We are just shy of one year on from the start of what became an uncomfortable few months for UK businesses. The series of high-profile cyber incidents that hit from the end of March 2025 felt relentless at the time, arriving one after another through spring and into summer. Starting with Marks & Spencer, Co-op and Harrods followed in quick succession. Later, Jaguar Land Rover brought disruption into manufacturing.
The disruption was unusually visible. As systems went offline, online orders halted, shelves ran low and customers were suddenly aware of how dependent everyday services are on complex digital infrastructure. Nearly a year on, the more interesting question is not who was breached. It is who managed to recover, and what made the difference which other organisations can learn from.
{{snapshot}}
The 2025 UK cyber wave at a glance
- Marks & Spencer was first, confirming an attack over the Easter weekend in March 2025.
- Co-op and Harrods followed in quick succession, with Jaguar Land Rover hit later.
- Incidents arrived one after another through spring and into summer, disrupting orders, shelves and services.
- The key question now is not who was breached, but who managed to recover and why.
{{/snapshot}}
| Organisation | What happened | Headline impact |
|---|---|---|
| Marks & Spencer | Attack confirmed over Easter weekend, March 2025; online ordering paused | Statutory profit before tax fell 99%, from £391.9m to £3.4m |
| Co-op | Attackers accessed core systems in late April; some stores went cash-only | Data of around 6.5 million members exposed; about £206m in lost revenue |
| Harrods | Attempted intrusion in early May; sections of IT shut down quickly | Largely contained; physical stores and online services kept trading |
| Jaguar Land Rover | Attack halted production across UK plants including Solihull and Halewood | Disruption lasting weeks; cost the UK economy close to £2 billion |
Marks & Spencer: Weeks of disruption and a 99% profit drop
Marks & Spencer was first to feel the impact. The retailer confirmed a cyberattack over the Easter weekend in March 2025 after detecting unusual activity across its systems. Online ordering was paused while the business worked to contain the incident. For several weeks, disruption rippled through digital operations and the supply chain.
Its household-name status brought with it heavy press coverage and significant financial scrutiny. Statutory profit before tax fell 99%, from £391.9m to £3.4m for the first half of the year. Services have since been restored, but the financial impact of those weeks was hard to ignore.
Co-op: 6.5 million members’ data exposed and £206m in lost revenue
The Co-op Group disclosed its own incident shortly after, when attackers gained access to core systems in late April. Ordering and logistics were disrupted, some stores reverted to manual processes and cash-only operations, and the personal data of around 6.5 million members was exposed.
The financial toll was significant. The attack contributed to an £80 million hit to operating profit and around £206 million in lost revenue in the first half of 2025. Despite that, the business did manage to restore systems and stabilise operations over the following months.
Harrods: Fast containment meant stores stayed open
Harrods confirmed it had restricted access to parts of its systems after detecting an attempted intrusion in early May. The business moved quickly to shut down sections of its IT infrastructure while investigations were carried out. Unlike the incidents before it, the disruption was largely contained before it could significantly affect operations. Both physical stores and online services continued to trade.
That swift containment is likely why the incident avoided the same level of operational and financial fallout. Decisive action in the early stages paid off. Following two high-profile incidents before it, heightened vigilance may also have played a part in the business's readiness.
Jaguar Land Rover: Production halted, £2 billion hit to the UK economy
Later in the year, attention shifted from retail to manufacturing. Jaguar Land Rover suffered a cyberattack that forced the company to halt production across several UK plants, including Solihull and Halewood. Manufacturing lines were brought to a standstill while systems were taken offline and investigations began, with production disruption lasting weeks.
Because modern car manufacturing relies on interconnected digital systems and just-in-time supply chains, the impact spread quickly beyond JLR itself. Suppliers paused deliveries, dealerships faced delays, and analysts later suggested the disruption cost the UK economy close to £2 billion. Into 2026, JLR continued to report losses directly tied to the incident.
{{snapshot}}
What set the fast recoverers apart
- Cyber incidents are rarely a question of if, but of when — what matters is the response.
- Businesses with structured security frameworks have documented incident response, risk management and reporting.
- Frameworks like ISO 27001 force governance, accountability and response planning before a crisis arrives.
- Harrods shows it working: fast containment, stores stayed open, minimal financial loss.
{{/snapshot}}
So how did some businesses recover quicker than others?
The tricky reality of cyber incidents is that it is rarely a question of if, it is a question of when. What matters far more is how organisations respond once systems are compromised and if they are ready for it.
Businesses that already have structured security frameworks in place are often better prepared because they have documented processes for incident response, risk management and reporting. Frameworks like ISO 27001 force organisations to think about governance, accountability and response planning before a crisis arrives. Without that structure, organisations often find themselves trying to build those processes in the middle of an incident, which extends disruption and increases regulatory exposure.
The Harrods response illustrates this well. Containment was fast, stores stayed open, and the financial loss was minimal compared to the incidents that preceded it. Preparation like this is what separates the businesses who recover fast and those who suffer from attacks like these.
This risk for organisations going forward…
As cyber incidents become more common, there is a real danger that organisations start to accept them as the cost of doing business, which is a massive mistake to make when there are easy ways to prepare.
Cyber warfare is a constant threat, and digital infrastructure has become a target in global conflicts. Large multinationals may have the resources to absorb the shock of a major incident, while many other organisations do not have that option. Cash-strapped public services, local authorities and the small and medium-sized businesses that make up the backbone of the UK economy could struggle to survive a serious attack. For organisations that serve communities directly, whether that is hospitals, councils or essential local services, prolonged disruption carries a human cost that goes well beyond the only financial risks.
{{snapshot}}
Lessons for resilience
- The fastest to bounce back had the governance, visibility and preparation to restore operations with confidence.
- Compliance achieved at a point in time does not translate into operational resilience.
- Regulators and partners now ask whether controls operate consistently and whether evidence can be produced.
- Treat preparation and resilience as something built before the incident, not a reaction to it.
{{/snapshot}}
How can organisations avoid this risk?
A year on from the cyber chaos of 2025, here is what businesses should take away from these incidents:
The organisations that bounced back fastest were not necessarily those that avoided disruption altogether. They were the ones with the governance, visibility and preparation in place to respond quickly and restore operations with confidence.
Compliance achieved at a point in time does not translate into operational resilience. Regulators and partners are increasingly asking not just whether controls exist, but whether they are operating consistently and whether evidence can be produced when needed.
If we want to protect the organisations that underpin our communities and economy, we need to move beyond accepting disruption as the new normal and start treating preparation and resilience as something that must be built before the incident, rather than reaction.
How can we help?
Hicomply helps organisations embed compliance into day-to-day operations, so evidence is ready when regulators, boards or partners ask for it. To see how continuous compliance works in practice, book a demo at www.hicomply.com/get-a-demo
{{snapshot}}
Hicomply's take
Hicomply recommends measuring recovery by the strength of the operating evidence behind cyber resilience, not just public statements after disruption. Keep incident response, supplier assurance and control ownership live so teams can prove resilience through frameworks such as ISO 27001.
{{/snapshot}}







%20(1).png)
%20(1).png)
