Back to News

Scattered Spider Sentencing — 5.5 Years Each for the £39m TfL Hack: What Every UK SME Needs to Know About Social Engineering and Managed IT

Scattered Spider Sentencing — 5.5 Years Each for the £39m TfL Hack: What Every UK SME Needs to Know About Social Engineering and Managed IT

On 16 July 2026, at Woolwich Crown Court, two young British men were sentenced to five years and six months in prison each for their part in the 2024 cyber-attack on Transport for London — the largest cybercrime prosecution the United Kingdom has ever brought under the Computer Misuse Act. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from East London, were both handed identical custodial terms for an intrusion that the National Crime Agency puts at roughly £39 million in total cost, that rendered 148 of TfL’s IT systems inoperable, that forced 27,000 employees to attend an office in person to reset their passwords, and that exposed the personal data of as many as 10 million customers. Both men are members of Scattered Spider, the loosely organised, English-speaking social-engineering collective drawn from the wider online community known as “The Com”.

What matters to every UK SME is not the scale of the target but the ordinariness of the method. Scattered Spider did not break into TfL with a zero-day exploit or a bespoke piece of malware. They broke in with a telephone call. Armed with partial credentials bought from criminal marketplaces, the attackers rang a TfL help-desk worker and, after several attempts, talked them into resetting a two-factor authentication code — then escalated their access until they held domain-administrator rights, what investigators called the “keys to the kingdom”. That same phone call works just as well against a 30-person accountancy practice as against a transport authority with 27,000 staff. This article sets out what the court heard at sentencing, why the National Crime Agency has named home-grown social-engineering threat actors as one of the biggest challenges facing UK business in 2026, and why managed IT support built around strict identity verification — not another antivirus licence — is now the decisive line of defence.

£39m
Total cost of the TfL breach — £29m recovery plus £10m lost income (NCA)
5.5 years
Custodial sentence handed to each defendant on 16 July 2026
148
TfL IT systems rendered inoperable by the attack
10m
Customers whose personal data was potentially exposed

What the Court Heard at Sentencing

The sentencing hearing on 16 July 2026 drew a line under a case the National Crime Agency describes as its largest-ever cybercrime prosecution and only the second of its kind brought under the Computer Misuse Act. The judge described the pair’s conduct as driven by “selfish bravado” — a phrase that captures the character of the whole Scattered Spider operation, in which teenagers with no state backing and no advanced tooling caused tens of millions of pounds of damage for status, money and the thrill of it. The court accepted mitigating factors, including the defendants’ youth at the time of the offending and autism diagnoses, which is reflected in the identical five-and-a-half-year terms rather than the longer sentences the aggravating features might otherwise have attracted.

The aggravating features were considerable. Jubair, the court heard, has 22 prior convictions dating back to the age of 14, and is separately wanted in the United States, where he is linked to ransom payments totalling around $115 million extracted from 47 victim organisations. Flowers was arrested in a raid that caught him mid-attack against two US healthcare providers — a detail that underlines how the group treated hacking as continuous, full-time work rather than a one-off. Most strikingly, both men were found with contraband mobile phones while on remand in prison, still using them to plan further intrusions. This was not a pair of curious adolescents who strayed once across a line; it was, on the NCA’s account, a determined and prolific criminal enterprise that continued operating even from a cell.

The technical account read to the court is the part every business owner should sit with. The attackers began with partial credentials — usernames and fragments of authentication data — purchased from criminal markets, the kind of low-grade stolen information that circulates for a few pounds after any commodity phishing campaign. They then telephoned a TfL help-desk worker and requested a reset of a two-factor authentication code. It did not work first time; it took multiple attempts and multiple calls. But persistence paid, the reset was granted, and from that single foothold the attackers escalated their privileges step by step until they controlled the domain. Every stage of that chain turned on a human being making a helpful decision under pressure. No firewall was breached in the conventional sense. No unpatched server was exploited. The perimeter that failed was a person on a phone.

Why this is an SME problem, not just a TfL problem

Every control Scattered Spider defeated at TfL exists inside a small business too — almost always in a weaker form. A 40-person firm has a help desk (often one overstretched IT manager or an outsourced first-line desk), uses SMS or basic app-based multi-factor authentication, keeps one or two shared administrator logins, and has no written identity-verification procedure for password resets. The attackers reached a £39 million target using nothing more than bought credentials and a persuasive phone call — the exact ingredients present in every SME. Social engineering does not lose effectiveness as the target shrinks; if anything it gains, because smaller organisations run more informal processes and their staff are more directly reachable. The National Crime Agency has been explicit that although Scattered Spider has been “heavily degraded and disrupted” by arrests, the threat from home-grown, English-speaking social engineers remains one of the UK’s biggest cybersecurity challenges. The phone call that reached TfL will reach your business unless you have deliberately designed it not to.

The Timeline: From Attack to Sentencing

31 August 2024 — Initial access to TfL
Using partial credentials bought from criminal marketplaces, Scattered Spider members telephoned a TfL help-desk worker and, over multiple attempts, persuaded them to reset a two-factor authentication code — the foothold from which the entire breach followed.
Early September 2024 — Privilege escalation and containment
The attackers escalated from that initial reset to domain-administrator rights — the “keys to the kingdom”. TfL took systems offline as a precaution; 148 IT systems were rendered inoperable, contactless and online services were disrupted, and refund processing was suspended.
6 September 2024 — First arrest
Owen Flowers, then 17, was arrested by the National Crime Agency in connection with the TfL attack. The raid caught him mid-attack against two US healthcare providers, demonstrating the group’s relentless, parallel targeting.
Late 2024 – 2025 — The wider Scattered Spider campaign
The same collective was linked to high-profile attacks on Marks & Spencer, the Co-op Group, Harrods, MGM Resorts and Caesars — proof that the TfL method was a repeatable playbook, not a one-off, and that no sector was out of scope.
2025 — Investigation, charges and the aftermath count
The NCA, working with US authorities, established the £39 million cost to TfL — roughly £29 million in recovery and £10 million in lost income — and the exposure of up to 10 million customers’ data. Jubair was separately linked to $115 million in ransoms across 47 US victims.
22 June 2026 — Guilty pleas at Woolwich Crown Court
Jubair, 20, and Flowers, 18, pleaded guilty to offences connected to the TfL breach. Both were later found to have used contraband mobile phones in prison to continue planning intrusions while awaiting sentence.
1 July 2026 — A linked US extradition
Peter Stokes, a 19-year-old US-Estonian national alleged to be connected to the wider Scattered Spider ecosystem, was extradited from Finland to Chicago — a sign of the coordinated international pressure now bearing down on the group.
16 July 2026 — Sentencing
Both defendants were sentenced to five years and six months each. The judge cited “selfish bravado” while accepting mitigation for youth and autism diagnoses. The NCA confirmed this as the UK’s largest-ever cybercrime prosecution.
22 July 2026 — Today’s position
UK SMEs now have a court-proven, fully costed case study in how social engineering bypasses technical controls. The open question is whether businesses will use it to audit their own help-desk and identity processes before the next call comes in.

How the Attack Chain Bypasses Every Technical Control

The most uncomfortable truth in the Scattered Spider case is that almost every security product a typical SME buys would have been irrelevant to the outcome. Antivirus does not stop a help-desk worker from resetting a two-factor code for someone who sounds legitimate and persists across several calls. A firewall does not inspect a telephone conversation. An email gateway does not see partial credentials being bought on a criminal forum, nor a privilege-escalation step being taken by an account that has already authenticated. The breach succeeds in the space between technology and human process — and in most organisations that space is owned by the IT support function. The bar chart below shows where the attack chain actually exerts its pressure, and how little of it perimeter technology addresses on its own.

Help-desk / service-desk manipulation for resets
Primary vector
Purchased partial credentials from criminal markets
High
Two-factor reset / MFA-device registration abuse
High
SIM-swapping and vishing (Scattered Spider staples)
High
Privilege escalation to domain administrator
Medium-high
Lateral movement undetected by perimeter tools
Medium
Traditional antivirus / firewall preventing the breach
Minimal effect

Read the chart from the bottom up and the strategic implication is stark. The control most SMEs treat as their primary defence — antivirus and a perimeter firewall — sits at the very foot of the chart in terms of relevance to this style of attack. Every vector above it is about identity: who can prove they are who they claim to be, and what process exists to verify it before an account is reset or elevated. This is precisely why the National Crime Agency, the NCSC and successive Five Eyes advisories now place identity and access control at the centre of their recommendations to business leaders. The defence is not a product you install once and forget; it is a set of processes, verification standards and monitoring practices that must be designed, documented, enforced and watched continuously — which is exactly what a managed IT support relationship exists to provide.

The Identity Verification Gap — Where SMEs Are Most Exposed

79%
Estimated share of UK SMEs with no documented identity-verification procedure for help-desk password or MFA resets

The single most effective change an SME can make in response to the Scattered Spider sentencing is also one of the cheapest: a documented, mandatory identity-verification procedure for any password reset or two-factor-device change handled by the help desk. The reason TfL had to reset 27,000 employees in person is that, once it knew an attacker had been talking its support function into resets, it could no longer trust any remote identity claim. A pre-agreed verification standard — a call-back to a number already on record, a manager-approval step for privileged accounts, a one-time code delivered through a separate trusted channel, or an in-person check for the most sensitive resets — removes the worker’s discretion to be talked around. It converts a judgement call made under pressure into a checklist that persistence and a convincing story cannot defeat.

For SMEs, this gap is structural rather than a matter of carelessness. Most small businesses built their IT support around helpfulness and speed: the entire purpose of the help desk is to unblock a colleague who is locked out and needs to work. Scattered Spider weaponises exactly that helpfulness. The attacker presents as a stressed employee who cannot reach a critical system before an important deadline, applies time pressure, and counts on the worker’s instinct to close the ticket quickly. The TfL reset did not succeed on the first attempt — it took several — which tells you the human on the other end had doubts and was worn down anyway. Without a verification standard that the worker is required to follow regardless of how urgent or senior the caller sounds, the help desk is the softest point in the entire security model, and no amount of perimeter spending compensates for it.

The SME Social-Engineering Exposure Scorecard

Where UK SMEs typically stand against the Scattered Spider playbook
Documented help-desk identity-verification procedureCritical gap — rare in SMEs
Phishing-resistant MFA (FIDO2 / passkeys) on admin accountsHigh — SMS still dominant
Elimination of shared administrator credentialsHigh — shared logins common
Least-privilege access model enforcedMid — partial in most firms
24/7 monitoring and anomaly alerting on identityHigh — absent in most SMEs
Conditional access / impossible-travel detectionMid — licensed but unconfigured
Staff drilled on vishing and MFA-fatigue tacticsMid — awareness without practice
Tested incident-response runbook for account compromiseCritical gap — most SMEs have none

The scorecard reflects a consistent pattern in what managed IT providers see day to day. The controls that defeat social engineering are disproportionately the ones SMEs have not implemented — not because they are expensive, but because they require process design and ongoing enforcement rather than a one-off purchase. A business can buy a firewall in an afternoon; it cannot buy a verification culture, a least-privilege model or a round-the-clock monitoring capability the same way. This is precisely the value of a proactive IT support relationship: the controls that matter most against the Scattered Spider method are operational, continuous and best owned by a partner whose job is to run them every day, rather than by an internal generalist juggling them alongside procurement, projects and the printer that will not connect.

The Cost of Getting This Wrong: Size-Band Analysis

OrganisationHeadcountTypical help-desk modelExposure to the Scattered Spider methodIndicative annual cyber spend
Micro business1–9Owner or ad-hoc external fixerVery high — no formal verification at all£10,000–£20,000
Small business10–49One IT manager or first-line outsourcerHigh — informal, pressure-driven resets£30,000–£150,000
Medium business50–249Small internal team, often no documented IAMMedium-high — shared admin accounts common£150,000–£500,000
Large enterprise250+Dedicated SOC and IAM functionMedium — still breached via help desk (MGM, M&S)£1m+
TfL (public-sector benchmark)27,000 staffEnterprise IT with formal controlsRealised — £39m total cost, 148 systems downN/A

The instructive comparison is between the bottom of the table and the top. TfL is a sophisticated, well-resourced organisation with a formal IT function and enterprise-grade tooling, and it still suffered a £39 million breach through social engineering — with 148 systems knocked out and up to 10 million customer records exposed. If an organisation of that scale and maturity can be reached through its identity and help-desk processes, the implication for a 40-person firm with one IT manager and SMS-based two-factor authentication is not subtle. The reassuring half of the picture is that the controls that would have mattered most — phishing-resistant MFA, a documented verification procedure, least-privilege access and continuous monitoring — are entirely within reach of an SME budget when delivered through a managed support model. The annual cyber spend that closes those gaps for a small business is a fraction of the recovery cost of a single serious account-compromise incident, let alone the £39 million TfL ultimately absorbed. Investigators also noted that had TfL been fully shut down, the knock-on cost to the wider economy could have run to as much as £56 billion — a reminder that the true blast radius of these attacks reaches far beyond the victim’s own balance sheet.

Reactive vs Proactive IT Support: The Two Postures

Reactive posture

What most UK SMEs operate today

  • Help desk resets passwords and MFA on request, under time pressure, with no formal identity check
  • SMS or basic app push used for MFA on all accounts, including administrators
  • One or two shared administrator logins used by whoever needs them
  • Everyone holds broad access “to be safe” — no least-privilege model
  • No monitoring of sign-ins; compromise discovered only after business impact
  • Conditional-access policies licensed but never configured
  • No tested runbook for a compromised account; response improvised on the day
  • Staff told to “be careful” but never tested with a vishing simulation

Proactive posture

Where managed IT support takes you

  • Mandatory, documented verification standard for every reset — call-back, manager approval or in-person for privileged accounts
  • Phishing-resistant MFA (FIDO2 security keys / passkeys) on all admin and remote-access accounts
  • Named, individual admin accounts with no shared credentials; privileged access granted just-in-time
  • Least-privilege model; access reviewed regularly and revoked on role change
  • 24/7 monitoring with anomaly and impossible-travel alerting on identity
  • Conditional access enforcing device compliance, location and sign-in risk
  • Tested incident-response runbook with a defined containment and recovery path
  • Regular phishing and vishing simulations with measured staff response

The difference between these two columns is less a matter of budget than of operating model. The reactive posture treats IT support as a break-fix utility that exists to unblock people quickly — and speed, unqualified by verification, is exactly what the TfL attackers exploited when they wore down a help-desk worker over several calls. The proactive posture treats IT support as the owner of the identity perimeter: the function responsible for ensuring every access request is verifiable, every privileged action is logged, and every anomalous sign-in is seen and investigated. Scattered Spider attacks the reactive posture and is largely defeated by the proactive one. Moving from left to right is the single most valuable security investment an SME can make in 2026, and it is the core of what a managed IT support engagement delivers.

23%
Approximate share of UK SMEs with phishing-resistant MFA on privileged accounts — the target is 100%
Start with the cheapest, highest-impact change first

If you do nothing else this week, write down a help-desk verification standard and make it mandatory. It costs almost nothing, can be drafted in an afternoon, and removes the exact discretion the TfL attackers exploited — a worker’s freedom to grant a reset because a caller was persistent and sounded urgent. Pair it with phishing-resistant MFA on your handful of administrator, finance and director accounts — in most SMEs that is only a few people — and you have closed the two highest-probability paths a social-engineering attacker would take against your business. Everything else deepens the posture, but those two moves deliver the majority of the risk reduction for the lowest cost. A managed IT support partner can stand up both within the first fortnight of an engagement, without disrupting day-to-day operations.

At-a-Glance: Key Facts for UK Business Leaders

TopicKey figure or factSource
Total cost of the TfL breach£39 million (£29m recovery + £10m lost income)National Crime Agency
Sentence per defendant5 years 6 months eachWoolwich Crown Court, 16 July 2026
DefendantsOwen Flowers (18, Walsall); Thalha Jubair (20, East London)Woolwich Crown Court
IT systems rendered inoperable148National Crime Agency
Staff forced to reset passwords in person27,000National Crime Agency
Customers potentially affectedUp to 10 millionNational Crime Agency
Initial access methodPhoned help desk, reset 2FA using purchased partial credentialsCourt evidence
Escalation outcomeDomain administrator — the “keys to the kingdom”Court evidence
Attack date31 August 2024National Crime Agency
Jubair’s prior convictions22, dating back to age 14Court evidence
Jubair’s US-linked activity$115m in ransoms across 47 victimsUS charges
Wider Scattered Spider targetsM&S, Co-op, Harrods, MGM Resorts, CaesarsPublic reporting
Linked US extraditionPeter Stokes (19, US-Estonian), Finland to Chicago, 1 July 2026US Department of Justice
Prosecution statusUK’s largest-ever cybercrime prosecution; second of its kind under the CMANational Crime Agency
Potential wider economic impactUp to £56 billion had TfL been fully shut downInvestigation estimate

Read Alongside: The 2026 Threat Landscape in Context

The Scattered Spider sentencing does not stand alone; it sits inside a run of 2026 developments that together define the threat environment UK SMEs now operate in. For the ransomware backdrop — the monetisation model that groups like this ultimately feed — our analysis of the 323 UK firms hit by ransomware and the City of London Police response shows how initial access so often begins with the same identity failures described here. The Check Point June 2026 data on 1,589 weekly attacks per UK organisation and The Gentlemen ransomware quantifies the sheer volume of pressure on the perimeter, while the NCSC and FSB router advisory covers the network-edge exposure that compounds it. On the patching side, our July 2026 Patch Tuesday review of the SharePoint and AD FS zero-days across 622 CVEs and the wider AI-driven CVE surge and patch programme analysis close out the technical half of the attack surface that identity controls cannot cover on their own. Read together, they describe the full baseline a UK SME should hold in mid-2026.

Close the gaps Scattered Spider exploited — before the next call comes in

Cloudswitched managed IT support owns the identity perimeter most SMEs leave exposed: documented help-desk verification, phishing-resistant MFA, least-privilege access, 24/7 monitoring and a tested incident-response runbook. Proactive by design, with a dedicated account manager and an industry-leading SLA response.

Talk to us about Managed IT Support

Frequently Asked Questions

What exactly were Flowers and Jubair sentenced for?
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five years and six months at Woolwich Crown Court on 16 July 2026 for their part in the August 2024 cyber-attack on Transport for London. The National Crime Agency puts the total cost of that attack at around £39 million — roughly £29 million in recovery and £10 million in lost income — and confirms it rendered 148 IT systems inoperable, forced 27,000 staff to reset their passwords in person, and potentially exposed the data of up to 10 million customers. Both men are members of Scattered Spider. The case is the largest cybercrime prosecution ever brought in the UK and only the second of its kind under the Computer Misuse Act. The judge described their conduct as driven by “selfish bravado” while accepting mitigation for their youth and autism diagnoses.
How did the attackers actually get into TfL?
They started with partial credentials — usernames and fragments of authentication data — bought from criminal marketplaces, the kind of low-grade stolen information that circulates cheaply after commodity phishing campaigns. They then telephoned a TfL help-desk worker and asked for a two-factor authentication code to be reset. It did not succeed on the first attempt; it took multiple calls and multiple tries before the reset was granted. From that single foothold the attackers escalated their privileges step by step until they reached domain-administrator level — described in court as the “keys to the kingdom”. No firewall was breached and no unpatched server was exploited in the conventional sense; the perimeter that failed was a human being persuaded, under pressure, to help.
Why should a small business care about an attack on something as large as TfL?
Because the method scales down perfectly. Scattered Spider did not use a sophisticated exploit that only works against large, complex infrastructure — they used bought credentials, a phone call and a help desk willing to reset a code. Every SME has those same ingredients, usually in a weaker form: an informal help desk, SMS-based MFA, shared administrator accounts and no documented identity-verification procedure. The National Crime Agency has been explicit that although the group has been heavily disrupted by arrests, the threat from home-grown, English-speaking social engineers remains one of the UK’s biggest cybersecurity challenges. Smaller organisations are often easier targets precisely because their processes are more informal and their staff more directly reachable. The TfL case is the clearest possible proof that social engineering, not malware, is the primary threat to organisations of every size.
Who are Scattered Spider and how do they operate?
Scattered Spider is a loosely organised, mostly English-speaking cybercrime collective that emerged from the wider online community known as “The Com”. Rather than relying on advanced malware, they specialise in social engineering: phishing, vishing (voice phishing over the phone), SIM-swapping and the manipulation of help desks into resetting passwords and multi-factor authentication. The group has been linked to a string of high-profile attacks including Marks & Spencer, the Co-op Group, Harrods, MGM Resorts and Caesars, as well as TfL. Its members are frequently young — Flowers and Jubair were teenagers when they offended — and treat intrusion as continuous, profit-driven work. The technical simplicity of their method is exactly what makes them so dangerous to ordinary businesses.
How do I stop my help desk being talked into resetting a password or MFA code?
You remove the worker’s discretion by giving them a mandatory, documented verification standard that must be followed for every password reset and MFA-device change, regardless of how urgent or senior the caller claims to be. Effective standards include a call-back to a phone number already on record (never one the caller supplies), a manager-approval step for privileged accounts, a verification code delivered through a separate trusted channel, or an in-person check for the most sensitive resets. The key principle is that the procedure must not be waivable under time pressure — time pressure and persistence are the attacker’s primary tools, and the TfL reset only succeeded because a worker was worn down across several calls. A managed IT support partner should establish this as the very first deliverable of any engagement.
Will antivirus and a firewall protect me against this kind of attack?
Largely no, and this is the most important misconception to correct. The Scattered Spider method operates in the space between technology and human process. Antivirus inspects files and does not stop a help-desk worker from resetting a code for a convincing impersonator. A firewall filters network traffic and does not see partial credentials being bought on a forum or a manipulative phone call taking place. An email gateway can reduce phishing volume but cannot prevent a credential that has already been phished from being used. These perimeter tools remain necessary for other threats, but against social engineering they are close to irrelevant. The controls that matter are identity-centric: phishing-resistant MFA, a help-desk verification standard, least-privilege access, conditional-access policies and continuous monitoring of sign-in behaviour. That is why the right response is a managed IT support model that owns those operational controls, not another product purchase.
What is phishing-resistant MFA and is it expensive for a small business?
Phishing-resistant MFA refers to authentication methods that cannot be intercepted, replayed or approved by mistake — principally FIDO2 hardware security keys and device-bound passkeys. Unlike SMS codes or simple push approvals, these are cryptographically tied to the specific legitimate website and to physical hardware, so an attacker who phishes the password or tricks the user still cannot complete the sign-in. For a small business the cost is modest: you do not need to deploy security keys to every employee on day one. The highest-value approach is to start with the accounts that matter most — administrators, finance, directors and anyone with remote or privileged access — which in most SMEs is a handful of people. Hardware keys are a one-off purchase of a few tens of pounds each, and passkeys are increasingly free and built into the platforms you already use. The return on that spend is the closure of the single most exploited attack path in 2026.
What is SIM-swapping and how does it defeat my multi-factor authentication?
SIM-swapping is when an attacker persuades or bribes a mobile network operator to transfer a victim’s phone number onto a SIM card the attacker controls. Once the number is ported, any SMS one-time codes or voice-call verifications sent to that number arrive on the attacker’s handset instead of the victim’s. This defeats the most common form of MFA used by SMEs, the SMS code, because the “something you have” factor is the phone number and the attacker now holds it. It is a signature Scattered Spider technique. The defence is to move privileged and recovery authentication off SMS entirely and onto phishing-resistant methods such as FIDO2 security keys or device-bound passkeys, which are tied to physical hardware that cannot be ported. For executives and administrators you should also request carrier-level port-out protection to make unauthorised SIM swaps harder to execute.
How does 24/7 monitoring actually help against social engineering?
Social-engineering attacks succeed by gaining legitimate-looking access, so the goal of monitoring is to catch the anomalies that a successful impersonation produces. Continuous identity monitoring watches sign-in behaviour for tell-tale signs: a login from an unexpected country minutes after one in the UK (impossible travel), a burst of repeated MFA prompts indicating push-bombing, a new MFA device registered to a privileged account, access at unusual hours, or a sudden change in the resources an account touches. With a manned response capability behind it, these alerts trigger investigation and containment while the attacker is still moving rather than after the damage is done. At TfL the attackers escalated from a single reset all the way to domain administrator; the difference between spotting an anomaly at the first step and discovering it after full compromise is, in financial terms, the difference between a contained incident and a £39 million recovery. For an SME, this round-the-clock watch is realistically achievable only through a managed IT support partner.
We already have IT support — isn’t that enough to cover this?
It depends entirely on what kind of IT support you have. A reactive, break-fix arrangement that exists to unblock users quickly can actually increase your exposure, because its instinct is to resolve access problems fast — which is precisely the behaviour social engineering exploits. What protects you is proactive managed support that explicitly owns the identity perimeter: a documented help-desk verification standard, phishing-resistant MFA, a least-privilege model maintained as staff change, conditional-access policies, 24/7 sign-in monitoring and a tested incident-response runbook. Ask your current provider whether they have a written identity-verification procedure for resets, whether your administrators use security keys rather than SMS, and whether anyone is watching your sign-ins overnight. If the answer to those is no, you have IT support but not the operational security posture the Scattered Spider case shows you need. Cloudswitched delivers both within a single managed engagement, with a dedicated account manager and an SLA-backed response.

The sentences are in — now fix the perimeter they exploited

The Scattered Spider sentencing is the most concrete proof yet that social engineering, not malware, is the threat that reaches UK businesses of every size. Cloudswitched managed IT support closes the exact gaps it exploited — verification, phishing-resistant MFA, least privilege and round-the-clock monitoring — with proactive ownership and a single point of contact. If your help desk could be talked into a reset today, this is where you start.

Talk to us about Managed IT Support
Tags:IT SupportCyber SecurityCyber EssentialsNetwork Admin
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Managed IT Support

Proactive monitoring, helpdesk and on-site support for London businesses

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

27
  • Cloud Email

Email Encryption: How to Send Confidential Emails Securely

27 Sep, 2025

Read more
12
  • Cyber Essentials

Cyber Essentials Gap Analysis & Remediation: A Step-by-Step Guide

12 Apr, 2026

Read more
12
  • Cyber Essentials

Cyber Essentials Certification in London, Manchester & Birmingham

12 Apr, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.