Nemstar Insights
By Sean Hanna, Founder & Director of Nemstar
June 4, 2025
Let’s be honest, nobody likes hearing about another big company getting hacked. The recent attacks on Marks & Spencer and the Co-op? They’re a wake-up call for everyone, not just the IT crowd. Even the big retailers, with all their money and resources, still got caught out by the oldest trick in the book. Social engineering. That’s just a fancy way of saying someone phoned up pretending to be staff, asked the help desk to reset passwords, and got the keys to the kingdom. No malware, no drama. Just a good story and someone willing to believe it.
The results were, frankly, a nightmare. M&S had to shut down online orders and contactless payments. Staff were told to stay home. In the space of a few days, thirty million pounds vanished and the market wiped £650 million off the company’s value. Co-op did slightly better – they spotted the attack before it could cripple everything, but still lost customer data. Harrods was lucky. They caught it early.
The National Cyber Security Centre jumped in straight away with advice. It’s simple stuff, really. Review how your help desk works, especially for password resets. Get multi-factor authentication in place. Keep an eye out for unusual logins and lock down those privileged accounts. Make your verification processes stronger. Monitor your network like you mean it.
Most of this is about mindset, not just tools. Too often, security gets reduced to a checklist, when really, it’s about how your people think and behave. If your IT team just says “no” to everything, you’ll have a business prevention department, not a security function. If you let managers run wild, you’ll get maximum flexibility and minimum security. The real skill is finding the balance, because security should protect the business, not strangle it.
“If your IT team just says ‘no’ to everything, you’ll have a business prevention department, not a security function. Security should protect the business, not strangle it.”
It’s simple. Attackers are creative. They think outside the box and look for the path of least resistance. If you want to stop them, you need people who can do the same – but for the right reasons. Certified Ethical Hackers are authorised to test systems, find the holes, and tell you about them before someone else does. That’s not just technical. It’s about understanding how businesses work, where the shortcuts are, and what actually matters when it hits the fan.
Here’s what’s keeping me awake at night. Twenty-seven percent of UK businesses don’t have advanced cybersecurity skills, like penetration testing, in-house. Northern Ireland is no different. In fact, with Belfast growing as a tech hub, we’re even more exposed because we need more skilled people than ever before. Banks, manufacturers, insurance firms – everyone is looking for staff with CEH qualifications because the risks are real and immediate.
If you want to learn how to do this properly, come and see us at Nemstar. We don’t do tick-box training. We teach you how real attackers think and operate, and we make sure you can put your knowledge to use the minute you walk out the door.
Here’s what you get with our CEH v13 course:
It does not matter if you’re an IT admin, a security analyst, or just someone thinking about making the jump into cybersecurity. We start with the basics and build you up to the hard stuff. And because employers in Northern Ireland are crying out for these skills, plenty of our students are sponsored through the course.
If you’re serious about a career in cybersecurity or just want to make sure your business isn’t the next one on the front page, get yourself booked onto our Certified Ethical Hacking training. Spaces are limited, and every time there’s another breach, the demand jumps up. Don’t hang about.
Let’s not kid ourselves. Technology alone will not save you from a breach. If your staff can be tricked, if you don’t know where your weak points are, or if you think “it’ll never happen to us”, you are exactly who the attackers are looking for. Northern Ireland’s future as a tech hub depends on growing a pool of skilled, confident security professionals who know how to spot the holes and close them.
For businesses, these retail hacks are a reality check. For local professionals, it’s a real opportunity to gain skills that are in demand everywhere. Invest in your people, invest in yourself, and let’s build a more resilient, more secure future for Northern Ireland.
See you in the training room.

Sean Hanna
Founder & Director
Sean Hanna founded Nemstar in 2009, leveraging 20+ years of cybersecurity expertise to deliver business-focused technical training. As EC Council’s Global Security Trainer of the Year, he has trained thousands globally, including at Microsoft, GCHQ, and the U.S. Navy. Sean led Microsoft Exchange 2000’s technical training launch and helps organizations strengthen their cybersecurity defenses.
Risk &
Compliance