Proudly supporting businesses across Hull & East Yorkshire
Everything Else, Microsoft 365

Five Lessons from the M&S Cyber Attack

Published 7 October 2025
Hands typing on illuminated keyboard with digital lights

The M&S cyber attack was a significant event, but it’s not our intention to scare you. Instead, we want to share five lessons that any business, regardless of size, can learn from this incident.

Lesson 1: Fish Resistant MFA

The most important thing for cyber criminals is gaining access to our identities, which we use to log into our computer systems. This remains the number one target for cyber criminals. Therefore, it’s crucial to strengthen our identities as much as possible. While multi-factor authentication (MFA) is essential, not all MFA methods are created equal. Standard MFA methods like SMS codes and app tokens can be intercepted or tricked out of us. Fish resistant MFA, which often relies on biometrics, are much harder to crack. If your business isn’t using fish resistant MFA today, you can set it up within Microsoft 365.

Lesson 2: Control Admin Access

People should only have the access they need to do their jobs. Full admin access should not be given just because someone is a business owner or needs to perform an admin task. In Microsoft 365, consider implementing Privileged Identity Management (PIM). With PIM, users apply for temporary admin access, which goes through a review process and requires approval. Additionally, conduct a full review every three months to ensure that only those who need admin access have it.

Lesson 3: Implement Cyber Awareness Training

Cyber criminals rely on tricking us into handing over usernames, passwords, and MFA codes. By implementing cyber awareness training, everyone in your business can learn to recognise these tactics. Microsoft 365 offers attack simulation training, which allows you to simulate phishing attacks and provide cyber awareness training to your team.

Lesson 4: Control Third Party Access

Third parties often have access to our technology, but how do we know they take cyber security seriously? It’s essential to have a process in place to monitor third parties and ask key questions about their IT management. Don’t give third parties full access to your systems; instead, limit their access to only what they need.

Lesson 5: Have a Plan

Cyber attacks can happen to any company, even those that take cyber security seriously. It’s crucial to have a plan in place for when your business becomes a victim of a cyber attack. This plan should involve not only technology but also processes and communication with customers, partners, and others. Marks and Spencers did a good job in this regard.

Conclusion

These are the five lessons that any business, regardless of size, can learn from the M&S cyber incident. We hope you found this information valuable and that it helps you strengthen your own business’s cyber security.

At Matthew Temple Consulting, we believe in treating our clients’ businesses as if they were our own. We are committed to providing clear communication, creative solutions, and long-term support to ensure your success. By learning from incidents like the M&S cyber attack, we can strengthen our own businesses and better protect ourselves from future threats.

If you have any questions or need assistance with your cyber security, don’t hesitate to contact us. Let’s work together to create a secure and thriving business environment.

Say Hello

We'd love to hear from you

However you'd like to reach us, a friendly local person is ready to help. We reply within one working day.
Visit us
K2 Tower, 60 Bond Street, Hull, HU1 3EN

Start the conversation

Pop your details in and we'll be in touch shortly.
Homepage Footer