What the Recent M&S, Co-op, and Harrods Cyberattacks Can Teach Us About Business IT Security

The recent cyberattacks on household names like Marks & Spencer, Co-op, and Harrods have highlighted just how destructive a cybersecurity breach can be. With M&S alone reportedly losing an estimated £30 million due to suspended online orders, these incidents are a wake-up call for businesses of all sizes to assess and tighten their cybersecurity defences urgently.

In these attacks, reported by tech site BleepingComputer, hackers impersonated employees while contacting IT help desks. By convincing staff to reset credentials, they gained access to internal systems, no sophisticated hacking tools needed, just clever social engineering and a weak process.

This is exactly why the UK’s National Cyber Security Centre (NCSC) is urging companies to review their help desk protocols. It’s also why at Ask4Support, we always say: cybersecurity isn’t just about firewalls and software, it’s about people and processes too.

Don’t Wait for a Breach to Act

At Ask4Support, we provide a layered and proactive approach to cybersecurity. We offer:

  • Core protections like antivirus, secure password management with LastPass, and multifactor authentication (MFA).
  • Advanced defences including Microsoft 365 XDR (Extended Detection & Response), SIEM (Security Information and Event Management), and our 24/7 Security Operations Centre (SOC).
  • Personalised staff training, because even the best tools are only as effective as the people using them.
  • Mobile Device Management (MDM) and Radius Wi-Fi setups to secure your devices and networks from end to end.

UK First: Morphisec Ransomware Protection

We’re proud to be the first UK provider of Morphisec, a solution that works alongside your existing antivirus tools to stop ransomware in its tracks before it even executes. It adds an extra protective layer at the endpoint level, neutralising threats proactively rather than reactively.

Microsoft Sentinel: Intelligent Threat Detection

We also partner with Microsoft Sentinel, a scalable cloud-native SIEM and SOAR platform that uses artificial intelligence and real-time threat intelligence to help detect, investigate, and respond to attacks faster and smarter. It also cuts down on “alert fatigue” so your IT team can focus on real threats.

Protect Your Supply Chain

It’s not always your own business that’s the weak link, it could be a supplier. Retailers, for example, often rely on legacy systems from external partners. These can become unintentional back doors if they’re not properly secured. We always advise clients to ensure suppliers are meeting your cybersecurity standards too.

Know Your Attack Surface

To understand where you’re vulnerable, you first need visibility. That’s where penetration testing (pen testing) and perimeter testing come in. These simulated attacks help uncover misconfigurations or gaps before a real hacker finds them.

Get the Basics Right

Our baseline security recommendations include:

  • Enabling MFA across all cloud services.
  • Using secure password managers like LastPass.
  • Performing regular reporting and system reviews.
  • Ensuring help desk protocols are secure and resistant to impersonation tactics.

And above all, work with an IT support partner with a proven track record in cybersecurity. At Ask4Support, we deliver fast response times, experienced support, and proactive security management to help keep your business safe in an ever-changing threat landscape.

If you’re unsure where your business stands from a cybersecurity perspective, or if you’d just like an honest review, get in touch on 01491 712344 or info@ask4support.co.uk. A quick chat now could save a lot of trouble later.