responsibly describe it as a confirmed £25,000 fake-invoice payment.

What makes the story relevant is the scale of the financial risk for an independent operator.

Imagine discovering the loss just before payroll. Wages remain due. Rent remains due. The food and drinks suppliers still expect payment. The cash intended to cover a quiet month has disappeared.

Most independent publicans do not have a celebrity owner or the exposure of a successful television series. They have limited reserves and a business that must support itself. There is no verified basis here for saying Amazon reimbursed or funded this loss.

What went wrong with the IT?

The reported incident concerns accounting-system access and financial loss. It does not establish whether the underlying failure was a stolen password, an insecure account, a compromised device, excessive permissions or a payment-control failure.

Those possibilities should be investigated separately. Treating them as interchangeable produces bad security advice.

For example, if an attacker signs into an accounting platform, the immediate questions concern authentication, access rights and account activity. If a criminal persuades someone to pay a false invoice without accessing the business's systems, the weakness may instead lie in payment verification.

A managed IT service needs to work with the finance function because neither can cover the entire risk alone.

How a plausible payment request can defeat an otherwise functioning business

Consider a separate, illustrative scenario, not a reconstruction of The Farmer's Dog incident.

A supplier appears to send an ordinary invoice with new bank details. The branding looks familiar. The amount seems plausible. Someone approves it during a busy afternoon.

The National Crime Agency explains that payment-diversion fraud can exploit compromised communications and genuine transaction details. Verification through a known, independent contact route is a key defence. NCA payment-diversion fraud alert

A second approval helps only if the second person performs an independent check. Two people trusting the same misleading email does not create meaningful protection.

The controls need to cover both accounts and payments

For financial accounts, the baseline should include individual logins, appropriate permissions and strong multi-factor authentication. The NCSC recommends moving towards phishing-resistant methods where the service supports them. NCSC: multi-factor authentication for your corporate online services

For payments, the process should require independent verification of changed bank details and unusual instructions. Use established contact information, not the telephone number supplied in the suspicious request. Staff should be able to stop a payment without being criticised for delaying it. Police guidance on mandate fraud We have written the finance-team rules up as a one-page set in our guide to phishing and invoice fraud.

If money has already gone, notify the bank or payment provider immediately through verified contact details. An IT investigation should not delay that step. Report Fraud guidance The first hour after an account compromise is set out step by step in What to do if an account is compromised.

Why the recovery can take so much work

Suppose a business earns a 10% profit margin. Replacing a £27,000 loss would require £270,000 in additional sales, assuming the same margin and no other changes.

That is an illustration, not a statement about this pub's accounts. It explains why the amount lost can represent months of additional effort.

Backups can help recover information. They do not reverse a fraudulent bank transfer. That distinction should shape the protection your business buys.

Our services cover cyber security health checks, multifactor authentication, Microsoft Defender and proactive IT management. These protect the systems the finance team uses, alongside the payment controls the business itself must own. Explore our services

Get IT security right: protect financial access and verify where the money is going.

Start with the free IT Health Check

What the right level of managed IT should deliver

The common thread is responsibility across prevention, detection, containment and recovery. A quick helpdesk response is valuable, but it does not establish that all four are covered.

Before renewing or buying managed IT, ask for a clear answer to each question:

AreaEvidence to ask for
Account securityThe process for password and authentication resets, including privileged accounts.
Administrator accessA current list of powerful accounts, their owners and why the access is needed.
MonitoringWhat is monitored, who investigates, response hours and escalation arrangements.
Critical systemsAn agreed map of the systems and suppliers needed to keep trading.
BackupsWhat is protected, how copies are separated from live systems and the latest restore-test results.
RecoveryA tested sequence for restoring complete services within agreed business limits.
Payment fraudClear ownership between IT, finance and leadership for verification and incident response.

These are practical purchasing questions, not claims that every organisation in this series lacked every control.

Your service should be proportionate to your business. A small pub and a global manufacturer need different arrangements, but both need clarity about what is protected, who is accountable and what happens when prevention fails. For most small businesses the UK baseline is the NCSC's Cyber Essentials scheme, covered in our Cyber Essentials guide. Our guide to choosing an IT support company turns the table above into the twenty questions to ask.

Our approach starts with an audit, then proactive management and ongoing IT planning. Use that conversation to establish your priorities and agree the service scope, including any specialist or additional work needed.

Get IT security right. Know your risks. Test your recovery. Keep business moving.

Book a Discovery Call

and we will tell you what we would fix first.

Not ready to talk yet? Run our free IT Health Check to see where your business stands in minutes, no commitment.

Based in Brighton or Hove? We are too: see IT support in Brighton.

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.