All news
Security
15 June 2023

MOVEit: how a supplier's software put UK payroll data on the internet

A flaw in a widely used file transfer product was exploited at scale, exposing data held by payroll bureaux, councils and outsourcers — including UK household names.

What this means for your business

Businesses that had never heard of MOVEit had staff data leaked because a supplier used it. Your risk is not just your own systems.

In mid-2023 attackers exploited a zero-day flaw in Progress Software's MOVEit Transfer product. Because MOVEit is used by payroll providers, outsourcers and public bodies to shift bulk files, the fallout reached organisations that had no direct relationship with the product at all. In the UK, staff data from a number of large employers was exposed through a payroll bureau.

The lesson for smaller firms

You can have tidy patching, MFA everywhere and good backups, and still have your employees' bank details published because your accountant's software had a bug. Third-party risk is the part of security small businesses most often skip.

What's actually practical

  • Know who holds your data. Payroll, accountancy, HR, CRM, marketing lists. Write the list down — it's also a GDPR requirement.
  • Ask them one question: what happens, and how quickly will you tell us, if you have a breach? A supplier who can answer clearly is usually a supplier who has thought about it.
  • Minimise what you hand over. Old employee records sitting in a portal you no longer use are pure liability.
  • Have your own incident contacts ready — ICO reporting is 72 hours, and that clock is unforgiving.

Cyber Essentials certification covers a lot of this ground and is increasingly asked for by customers and insurers.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.