00:00:02
[Music] Welcome to TechTV Live. We’re covering the technology stories that really ma matter and today we’re covering the M&S hack. Uh my name is Bill MW and hopefully I’ll be helping to bring a lively debate here today. Um, helping me do this is our main reporter on this particular topic, Pete Warren. And Pete is going to be joined by uh our main guest, uh, Graeme Stewart, who’ll be leading us through some of the information here. Um, Pete, Graeme, over to you, Graeme. It’s just a hack, isn’t it? I
00:00:46
mean, on the high street, we we we we see these all of the time. We’ve seen so many of these, and they’re they’re just these anonymous people, aren’t they? They uh uh this is scattered spider. They’ve all got these wonderful names. Who are the people behind this? So the way to think about this is there are probably four different types of g okay or four different types of tax. So at the bottom end you’ve got the the the kind of offused trope the kind of teenager in a hoodie that is sort of you
00:01:17
know hobbyists effectively. At the top end of the scale you’ve got nation state actors. So you’ve got the the usual Iran, North Korea, Russia type things. The next one down from that are the more mercenary groups that tend to be used by nation state actors to to to um basically do their work for them. So there’s a level of uh plausible deniability. Um these people that have gone after the retailers recently sit in a third group which is strictly in it for the money. And in terms of the way
00:01:46
to think of this, these are the guys that they’re like old school bank heist. Okay? So what they’re in it is strictly for the money. So 30 years ago, these would be guys with balaclavas and shotguns taking down, you know, going after the local bank. They are looking for um uh an organization where they can uh extract some data and um extort the organization and um this sits squarely in in that that space. So um and there’s there’s lots of these. I mean, we we we would estimate at checkpoint there’s
00:02:16
probably over 650 of these gangs operating in the world at any one time. They’re geographically disperate in terms of the the um uh organizations. So there was a claim, Dragon Force made a claim um earlier on this week or by inference they they sent out a press release saying actually if anyone retaliates and goes after organizations in the the CIS so the former Soviet Union so Russia will look down and strike strike back with sort of mighty vengeance. Um that’s a massive red herring. This is a geographically
00:02:49
desperate organi um organization. Um the way I was thinking of it they’re a bit like a jazz band. you’ve got like your core people and then people dropping in and out and joining and um this is this is the the reality of every day now um for in in terms of cyber. Um these gangs are very well funded. Dragon force are an interesting business model and maybe we can look at that in a bit of detail if you like. Um but this is a business and these are uh the modern day equivalents of the guys knocking off the
00:03:19
bank. And so these are straight criminals. Do they have any uh activities in uh other criminal areas? Do they have No, this is this this is this this is what they do. This is their their their MMO and this this is what they’re after. I mean, and that’s why I tend to separate them into different groupings. Um so this isn’t politically motivated despite the kind of press release which I like I said I broadly discount. Um these are in it for the money, in it for themselves. There’s no
00:03:49
small amount of machismo attached to this as well. Um there’s quite a lot of that going on here and you know make a big point of um you know it’s like sort of you know guys tagging when they do graffiti and things like that. There is a there there’s a large amount of mechisma and there there’s bragging rights attached to these kind of things. Um but you know this is this is their sole purpose for existence. Okay. and Ross Ross Brewer um from Greylock. What what what’s the impact of
00:04:19
this? What what what is has um M ands actually suffered? Well, in terms of the just generally speaking, as Graeme said, we see this every day and we see this, you know, hundreds of times a day at global, you know, phenomena. The reality is that it’s impacting it’s the operational outage. So, that impacts revenue direct to the bottom line. uh then there’s a reputational risk. We see shareholders uh sort of leaving these businesses. So this table stakes have got really high and organizations especially in retail
00:04:52
where they’re traditionally focused on footfall and lowest cost widget. Okay, that’s their that’s their that’s their bread and butter. That’s where they come from. And now they’re actually an online business and some of them are even online banks. So the table stakes have changed, the threats changed. This is massively disruptive to those organizations. And sadly, this is what one of these organizations might think of as a black swan event. Like this has just happened to them. It’s the worst
00:05:18
thing in 5 years from an IT perspective. So, you know, what could we do? It’s happening to everyone. Well, imagine as this increases in veracity and frequency with the help of AI that these black swan events won’t be every year, they’ll be every month, every day, every hour, every second. So how are these organizations going to deal with that when they can’t even deal with the black swan that’s a one a year? So we’ve really got a fundamental shift in thought in terms of how we approach
00:05:48
these problems going forward. I mean this has cost um according to the Bank of America it’s cost uh costing M&S uh 43 million a year and as you say uh this is happening to so many other organizations. We’re actually seeing a spate of things that are being described as hacking at the moment and a lot of companies don’t seem to have any protection at all, do they? Well, I think that the challenge for most organizations is that have a complex IT environment. IT environments inherently
00:06:18
have vulnerabilities. But the reality is that not enough’s being done within these organizations to monitor for this kind of behavior and effectively stop these attacks. in there embionic. Some of these attacks go over weeks and months and years. So, you’ve got to be looking for the telltale signs, the digital footprints of the activity and then stopping them as quickly as you can, but also making sure that you realize that you’re not going to stop them. There will be incidents. So, you
00:06:44
need to make sure that you’ve got an incident plan. It’s well rehearsed and more importantly, you’ve got the forensic data on standby knowing that these things are going to happen. So when the invariably Black Monday happens, you can actually get in there and and and find it and actually work out systems that are impacted. You know, user profiles that are impacted so you can remediate and get back up and running. So it’s actually getting up back up and running quickly is becoming
00:07:11
more important than the actual incident itself. And this is where forensics play a big part in uh coming back online as quickly as possible. and professor Mo Shari from Sulford University. Uh as Ross has said, brand is is is a going to be a big issue here, isn’t it? There must be an impact on M&S from this. Yeah, as as we know, brand trust and brand loyalty is quite difficult to build. It take years of work from a retailer or any organization to build a strong group of loyal customers. M&S
00:07:47
does have one definitely more than the the the remineration or the income or the impact on economics there’s there’s a bigger impact on brand trust now how M&S communicates to their customers that’s external but also to their internal stakeholders from an employer brand perspective as well because quite clearly there are 65,000 plus employees who are dealing this on a face value every day in and out at the moment speaking to the customers trying to explain to them so that is a bigger
00:08:14
issue for M&S2 at the moment to deal with. However, coming out with a transparency and honesty in terms of where they are, what they are doing, what steps they’ve been taking. I think that will that will help the organizations like M&S to ensure that the impact the negative impact on brand trust is as not as massive or as big as other organizations might face. M&S also has a strong loyalty from customers, you know, who have been there for decades now. And I think supporting those
00:08:42
customers to understand how an organization like M&S has suffered through this certainly will help them. But equally I believe the communication package you know to explain to to all of their stakeholders. I think that will be key at this stage to ensure as minimum impact on their brand trust. But we’ve been talking to some M&S customers. They don’t seem to be particularly happy with the amount of communication that they’ve been getting. they see it see it as rather opaque. I one of the quotes that
00:09:12
we got from them was this is a classic fail by M&S. Um how’s that going to affect them? Yeah and and and this is key how they deal with this kind of scenarios. So they’ve been quite clear in terms of what what sort of issues they are dealing with I whether it is to do with online shopping or customers accounts you know whether it is to do with sparks you know reactivation of those accounts I think key is to making sure how they are communicating effectively maybe it is on a daily daily
00:09:39
basis at the moment you can see the coms is coming out but on a very staggered basis and I think that’s where M&S probably their communication team needs to be really active in ensuring if it is if it is you know the the basics of even just an email or even speaking out even in the stores to your customers. I think that will help because a lot of customers are not techsavvy for M&S at the moment. So you got to be really communicating with all sorts of channels of engagement to your customers to
00:10:05
ensure that where there are gaps of understanding within a customer base they are covered. But this is an issue, isn’t it? Because you think about M&S. I mean, this is why this is a little bit different because M&S, as you say, it’s a middle-aged middle class. There’s it’s got a it has this reputation of being, oh, you can trust M&S. It’s where you go to for your underwear. Uh, it’s not a good look, is it? So, this is this trusted organization, and you can’t trust them
00:10:37
with your data. Yeah. And again this this is this goes back to how much resilient are they in ensuring that they they they how they’re dealing with this in with all sorts of stakeholders at the moment. It will be always difficult on this side of an organization when they know there are a lot of issues that they need to really patch up whether they are whether it is to do with the technology whether it is to do with that infrastructure and digital technology or whatever it is. However, the basic for them will be or
00:11:05
the focus for them will be to ensure that the minimal impact on their consumer base. Now, how they do with it is to ensure the rebuilding of their brand, rebuilding of their loyal customers. Whether it is to do with incentivizing those customers at a certain stage all those those things should be planned right now. They can’t wait for this issue to be resolved and then start thinking about what do we do next. I think that sort of planning should be already happening in the back house somewhere.
00:11:36
Dion, you’re heavily involved in um Dion Rooney of Reiny. You’re heavily involved in this sort of online marketplace, this online area. You’ve got considerable experience in it. What do you think about this? Do you think that this cyber incident has damaged the is is a brand damager? It is absolutely a brand damager. and Vic said it very well. Part of it is the issue itself that occurred, but a big piece of this is their reaction to the the incident, their communication to their customers, stepping them through
00:12:12
what they need to do to protect themselves and and you know, their ecosystem and and with a mixed audience, they need to be very thoughtful about how they address it. And you know, unfortunately, you get into situations where they’re trying not to say too much and and and unfortunately that leaves customers feeling like they’re not being, you know, given the full story or the truth. Graeme, this is the it’s the equivalent really of having a um a smashed window on the high street, isn’t it? This is
00:12:44
what these people are doing. This is what these gangs are doing. Do you It’s a very wild west world. Do you think we should be taking this a lot more seriously? Do you think businesses should be taking these incidents from these gangs a lot more seriously? Um, so I I would say for my part and and my experience in this space that they do. Um, I think there’s a number of things in play here and it actually plays back into the brand value piece. Um, I think that, um, and and one of the things that
00:13:14
M&S has in its favor is a longstanding relationship with its customers and a long-standing relationship culturally. Um, I actually think M&S will recover from this quite quite easily. I mean, what’s interesting is that this is not and that’s a relatively easy, let me qualify that statement. I think that um part of the the the the bit that sits there is that 99% of people don’t actually understand what’s gone on here and that actually plays to M&S’s favor. Um and um I’ve done I’ve done quite a
00:13:46
few pieces this week kind of explaining to people what the net output of this is likely to be for them as a as as a consumer as a customer. So, one of one of the the pieces you see in these kind of attacks, and let’s be honest, this is an entirely typical type of attack. There’s nothing unusual about this. It’s depressingly familiar. Um, where you have, uh, a break into a system. And in this case, it wasn’t actually, it appears, a technology failure. It was a process failure. Um, uh, exfiltration of
00:14:16
data. So, removal of data. And then the next stage on is the ransom ransomware, the encryption of systems. Um, the exfiltration of data typically leads to what what we would describe as a secondary attack. And we’ve all had it, okay? We’ve all had a text message claiming to be from the post office claiming that our parcels been held up and actually there’s a problem and could you please click here and and do this and do that and sometimes you go, “Yeah, it’s going to cost you an additional £10
00:14:43
to get uh your data get your your parcel delivered.” So those secondary attacks use the data from the primary attack, but most people 99% of people just look at see that as a thing of everyday life because everybody gets them. Um and so um I think unless there is uh a significant uptick in uh what’s happened and it’s not just M&S, it’s the other retailers as well in in the damage that’s been done and that that comes out. And if you take the the other attack that happened, the co-op attack,
00:15:19
uh it sounds like someone um in old school terms ripped the cable out the wall when they realized what was going on and actually stopped the the ransomware attack. I actually don’t think the brand longstanding brand damage on this is is is very high. I think once they get past this and once they move on, the cultural attachment of the UK to M&S to to co-op to the other one was Harrods as well. heritage is obviously an interesting case in point in terms of its cultural attachment, but I actually think that that um they’ll
00:15:50
get past this pretty quickly and people will forget about it pretty quickly. Um the the the issue is as um as Ross was talking about is the frequency of these attacks and what you you this phenomena that we’ve explored ourselves in the past is this idea of reach fatigue. Um, which is frankly people get these text messages the whole time. They hear about hacks the whole time. They go, “Doesn’t bother me. Doesn’t affect my daily life. I’m clearly not going to respond to.”
00:16:20
There was one going around last week which I was asked to comment on. Um, uh, offering M& and it was it was obviously, you know, a a nefarious thing. It wasn’t from M&S. Offering M&S customers free tea. We’re really sorry here. Click on this link and we’re going to give you some free tea. Now, obviously the that as a nation of tea drinkers, um we’re going to respond positively to that and you’re going to get clicks on it. That’s a secondary attack, but I just think
00:16:46
that the the the the the very careful to separate the attack itself and the the the damage to the organization and you you’ve kind of highlighted there’s there’s there’s um a financial damage to this both in terms of share price and both in terms of the the revenue. Um, anybody that stopped it in an M ands uh in the last week or so will will notice that the brands the the the shelves are pretty bare and the same with co-op. Um, so there’s a revenue uh uh problem with this but I think the brand will recover
00:17:17
well. The problem we’ve got here is um attackers attacks on retailers has gone is is going you know it’s is going through the roof. So um uh retail used to be like the 10th 12th most t attacked sector within the UK economy and it’s gone up to fifth in the last couple of months and those those figures based on checkpoint data that that from from our monitoring. So um I I I I don’t think the brand value is long-standing. I think the issue here is these attacks are going to continue and going to get
00:17:51
worse and and the question is is how much breach fatigue. You know, you see another attack on a on the news and you just go, “Yep, there’s another one.” Does it affect me directly in my everyday life? No. So, I’m just going to get on with it my life and it’s not going to make a huge difference. So, um I I I don’t think it’s long-standing is my message. Ross, this epidemic that uh Graeme’s talking about, do we just have to put up with it? What are the police doing? Do we need more cyber cops on the
00:18:22
online street? Well, I think I was thinking about referring to it as a as a cyber cyber demic. Uh because I think that’s what we’re in the middle of. And I think we’ve got to really look at this seriously because it’s now having a profound impact. And just expanding on what Graeme just said there. Yes, at this point in time the executives can go to the board and say, “Well, look, we got caught out. We got caught a little bit short. It’s okay. We’ve put these protective measures in place to make
00:18:50
sure it doesn’t happen again.” We are in a very different economy. Uh and so retailers and every business is really working on fine margins uh and any disruption can then call into question other decisions. So I actually sort of would say a little bit differently to Graeme in as much that there is a long tale on these things and we have seen big retailers in the US that what happened was the cyber security incident just started to get shareholders and key stakeholders questioning the executives
00:19:21
decisionmaking processes and and and their professionalism and then later on you found that other things got called into question and then you go back six months later and the chief executive officer’s gone the chief information office is gone. The chief information security officer is gone. So all of these executives on, you know, tens of millions of dollars uh all lost their roles as a result of a cyber incident that that was the start of it. But it just it just started to call into questions uh other things about that
00:19:49
management team. So I think executives have to be really careful about this because it does have a long tail and it’s got a sting in that tail that can bite them in the end. And so as far as the what we have to do as an industry in law enforcement, yes, law enforcement’s all across this. There’s some claim that 50% of the people on the dark web are actually law enforcement officers. So you think you’re speaking to a criminal, you’re actually speaking to a cop. Uh so yeah, and just to think these groups
00:20:15
don’t know that they don’t they think that in the authorities don’t know who they are and where they are. Of course they do. They know where, you know, they’ve got that that side of it covered. It’s just a question of how to get to them and when. But I think as a world we have to treat this like uh terrorism and actually take a totally different approach. That’s we can’t just leave it down to the uh companies to solve this problem. We can’t leave it to the individual country searchs to solve
00:20:41
this problem. We need to really invoke there’s been some question about kinetic responses you know drop bombs on people that are doing this. That’s not going to work because of attribution. These people all over the world even though they could be from a country. What we need to do is start penalizing them. Say for instance that area of Myanmar where all the scam warehouses are, we cut their internet off. We cut the internet off for the country. Tell you what, you cut the internet off for a country, you
00:21:08
will have riots in the street and you’ll see hackers ejected out of those buildings as quick as lightning. And I think that’s the kind of crazy I know that’s a crazy concept, but that’s how serious this needs to get to stop this because organized crime is in this in a big way. And there are other impacts to that. So there money laundering, there’s, you know, child exploitation. All of these things are now becoming interrelated and interconnected. So this isn’t a sort of a, you know, a, you
00:21:35
know, a sort of a basic sort of soft financial crime with no, you know, personal consequences. It’s it’s bigger than that. V, as Ross has just said, you know, the there’s an impact on the board. One of the things that we’re seeing with legislation that’s coming down the line is that increasingly people on on the board are being expected to have some technological familiarity. Do you think that that’s something that they can actually boast about in a broaden sense that they can
00:22:05
say hey we’ve got people on our board who are completely wired? Yeah, absolutely. I think this connects to a softer piece of consumer psychology here. So the consumer psychology if you look at that way it also affects positively or negatively the the trust been built in the brand. So if your consumers and customers are looking at the the company, the organization and even the people at the at the high top thinking that they all are fully aware of all sorts of scenarios whether it’s to be technological development or the
00:22:35
issues like cyber attacks is it certainly gives you that kind of satisfaction as a consumer thinking I’m in the right hands my data is in the right hands you know I am dealing with the correct organization where everybody’s fully aware I think in this case particularly in M&S if you see the whether we say there was a backup plan or not I think the key case was that employees were not ready for this. They were not trained enough to deal with this. Now whether it was the top board or whether it was the middle level
00:23:02
managers or the shop floor managers, they were just not prepared. I think the the biggest lesson they would learn from this and I hope they do because of the strength in the brand uh is to to ensure that the full awareness is there the kind of understanding of what impact it could create on a brand. They they do come out of this one as well. And I think how that plays into the consumer psychology will be will also kind of relate to its kind of rebuilding stage as well. At the moment if you see the
00:23:29
data says to us about 7 to 9% only brand trust has been lost for M&S currently. So and that’s not massive you know as Graeme was saying earlier this will take you know a short period for them to rebuild but how they do it now both internally and externally that will play on emotions that will play on symbolism that will play on cognitive thinking of those consumers and that will whether it will continue to build that strong psychology for your consumers to come back to you or whether it will come
00:23:55
completely diminish and thinking well I have lost trust in you as an organization that’s key for eminence to go ahead now so what is that that that that forwardlooking piece then what what what should they be doing? What what should the world look like? Because online is where we are going to be in the future, isn’t it? Everybody’s buying online now. Yeah. And and you know, I think I think retailers in particular, but but many companies fall into um a compliance mindset. And you know, I always spoke to
00:24:31
my team about, you know, security first, compliance will follow because if we’re waiting for rules and guidance and regulation, the bad actors are moving much quicker than than that will help. And I think it does leave some companies um and and you know challenged in in where they focus and and security should be the focus. Compliant will come along for the ride. But I also think companies need to be more vigilant about a multi-layered approach of protection. It used to be important to lock all the
00:25:04
doors of your organization and you thought you were protected. You now have to assume people are going to get in and you need multiple layers of protection and you know many companies that have been breached their backups were the first thing to go right. So, how do you how do you create an environment where you have either a vapor lock or some sort of a timephased backup where you can dial the clock back? Those technologies exist. And then proactive, you know, intrusion prevention and detection things like, you know, we have
00:25:35
a product for VM that, you know, has um a component in there that would have shut down the encryption before it occurred. And my point is, you need all those layers. You can’t have one line of defense and hope that you’re going to be protected. And on the social engineering side, it’s it and Bish is right. We need greater awareness, but we also need to test those individuals. We need to simulate, you know, bad actors trying to socially engineer. You know, we used to call the help desk regularly to see if
00:26:06
we could get them to give up credentials and it was a coaching moment for those folks. So again, I think it’s got to be a much more comprehensive program and and investment is a question and we talked about retailers running on thin margin. How do they reduce the run portion of their budget and move some of those dollars to categories that are going to be more beneficial for the organization because keeping the lights on is just not enough anymore. Do you think that they should make a virtue of
00:26:33
this? they should put out adverts saying, “Hey, we’ve really invested a lot in cyber because that’s been one of the issues for a long time. A lot of people in cyber have complained that they’re the people who don’t get the money. They don’t get the budget to deal with this because they’re seen as an overhead. They’re not seen as an essential.” Yeah. And I and I think I think in part, you know, in in my history, we looked at we looked at risks in in two dimensions. you know, its
00:27:01
likeliness to occur and the severity of if it does incur and and a good security program can highlight the risks that people need to invest in to mitigate or remediate and and I think it it is in part um the the job of the organization to you know one collectively view security as their responsibility. It is not it’s job. It is not the CISO’s job. It is the organization’s job and I think they need to make a case for investments are necessary or get the appropriate alignment with the board that we talked
00:27:36
about the executive committee on the risks we are willing to accept because some are some do make sense right the it’s low likelihood to occur it’s a low impact risk so you can’t you can’t fund all of them but alignment within the organization is critically important on how you invest and there are creative ways to reduce that run portion and move those dollars into more important categories of IT spend. I mean, it’s interesting. Uh about 15 years ago, I spoke to somebody who was involved in
00:28:08
cyber and they were doing uh a lot of very sensitive cyber operations for the UK government. And I’d said to them, why don’t we go out and identify these people? And they turned around to me and said, oh no, you got to be very careful of these people. They break your legs. Um they literally said that to me. Um and do you think that there is that sort of fear thing that if somebody does say hey we’re very good at cyber that they make themselves a target? Absolutely. You know, you heard the
00:28:40
comment, you know, about bravado and and the the the I can do anything mentality of some of these organizations and you are somewhat putting a target on your on your back when you you kind of dare them, if you will, to to penetrate or to impact your organization. Is that is that the case, Glenn? is is is that yeah I I I again they and I’ve used the analogy already but I’m going to stick with it because it’s a really good one here. It would be like the the bank standing up and going saying our
00:29:12
our our vaults are heist proof. It it it it’s just a dar thing to say. You’re encouraging um uh people to come, you know, come and have a go. And and that’s um one of the interesting things about this of course is one of the comments earlier on was was talking about this kind of sort of judicial element of this following this up. The difficulty lies in the the the disperate nature of of these organizations. They’re geographically spread. So there were reports in the last month or so that
00:29:42
there were uh members of the Dragon Force uh group um had been arrested. There was a Scottish chap that was arrested. Um there was a guy arrested in Florida. Um these people are spread all over and and the difficulty in in in lies in following up with these people is that you’re talking about a multi-jurisdiction action and you know interpole operating uh don’t operate at a speed anything like the the the speed that these groups move at. So um putting your head above the parapit and saying
00:30:14
we’re completely cyber attack proof is as daft as saying that your vault is heist proof and similarly realizing that actually uh uh it’s going to be very hard to prosecute these people in both the the the the literal and actual sense of this. Um it’s going to be very hard to do that. So does that mean then Ross that we just have to tolerate this situation that the that everybody has to just essentially say I’m cyber aware now I have to make myself as safe as I possibly can and that’s the best that I can do in the
00:30:51
current situation maybe encrypt my data make sure as as as Dion’s been saying just you know make sure that I can minimize the damage no not at all um it’s really well documented now by the MITER organization in terms of the the tools, techniques and procedures the TTPs as we call them uh that these hacking groups are using. There’s a lot of information around how they actually get in and how they propagate around the organization, how they exfiltrate data and so forth. So the reality is that
00:31:22
we’re dealing with a digital hygiene problem. This isn’t this isn’t nation state North Korea, the best in the world that are going at these retailers. versus basic vulnerabilities, basic um you know sort of uh impacting an employee, getting the you know social engineering an employee, getting them to give up their ID and then going in with that ID. So these are these are things from a monitoring and analytics standpoint that are that have been around. And I’ve been in monitoring
00:31:48
analytics and forensics for the past three decades and nothing’s changed in the space and as much that you need to make sure that the controls that you’ve deployed are effectively configured and working properly. Too much time spent buying this tech and not enough time spent testing this tech and making sure it works. And then there’s just been some fundamental maturity problems. So for instance, if you take the logging and monitoring space, you know, that Greylog works in, it’s sort of taken us
00:32:13
30 years to sort of come to the conclusion actually we need to stop charging customers for all their data because then they’re making decisions about can I afford to collect this forensic data? Can I afford to collect these systems, you know, and I’m making these tradeoffs all the time. So it’s only now that we’ve reached this point where from a licensing standpoint, we now say to organizations, no, we’ll let you collect everything. We’ll process it all for you, but you will only charge
00:32:40
you for what you’re using and what you need and what you see value in. So, we’re just just that change has just happened in the last few months, the last year or so. And I think that’s going to help organizations do a lot better job around preparing for their incident response, preparing for their forensics, you know, and do better, more effective monitoring uh and and analytics uh and you know, and applying um uh AI and so forth to to to those to that analysis as well. So we we are
00:33:08
about to make a step change in the industry that’s going to help the client base uh and hopefully they’ll do a lot better uh in these situations by first averting them in the first place but certainly cleaning up afterwards. Is um cyber something that you teach on your marketing courses at Sulford? Is is cyber raise its edge very much? Yes, surely this is this is now becoming one of the newest development in the curriculum planning as much as other things. Going back to the point of uh do
00:33:37
we shout about it you know our preparation our strength again yeah again I fully agree we don’t have to shout about it however having cyber as one of your top risks in in an organization certainly will help in the first place because then clearly you know your focus is on there to ensure that we prepared as an organization whether it is to do with a retail sector or any other sector in higher education sector we deal with a lot of data for example you know student data staff data and every other thing that we deal with
00:34:03
and cyber becomes one of the top risks for for the institution. Even the students who are coming now and though and they will be the the future graduates, you know, they they will be benefiting from this kind of operation in the classroom as well to get them prepared for the practical world outside. But having having a cyber as the top risk and making sure that your stakeholders internally are fully aware of how you’re preparing that certainly will help to rebuild trust and ensure that customer has that assurance
00:34:32
of that data being dealt in the appropriate manner. I think that will massively help in ensuring the brand value is not lost. So both yeah from a perspective of yes of course they’re looking at the practical world out next for the next generation. Certainly the the university is always preparing for that. But equally going from the the traditional mode of actual consumer assurance, these things will certainly help to have cyber as your topics because clearly this is the world we are living in now.
00:34:58
And Dan, I’ll give you the last word. Uh um obviously the word AI has reared its ugly head. I mean it rears its ugly head in my inbox every sing. Um but in this AI world data is going to be all important isn’t it? So confronting that offer and online operation has got to be a big issue. Yeah certainly you know in retail in particular there is vast amount of data and transactions that need to be protected. Um but yes, you know, people are going to look for and continue to look for more strategic ways to leverage
00:35:38
AI, which requires, you know, a comprehensive organizational data because, you know, a lot of software companies are coming out with products that have AI in it. But the real benefit in my opinion on AI is, you know, looking across your entire organization and leveraging that data set. which means some organizations are going to pull together a data lake or some sort of an environment that’s going to be a target for bad actors like these and retailers need to find ways to have that multi-layered approach to protect it for
00:36:14
sure. Gentlemen, thank you very much. And a very big thank you to all of our panel and to Pete. Um, obviously a very big issue here and one that I’m sure that we’re going to be returning to. Um, after all, this wasn’t just any brand disaster. This was a mass M&S brand disaster and it’s one that I think will carry on in the news for a while yet and we’ll be revisiting soon. We’d also invite you to return to TechV TV to come and have a look all the other many uh major issues that we’re going to be
00:36:51
covering in the near future. Thank you again to our panelists and to Pete and we look forward to seeing you all soon. [Music]




