In recent weeks, major UK retailers including Marks & Spencer and the Co-Op have been hit by a wave of cyber-attacks that crippled systems, disrupted supply chains, and exposed sensitive data. Online shopping at M&S remains down, and Co-Op’s operations, from supermarkets to funeral services, are still recovering. Authorities have now identified Scattered Spider, a loosely organised, English-speaking cyber-criminal group, as a primary focus of their investigation. Known for using off-the-shelf ransomware tools like DragonForce, the group’s tactics are methodical and highly disruptive.
These are not opportunistic hacks, they are calculated infiltrations. Like the 2017 Maersk attack, which cost over $250 million and was triggered by a compromise in third-party software, these incidents often begin at the edges, through supply chain vulnerabilities or compromised credentials. Once inside, attackers move quietly, embedding themselves in critical systems and waiting for the right moment to strike.
Despite mounting evidence, many commercial organisations still approach cyber security with a “Maginot Line” mentality: build a strong perimeter and hope for the best. But modern attackers don’t smash through the gates. They sneak in quietly, “living off the land” within your systems, studying how things work, neutralising defences, exfiltrating sensitive data, and preparing to strike.
Compare that with how the Ministry of Defence (MOD) or other high-security environments like railways approach cyber resilience. They adopt a strategy known as defence in depth, a layered model that assumes compromise is inevitable, and therefore builds internal barriers to slow, trap, or contain an attacker.
To put this into perspective: the MOD was reportedly hit by six million cyber-attacks in the year following the Russian invasion of Ukraine. That’s over 16,000 a day. While many are low-level, some are advanced, state-sponsored threats. Occasionally, even they get through, but they don’t cripple entire systems.
So, what’s the difference?
First, segmentation. The MOD enforces strict rules about how systems interconnect, even when those systems share the same security classification. Communication between systems must pass through controlled gateways, which perform more than just firewall checks. These gateways can inspect for malicious code, search for suspicious keywords or hidden content, and enforce business rules to prevent inappropriate data movement.
In a commercial context, imagine HR systems being technically incapable of accessing customer credit card data. Or marketing platforms physically prevented from exporting employee payroll information. Even if an attacker gains access, they cannot freely traverse the network or exfiltrate data, because business logic and architecture stop them.
Second, when moving data between trusted and untrusted networks (e.g., from external partners into core business systems), the MOD requires hardware-enforced one-way data flow. This ensures that once data enters, nothing can be sent back out, even if an attacker is inside. This technique breaks down the OSI stack, strips out protocol-level information, and reconstructs the data at the other end, enabling secure transformation in transit. All of this is built according to NCSC-endorsed design patterns.
Forward-thinking defence companies are beginning to adopt similar safeguards. Sopra Steria, for example, recently introduced Bluejay — a solution that enables secure collaboration between multiple defence agencies.
So why isn’t the corporate world doing the same?
We believe it’s time for corporate Britain to move beyond Cyber Essentials and tick-box compliance. The stakes are simply too high. What’s needed is a shift towards secure, multi-layered system architectures, built with the assumption that breaches will occur, and with the controls to minimise their impact.
At Nexor, we’ve spent over thirty-five years helping defence and government organisations; including NATO, all NATO member nations, the UK MOD and critical national infrastructure providers, to implement secure cross-domain data exchange. Every time you board a train or enter a critical infrastructure facility, our technology may be quietly protecting you behind the scenes.
If your business relies on sensitive data, complex supply chains, or uninterrupted operations, it’s time to stop hoping for the best and start preparing for the worst.
Let’s talk about how Nexor can help you protect what matters most.