No One is Immune: What Major Breaches Teach Us
In today’s digital world, cybersecurity is not a nice-to-have, it is a core business necessity. And recent events have proven that even the most trusted names can fall victim.
In May 2025, Marks & Spencer, one of the UK’s most established retailers, suffered a significant cyberattack that reportedly led to over $400 million in losses. The breach disrupted online sales, compromised customer data, and impacted operations at a critical time in the retail calendar.
Shortly after in Jun 2025, Cartier, the luxury French jeweller under Richemont Group, faced its own cybersecurity crisis. A ransomware group claimed responsibility for exfiltrating over 2 million confidential files, allegedly including client data, internal communications, and operational documents. The incident struck at the heart of a brand synonymous with discretion and trust.
In South Korea, SK Telecom, the country’s largest wireless carrier, saw its stock plunge after revealing a large-scale data breach in April and was fined for negligence by the authorities. Reports indicated that hackers gained unauthorised access to sensitive systems, prompting a nationwide investigation and concern over the resilience of national infrastructure.
“What these cases tell us is that no organisation is too big, too secure, or too well-resourced to be targeted,” says John Leong, cybersecurity and services director at Knovel Engineering. “If Cartier, SK Telecom, and M&S can fall victim, it begs the question: what would happen if it were your business?”
The Cost of a Breach Goes Beyond the Immediate Fallout

Cyberattacks today do not just disrupt systems. They can derail years of brand trust, customer loyalty, and investor confidence.
When a company is breached:
- Customers may leave. They would be worried about the safety of their information.
- Regulators impose fines for non-compliance with data protection laws. The penalties can be hefty amounts that bleed the business’s profit.
- Reputation suffers, often for the long term.
- Stock prices drop, affecting shareholder value.
- Business operations slow down or halt, especially if ransom is involved
“Cybersecurity is no longer about prevention alone,” John notes. “It’s about detection, response, and most critically, recovery.”
Five Imperative Measures to Strengthen Cybersecurity

While there is no one-size-fits-all solution for cybersecurity, there are foundational strategies that businesses of all sizes can implement to dramatically reduce their risk and improve resilience.
1. Secure Endpoints: Your First Line of Defence
With hybrid work now the norm, employee devices from laptops to phones and tablets are common entry points for attackers. Endpoint security ensures every device connected to your network is monitored and protected.
A strong endpoint strategy includes:
- Device encryption to prevent data theft if lost
- Real-time malware detection and response
- Patch management to fix vulnerabilities quickly
- Mobile Device Management (MDM) for remote oversight
Without endpoint controls, one compromised device can give attackers a foothold into your entire system.
2. Adopt a Zero Trust Architecture
The idea that users or systems inside your network can be trusted by default is outdated. Zero Trust is built on the principle of “never trust, always verify.”
This involves:
- Enforcing multi-factor authentication (MFA)
- Strict identity and device verification
- Limiting user access based on roles (least privilege)
- Network segmentation to contain breaches
“Zero Trust isn’t about distrust. It’s about minimising exposure”, John explains. “It reduces the chances of a small breach becoming a major incident.”
“Zero Trust isn’t about distrust. It’s about minimising exposure”, John explains. “It reduces the chances of a small breach becoming a major incident.”
John Leong, Cyber Security and Services Director
3. Use Security Proxies to Monitor and Control Internet Access
Many breaches begin when employees unknowingly click on malicious links or download infected files. A security proxy acts as a filter between your internal systems and the internet.
Security proxies:
- Block access to dangerous or unauthorised websites
- Monitor user activity for signs of compromise
- Quarantine suspicious downloads
- Enforce browsing policies in real time
For companies with remote teams, contractors, or Bring Your Own Device (BYOD) policies, proxies add a vital layer of protection against human error.
4. Back Up Frequently and Test Recovery Plans
One of the most effective defences against ransomware is a secure, reliable backup strategy. If data is compromised, encrypted, or deleted, backups allow you to restore systems quickly without paying a ransom.
A robust backup plan should include:
- Regular, automated backups
- Encryption of backup data
- Storage in a separate, isolated environment
- Routine testing of restore procedures
“Backups are like seatbelts,” says John. “You don’t think about them every day but when something goes wrong, they save lives!”
In regulated industries, backup and recovery practices are not only recommended, but they are also required for compliance.
5. Enhance Monitoring with AI and Automation
Attackers are constantly evolving their tactics. Often mimicking legitimate behavior to evade detection. That’s why traditional tools alone aren’t enough.
AI-powered monitoring systems:
- Learn normal behavior across users and systems
- Detect anomalies (e.g., data transfers at odd hours)
- Trigger alerts or automatic containment of threats
- Reduce alert fatigue by filtering out false positives
When layered with human oversight, AI enhances detection accuracy and enables faster response times, which can make all the difference during an active breach.
Cybersecurity Is Now a Measure of Business Maturity
In the past, cybersecurity was viewed as a cost centre, but today, it should be seen as a strategic asset. It protects revenue, safeguards brand reputation, and enables safe innovation.
“You don’t need to be a tech company to take cybersecurity seriously,” says John. “You just need to understand that your data is your business and it’s worth protecting.”
As cyberattacks grow more targeted, automated, and relentless, companies must move from reactive to proactive. That means investing not just in tools, but in a security culture from the boardroom to every employee’s device.
Final Thoughts: If It Can Happen to Them, It Can Happen to You
Marks & Spencer. Cartier. SK Telecom. Just to say the least are global brands with world-class security budgets. If they can be breached, what makes your business less vulnerable?
Cybersecurity is not about fear, it’s about readiness.
At Knovel Engineering, we help businesses of all sizes strengthen their cybersecurity posture practically and strategically. Want to know how resilient your company is?
Reach out here or email us at hello@knoveleng.com for a cybersecurity readiness discussion.




