M&S parts ways with CTO after cyber attack

M&S chief digital and technology officer Rachel Higham steps back from her role in the wake of the April 2025 cyber attack on the retailer’s systems.

Alex Scroxton

By

Published: 11 Sep 2025 20:55

Marks & Spencer chief digital and technology officer Rachel Higham is to leave the retailer, in the wake of a ransomware attack on its core systems from which it is still recovering.

Higham, who had been in post for less than two years, will be replaced by current retail director Sacha Berendji, according to M&S, which said Higham plans to take a career break.

In an internal memo obtained by specialist retail magazine The Grocer, M&S chief exec Stuart Machin said that having steered the team through “a challenging six months” Higham herself had taken the decision to step back.

“Rachel has been a valued part of the leadership team since joining, building a strengthened digital and technology function, playing a key role over recent months, and laying foundations for the future,” Machin wrote.

“Rachel has been a steady hand and calm head at an extraordinary time for the business, and we wish her well for the future.”

The Scattered Spider attack on M&S crippled the retailers’ systems at Easter after IT teams were forced to take emergency action and pull systems offline.

The high street stalwart was forced to contend with gaps on shelves due to problems with its stock systems, and the suspension of various online services such as click-and-collect. Similar attacks befell Co-op and Harrods at the same time, although these are not thought to have been as severe in their impact.

In M&S’ case, although most of the disrupted services are now back up and running, the financial impact will be long lasting, with the retailer previously saying it expects to be out-of-pocket to the tune of at least £300m.

Traumatic experience

Managing incident response in the wake of a high-profile cyber attack is an intense and difficult job, and IT and security leaders on the frontlines frequently find themselves having to shoulder a certain amount of blame, although there is no indication that Higham and M&S have parted ways amid any negative sentiment.

Nevertheless the psychological impact of experiencing such an incident – particularly when a gang such as Scattered Spider, which has on occasion been known to resort to violent threats against its targets – is not to be underestimated.

Indeed, burnout has become a perennial problem among CISOs and security pros, not helped by the widening scope of both the threat landscape, and the responsibilities linked to the role.

Writing in Computer Weekly in July, Tim Grieveson, CSO at ThingsRecon, said: “The CISO and security leader role has been stretched as they become accountable and responsible for more assets, processes and capabilities critical for business operations.

“The more critical cyber security becomes to business continuity, customer trust, and regulatory compliance, the more the CISO role is being morphed beyond recognition, and we’re approaching breaking point,” he said.

Describing the impact of the M&S cyber attack before a parliamentary committee in July, the retailer’s chairman Archie Norman said: “It’s fair to say that everybody at M&S experienced it.

“Our ordinary shop colleagues [were] working in ways they hadn’t worked for 30 years, working extra hours just to try to keep the show on the road. Let aside our tech colleagues, for a week, probably, the cyber team had no sleep.

“It’s not an overstatement to describe it as traumatic,” said Norman.

Computer Weekly contacted M&S seeking further comment but the organisation had not responded at press time.

Read more on IT for retail and logistics

Read More
Blythe Ramage

Latest

Control Resonant Hands-On: Giving One Of The Most Consistently Surprising Developers The Benefit Of The Doubt

When Remedy released Control in 2019, it didn’t fit neatly into any existing space. It wasn’t quite a booming AAA shooter, nor quite an indie darling, but rather its own strange little AA joint destined for “cult classic” status. Control ‘s winning combination of brutalist aesthetics, mundane everyday items and office spaces, and the weird

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

Newsletter

Don't miss

Control Resonant Hands-On: Giving One Of The Most Consistently Surprising Developers The Benefit Of The Doubt

When Remedy released Control in 2019, it didn’t fit neatly into any existing space. It wasn’t quite a booming AAA shooter, nor quite an indie darling, but rather its own strange little AA joint destined for “cult classic” status. Control ‘s winning combination of brutalist aesthetics, mundane everyday items and office spaces, and the weird

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever The National Football League remains the most popular sports competition in the United States, attracting millions of viewers every season and generating enormous interest among fans, analysts, scouts, and bettors alike. While star quarterbacks and championship contenders often dominate headlines, the foundation of every

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID