
8.7 million reasons to decide who you'd call. What the Manchester Airport breach teaches every business.
When the Manchester Airports Group breach made the headlines, ITV asked Aruga's founder David Taylor to explain what it meant. Here's what he told them, and the harder truth about the hundreds of incidents that never make the news.
David Taylor
Managing Director

This week I was on ITV's Granada Reports talking about the cyber incident at Manchester Airports Group.
If you missed the story: MAG confirmed that an unauthorised third party got hold of customer data from car park, lounge and Fast Track bookings, and airport Wi-Fi sign-ups, across Manchester, Stansted and East Midlands. Email addresses, phone numbers, postcodes and vehicle registrations, for a reported 8.7 million people. No bank or card details. No impact on flights or safety.
I said on air what I'll say here. On what MAG has published, they've done the right things. They contained it, brought in specialists, told the authorities, and told their customers what to watch for. The real test is the weeks ahead.
But I run a cyber security business in this region, and the question I've been asked since isn't about the airport.
It's "what does this mean for us?"
Fair question. Here's my honest answer.
You are not an airport. That's exactly the point.
Most of those 8.7 million people just wanted the free Wi-Fi. You land, you connect, you tap in your email and phone number, and you never think about it again. But it sits in a system somewhere, for years, until someone takes it.
Every business does a version of this. Customer lists, booking records, enquiry forms, old CRM exports. If you collect people's details, you're responsible for them for as long as you keep them. So the first lesson costs nothing: know what customer data you hold, and get rid of what you don't need.
The second lesson is the one I care about most.
On what's been reported, this incident was spotted and contained quickly. That's what kept it a data story rather than an operational one. Which brings me to the question I put to every business, and the one I gave Granada Reports:
Would you know, within minutes, if someone was inside your systems?
Minutes or days. That's the difference between a small incident and a headline.
For organisations that need continuous visibility of what is happening across their environment, a Managed Security Operations Centre can provide 24/7 detection, investigation and containment rather than relying on somebody discovering an attack after the damage has been done.
The incidents you never read about
Here's the part of this job the headlines miss.
While a story like the airport's is on the news, businesses all over the country are quietly having their own worst week. Nobody reports on those. There's no statement, no coverage, no expert on the telly. Just a business owner on the phone, dealing with something they've never faced before.
I've sat with owners in recent weeks working through exactly that, and the same things come up every time.
They learn about the 72-hour rule mid-incident. If personal data has been taken, you've got 72 hours from becoming aware of it to report to the Information Commissioner. Most owners hear that for the first time with the clock already running.
They find out what their insurance does and doesn't cover, or that they haven't got any, at the worst possible moment to find out.
And there's a moment I wouldn't wish on anyone: seeing your own company's files listed by the criminals who took them. That's the point where this stops being an IT problem and becomes the most stressful thing that's ever happened to that business.
None of that is written to frighten you. It's written because every one of those moments is easier to face with an hour of preparation behind you, and almost nobody does the hour.
The first hour decides everything
Government figures say around half of UK businesses reported an attack or breach in the last year, and roughly three quarters have no formal incident response plan. For small businesses, the average cost of recovering from their most disruptive breach is just under £8,000.
So the starting point is this. An incident isn't unlikely. Most businesses aren't ready. And what separates a bad day from a disaster is usually the first hour.
Here's what a well-handled first hour actually looks like, from the incidents we guide businesses through every week.
Disable the compromised accounts and revoke their active sessions. Changing a password on its own doesn't log an attacker out.
Check for mailbox forwarding rules and remove them. That's how attackers quietly keep reading your email after you think they've gone.
Isolate affected devices, but don't wipe them. A wiped machine destroys the evidence your insurer, and possibly a regulator, will want later.
And move your team's conversations somewhere the attacker can't read. If you're coordinating your response inside a compromised email system, the attacker is reading your plan as you make it.
None of that is complicated. All of it is hard to do calmly, for the first time, at 2am, with your business offline.
That is why having an incident response plan and specialist support in place before an attack happens matters. You don't want the first hour of an incident to be spent working out who is responsible for what.
The three mistakes I see over and over
Deciding who to call during the incident
The worst time to choose an incident response provider is while the incident is happening. Emergency help bought on the day can be expensive, sometimes with a wait before anyone can even start. Decide who you'd call now, write it down, and put the number somewhere your team can find it in a hurry.
If an attack is happening now and you don't already have an incident response provider, Aruga also provides 24/7 emergency cyber incident response.
Assuming insurance is a response
Cyber insurance matters, but it pays for things after the fact. It doesn't answer the phone at 2am, and many policies expect you to take reasonable containment steps, which is hard if nobody knows what those are.
Assuming your IT provider is an incident response team
Most IT providers are brilliant at what they do, and in an incident they're usually the hands that carry out the containment. But incident response is its own discipline.
The best outcomes I see, first hand, are where everyone does what they're best at: the IT provider executing, an incident specialist directing, and a solicitor handling the legal and reporting side.
Serious incidents are a team sport. Build the team before kick-off.
One more thing, because of this week specifically
The data taken in the MAG incident is exactly what criminals use to write convincing scam messages. A text about a parking fine with your real car registration on it. An email about a lounge refund asking for your card details.
Those messages will land on your staff's phones too, work phones included. So brief your team this week: don't click links in messages about parking, fines, refunds or bookings. Go to the website directly.
Scam texts can be forwarded free to 7726, and scam emails to report@phishing.gov.uk.
What to sort this week, for free
Write a one-page plan. Who declares an incident, who you'd call and in what order, your IT provider's details, your insurer's hotline, and how your team talks to each other if email is compromised.
Print it, because a plan stored on the system that's just been encrypted isn't a plan.
That single page puts you ahead of most UK businesses.
And if you do line up professional help in advance, one thing worth knowing: the National Cyber Security Centre assures incident response providers against its own standards and maintains a public list of assured providers. Whoever you choose, us or anyone else, checking they hold that assurance is a five-minute job that tells you a government body has looked at how they work.
Aruga offers two ways to put professional response capability in place before an incident: Incident Response Assurance for organisations that fit the Assurance model, and a bespoke Incident Response Retainer for larger, regulated, international or critical-infrastructure organisations.
The honest bit
We sell incident response services, so you'd expect me to say all of this. But everything above stands whether you ever spend a penny with us or not.
The airport had specialists to call and, on what they've said publicly, it showed. Most businesses don't, and the first hour gets spent deciding what to do.
Decide who you're going to call before you need to call them.
That's it. That's the whole lesson.
Keep reading
Get practical cybersecurity thinking in your feed.
Subscribe to Aruga's LinkedIn Newsletter for practical insight on cyber risk, incident response and security operations.

David Taylor
Managing Director
Keep reading
Related posts


Defending your inbox – SPF, DKIM and DMARC explained!
Read article →
