M&S boss tells MPs reporting attacks should be mandatory for all businesses

Wednesday, July 9, 2025
As Norman consulted parliament’s subcommittee for business and trade, he pointed out M&S had been quick to report the attack to higher authorities, the UK’s cyber watchdog and the National Cyber Security Centre. This deed benefited other businesses providing alert and protection from the circle of attacks going around. Norman also criticised the lack of communication around “quite a large number of serious cyber-attacks” that never get reported. He advocated to make reporting to the NCSC mandatory as companies have also tried to negotiate with hackers offering ransoms in some cases.
Dr. Ilia Kolochenko, CEO at ImmuniWeb and a Fellow at the British Computer Society (BCS), has thrown doubt on a new law mandating reporting of attacks.
“Whilst the idea to add another law that would require mandatory reporting of major cyber-attacks in the UK is sound and appealing, it may eventually bring more harm than good unless properly shaped and pragmatically implemented.
First, most “major” cyber-attacks inevitably implicate theft of personal data – thereby triggering the already existing reporting and notification requirements under the UK GDPR. It is true that some companies find “creative” ways to avoid mandatory disclosure of data breaches under dubious legal pretexts, however, merely adding another law will unlikely fix the problem”. Read Full Article
CPO Magazine: Cloudflare Announces New Content Scraping Protection Feature; “Easy Button” Stops AI Bots With a Click
Forbes: Cloudflare Sidesteps Copyright Issues, Blocking AI Scrapers By Default