Cyber attack on Marks & Spencers was human error

Successful cyber attack on Marks & Spencers was due to human error

Human error and lack of awareness will lead to security incidents. When you combine social engineering with lack of human awareness, as a criminal, you are very likely to succeed.

Both Marks & Spencers and The Co-Op recently suffered cyber incidents recently and neither was a hack. No technical vulnerabilities were exploited! This was ALL done by social engineering techniques and taking advantage of the lack of cyber awareness within the organisations.

UK business lose billions through preventable cyber attacks

UK businesses have lost an estimated £44 Billion due to cyber attacks, most of which could have been prevented. According to research carried out by Vodafone, the average cost of a cyber attack to a small business is £3398, this rises to £5001 for businesses which have up to 50 employees.

This figure does not include any legal fees or fines should the attack be have to be reported to the Information Commissioners Office (ICO).

For a medium sized business this figure again rises to an average of £10,830 per breach, which does not include any legal fees or fines should the report be a personal data breach. Not many SME’s can afford this type of disruption, and sometimes, depending on the type of attack carried out, a network, systems or applications can be unavailable for undetermined amounts of time – a day, a week, sometimes more.

Businesses may not recover from a cyber attack

The disruption can bring a business to a grinding halt, and some businesses do not recover.

  • A haulage firm, The Knights of Old, based in Kettering, which had been operating for 160 years has recently experienced a cyber attack which left their business with the administrators, and is now closing.
  • Travex closed in 2020 due to a devastating cyber attack.
  • Code Spaces, a cloud hosting services, went out of business in just 12 hours when a hacker deleted all it’s data and then hit the network with a DDoS attack.
  • Vastaamo was forced into bankruptcy when they were hit with a ransomware attack.

The attacks, when successful, are devastating, because they are not just harmful to the business, but its customers too, this makes the attack irreparable. Your customers can withdraw their contracts with you because they have been compromised just by doing business with you, it is near impossible to recover from the bad reputation this kind of disruption brings.

Training can help prevent cyber attacks

At Strident, our training is targeted to prevent these types of attacks, we show how these attacks are carried out and why they can be successful, and how employees can identify and thwart social engineering attempts – we can help businesses avoid what Marks & Spencers and The Co-Op did not.

We show real world examples of how it has gone horribly wrong for other organisations and what they could have done to prevent it.

The typical benefits a company will see after installing a regular training / awareness program:

  • Cost savings – less human error, reduced “insider threat” risk, less chance of legal fees and fines
  • Risk reduction – security awareness training can reduce security related risks by up to 70%.
  • Fewer security incidents – organisations who implemented an effective security training program have reported 80% fewer successful phishing attacks
  • Reduced phishing link click rates – studies show that ongoing security awareness training reduces phishing link licks from 32% to just 5% within 1 year
  • Behavioural change – employees who ate subject to regular security awareness training, adopt secure behaviours both at work and at home, keeping both the business and themselves, up to 70% safer.

Businesses cannot afford to skip on security. In addition to comprehensive security software, Strident can offer invaluable cyber awareness training to ensure your employees understand the risks and what to do. To find out more, then please get in touch here.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection