
Marks and Spencer recently became the latest major retailer to face a cyber-attack. The incident is a clear reminder that cyber security breaches don’t just threaten systems, they threaten brands.
Retailers, especially large multi-channel operations are increasingly vulnerable to cyber attack. However, when the breach comes, and statistics show that it inevitably will, the technical response is only half the story. What defines the long-term damage is how the incident is communicated.
At PRPR, we work with our clients to create a bridge between cybersecurity and storytelling. This blog explores the growing cyber threats that the retail industry faces, the reputational stakes, and what brands should be doing now to prepare for the next crisis, before they become the next headline.
Retail is now a prime target for cybercrime
Retailers are prime targets for attackers. They hold sensitive customer data, payment information, operate across a number of platforms and manage systems that are hard to secure at scale.
As shopping experiences become more digitised and most organisations have adapted to mobile apps or third-party payments, the entry points for cybercriminals have multiplied. Supply chain attacks and ransomware campaigns are increasingly common and sophisticated, with attackers often looking to cause maximum reputational disruption, not just financial gain.
According to IBM’s Cost of a Data Breach Report 2024, the retail industry now faces average breach costs of over $3.8 million. The global average cost of a data breach increased 10% in one year, reaching $4.88 million, the biggest jump since the pandemic. However, beyond the financial hit, the impact on customer trust and future sales can be equally damaging.
Reputation is the real risk
Consumers rely on brand perception. They don’t just choose where to shop based on price, but also on experience and trust.
When a cyber incident occurs, the public doesn’t tend to see the technical complexity behind it or why it happened, but they do see the speed and transparency with which you respond. They will forgive the breach or even delays getting back up and running, but they won’t forgive being made to feel like they don’t matter.
Delayed or vague messaging only causes your customers to lose trust, and in today’s fast-moving media, you won’t always have the luxury of deciding what to say, or what other says about you.
Brands that recover best are those that treat crisis communications as a core part of their cyber resilience. That means integrating PR, legal, and security teams into your organisation before anything goes wrong.
Marks and Spencer is an example of a company getting it right. They acknowledged the incident, communicated what they were doing to resolve and regularly updated. They apologised for the issues customers were experiencing and reassured them. As a result, the company has been largely praised for its response and its transparency.
Your people are the front line
Cyber risks don’t just sit in the IT department. Phishing remains one of the most common entry points for attackers and retail staff, especially those in customer service, are frequently targeted. A simple miss-click can trigger a breach with far-reaching consequences.
That’s why awareness training should be a fundamental part of any retailer’s cyber defence, not just an annual checkbox exercise.
Effective programmes should equip staff with the practical knowledge to spot suspicious behaviour and report issues early, including phishing emails, understanding the risks of unsecured devices, and how to respond if ransomware locks systems down.
Retailers that invest in regular training are significantly better prepared to respond in the critical first hours of an attack.
Why retailers must prepare now
The key to a strong crisis response isn’t just speed, but coordination, and that requires preparation well before anything happens.
While many brands have IT protocols or legal frameworks in place, they may lack a comprehensive communications plan for cyber incidents. This needs to lay out a clear roadmap for engaging with customers, employees, the media and any other stakeholders. Leadership and marketing teams may be unsure what they can say and when they should say it.
Retailers that take this seriously are far more likely to protect long-term brand value. Those who don’t, may find themselves struggling to get back to normalcy and trying to repair what left of their reputation.
Handled poorly, communications after a data breach can destroy customer loyalty and damage a brand for years. Handled well, it can actually strengthen a brand’s reputation for integrity and transparency.
The brands that respond with honestly, confidence, and clear leadership, such as Marks and Spencers, often come out stronger than the ones that go silent or delay acknowledgment. This shift is why cybersecurity can no longer be separated from communications strategy, the two need to be deeply intertwined.
If you’re a retailer, you should be asking: if a breach happened tomorrow, would we know what to say, when to say it and who to say it to do?
If the answer isn’t clear, you’re not ready.
The time to plan is now, not during a crisis. Because in today’s threat landscape, it’s not a matter of if, it’s when.
At PRPR, we work closely with our clients to develop bespoke crisis communications programmes. We also offer training to leadership and comms teams so the whole organisation is prepared when it matters most.
Get in touch with us today to learn more or for a free, informal chat.