News: 1750678173

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Experts count staggering costs incurred by UK retail amid cyberattack hell

(2025/06/23)


Britain's Cyber Monitoring Centre (CMC) estimates the total cost of the cyberattacks that crippled major UK retail organizations recently could be in the region of £270-440 million ($362-591 million).

The organization – which [1]launched earlier this year and introduced standardized grading of cyberattacks – gave the criminals' digital intrusions of retail outlets across the country high marks, characterizing them as a category 2 systemic event.

[2]Marks & Spencer , the [3]Co-op, and Harrods were all targets. Luxury Brit retailer Harrods said its flagship store remained open and continued to operate its online sales at the time of the attack, so the impact there may have been far less. At any rate, CMC did not include its data due to the low level of info disseminated about their attack.

[4]

The CMC's Cyber Monitoring Matrix grades systemic cyber events between category 0 for the lowest impact and category 5 for the highest. Overall impact is determined by how many people are affected by any given attack, and by the financial impact.

[5]

[6]

In its public assessment statement, the CMC said: "The impact from this event is 'narrow and deep,' having significant implications for two companies, and knock-on effects for suppliers, partners, and service providers. This contrasts with a 'shallow and broad' event like last year's CrowdStrike event, where a large number of businesses across the economy were affected, but the impact to any one company was far smaller.

"We are yet to see a deep and broad category 4 or category 5 event impact the UK. Had there been further widespread disruption in the sector, the categorization could have been higher, but because the impact was confined to two companies and their partners, it is judged to be at the lower end of severity on the CMC's scale."

[7]

It previously said that [8]CrowdStrike's outage last year would have been designated a category 3 systemic event, had the CMC been launched at the time, due to the scale of its impact across the UK.

CrowdStrike's faulty file update – which inadvertently led to what has been described as the [9]largest IT outage in history – may have earned category 4 status if it was a malicious cyberattack, instead of a faulty sensor update. This is because of the increased costs involved in cleaning up attacks, said the org. Hypothetically, an example of a cat-5 attack would be Russia's [10]NotPetya campaign.

The CMC said M&S and Co-op were likely losing big on things like lost sales, as well as incident response, IT restoration, and legal counsel.

[11]

The model used by the CMC indicates that the cost to retailers unable to fulfil normal sales could be in the region of £1.3 million ($1.74 million) per day. For M&S, its online orders weren't expected to return until July, but have since been partially restored, limiting the daily losses from sales.

Fable Data informed the CMC's assessment of lost revenues; it indicated that M&S had to contend with a 22 percent reduction in daily spend [12]while online shopping was unavailable . Early reports focused on [13]contactless payments being down in stores , and while in-store purchases fell by around 15 percent, pausing online sales had the biggest impact on the retailer's financials, dropping to near zero.

The same data indicated that Co-op had a slightly better time of things, with daily spend dropping just 11 percent for the first 30 days after its attack.

While Co-op's financials may have taken less of a hit, it could be argued the impact of its attack on parts of the UK was much greater than that of M&S. Co-op acts as a sole provider in remote and rural areas such as the Scottish Highlands and the islands around the Scottish coast.

About the CMC

The assessment of the recent [14]UK retail attacks is the first contemporary incident categorization to come from the world-first CMC.

At launch, it offered theoretical assessments based on previous attacks, but the hits on UK retail mark the first time the CMC has been called into action since it was founded.

The CMC is chaired by the UK NCSC's former founding CEO [15]Ciaran Martin , and is comprised of cybersecurity experts and finance specialists.

The whole idea behind organizing the CMC was to remove the ambiguity around what constitutes a systemic cyber event – crucially one that allows cyber insurers to claim on their reinsurance policies.

Systemic risk remains a pain point for the insurance industry, largely because it lacks a clear, standardized definition. Due to this, different parties can be confused by an insurance policy's terms, and whether it could or should pay out.

[16]UK industry leaders unleash hurricane-grade scale for cyberattacks

[17]CrowdStrike still doesn't know how much its Falcon flame-out will cost

[18]Cyber fiends battering UK retailers now turn to US stores

[19]M&S stops online orders as 'cyber incident' issues worsen

The CMC pitches itself as more than a body to help insurers claim on their own protection policies. The reports it promises to produce on systemic events that lead to losses of £100 million ($133 million) or more will, we're told, feed into national security and cyber resilience discussions that could help more than just those organizations caught up in the attacks it assesses.

Its role could also evolve in the future. CEO Will Mayes said that if the UK government introduced a backstop to cover systemic cyberattacks that lead to massive costs, the CMC could potentially be called in to say whether additional funding should be released.

Experts speaking to The Register at the CMC's February launch were broadly positive about the organization, although there was a feeling that the non-profit would have to prove its worth over the long term. ®

Get our [20]Tech Resources



[1] https://www.theregister.com/2025/02/07/uk_cyber_monitoring_centre/

[2] https://www.theregister.com/2025/05/13/ms_confirms_customer_data_stolen/

[3] https://www.theregister.com/2025/05/02/ncsc_steps_in_as_harrods/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aFl6E7P5ui9jtSu596KuTwAAAQU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aFl6E7P5ui9jtSu596KuTwAAAQU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aFl6E7P5ui9jtSu596KuTwAAAQU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aFl6E7P5ui9jtSu596KuTwAAAQU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/11/27/crowdstrike_q3_2025/

[9] https://homeland.house.gov/2024/07/22/chairmen-green-garbarino-request-public-testimony-from-crowdstrike-ceo-following-global-it-outage/

[10] https://www.theregister.com/2017/06/28/petya_notpetya_ransomware/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aFl6E7P5ui9jtSu596KuTwAAAQU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2025/04/25/ms_halts_online_orders/

[13] https://www.theregister.com/2025/04/22/marks_spencer_cyber_incident/

[14] https://www.theregister.com/2025/05/15/cyber_scum_attacking_uk_retailers/

[15] https://www.theregister.com/2024/03/04/experts_echo_calls_for_ransomware/

[16] https://www.theregister.com/2025/02/07/uk_cyber_monitoring_centre/

[17] https://www.theregister.com/2024/11/27/crowdstrike_q3_2025/

[18] https://www.theregister.com/2025/05/15/cyber_scum_attacking_uk_retailers/

[19] https://www.theregister.com/2025/04/25/ms_halts_online_orders/

[20] https://whitepapers.theregister.com/



Rate my breach

elsergiovolador

The Cyber Monitoring Centre isn’t about prevention - it’s about formalising failure.

It doesn’t enforce investment, improve resilience, or hold anyone accountable. It just gives disasters a neat classification so insurers and execs can do risk maths on a spreadsheet.

Because let’s be honest: most corporations have already done their cost-benefit analysis.

Pay local talent properly and invest in robust systems? Too expensive.

Outsource everything, gamble on thin defences, and when it all burns down - shrug, file a report, and pass the cost to customers.

It’s not a strategy, it’s managed neglect.

Imagine if construction firms skimped on concrete, and instead of enforcing safety, we built a “Building Collapse Monitoring Centre” to grade the rubble.

That’s where we are.

Re: Rate my breach

ecofeco

Who has to imagine construction companies cutting corners and ending in disaster? :) Plenty of examples already exist. Contemporary ones at that.

The problem is indeed about managed neglect and it's found across all industries. And I wouldn't even say it's managed, just neglected and perfectly acceptable due to lobbying and backhanders and lots of quid pro quo.

Re: Rate my breach

StewartWhite

'Imagine if construction firms skimped on concrete, and instead of enforcing safety, we built a “Building Collapse Monitoring Centre” to grade the rubble.'

They already have - witness the RACC scandal in schools and hospitals.

Re: Rate my breach

elsergiovolador

Looks like it's becoming a very British tradition:

“What are you looking at?”

“Oh, just another catastrophic failure.”

“Thinking of how to fix it?”

“No, just figuring out how to rate it.”

"Nice sarcasm."

"What?"

"Surely you are not going to just rate? Sorry to be this guy."

"No, this is exactly what I am doing!"

"Oh, sarcasm again? Nice one."

"For umpteenth time! I am going to assign a rating to it!"

"Why?"

"To see how it compares to other catastrophic failures."

"And?"

"What do you mean, and? I'll keep calm and carry on."

Re: Rate my breach

Blazde

managed neglect

This is the sad reality of the British bricks n' mortar retail space, with it's twin ball and chain of long-term leases on once prime real estate that now suffers unfair business rates and effectively shuts them out of the efficient online-only business model, and the cultural legacy of defined benefit pension scheme obligations. Ultimately the neglect is a central government decision.

Maybe I'll eat my words one day but it's hard to imagine Amazon online sales being 'down until July'. It's not too expensive for them to invest in robust systems.

Re: Rate my breach

elsergiovolador

that now suffers unfair business rates and effectively shuts them out of the efficient online-only business model,

I don’t want to nitpick, but even online-only operations face business rates - their warehouses and offices are often far larger and more expensive than a single high street shop. And yes, they have long-term leases too.

The notion that e-commerce avoids these burdens is a convenient myth.

Yeah, whatever ....

JimmyPage

Sorry, this is what happens when you decide your shareholders and dividends are more important than your core business.

"But our core business is retail"

No, my dim COE friend. Your core business is IT. You just happen to have the terminals in shops.

"But our business is banking"

No, my dim COE friend. Your core business is IT. You just happen to have the terminals in shops.

&c &c

Many years ago, a very intelligent friend commented that it was stupid to allow a lot of experience and talent to slosh around underemployed in the economy as the damage they could do was far greater than the damage the same number of YTS* placements could do. This was when floppy borne viruses were around.

*Youth Training Scheme. An early source of cheap unskilled labour.

Re: Yeah, whatever ....

ecofeco

Oh, we just call them interns now. :)

Aaaaand...

Anonymous Coward

So you'll be investing how much more in your cyber security 10%? 5%? 0%?

Oh you're actually planning cuts.

No shock really

This TOPS OFF my partygoing experience! Someone I DON'T LIKE is
talking to me about a HEART-WARMING European film ...