Your Cyber Security Is Only as Strong as Your People

By: Ben Fielding | Estimated Reading Time: 3 minutes

The Real Risk of Social Engineering

Imagine spending thousands (maybe even millions) on firewalls, endpoint protection, and backup systemsโ€ฆ only for an attacker to stroll right through the front door. Thatโ€™s exactly what happened to Marks & Spencer and the Co-op in a recent cyberattack that sent shockwaves across UK retail. Despite having access to the latest IT infrastructure, hackers didnโ€™t need to breach the system through brute force or advanced malware. Sources report they simply tricked someone into letting them in.

This is the danger of social engineering. It’s a risk that no tool can fully eliminate without the right processes and training.


The M&S Attack: A Costly Lesson in Human Vulnerability

In April, Marks & Spencer found itself at the centre of a major cyber incident. Payments stopped working, online orders failed, and hundreds of agency workers were told not to come in. Within days, the company had lost ยฃ650 million in value.

So what happened?

Hackers from the infamous Scattered Spider group contacted IT help desks at both M&S and the Co-op, pretending to be employees. They manipulated support staff into resetting passwords and unknowingly granting access to internal systems. Once inside, the attackers were able to escalate privileges and pave the way for further damage.

This wasnโ€™t a software flaw. It wasnโ€™t a missing patch.
It was a human being trying to help and that instinct was exploited.


Social Engineering: The Oldest Trick in the Book

Unlike technical hacks, social engineering relies on deception and trust. Itโ€™s a digital con job, where attackers pose as colleagues, clients, or support providers to convince someone to click a link, share credentials, or reset a password.

In the M&S case, all it took was a convincing voice, a believable story, and a few minutes on the phone.

Thatโ€™s the uncomfortable truth:

Even the most secure IT system can be undermined by a single conversation.


Technology Canโ€™t Fix Human Error But Training Can

This is why cybersecurity training isnโ€™t optional. Itโ€™s essential. Your staff (from the front desk to IT support) are your first and last line of defence. Hereโ€™s what businesses need to do:

  • Regular Cyber Awareness Training: Teach your team how to spot phishing emails, suspicious requests, and the signs of impersonation. Role-playing exercises work wonders.
  • Strict Identity Verification for Internal Requests: Especially around sensitive processes like password resets or admin access. No ID, no change, no exceptions.
  • Limit Access, Especially for Admin Accounts: Most attacks escalate because of excessive permissions. Use the principle of least privilege and audit access regularly.
  • Implement and Review Help Desk Protocols: As advised by the NCSC, make sure your support team has clear, robust procedures to handle identity checks, especially under pressure. Your company or IT support team might not small enough to know everyone.
  • Monitor and Test with Penetration Simulations: See where your weak points are before attackers do. A good pen test doesn’t just probe systems. It tests processes and people, too.

Itโ€™s Not Just About Tools. Itโ€™s About Trust.

At Nxt Gen IT, we believe that security isnโ€™t a product. Itโ€™s a culture. The latest tech is vital, but real protection comes from a team that understands the role they play in keeping your business safe.

We help organisations go beyond firewalls and antivirus software to build a human firewall. Your staff trained, empowered, and supported by strong processes that make secure behaviour second nature.


Nxt Steps

If you’re unsure whether your people are your weakest link or your strongest asset, we can help you find out.

Book a Cyber Awareness Audit with our team. We’ll assess your current training, processes, and IT support policies to identify the gaps before an attacker does.

Or simply get in touch for a chat about strengthening your human defences because in cyber security, the door is only closed if everyone knows not to open it.

Letโ€™s turn your people into your best protection.
Get in touch with Nxt Gen IT today.