TCS under scanner amid growing cybersecurity pressures after M&S breach

TCS, which has been a longstanding IT services provider for M&S for over a decade, is reportedly aiming to conclude its investigation by the end of this month.

By  Storyboard18| May 23, 2025 6:53 PM
TCS plans to reduce its workforce across all global locations where it operates during the fiscal year 2026 (April 2025 to March 2026).

India’s tech giant Tata Consultancy Services (TCS) has launched an internal probe to assess whether vulnerabilities within its systems played a role in the cyberattack that recently hit British retailer Marks & Spencer (M&S), according to a report by the Financial Times. The move marks a critical moment not just for TCS, but for the broader conversation around third-party cybersecurity risks in global outsourcing partnerships.

TCS, which has been a longstanding IT services provider for M&S for over a decade, is reportedly aiming to conclude its investigation by the end of this month. The probe’s findings could have far-reaching implications for how companies evaluate their vendor ecosystems in an era where cyberattacks increasingly exploit third-party access points.

The breach, first disclosed by M&S in April, has already dealt a significant blow to the UK retailer, with estimated losses of £300 million ($404.9 million) in operating profit. The attack also disrupted online operations—a key revenue stream for M&S with full restoration not expected until July.

Neither TCS nor M&S has issued an official statement confirming the link or details, while Reuters reported that both companies declined immediate comment.

The incident highlights the rising scrutiny on IT service providers and the growing accountability they face as cyber threats evolve. With large enterprises relying heavily on outsourced digital infrastructure, even trusted, long-term partners are being reevaluated under a new cybersecurity lens.

As TCS works to identify any potential lapse, the episode raises broader industry questions about the resilience of managed service partnerships and whether companies are adequately prepared to detect, respond to, and recover from breaches originating within their extended digital supply chains.

First Published onMay 23, 2025 6:53 PM

SPOTLIGHT

Brand MarketingAI, storytelling or speed: What’s the new B2B marketing edge?

Today’s B2B marketers wear many hats: strategist, technologist, and storyteller.

Read More

Explained: What the Online Gaming Bill means for the industry, users and platforms

The Online Gaming Bill 2025 imposes severe penalties, allows warrantless search and seizure, and empowers a central authority to regulate the digital gaming ecosystem. It is expected to disrupt platforms, payment systems, and advertising in the sector. Here's all you need to know about the bill.