Skip to main content
M&

Marks & Spencer

Marks & Spencer is a British retail institution - founded in 1884, now operating over 1,300 stores worldwide and serving millions of customers weekly across Food, Clothing & Home, Beauty, and Banking services. The company also runs M&S Bank and maintains partnerships with Ocado Retail and Costa Coffee, making its attack surface a sprawling, multi-vertical environment spanning e-commerce, payment processing, supply chain logistics, and physical retail infrastructure. From a security standpoint, the threat model is substantial: a retailer of this scale handles high-volume transaction data through its banking arm, manages customer PII across loyalty programs and online platforms, and coordinates with third-party partners whose integrations expand the perimeter. The company has been investing in modernisation efforts - meaning security teams are operating alongside a tech stack that's in active transition, a familiar and challenging position for anyone who's defended legacy systems mid-migration. With over 65,000 colleagues globally, the human factor is non-trivial. M&S has signalled commitments to sustainability and responsible sourcing, which increasingly extend to digital supply chain risk. The cultural emphasis on protecting core brand value while evolving technically suggests security isn't an afterthought but a constraint the business has to architect around - whether defending point-of-sale environments, securing cloud-native services, or managing the identity sprawl that comes with a workforce and customer base at this scale.

1 job

We use cookies

We use cookies to understand how this board is used and to improve it. Analytics run only if you accept. Cookie Policy