The recent headlines were hard to miss as Harrods, M&S, and the Co-op we’re all caught out by serious cyber incidents within weeks of each other. But this wasn’t a wave of cutting-edge cyber-attacks — it was a combination of basic social engineering exploits (impersonating users to the IT helpdesk for password resets) and a lack of standard cybersecurity practices. These weren’t just accidents, they were predictable, preventable, and avoidable oversights. And, if such well-known brands like these can fall victim, SMEs must ask themselves: are we asking the right questions, or just hoping for the best?
When cyber complacency becomes cyber consequence
The real story as three of the UK’s most iconic brands, Harrods, M&S, and the Co-op have all made headlines isn’t in what happened. It’s in why it happened and why it keeps happening.
The incursions were not highly sophisticated attacks by cutting-edge cybercriminals. The techniques used — social engineering, impersonation, and the lack of core system separation have been around for decades. What’s shocking is that large, well-resourced organisations are so vulnerable to them.
At M&S and the Co-op, attackers reportedly tricked service desks into resetting passwords by impersonating staff. In M&S’s case, it seems those credentials gave access across critical systems, including their hosting environment, a sequence of events that should never have been possible. At Harrods, details remain limited, but their response, a full shutdown of internet access across all sites, points to a lack of containment capability.
This wasn’t pure bad luck. It was bad design.
Big budgets. Bigger blind spots.
Many SME leaders may see these stories and think: “That wouldn’t happen to us.” But that’s a dangerous takeaway.
These are businesses with enormous resources, IT teams, consultants, and security vendors. If they’re still getting caught out by basic attack vectors, it means the issue isn’t capability — it’s mindset.
The painful truth is that most organisations aren’t investing in cyber security because they’ve pro-actively assessed the risk. They’re investing because they’ve waited too long and experienced a breach.
In other words: These big brands weren’t asking the right questions. And neither are most SMEs.
Are you protected — or just lucky so far?
A business’s resilience isn’t defined by how strong its tech stack looks on paper. It’s defined by how its systems work in practice:
- Are your core systems segmented from user access?
- Is there identity and location-based access control in place?
- Can your staff follow clear, tested processes in response to suspicious activity?
- Are your internal IT staff trained to detect impersonation — or better yet, protected by tools that can?
If the answer to any of these is “I’m not sure,” you’re very likely not alone. But that’s exactly why so many businesses are still vulnerable.
Stop guessing. Start securing.
These incidents weren’t just breaches — they were warnings. Warnings that strategy gaps, technical oversight, and weak processes are being exploited daily. Warnings that even the biggest brands, with access to all the best tools, are still getting the basics wrong.
We work with ambitious SMEs who want to avoid that fate, by building a more resilient foundation. From isolating critical systems to deploying practical features like location-based access controls and conditional MFA, we help organisations make informed, effective decisions.
This isn’t about scare tactics. It’s about clarity.
If someone tried to breach your business today, would they succeed? If you don’t know, we should talk.



