Manchester Airports Group kept its airports operating through a major cyber incident. At the same time, data relating to millions of customers was stolen.
Together, those outcomes show why cyber resilience needs to be measured across the business, rather than by operational uptime alone.
On 27 August 2026, Manchester Airports Group (MAG) disclosed that an unauthorised third party had obtained customer data associated with Manchester, London Stansted and East Midlands airports. Approximately 8.7 million customers were affected. The compromised information included email addresses, phone numbers, postcodes and vehicle registration numbers collected through services including parking, lounges, Fast Track and airport Wi-Fi. MAG said the affected systems did not hold customers’ bank or payment details.[1]
Airport operations continued. Passenger safety and aviation security were unaffected, parking remained available and MAG restricted access to affected systems while investigating the incident. Its online Manage My Booking service was suspended as a precaution.
That is a meaningful resilience outcome. It is also only part of the story.
Want to build a more connected view of cyber risk across your business? Download our From cyber fragmentation to cyber risk clarity eBook for practical guidance on connecting cyber risks, controls, incidents and business impact.
The breach that did not stop the airport
Reporting indicates that the incident involved data theft and extortion rather than ransomware. MAG told The Register that attackers compromised one of its systems and stole files from a database hosted by a third party. The overwhelming majority of affected customers had only their email addresses exposed, most commonly through airport Wi-Fi registration. MAG also said it had not paid the extortionists.[2]
There are limits to what can be concluded at this stage. As of 1 September, MAG had not publicly identified the initially compromised system or explained how access was gained. But the broader lesson from MAG does not depend on knowing the eventual root cause.
Critical services continued to operate while a large volume of customer information was compromised. Both outcomes belong in the assessment of resilience.
The UK National Cyber Security Centre defines cyber resilience around an organisation’s ability to protect itself from, prepare for, respond to and recover from cyber incidents, data breaches and service outages.[3]
Keeping the airports operating demonstrates one part of that capability. The consequences of the stolen data show another.
The impact extends beyond the compromised system
The personal information exposed in the breach may remain useful to criminals after the original intrusion has been contained.
An email address has limited context on its own. An email address associated with a particular airport, parking service or travel activity can support a much more credible message. Phone numbers, postcodes and vehicle registrations add further detail.
The NCSC warns that criminals can use information obtained in breaches to make phishing communications more convincing. They may also impersonate an organisation after a publicly disclosed incident, taking advantage of customers who are already expecting communications about the breach.[4]
Experts commenting on the MAG incident raised the same concern. They highlighted the potential for stolen information to support convincing messages about parking, Fast Track bookings or the breach itself. They also pointed to Wi-Fi, parking and lounge services as examples of systems that can create meaningful cyber exposure even though they sit outside core aviation operations.[5]
This widens the business impact considerably. A cyber incident can activate privacy or data breach reporting obligations, fraud exposure, additional customer-service demand, regulatory scrutiny and reputational consequences without interrupting the organisation’s primary service.
For risk leaders, that makes the customer data platform or parking access system part of the cyber risk picture even if it never controls a flight, factory, payment network or other critical operation.
The cyber perimeter follows the business
Modern organisations depend on a broad network of applications, cloud platforms, suppliers, outsourced services, APIs and data stores.
Systems that appear peripheral from an infrastructure perspective can be central to a customer journey or hold information that creates significant regulatory and reputational exposure.
For CISOs, that raises a practical assurance question: do customer platforms, supporting applications and third-party data stores receive the same dependency mapping and risk scrutiny as systems already classified as operationally critical?
The UK Cyber Governance Code of Practice reflects this broader view. It asks boards to identify the technology, processes, information and services critical to organisational objectives, integrate cyber risks into wider enterprise risk management and internal controls, and build resilience to risks arising through suppliers and business partners.[6]
This requires a wider view than a list of critical systems.
A supplier may host data used by a customer-facing application. That application may support a business service. Several controls may protect the relationship. A breach may trigger incidents, remediation, regulatory obligations and assurance work across different teams.
The connections already exist in the business. Risk management needs to be able to see them.
Protecht helps bring cyber risks, controls, incidents, obligations and third-party relationships into a connected view, so teams can examine cyber exposure in its wider business context rather than rebuilding those relationships when an incident occurs.
Containment depends on context
MAG says it restricted access to affected systems while airport operations continued.
That points to an important resilience objective: limit how far a compromise can spread.
Technical controls remain essential. Segmentation, identity and access management, monitoring and secure development can all reduce exposure and help protect critical services.
Effective containment also requires context.
During an incident, teams need to understand which systems and data are affected, what those systems connect to, which suppliers are involved, which business services depend on them, and which controls are expected to limit the impact.
The test is how quickly those relationships can be understood. If a third-party data store is compromised, can the organisation identify the affected services, customers, obligations and control dependencies within hours, or does that picture take days to assemble?
If this information sits across separate registers, spreadsheets, vendor records, control libraries and security systems, incident response can become an exercise in reconstructing the business under pressure.
The same connections matter once the immediate threat has been contained. Teams need to understand whether controls require reassessment, whether similar exposures exist elsewhere, which actions need to be tracked and whether the event changes the organisation’s wider risk profile.
Good resilience therefore includes learning. The organisation should be able to convert what happened into changes to controls, risk assessments and future response.
Measure resilience across the business
It would be premature to draw broad conclusions about MAG’s overall cyber resilience from the information currently available.
We can, however, see two very different outcomes. Critical airport operations remained available. Customer information was exposed on a significant scale.
A useful resilience assessment needs to accommodate both.
Boards and risk teams should look at how quickly incidents are detected and contained, what an attacker can reach, which services continue operating, what information is exposed and what harm could follow. They also need confidence that control performance can be demonstrated, similar weaknesses can be identified elsewhere and the change in business risk can be understood.
The NCSC’s Cyber Security Toolkit for Boards takes this organisation-wide approach, covering preparedness, incident response, recovery, assurance and the integration of cyber resilience throughout the business.[7]
These are more useful measures than treating the absence of downtime as proof that an incident was successfully contained in every meaningful sense.
Cyber resilience needs a connected view
The MAG incident does not point to a simple prescription for another cyber security tool.
Its stronger lesson is about how cyber risk travels through a business.
Core operational systems matter. So do the applications around them, the suppliers they rely on, the data they hold, the controls protecting them and the customers who may be affected when something goes wrong.
Organisations cannot eliminate the possibility of compromise. They can improve their ability to understand exposure, protect critical services, contain incidents and respond with evidence.
That becomes much easier when cyber security information can be connected with enterprise risks, controls, third parties, incidents, obligations and business services.
Manchester Airports Group kept its airports running. Millions of customers were still caught in the breach.
Cyber resilience needs to account for both.
Protecht helps organisations connect cyber and IT risk with the wider enterprise risk picture, giving teams clearer visibility of controls, incidents, dependencies and business impact. Book a demo to see how Protecht can support a more connected approach to cyber resilience.
References
[1] Manchester Airports Group, “Data Security Incident - 27.08.26”, Manchester Airport, August 2026
[2] Connor Jones, “Cybercrooks jet off with Manchester Airports Group customer data”, The Register, August 2026
[3] National Cyber Security Centre, “Introducing the Cyber Security Toolkit for Boards”, version 3.0, April 2025
[4] National Cyber Security Centre, “Data breaches: guidance for individuals and families”, January 2021
[5] Benedict Collins, “How did the Manchester Airports Group cyberattack take place, and what data was exposed in the 8.7 million customer records? The experts weigh in”, TechRadar Pro, August 2026
[6] Department for Science, Innovation and Technology and National Cyber Security Centre, “Cyber Governance Code of Practice”, GOV.UK, April 2025
[7] National Cyber Security Centre, “Cyber Security Toolkit for Boards”, version 3.0


