Contact us

What the Transport for London cyber attack teaches every organisation about cyber resilience

Our expert

Sarah Formosa

Head of Digital Forensics and Incident Response

When major cyber incidents hit the headlines, attention naturally turns to who carried out the attack. 

For those of us working in digital forensics and incident response, identifying the attackers and understanding how an attack unfolded is a critical part of the job. But every incident also provides valuable lessons that can help organisations strengthen their cyber resilience. 

The recent guilty pleas of two individuals linked to the Scattered Spider cybercrime group in relation to the 2024 Transport for London (TfL) cyber attack have brought one of the UK’s most significant recent cyber incidents back into the spotlight. According to reports, the attack affected up to 10 million customers and ultimately cost TfL £39 million. 

While the guilty pleas represent an important step in holding those responsible to account, the incident also provides valuable insight into the modern threat landscape and the challenges organisations face in building genuine cyber resilience. 

At Resillion, our Digital Forensics and Incident Response (DFIR) specialists support organisations before, during and after cyber incidents. From uncovering how attackers gained access and preserving forensic evidence, to helping organisations contain threats, recover operations and strengthen their defences, we see first-hand how quickly cyber incidents can escalate from technical events into major business challenges. 

From critical national infrastructure and public sector bodies to commercial enterprises, we repeatedly see the same reality: cyber attacks are no longer rare events. They are business risks that every organisation must be prepared to manage.

TFL cyber attack

Cyber crime is getting closer to home

One of the most striking aspects of the TfL case is not just the scale of the disruption, but the profile of the attackers. 

For many years, organisations associated serious cyber attacks with sophisticated overseas groups operating from distant jurisdictions. The National Crime Agency (NCA) has highlighted that the offenders linked to this case demonstrate the growing threat posed by English-speaking cybercriminals operating from within the UK and other Western countries. 

That change matters. 

Modern threat actors are highly organised, collaborative and capable of launching attacks that can have substantial operational and financial consequences. They are also increasingly skilled at exploiting human behaviour rather than just technical vulnerabilities. 

That reflects what we see across many investigations at Resillion. Successful attacks often begin with compromised credentials, social engineering or the abuse of legitimate access rather than highly technical exploits. 

Cyber attacker hacking Transport for London TfL

The three lessons we see time and time again

Every investigation provides valuable insight, but three lessons consistently emerge. 

Preparation is more valuable than perfection

No organisation can guarantee that it will never experience a cyber incident. 

The objective should not be perfection. It should be preparedness. 

Organisations that have tested incident response plans, conducted resilience exercises and clearly defined decision-making responsibilities are almost always better positioned to respond effectively when an incident occurs. 

At Resillion, we often find that the difference between a manageable incident and a major business disruption comes down to preparation conducted months or even years beforehand. 

Speed matters

When attackers gain access to an environment, every minute counts. 

The faster an organisation can identify malicious activity, understand what has happened and implement containment measures, the greater its chances of limiting both technical and business impact. 

That makes digital forensics and incident response capabilities critical. Decision-makers need evidence-based answers quickly: 

  • How did the attacker gain access? 
  • What systems have been affected? 
  • What data may have been accessed? 
  • Are the attackers still present? 

Without those answers, organisations are often forced to make critical decisions with limited visibility.

Recovery starts long before an incident

Many organisations focus heavily on prevention, but resilience requires a broader approach. 

Recovery planning, business continuity arrangements and forensic readiness are just as important as preventative controls. 

The organisations best placed to withstand a cyber incident are those that understand how they will continue operating if critical systems become unavailable. 

Cyber resilience is ultimately about maintaining business operations under adverse conditions. 

Why the TfL case matters beyond transport

The specific details of the TfL attack may relate to a transport authority, but the lessons apply across all sectors. 

Whether you’re operating a healthcare provider, utility company, financial services organisation, retailer or local authority, the fundamental challenges are remarkably similar: 

  • Protecting customer data 
  • Maintaining critical services 
  • Managing operational disruption 
  • Responding to regulatory obligations 
  • Preserving trust and reputation 

Every organisation now depends on digital systems to some degree. That means every organisation needs to think seriously about resilience. 

The question is no longer whether cyber attacks happen. The question is how prepared organisations are when they do.

Looking beyond the headlines

The guilty pleas in the TfL case represent an important moment of accountability and demonstrate the value of digital forensics in supporting investigations and bringing offenders to justice. 

They also provide an opportunity for every organisation to reflect on its own resilience. 

At Resillion, we see first-hand how effective preparation, strong response capabilities and forensic expertise can significantly reduce the impact of a cyber incident and accelerate recovery. 

The TfL attack is a reminder that cyber resilience is no longer just about keeping attackers out. It is about ensuring organisations can detect threats, investigate incidents, respond effectively and continue operating in the face of an increasingly sophisticated threat landscape. 

Because when the next cyber incident makes the headlines, every organisation should be asking itself one question: 

Would we be ready?
Three professionals reviewing documents on a illuminated table in a dark office