Royal Mail's parent company, International Distributions Services plc (IDS), has revealed that it spent a total of £10 million in the six months to September 24 to troubleshoot and improve the resilience of its systems, following a ransomware .
See also: Royal Mail: Breach linked to LockBit ransomware group

The incident, which IDS is now reporting as a cyberattack, and which took place on the IT systems of the Heathrow Worldwide Distribution Center, took place in January 2023.
This 25-acre building in Langley, near Slough in Berkshire, handles almost all the mail that comes into and goes out of the UK. The attack caused chaos across the country, leaving consumers and businesses unable to send and receive parcels.
The Postal Group eventually managed to restore its export services about a month later. However, the disruption also extended to its sister company, the Post Office, which was forced to compensate postmasters for the loss of their business.
Meanwhile, the LockBit team initially denied any responsibility for the incident, but eventually revealed the truth. Later, frustrated by Royal Mail’s refusal to pay an “unacceptable” £66 million ransom, it leaked data that included technical information, contracts with third-party suppliers, HR and administrative staff information, pay and overtime, and even Covid -19.
For obvious reasons, IDS did not provide details on how or what it spent its increased cybersecurity, but SecurityScorecard CISO Steve Cobbhighlighted a few key areas it likely focused on.
See also: Royal Mail: Suspends its international services due to cyberattack
The £10m cyber security upgrade contributed to a 5.6% in IDS's most recent financial statements, but overall, non-human costs, which include infrastructure, fell by 0.5%.

It is possible that this drop is partly attributable to the cyberattack, with IDS reporting that there was a significant reduction in international mail volume, resulting in a reduction in international shipping costs and terminal fees.
The potential consequences of not investing in cybersecurity measures can be devastating for a business. Cyberattacks can lead to the loss of sensitive information, such as customer personal data, intellectual property or confidential business information. This can lead to a loss of trust from customers and serious financial losses for the business.
Additionally, a lack of investment in cybersecurity can lead to business disruption due to a cyberattack. Cyberattacks can cause service disruption, loss of system , and disruption to employee work. This can lead to significant productivity losses and lost revenue for the business.
Additionally, not investing in cybersecurity can have legal consequences. Businesses that fail to adequately protect their customers’ data can face lawsuits and fines from data protection authorities. In addition, customers who have suffered losses due to a cyberattack may seek compensation from the business.
See also: Dangerous Royal Mail scam steals your money with new tactic
Finally, not investing in cybersecurity can have a negative impact on a company’s reputation and prestige. Cyberattacks can cause publicity for a company and call into question its ability to protect its customers’ data. This can lead to a decrease in public trust and a loss of customers.
Source: computerweekly
