ASOS HACKED landed on my phone an hour after the NCSC warned us about ransomware
Head of Corporate Secretarial Services Ben Turner shares his insights into the most immediate threat facing UK organisations.

This morning I sat in a room of company secretaries, legal experts and governance professionals at the The Chartered Governance Institute UK & Ireland North conference in Manchester. The National Cyber Security Centre (NCSC) told us ransomware is the most immediate threat facing UK organisations. Less than an hour later, a push notification from ASOS lit up phones across the country. Two words were in the title: ASOS HACKED.
The demand did not go to the chief information security officer, it went to customers' lock screens, in a channel they trust, in full public view.
If that notification had carried your company's name, what would have happened in the next sixty minutes? Who would have decided?
What the NCSC told us
Cub Llewelyn-Davies, Senior National Resilience Lead for Economy and Society at the NCSC, opened with what he called the “scary part first”. He said the cyber threat to the UK is more acute and more complex than ever before, and it is changing faster.
Nation states remain active against critical sectors and technology providers. For most people in the room, the bigger problem is organised crime. Cub said these groups run with a discipline that would shame some of our own governance processes. Their model is extortion. They encrypt systems, steal data, and apply pressure until someone pays.
He raised two trends:
- Supply chain. Almost every major incident the NCSC sees has a supply chain component. Attackers compromise a supplier, often without knowing who sits upstream. That foothold then turns out to matter to someone else's ability to operate.
- Artificial intelligence. It lowers the barrier to entry for criminals and raises the speed and scale of attacks. The gap between a vulnerability being found and exploited is shrinking sharply. Cub cited a well-known internet browser that usually ships 40 to 60 security patches a month. It recently shipped around 450 in one month as AI tools sped up discovery. His advice to boards was blunt. The risk assumptions you set at your annual offsite will go stale much faster than they used to.
My main takeaway was that the gap between well defended and poorly defended organisations will widen. Those already doing the basics well will gain most from AI. Everyone else faces a much steeper hill.
What has been reported at ASOS
A note of caution: This story is still developing and the claims in the notification are unverified. Nothing here is a judgement on ASOS or its people. Any organisation can be targeted and one thing is certain, there will be many others in the months and years ahead.
Shortly before 10am, ASOS app users received a notification titled "ASOS HACKED". It was publicly addressed to the company's Data Protection Officer and IT team. It claimed a Snowflake instance had been compromised and linked to a Telegram channel. Snowflake is a widely used, cloud-based data platform. Other news outlets reported that the website and app kept working. ASOS said it was investigating. ITV News reported the share price fell by more than 10% during the morning.
Ransom demands are normally negotiated in private. This one went out through ASOS's own customer channel. Customers, journalists and investors became the audience, and the pressure landed on the board. The claimed entry point is a third-party cloud data platform. That is the supply chain dependency the NCSC described an hour earlier.
Any board in that position would be asking these questions.
Has the agreed plan been invoked, and who invoked it? Is there a named incident lead, and does each executive and non-executive director know their role?
What do we actually know? Is the claim genuine, and what data is involved? How did someone gain the ability to push messages to our customers?
What must we disclose, and by when? A listed company has market announcement duties. A personal data breach must be reported to the regulator within 72 hours. Customers should hear from us before they hear from someone else.
What is our position on engaging or paying? Cub urged every board to settle this in advance. The ethical, legal and commercial arguments all collide, and mid-incident is the worst time to hear them for the first time.
Who speaks for us? One voice and one message, across the market, press, customers and staff.
Can we keep trading? If key systems or channels went offline, how would we keep serving customers?
Every one of those is a governance question. Many firms have been asking these questions since the well-publicised M&S and Co Op cyber-attacks last year.
Five questions for your next board meeting
The NCSC's Cyber Governance Code of Practice was developed with input from the industry and the CGI. It is a short companion to the longer Board Toolkit and sets out five principles. Each one converts into a question.
- Risk management. Do we know our most critical digital assets? These are the systems without which the business stops. Is our cyber risk appetite explicit enough for the technology team to decide where to spend time and money? Do we know where our key third party dependencies sit?
- Strategy. Do we have a cyber resilience strategy aligned to the business strategy? Cub said around 40% of large organisations still do not. A strategy written before AI enabled threats needs a fresh look.
- People. What behaviours are we reinforcing? Cub described a manager who shouted for fifteen minutes at staff who failed a phishing test. Ask who in that room will own up to clicking a real link. A blame culture buys silence, and silence costs time during an incident. The NCSC offers free cyber e-learning for board members and governance professionals.
- Incident planning, response and recovery. Could we keep operating through a significant incident? IT restores systems. The board and the business decide how to serve customers with minimal technology. Exercise this at least annually with the right people in the room, and settle your ransom stance beforehand.
- Assurance and oversight. How confident are we that our controls work under pressure? Clear accountability, good reporting and independent assurance against a framework all help. Examples are Cyber Essentials, ISO 27001 and the National Institute of Standards and Technology (NIST) framework. A control that has never been tested is an assumption. Are these being scrutinised enough by your Board, or do you need to re-assess your governance structure given how rapidly threats are evolving?
What to put in the board pack
Someone on the floor asked what good board reporting looks like. Cub's reply is worth passing to your directors.
The usual metric is the number of attempted attacks blocked. It makes the IT team look good, but it says little about how the business would cope with a breach. He suggested two better measures.
Mean downtime. When an attack gets through, how long are systems offline and how quickly are they restored? Track it over time and push it from half a day towards hours. It also tests how fast the board makes prioritisation decisions.
Time to deploy critical patches. Cyber Essentials sets 14 days as the benchmark. With AI shrinking the time to exploit, each extra day is a day of exposure.
If your board pack celebrates activity, check what it leaves out. Enable your directors to challenge what is being presented.
Over to you
Company secretaries and general counsel often know where accountability sits, who can convene the board at short notice, and what must be disclosed. They also tend to know whether the plan on the shelf has ever been tested.
When did your board last run a cyber incident exercise, and who was in the room? Has it agreed its position on ransom payments? I would like to hear your answers, here or by direct message.
At The Law Debenture Group, our Corporate Secretarial Services team supports boards with governance frameworks, advisory work and independent board effectiveness reviews. If today raised questions for you, I am happy to talk them through.
Please do reach out to ben.turner@lawdeb.com