Skip to main content

Aeronautics supplier begins a journey to better cyber resilience

The CRC Network often meets small businesses that have suffered cyber attacks. In most cases, these attacks occurred due to a vulnerability; they were not specifically targeted because of the business’s sector, location, size, or trading activities.

It is essential to recognise that cybercriminals primarily target technical and human vulnerabilities, such as unpatched software, weak passwords, and phishing, rather than specific companies. This means that all organisations, regardless of size, are potential victims. However, small businesses are frequently victims because they have limited cyber security resources. This, in turn, creates challenges for larger companies that rely on SMEs in their supply chains.

People often assume these SMEs are low-tech startups run by inexperienced owners, but that’s not always true. The Cyber Resilience Centre for London recently helped a small, well-established, and innovative business that develops advanced technology for the aeronautics industry. Their clients include many top global companies in aeroplane design and manufacturing.

The CEO clicked a link in an email she thought was from a customer. By the time she realised it was fake, the damage was already done. Malware had entered their systems, causing ongoing data corruption and hurting their ability to analyse information. The team tried to keep the business running as usual, even though this happened during a period of growth. They didn’t know what data had been lost or how to respond.

Soon after signing up with the London CRC, they received the standard one-to-one consultation call during which they disclosed the ongoing problem. We immediately guided them through the Report Fraud process and advised them to use the 0300 123 204 telephone service, given the urgency of their situation.

Following the immediate actions provided by PROTECT, we offered a further consultation to support them in becoming more resilient. We introduced them to the Cyber Action Toolkit, an NCSC online platform that provides step-by-step guidance specifically designed for SMEs with little or no internal cyber security resources.

We also suggested our fully funded Cyber PATH Security Awareness Training for all their staff, which they were happy to accept. Since then, the company has become much more aware of cyber risks and has joined webinars hosted by the CRC Network.

Speaking to London CRC, the company’s CEO said:

"I thank you very much for your support, and for the time you have taken to teach me how to protect my business, and to report any cybercrime. As discussed, I already see the positive impact of the Cyber Resilience Centre on my business.


"I feel much better prepared to face and manage cyber attacks to keep my business safe. As soon as the remedial work is finished, I will contact Cyber PATH for further support".


Speaking about the incident, the Director at London CRC, Richard Morrison-Butcher commented:

“It was great to be able to support the company, initially on their recovery journey with the help of PROTECT, but also to be providing ongoing services that will make them more resilient in the future.


“This is an excellent example of how even sophisticated technology businesses can become victims of cyber attacks. Given the significant global organisations they work with, the potential damage could have been far-reaching. It serves as an important reminder that all businesses have a responsibility to protect themselves and those in their supply chain.”


Written by:
FatBuzz
22 April 2026