Recent cyber attacks targeting major British businesses, including Marks & Spencer, Co-op, and Harrods, have put businesses on high alert. These attacks have exposed vulnerabilities in IT systems, with cybercriminals increasingly using sophisticated social engineering techniques to bypass security measures. For businesses, this is a wake-up call to review their cybersecurity strategy and take swift action to protect their organisations.
Cybercriminals are Adapting Quickly
According to a warning issued by the National Cyber Security Centre (NCSC), cybercriminals are now impersonating IT help desks to infiltrate organisations. Through tactics like email phishing and voice scams, hackers trick employees into revealing login credentials and security codes, while also targeting help desk staff by posing as locked-out employees.
The group behind these latest attacks have successfully targeted multiple businesses, stealing sensitive customer and employee data. These incidents emphasise the growing threat of financially motivated hackers employing advanced methods to exploit vulnerabilities in organisational systems.
What’s Behind the Rise in Social Engineering?
Social engineering is increasingly among the top techniques used by hackers today. It exploits psychological manipulation to deceive employees into divulging confidential information or granting access to secure systems. Whether through a convincing email that appears to be from an internal department or a phone call with a false sense of urgency, the goal is the same—to bypass traditional security measures.
Organisations with employees managing IT systems, financial databases, or customer data face significant risks. One vulnerability in your team could lead to a breach that compromises your entire operation.
Key Actions Your Business Should Take
To protect your organisation from falling victim to these types of cyberattacks, it’s crucial to take proactive measures. These essential steps can help safeguard your systems, data, and operations from potential threats.
- Reassess Password Reset Procedures
Ensure that your IT policies for password resets are robust. Multi-step authentication and verification are required to confirm the identity of any employee requesting access.
- Deploy Multiple Layers of Security
Adopt advanced protection tools, such as multi-factor authentication (MFA), endpoint detection systems, and encrypted access. Solutions like Keeper‘s password management platform can help securely manage login credentials and mitigate risky behaviour.
- Invest in Employee Training
Educate your staff on identifying phishing emails, suspicious phone calls, and other social engineering techniques. Platforms like KnowBe4 provide industry-leading security awareness training with realistic phishing simulations to prepare employees for real-world scenarios.
- Monitor Suspicious Activities
Regularly review employee login behaviour for unusual activity, such as access requests at odd hours or from unfamiliar locations. Active monitoring ensures that vulnerabilities are detected and addressed before being exploited.
- Code Words for Verification
Implementing unique code words for sensitive requests. This added layer of protection helps validate the authenticity of internal communications, ensuring greater security and peace of mind.
How MRD Technologies Can Help
At MRD Technologies, we understand that cybersecurity is not one-size-fits-all. Our experts provide tailored solutions to help your business meet the latest cybersecurity standards while safeguarding your operations. We offer:
- Cyber Essentials Certification to ensure baseline security standards.
- Keeper Password Management to protect against compromised credentials.
- KnowBe4 Training to arm your team with the knowledge to combat sophisticated cyber threats.
Staying Ahead of the Threat Landscape
The age of opportunistic cybercrime is evolving into a battleground of increasingly organised and innovative attacks. Businesses must adopt proactive measures to stay one step ahead of hackers, such as those behind the recent incidents at M&S, Co-op, and Harrods. Protecting your organisation begins with recognising the risks and implementing advanced tools to mitigate them.
MRD Technologies is here to help you strengthen your cybersecurity defences and equip your team with the best solutions and training during these uncertain times. Don’t wait until it’s too late. Take action now to ensure your business remains secure.





