TCS under scanner amid growing cybersecurity pressures after M&S breach

TCS, which has been a longstanding IT services provider for M&S for over a decade, is reportedly aiming to conclude its investigation by the end of this month.

By  Storyboard18| May 23, 2025 6:53 PM
TCS plans to reduce its workforce across all global locations where it operates during the fiscal year 2026 (April 2025 to March 2026).

India’s tech giant Tata Consultancy Services (TCS) has launched an internal probe to assess whether vulnerabilities within its systems played a role in the cyberattack that recently hit British retailer Marks & Spencer (M&S), according to a report by the Financial Times. The move marks a critical moment not just for TCS, but for the broader conversation around third-party cybersecurity risks in global outsourcing partnerships.

TCS, which has been a longstanding IT services provider for M&S for over a decade, is reportedly aiming to conclude its investigation by the end of this month. The probe’s findings could have far-reaching implications for how companies evaluate their vendor ecosystems in an era where cyberattacks increasingly exploit third-party access points.

The breach, first disclosed by M&S in April, has already dealt a significant blow to the UK retailer, with estimated losses of £300 million ($404.9 million) in operating profit. The attack also disrupted online operations—a key revenue stream for M&S with full restoration not expected until July.

Neither TCS nor M&S has issued an official statement confirming the link or details, while Reuters reported that both companies declined immediate comment.

The incident highlights the rising scrutiny on IT service providers and the growing accountability they face as cyber threats evolve. With large enterprises relying heavily on outsourced digital infrastructure, even trusted, long-term partners are being reevaluated under a new cybersecurity lens.

As TCS works to identify any potential lapse, the episode raises broader industry questions about the resilience of managed service partnerships and whether companies are adequately prepared to detect, respond to, and recover from breaches originating within their extended digital supply chains.

First Published onMay 23, 2025 6:53 PM

SPOTLIGHT

Brand MakersDil Ka Jod Hai, Tootega Nahin

"The raucous, almost deafening, cuss words from the heartland that Piyush Pandey used with gay abandon turned things upside down in the old world order."

Read More

The new face of the browser: Who’s building AI-first browsers, what they do and how they could upend advertising

From OpenAI’s ChatGPT-powered Atlas to Microsoft’s Copilot-enabled Edge, a new generation of AI-first browsers is transforming how people search, surf and interact online — and reshaping the future of digital advertising.