Key Takeaways
Cybersecurity incidents are often analysed individually. A breach affecting a transport organisation is viewed as a critical infrastructure problem, while an attack against a retailer is treated as a business continuity issue. However, examining major incidents together often reveals broader trends that are less obvious when each event is considered in isolation. The cyberattacks affecting Transport for London (TfL) and Marks & Spencer (M&S) provide a useful comparison because they represent two different organisations facing a similar style of modern threat. One operates a public transport network used by millions of people, while the other manages one of the UK’s most recognisable retail brands. Despite the differences in their missions, both incidents demonstrate how attackers increasingly target identity, trust and operational processes rather than relying solely on technical exploitation. The attacks also challenge some long-standing assumptions about cybercrime. Significant disruption has historically been associated with highly advanced adversaries using sophisticated malware or previously unknown vulnerabilities. Recent incidents suggest a different reality. Attackers can achieve substantial operational impact by combining social engineering, stolen credentials, legitimate administrative access and knowledge of how organisations function. The most important lesson from both incidents is that modern cybersecurity is increasingly about protecting trust. Organisations no longer operate within clearly defined network boundaries, and attackers understand that compromising a legitimate identity can provide more value than attempting to bypass technical controls directly. The Transport for London Cyber AttackTransport for London disclosed in September 2024 that it had experienced a cyber incident affecting parts of its n |