{"id":9567,"date":"2025-09-15T04:08:00","date_gmt":"2025-09-15T04:08:00","guid":{"rendered":"https:\/\/sawahsolutions.com\/lap\/ms-undergoes-leadership-shake-up-and-accelerates-digital-overhaul-after-cyberattack\/"},"modified":"2025-09-15T07:50:52","modified_gmt":"2025-09-15T07:50:52","slug":"ms-undergoes-leadership-shake-up-and-accelerates-digital-overhaul-after-cyberattack","status":"publish","type":"post","link":"https:\/\/sawahsolutions.com\/lap\/ms-undergoes-leadership-shake-up-and-accelerates-digital-overhaul-after-cyberattack\/","title":{"rendered":"M&#038;S undergoes leadership shake-up and accelerates digital overhaul after cyberattack"},"content":{"rendered":"<p><\/p>\n<div>\n<p>Following a damaging cyberattack attributed to social engineering tactics, Marks &amp; Spencer is re-evaluating its leadership and fast-tracking its digital recovery efforts amidst significant financial and operational upheaval.<\/p>\n<\/div>\n<div>\n<p>Marks &amp; Spencer (M&amp;S) is navigating a period of significant upheaval following a debilitating cyberattack that has had profound financial and operational consequences for the British retailer. Rachel Higham, the company\u2019s Chief Digital and Technology Officer, has departed just months after the attack, which forced the shutdown of M&amp;S\u2019s online operations and left physical stores struggling with empty shelves. According to an internal memo, Higham, who joined M&amp;S in 2014 from roles at WPP and BT Group, is &#8220;stepping back from her role&#8221; after a turbulent period for the business. The company commended her as &#8220;a steady hand and calm head at an extraordinary time,&#8221; though she is understood to be taking a career break. Sacha Berendji, a seasoned executive within M&amp;S, has been appointed to head the digital and technology division alongside his current duties.<\/p>\n<p>The cyberattack, attributed to a hacker group known as Scattered Spider, exploited human vulnerabilities rather than technical flaws in M&amp;S\u2019s defences. Investigations revealed that the attackers breached the retailer\u2019s systems via social engineering tactics targeting a third-party contractor, bypassing M&amp;S\u2019s own digital safeguards. This sophisticated intrusion occurred over the Easter weekend in April and subsequently led to a near four-month suspension of parts of M&amp;S\u2019s digital operations, including the popular &#8216;click and collect&#8217; service. The National Crime Agency is investigating the group reportedly responsible. Despite the severe impact, M&amp;S has refrained from commenting on any ransom demands, citing law enforcement guidance.<\/p>\n<p>Financially, the breach has been catastrophic. Industry estimates project a \u00a3300 million hit to M&amp;S\u2019s operating profit for the current financial year, coupled with a market capitalisation loss approaching \u00a3750 million. CEO Stuart Machin has emphasised that the setback, largely due to human error linked to the third-party contractor, has overshadowed an otherwise strong year for the company, which reported a 22% rise in adjusted pre-tax profits to \u00a3875.5 million and 6.1% sales growth to nearly \u00a314 billion. M&amp;S is employing various strategies to mitigate the losses, including cost management and insurance claims, with hopes of recovering around half the estimated impact.<\/p>\n<p>Amidst this turmoil, leadership stability has been a topic of internal discussion. The company is reportedly considering extending the tenure of Chairman Archie Norman beyond the typical UK-recommended nine-year limit, given his pivotal role in steering M&amp;S through a turnaround and now through this crisis. The final decision rests with the board and shareholders.<\/p>\n<p>Adding complexity to the situation is the involvement of Tata Consultancy Services (TCS), M&amp;S\u2019s primary technology partner since 2018. TCS is conducting an internal probe to determine whether its systems served as the entry point for the attack. M&amp;S CEO Machin has declined to specify whether ransom payments were made or to confirm TCS\u2019s direct involvement, while both parties maintain silence on these details. This incident has also cast a shadow over TCS\u2019s reputation, highlighting the growing cybersecurity risks faced by global IT service providers.<\/p>\n<p>Despite the setbacks, M&amp;S asserts its commitment to accelerating its technology transformation, compressing initially planned digital overhaul timelines from two years into six months, in an effort to fortify its systems against future threats. The company\u2019s leadership changes and strategic focus underscore the critical importance of digital resilience in the retail sector as cyber threats become increasingly sophisticated.<\/p>\n<h3>\ud83d\udccc Reference Map:<\/h3>\n<p>Source: <a href=\"https:\/\/www.noahwire.com\" rel=\"nofollow noopener\" target=\"_blank\">Noah Wire Services<\/a><\/p>\n<\/p><\/div>\n<div>\n<h3 class=\"mt-0\">Noah Fact Check Pro<\/h3>\n<p class=\"text-sm\">The draft above was created using the information available at the time the story first<br \/>\n        emerged. We\u2019ve since applied our fact-checking process to the final narrative, based on the criteria listed<br \/>\n        below. The results are intended to help you assess the credibility of the piece and highlight any areas that may<br \/>\n        warrant further investigation.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Freshness check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>8<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The narrative is recent, with the earliest known publication date being 11 September 2025. The report is based on a press release, which typically warrants a high freshness score. However, the narrative has been republished across multiple outlets, including Reuters and Cybernews, indicating widespread dissemination. No significant discrepancies in figures, dates, or quotes were found.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Quotes check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>9<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>Direct quotes from the internal memo and company statements are consistent across sources. No earlier usage of these exact quotes was found, suggesting original or exclusive content.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Source reliability<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>9<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The narrative originates from reputable organisations, including Reuters and Cybernews, enhancing its credibility. The involvement of well-known entities like Marks &amp; Spencer and the National Crime Agency further supports the reliability of the information.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Plausability check<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Score:<br \/>\n        <\/span>8<\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Notes:<br \/>\n        <\/span>The claims align with known events, such as the cyberattack attributed to Scattered Spider and the departure of Rachel Higham. The narrative includes specific details, such as the \u00a3300 million estimated impact on operating profit, which are consistent with previous reports. The language and tone are appropriate for the context, and there are no signs of excessive or off-topic detail.<\/p>\n<h3 class=\"mt-3 mb-1 font-semibold text-base\">Overall assessment<\/h3>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Verdict<\/span> (FAIL, OPEN, PASS): <span class=\"font-bold\">PASS<\/span><\/p>\n<p class=\"text-sm pt-0\"><span class=\"font-bold\">Confidence<\/span> (LOW, MEDIUM, HIGH): <span class=\"font-bold\">HIGH<\/span><\/p>\n<p class=\"text-sm mb-3 pt-0\"><span class=\"font-bold\">Summary:<br \/>\n        <\/span>The narrative is recent and based on reputable sources, with consistent and plausible claims. The use of direct quotes and specific details supports its credibility. No significant issues were identified, leading to a high confidence in the assessment.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Following a damaging cyberattack attributed to social engineering tactics, Marks &amp; Spencer is re-evaluating its leadership and fast-tracking its digital recovery efforts amidst significant financial and operational upheaval. Marks &amp; Spencer (M&amp;S) is navigating a period of significant upheaval following a debilitating cyberattack that has had profound financial and operational consequences for the British retailer.<\/p>\n","protected":false},"author":1,"featured_media":9568,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40],"tags":[],"class_list":{"0":"post-9567","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-london-news"},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/posts\/9567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/comments?post=9567"}],"version-history":[{"count":1,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/posts\/9567\/revisions"}],"predecessor-version":[{"id":9569,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/posts\/9567\/revisions\/9569"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/media\/9568"}],"wp:attachment":[{"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/media?parent=9567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/categories?post=9567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sawahsolutions.com\/lap\/wp-json\/wp\/v2\/tags?post=9567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}