What Marks & Spencer, Transport for London and Jaguar Land Rover teach boards about limiting the damage.
In brief. Recent UK incidents show that a breach is rarely the expensive part. The cost comes from how far attackers can reach once inside, and how long recovery takes. Zero Trust, done as a sequenced programme rather than a product purchase, is the discipline that limits that reach. This paper sets out what the public record shows, what it cannot tell us, and the questions a board should be asking.
1. Three incidents, three lessons in reach
The facts below come from public sources: regulators, law enforcement, the companies themselves and the Cyber Monitoring Centre. Where a detail is reported by secondary sources rather than confirmed, we say so.
Marks & Spencer, April 2025
What the public record shows. Disclosed to the London Stock Exchange on 22 April, with online orders paused on 25 April. Initial access is reportedly through social engineering of an IT help desk, with the intrusion said to have begun in February. Secondary reporting describes stolen Active Directory credentials, weeks of movement using legitimate admin tools, and ransomware deployed against virtualisation hosts. Attribution to Scattered Spider is assessed, not confirmed.
Reported impact. M&S results for the year to 28 March 2026 show a £131.3m incident cost within adjusting items and £100m of insurance proceeds. It had guided to about £300m of profit impact in 2025. The Cyber Monitoring Centre put M&S and Co-op together at £270m to £440m, a Category 2 systemic event.
Transport for London, August to September 2024
What the public record shows. A sustained intrusion detected on 1 September 2024. In July 2026 two members of Scattered Spider were each sentenced to five years and six months under the Computer Misuse Act. The public sources we reviewed do not describe the method of entry.
Reported impact. 148 systems rendered inoperable, password resets for all 27,000 staff, and £29m in loss and recovery costs according to the National Crime Agency. Customer data on around 5,000 people was accessed.
Jaguar Land Rover, September 2025
What the public record shows. A cyber incident halted production and rippled through the supply chain. The Cyber Monitoring Centre modelled disruption lasting until January 2026.
Reported impact. Estimated £1.9bn cost to the UK economy (range £1.6bn to £2.1bn), a Category 3 event affecting more than 5,000 organisations. Government backed a £1.5bn loan guarantee.
2. What the pattern shows
Entry is only the beginning. At M&S, reporting suggests weeks passed between first access and the encryption that stopped trading. Attackers who are inside a network have time to look around, collect credentials and choose their moment. Every environment where a stolen identity can reach far beyond its owner's job hands them that time.
Reach decides the cost. The number of systems an incident touches is the multiplier on its cost. TfL lost 148 systems. JLR's incident spread to thousands of suppliers. In each case, the question after the breach was the same: how much of the estate could be reached from where the attackers stood?
Regulators look at the same things. The ICO fined Capita £14m in October 2025 over a breach that affected 6.6 million people. Its findings included no tiering of administrative accounts, which let an attacker who compromised one device escalate privileges and move across multiple domains, and 58 hours to quarantine that device against a target of one hour. It also found a Security Operations Centre that missed its alert response targets, and penetration testing carried out only when systems were commissioned. The Information Commissioner said that no organisation is too big to ignore its responsibilities.
Recovery is measured in months. TfL had spent over £30m by December 2024 and was still restoring services months after the attack. Its response included limiting and shutting down systems to stop ransomware spreading, which is itself a form of segmentation performed in the middle of a crisis.
3. What Zero Trust can and cannot do
It would be wrong to claim that Zero Trust would have prevented any of these incidents. Social engineering of a help desk is a people and process failure, and it needs its own controls, from identity verification to privileged access management. What a properly delivered Zero Trust programme does is change what a successful intrusion is worth to the attacker.
- Fewer places to go. Segmentation and workload isolation mean a compromised account or host cannot reach the systems that matter most.
- Less standing access. Least privilege and access recertification remove the accumulated permissions attackers rely on.
- Earlier detection. Once flows are understood and monitored, movement that does not fit the pattern stands out.
- A smaller blast radius for recovery. Critical workloads that are isolated can be protected, restored and proved clean independently.
4. From principle to programme
The NCSC describes zero trust as an architectural approach and sets out seven design principles. They are a sound frame, but principles do not sequence themselves. Most stalled programmes fail at the point where principles meet a real estate of hundreds of applications, competing owners and finite change windows.
- Know your architecture. Criticality assessments that rank every application by confidentiality, integrity and availability impact, so effort goes where consequence is highest.
- Know identities. Named owners for every workload, and a clear view of which identities, human and non-human, can reach it.
- Authenticate and authorise everywhere. Access designed per workload, across workforce, privileged, third-party, workload and data access.
- Trust no network. Transaction flow analysis and blueprints that replace broad network trust with explicit, least-privilege paths.
- Monitor users, devices and services. Hypercare after each cutover, with flow monitoring that stays in place once the programme has finished.
Our Zero Trust Network Delivery follows this logic workload by workload: criticality assessment, transaction flow analysis, blueprint and migration plan, migration and cutover, risk assessment, then embedding the process so your own teams run it. Cutover happens only when readiness is confirmed.
5. The pressure is rising
- Prevalence. The government's 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses and 69% of large businesses experienced a breach or attack in the previous year.
- Supply chain blind spots. Only 15% of businesses reviewed the cyber risk of their immediate suppliers, and 6% looked at the wider supply chain.
- Regulation is widening. The Cyber Security and Resilience Bill, introduced in November 2025 and in Lords Grand Committee in September 2026, extends regulation to managed service providers, data centres and critical suppliers. It proposes fines of up to £17m or 4% of annual turnover, and incident reporting in two stages, at 24 and 72 hours. Its passage is still in progress, so check its status before relying on any detail.
6. Seven questions for the board
- Which ten of our applications would hurt most if lost, and how do we know?
- If one employee credential were stolen today, what could an attacker reach?
- Where does our network still trust a device or user because of where it sits?
- Do we know, from evidence, how our most critical systems communicate?
- Who owns each critical workload, and who signs off changes to its access?
- How would we detect an attacker moving between systems, and how quickly could we isolate a compromised device?
- Which suppliers and managed service providers can reach our estate, and on what terms?
7. Where to start
A Zero Trust Discovery and Roadmap is a fixed scope engagement that answers these questions. It assesses your current state across nine capability areas, identifies the use cases that matter to your business, and produces a phased roadmap with investment priorities. It gives the board a defensible basis for deciding how much to do, and in what order. Public examples of the approach: Segmentation and Access Governance and Lateral Movement Risk.
Sources
- National Crime Agency, two sentenced for hacking Transport for London (nationalcrimeagency.gov.uk).
- Computer Weekly, TfL cyber attack cost over £30m to date, December 2024.
- M&S full year results, 52 weeks ended 28 March 2026 (corporate.marksandspencer.com).
- ICO, Capita fined £14m for data breach affecting over 6m people, October 2025 (ico.org.uk).
- The Register, peers ask why the Cyber Security and Resilience Bill leaves executives off the personal liability hook, 7 September 2026.
- Cyber Monitoring Centre, statement on ransomware incidents in the retail sector, June 2025.
- Cyber Monitoring Centre estimate for the Jaguar Land Rover incident, as reported by Computer Weekly, October 2025.
- M&S timeline and technical reporting: CM Alliance and Specops Software (secondary sources, treat technical detail as reported).
- GOV.UK, Cyber Security Breaches Survey 2025/2026, published 30 April 2026.
- House of Commons Library briefing and Hansard on the Cyber Security and Resilience Bill.
- NCSC, zero trust architecture design principles (ncsc.gov.uk).
