Disaster Recovery in the Real World: Lessons from the M&S Cyberattack

When organisations talk about cybersecurity, the focus is often on prevention, firewalls, vulnerability scans and patch management. But even the best defences can be breached. What happens next depends entirely on how well your business has planned for the worst. The recent cyberattack on Marks & Spencer is a powerful case study in the importance of disaster recovery.
The Attack That Stopped a Retail Giant in Its Tracks
In April 2025, M&S experienced a major cyber incident believed to have been carried out by the hacking group Scattered Spider. The attackers gained access to internal systems, deployed ransomware, and caused chaos across the company’s operations.
The impact was immediate and widespread:
– Online orders and click and collect suspended
– Payment systems and stock deliveries disrupted
– Job listings pulled and recruitment paused
– Customer frustration and reputational damage
– Over £650 million lost in market value
Despite no confirmed loss of customer data, the operational toll was immense. The situation made it clear: M&S didn’t just face a security breach—it faced a full-scale business disruption.
Disaster Recovery: More Than Backups
Disaster recovery (DR) isn’t just about having backups of your data. It’s about your ability to restore systems, processes, and trust in the shortest time possible. It’s your game plan when the worst happens.
From the outside looking in, the M&S response highlights several key lessons:
Speed Is Everything
Disaster recovery plans must outline how quickly critical systems can be restored. If your online services are down for days or weeks you risk not only losing revenue but long-term customer loyalty. M&S encouraged shoppers to visit stores in person during the outage, but for many, that simply wasn’t feasible.
Communication Is Critical
M&S leadership, including CEO Stuart Machin, publicly acknowledged the disruption and urged patience. This transparency helped maintain some level of trust. But without clear internal and external communication protocols, organisations can fuel speculation and damage their reputation even further.
Is Your DR Plan Tested, and Really Tested?
Too many businesses treat DR as a checklist exercise. They might have backups and a plan written down, but when was the last time it was actually tested in a live simulation? Would your team know what to do if systems went down for a week? Could they function without core platforms?
People Are Part of the Plan
The M&S workforce faced slow tills, delayed deliveries, and confused customers. A good Disaster Recovery plan should include role-specific procedures, fallback processes, and ongoing staff training, especially for customer facing teams who often bear the brunt of operational fallout.
The Takeaway: You Can’t Prevent Every Attack, But You Can Prepare for Recovery
Cybersecurity isn’t fool proof. Threat actors are constantly evolving. Even with robust defences, no business is immune to compromise. But what separates resilient organisations from the rest is how they respond and recover.
Ask yourself:
Can your business function without internet access for 48 hours?
If your payment systems were encrypted overnight, how would you process transactions?
Who and how would you communicate with customers, staff, suppliers?
The time to answer those questions is now, not after an incident.
A tested disaster recovery plan is not a luxury. It’s business critical.
Don’t wait for a breach to expose your gaps. Invest in a Disaster Recovery plan now.
For more information or a confidential chat, contact info@ds-cic.com

