#245: Applying Zero Trust to Modern Identity AttacksLessons from Transport for London and Marks & Spencer, p. 1Key Takeaways
The cyber attacks affecting TfL and M&S have become two of the most widely discussed security incidents in the United Kingdom over the past two years. Although the organisations operate in completely different sectors, the attacks demonstrate several common characteristics that have become increasingly familiar to cybersecurity professionals. Public reporting indicates that both incidents involved identity compromise and social engineering rather than highly sophisticated software exploitation, illustrating how attackers continue to prioritise trusted access over technical complexity. Like many modern incidents, relatively little has been publicly disclosed about the complete technical details of either compromise. Organisations rarely publish full forensic investigations, while law enforcement and criminal proceedings often limit the amount of operational information that becomes available. Any external analysis must therefore distinguish between confirmed information, official statements, and informed observations based upon publicly available reporting. This is, in short, an admission that some aspects of the information we have is limited and we should prepare maximally on that minimal information Zero Trust—AppliedThese incidents also raise an important architectural question. If attackers succeed in obtaining valid credentials or convincing an organisation to grant them legitimate access, what happens next? Traditional security architectures often assumed that authentication represented the beginning of trust: once users successfully logged in, they were generally considered trustworthy until they logged out again. Modern enterprise environments are considerably more complex and, as such, that assumption has become increasingly difficult to justify. This is precisely the challenge that the NIST SP 800-207 seeks to address. Rather than attempting to build an impenetrable perimeter around enterprise systems, Zero Trust assumes that compromise is possible and designs security controls accordingly. Every access request is evaluated continuously, trust is never considered permanent and security decisions are based upon multiple contextual factors rather than authentication alone. Viewed through this lens, the TfL and M&S attacks provide useful case studies for understanding how |