Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Friday 03 October 2025 12:49 pm  |  Updated:  Monday 06 October 2025 10:13 am

Ex-GCHQ chief: No company should be offline for weeks after cyberattack

By: Ali Lyon

Add as a preferred source on Google
Robert Hannigan said no company hit by a cyberattack should be offline for two weeks (Photo by Ben Birchall/AFP via Getty Images)
Robert Hannigan said no company hit by a cyberattack should be offline for two weeks (Photo by Ben Birchall/AFP via Getty Images)

No vigilant company should need to go offline for more than a few days after a cyberattack, the former director of GCHQ has said in comments that will pile fresh scrutiny on Jaguar Land Rover’s (JLR) preparedness before its hack left production at a standstill for over a month.

Robert Hannigan, who ran the UK government’s blue-chip cybersecurity agency for three years, told City PM that even when an attack gets through a company’s defences, “it doesn’t need to paralyse the company for weeks and months”.

“It is perfectly possible to build the right prevention defences and then build the right resilience,” he said.

“And although the companies that get hit in the headlines are big names, there are thousands of companies who are protecting themselves every day, and even if an attack gets through, they are back up and running quickly. So we tend to focus, understandably, on the disaster, but there are plenty of companies doing the right thing every day, and so it’s not impossible at all.”

The comments from one of Britain’s pre-eminent cyber security experts threw into sharp relief the resilience at some of the UK’s most renowned blue-chip firms, after cyberattacks forced the likes of Marks and Spencer, JLR and the Co-op to halt core business lines for weeks.

Firms should not expect government cyberattack support

JLR remains in the throes of its response to a crippling attack, which has left it unable to restart production over a month after news of the attack became public.

It has also forced the government to unveil a taxpayer-backed loan in a bid to prop up the dozens of firms and hundreds of thousands of workers that make up JLR’s sprawling supply chain.

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

The Tata-owned company said on Monday that it hoped to partially restart operations “within days”. But Hannigan said there was “absolutely no need for a major company to be taken offline for weeks or months” in the way JLR has been. But it still faces mounting questions of the extent and efficacy of its cyber defences, after it outsourced much of its computer systems to its owner’s sister company, Tata Consultancy Services.

JLR’s attack is just one of a string of household name businesses whose operations have been ground to a halt in the wake of a vast proliferation of malware or ransomware attacks.

Brewing giant Asahi, which owns Peroni, Grolsch and London Pride, is also responding to an attack of its own that has reportedly left it days away from running out of beer in its native Japan. And M&S was forced to announce a £300m write-down after a devastating cyberattack disrupted its services for weeks.

Hannigan – who is now warden of Wadham College, Oxford – added that while he supported the government’s decision to support JLR’s suppliers with a taxpayer-backed commercial loan, bosses should not expect ministers to intervene habitually.

“Government… can’t protect every company,” he told City PM at the Global Cybersecurity Forum. “They can focus on government and critical industries – utilities for example – but they can’t do it for [everyone]. That’s up to boards and companies to do it themselves with advice from government.”

A spokesman for JLR said: “As the controlled, phased restart of our operations continues, we are taking further steps towards our recovery and the return to manufacture of our world‑class vehicles.

He added: “We continue to work around the clock alongside cybersecurity specialists, the UK government’s NCSC and law enforcement to ensure our restart is done in a safe and secure manner.”

Read more

TG Jones owner Modella puts jobs at risk in shoe retailer overhaul

High streets emptied out as retail sales fell in May.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Asahi
  • Co-op
  • cyberattack
  • cybersecurity
  • gchq
  • Jaguar Land Rover
  • JLR
  • Marks & Spencer
  • robert hannigan
  • tata consultancy
  • tata motors

Trending Articles

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • Barclays and Lloyds join banking sector plan for digital ID

  • Clarkson’s Farm and why businesses must stop blaming the weather

More from City PM

  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • TG Jones owner Modella puts jobs at risk in shoe retailer overhaul

    Retail
    High streets emptied out as retail sales fell in May.
  • ‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

    Tech
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Kraken Launches Autonomous Agents for Utility Customer Service Built in Partnership with Sierra

    Business Wire
  • Small businesses can help solve defence procurement

    Opinion
    Business professionals in a modern office discussing a strategic plan with charts and graphs displayed on a large screen
  • Fanzo: London-founded app bets on World Cup in US expansion drive

    Sport Business
    GettyImages 2161431113 showing an engaging business meeting with diverse professionals discussing innovative strategies
  • Cruxy founder: The worst advice I’ve ever had? Stay in your lane

    Opinion
    Carrie Osman, business strategist, speaking at a conference with a focused audience in a modern, well-lit venue.
  • Balfour Beatty emerges from US oversight scheme after fraud against military

    Transport & Infrastructure
    Balfour Beatty construction site showcasing cranes, workers, and building progress against a city skyline backdrop

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy