Cyber resilience is now an FM and operational issue: what businesses should learn from the UK retail attacks
What has happened?
A series of recent cyber attacks affecting major UK retailers including M&S, Co-op and Harrods is creating wider concern around operational resilience, supplier vulnerability and business continuity.
The disruption has gone far beyond IT systems alone.
Reports linked the attacks to:
- interrupted online operations
- supply-chain disruption
- customer-service failures
- stock and fulfilment issues
- operational downtime
- reputational damage
M&S alone warned the cyber incident could cost the business up to £300 million after online services and operational systems were disrupted for weeks.
At the same time, the UK Government’s latest Cyber Security Breaches Survey reported that:
- 43% of UK businesses experienced a cyber breach or attack in the last year
- 65% of medium-sized firms were affected
- 69% of large businesses were affected
For FM teams and operational leaders, this is no longer only an IT story.
It is a resilience story.
Why this matters for FM and workplace operations
Modern workplaces rely heavily on connected systems.
Access control, CCTV, visitor management, smart buildings, helpdesk platforms, cleaning schedules, contractor systems, asset tracking and operational reporting are all increasingly digital.
That means cyber disruption can now affect:
- building operations
- security services
- front of house functions
- contractor coordination
- logistics and deliveries
- workplace access
- procurement systems
- customer experience
Cyber specialists increasingly warn that businesses must move beyond basic IT protection and focus on wider operational resilience instead.
This is especially important because many attacks now target suppliers, third parties and operational systems rather than only core data environments.
What different organisations should take from this
Small businesses
For smaller businesses, the biggest issue is preparedness.
Many SMEs assume cyber risk only affects large corporations, but attackers increasingly target smaller organisations because systems and controls are often weaker. Simple operational planning and stronger cyber hygiene can reduce exposure significantly.
Medium and large organisations
Larger organisations face wider operational-risk challenges.
Multiple sites, third-party suppliers and connected operational systems can create vulnerabilities across entire estates. FM and operational teams increasingly need visibility over supplier access, device management and continuity planning.
Multinationals
For multinational organisations, cyber resilience increasingly sits alongside ESG, governance and operational resilience discussions.
Insurers, regulators and procurement teams increasingly expect businesses to demonstrate resilience not only technically, but operationally across supply chains and service delivery.
Public sector buyers
Public-sector organisations face additional scrutiny because disruption can affect critical services and high-footfall environments.
Government policy and proposed legislation are placing increasing focus on resilience, reporting and protection of critical systems across public infrastructure.
Contractors and service providers
For contractors, especially FM, security, front of house and IT disposal providers, operational controls are becoming more important.
Buyers increasingly expect:
- secure asset handling
- controlled data disposal
- stronger contractor vetting
- access-management controls
- continuity planning
- incident escalation procedures
This is particularly important when handling workplace devices, operational systems and client-sensitive information.
What organisations should check now
There are five practical questions organisations should now ask:
- Could operations continue if core digital systems failed temporarily?
- Are third-party suppliers and contractors being managed securely?
- Are workplace devices and retired IT assets being disposed of safely?
- Could the organisation evidence operational resilience to buyers or insurers?
- Are cyber risks being considered operationally rather than only technically?
The biggest lesson from recent attacks is simple.
Cyber disruption now affects operational continuity directly.
Where TPMG FM fits
This is where structured FM and operational support become increasingly valuable.
TPMG FM helps organisations strengthen operational resilience through better contractor oversight, secure operational processes, stronger site coordination and controlled service delivery.
This includes support around:
- Security Services
- Secure IT Disposal & Data Erasure
- Front of House & Concierge
- Waste & Recycling Services
- Mobilisation and operational continuity
Good FM is no longer only about maintaining buildings.
It is about helping organisations operate safely, securely and resiliently in increasingly connected environments.