The Real Risk of Social Engineering
Imagine spending thousands (maybe even millions) on firewalls, endpoint protection, and backup systemsโฆ only for an attacker to stroll right through the front door. Thatโs exactly what happened to Marks & Spencer and the Co-op in a recent cyberattack that sent shockwaves across UK retail. Despite having access to the latest IT infrastructure, hackers didnโt need to breach the system through brute force or advanced malware. Sources report they simply tricked someone into letting them in.
This is the danger of social engineering. It’s a risk that no tool can fully eliminate without the right processes and training.
The M&S Attack: A Costly Lesson in Human Vulnerability
In April, Marks & Spencer found itself at the centre of a major cyber incident. Payments stopped working, online orders failed, and hundreds of agency workers were told not to come in. Within days, the company had lost ยฃ650 million in value.
So what happened?
Hackers from the infamous Scattered Spider group contacted IT help desks at both M&S and the Co-op, pretending to be employees. They manipulated support staff into resetting passwords and unknowingly granting access to internal systems. Once inside, the attackers were able to escalate privileges and pave the way for further damage.
This wasnโt a software flaw. It wasnโt a missing patch.
It was a human being trying to help and that instinct was exploited.
Social Engineering: The Oldest Trick in the Book
Unlike technical hacks, social engineering relies on deception and trust. Itโs a digital con job, where attackers pose as colleagues, clients, or support providers to convince someone to click a link, share credentials, or reset a password.
In the M&S case, all it took was a convincing voice, a believable story, and a few minutes on the phone.
Thatโs the uncomfortable truth:
Even the most secure IT system can be undermined by a single conversation.
Technology Canโt Fix Human Error But Training Can
This is why cybersecurity training isnโt optional. Itโs essential. Your staff (from the front desk to IT support) are your first and last line of defence. Hereโs what businesses need to do:
- Regular Cyber Awareness Training: Teach your team how to spot phishing emails, suspicious requests, and the signs of impersonation. Role-playing exercises work wonders.
- Strict Identity Verification for Internal Requests: Especially around sensitive processes like password resets or admin access. No ID, no change, no exceptions.
- Limit Access, Especially for Admin Accounts: Most attacks escalate because of excessive permissions. Use the principle of least privilege and audit access regularly.
- Implement and Review Help Desk Protocols: As advised by the NCSC, make sure your support team has clear, robust procedures to handle identity checks, especially under pressure. Your company or IT support team might not small enough to know everyone.
- Monitor and Test with Penetration Simulations: See where your weak points are before attackers do. A good pen test doesn’t just probe systems. It tests processes and people, too.
Itโs Not Just About Tools. Itโs About Trust.
At Nxt Gen IT, we believe that security isnโt a product. Itโs a culture. The latest tech is vital, but real protection comes from a team that understands the role they play in keeping your business safe.
We help organisations go beyond firewalls and antivirus software to build a human firewall. Your staff trained, empowered, and supported by strong processes that make secure behaviour second nature.
Nxt Steps
If you’re unsure whether your people are your weakest link or your strongest asset, we can help you find out.
Book a Cyber Awareness Audit with our team. We’ll assess your current training, processes, and IT support policies to identify the gaps before an attacker does.
Or simply get in touch for a chat about strengthening your human defences because in cyber security, the door is only closed if everyone knows not to open it.
Letโs turn your people into your best protection.
Get in touch with Nxt Gen IT today.
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
