Marks & Spencer CEO Stuart Machin will not receive an annual bonus following the cyberattack that disrupted the retailer’s operations and affected its financial performance.

The decision was revealed in the company’s latest annual report, which showed the impact the incident had on the business. While the board praised management’s response to the crisis, it concluded that bonus payments were not appropriate given the disruption experienced by customers, employees, and shareholders.

The M&S cyberattack bonus decision comes after one of the most significant cyber incidents to hit a major UK retailer in recent years.

Attack Caused Months of Disruption

The attack struck Marks & Spencer in April 2025 and quickly affected several parts of the business. Online operations faced disruption, while internal systems and retail processes also experienced difficulties.

The company spent months restoring affected services and managing the fallout. The incident created operational challenges throughout the year and forced the retailer to dedicate significant resources to recovery efforts.

Although stores continued operating, the cyberattack affected the company’s ability to serve customers efficiently. The disruption also increased costs and placed pressure on business performance during the financial year.

Marks & Spencer has previously warned investors that the attack would have a substantial financial impact. The company continues to assess the full cost of the incident as recovery work progresses.

Board Links Pay to Performance

According to the annual report, the remuneration committee decided that executive bonuses should reflect the challenges faced by the business during the year.

While directors acknowledged the efforts made by leadership teams during the crisis, they determined that awarding annual bonuses would not align with overall company performance.

As a result, Stuart Machin did not receive an annual bonus payment. The decision contributed to a noticeable reduction in his total compensation package compared with the previous year.

The move reflects a growing trend among large organizations to connect executive rewards with operational resilience and risk management outcomes.

Cybersecurity Reaches the Executive Level

Major cyberattacks are increasingly influencing decisions far beyond technology departments. Incidents that disrupt operations can affect financial results, shareholder value, and executive compensation.

For retailers, cyber resilience has become a critical business issue. Modern retail operations depend heavily on digital systems that support e-commerce, inventory management, logistics, and customer services.

When those systems become unavailable, the consequences can spread across the entire organization. Companies are therefore facing greater pressure to strengthen cybersecurity defenses and improve incident response capabilities.

The Marks & Spencer case demonstrates how boards are treating cyber risk as a core business concern rather than a purely technical issue.

Conclusion

The M&S cyberattack bonus decision highlights the lasting consequences of major cyber incidents. Stuart Machin lost his annual bonus after a year marked by operational disruption and costly recovery efforts. As cyberattacks continue to affect large organizations, executive accountability and cyber resilience are becoming increasingly connected.


0 responses to “M&S Cyberattack Bonus Cut Leaves CEO Without Payout”