Skip to content
Friday 7 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,901.09
+0.31%
DAX
26,319.45
+0.69%
CAC 40
8,714.93
+0.17%
STOXX 50
6,523.86
+0.33%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 20 May 2025 5:11 am  |  Updated:  Monday 19 May 2025 4:20 pm

Protecting against cyber attacks means tackling rational inattention

By: Paul Ormerod

Add as a preferred source on Google
The board unaminously agreed to extend Norman's position as Chair
M&S was among a number of household names that suffered cyber attack losses

Cybersecurity, highlighted by recent attacks on the Co-op and Marks & Spencer, is not just a technical challenge but also a human and economic one, says Paul Ormerod

Cyber security has featured prominently in the media, following the attacks on the Co-op and Marks and Spencer.  

The Co-op has recovered rather the better of the two. By taking their IT systems offline, they suffered more immediate damage, with empty shelves in many stores. But by so doing, they both prevented a ransomware attack and made the problem easier to remedy.

Their action prompted the criminals to complain, as old-fashioned burglars used to when breaking into coin-operated electricity meters and finding pennies filed down to resemble coins of a higher denomination. They accused the company of “torching shareholder value” – by preventing a ransomware attack!

Cyberattacks involve illegal activities. But otherwise it is an industry just like any other such as cars or televisions. It has firms which develop and supply products. It has business-to-business markets where bits of kit can be traded. It has business-to-consumer markets, although in this case the “consumers” such as Marks and Spencer are not exactly demanding its products.

A key feature of this industry is its rapid pace of innovation. At a basic level, simply reflect on how often your laptop or smartphone demands that updates be installed.  Most of these are part of the ongoing evolutionary game which is played between the would-be attackers, and the defenders who want to prevent disruption to their systems.

But providing cyber security involves far more than being good at technological innovation, essential though this is.  

Human motivations and incentives are also a key part of the defence against cyberattacks.

An important aspect of this is the phenomenon which economists describe as “rational inattention”. Even the smartest and most productive individual has limits to the bandwidth which he or she can deploy.  Not everything can be given the same degree of attention.

Read more

M&S to face shareholder grilling over cyber attack recovery

Marks and Spencer was one of three UK retailers to be targeted

Companies will often have many operating procedures in place. But staff may not follow them to the letter, discovering short cuts, especially when the chances of anything going wrong are perceived as being low.

Hackers move in where threats are perceived as less likely

For example, from the outset of the pandemic I thought it was wrong to dismiss the lab leak hypothesis. Three researchers from the Wuhan Institute, along with some American scientists, had published a paper in Nature Medicine, a very prestigious outlet, in 2015 with the title “A SARS-like cluster of circulating bat coronaviruses shows potential for human emergence”. Wuhan was working on the issue. A lab technician finds a short cut in the security process, which almost all the time is secure.  Except the rare event happens and the virus escapes.  All very plausible.

The same principle applies to cyber security. Staff rationally pay less attention to areas where threats are perceived as being very unlikely, and the hackers move in.

Rational inattention prevails in many boardrooms. The probability of a damaging attack is thought of as low, and so other items on the agenda consume the time and energy of the members.

More generally, from a national security perspective, the low level of priority given to security by the individual companies creates what is known as a “negative externality”. 

Firms which underinvest in security do not bear the full costs of their actions. The Co-op itself suffered, for example, but so too did its many suppliers, who lost sales. The end result is that the level of security at the national level is lower than is desirable.

Externalities are a very familiar concept in policy making. On climate change, for example, the negative externalities of emissions has led to a whole raft of taxes and subsidies designed to offset them.

The government must start regarding cyber threats in the same way and come up with a policy package to enhance national security.

Paul Ormerod is an Honorary Professor at the Alliance Business School at the University of Manchester, an economist at Volterra Partners LLP, and author of Against the Grain: Insights of an Economic Contrarian, published by the IEA in conjunction with Morning Wire

Read more

UK government probes OpenAI breach after ‘unprecedented’ hack

Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Opinion

Categories

  • Opinion

Trending Articles

  • Revolut founder’s wealth set to balloon amid talks of share award at $500bn valuation

  • Rupert Lowe axes pensions triple lock and pledges tax cuts in economic plan

  • WPP slashes jobs as revenue continues to fall

  • Liverpool owners tipped to sell – but not to Amazon boss Bezos – by former CEO

  • As it happened: Stocks rise as oil fluctuates after Red Sea attack; US-Iran deal ‘being circulated’

More from Morning Wire

  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Ocado lets Marks & Spencer off hook in £190m payout dispute

    Retail
    Ocado's partnership is the latest in a line of robotics rollouts from other grocers.
  • Tiktok pledges three-stage age checks as it pilots alcohol sales

    Tech
    Tiktok appeals to overturn US ban in a broader battle for tech regulation
  • It’s hard to picture a more nightmarish vision of our AI future than this

    AI
    Stack of diverse books showcasing various genres and authors, illustrating the articles focus on literary diversity and tr...
  • Ocado boss Steiner ‘energised about future’ despite succession battle

    Retail
    Business professionals discussing market trends at a conference table, analyzing data on laptops and charts, emphasizing t...
  • ‘Extremely dangerous’: AI warfare much bigger threat than LLM model advances, experts warn

    AI
    Swarm of AI-powered drones flying over a city skyline, symbolizing modern warfare and autonomous technology.
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook