8.7 million reasons to know where your data is

This week, Manchester Airports Group (MAG) confirmed that an unauthorised third party had accessed customer data linked to car park, lounge and Fast Track bookings, plus in-airport WiFi sign-ups, across Manchester, Stansted and East Midlands airports. Around 8.7 million customers were affected. Email addresses, phone numbers, vehicle registrations and postcodes were exposed. No bank details were taken, and MAG says a ransom demand went unpaid.

It's a big number, from a big organisation, with a well-resourced security team. Which is exactly why it's worth paying attention to.

Why this matters more than the headline number

The size of a breach isn't really the story. The story is what happens in the hours and days after it's discovered and that's where organisations either hold their ground or lose control of the narrative entirely.

Knowing where your data lives. MAG could say fairly quickly which systems were touched car parking, lounge, Fast Track, WiFi sign-ups — and which weren't, including operational and payment systems. That kind of clarity doesn't happen by accident. It comes from knowing exactly what data you hold, where it sits, and which systems talk to which. Without a clear data map, incident response starts with guesswork, and guesswork costs time you don't have.

Immutable backups and cyber vaults. Ransomware groups don't just steal data anymore — they go after your backups first, so you can't recover without paying. An immutable, air-gapped copy of your critical data (one that can't be altered, encrypted or deleted, even by someone with admin credentials) is what turns a ransom demand into a non-event. MAG says it didn't pay. That's only a viable stance if you've already made paying unnecessary.

How fast you can actually recover. Backups you've never tested are a hope, not a plan. The organisations that come through an incident looking composed are the ones that have rehearsed recovery who knows what to restore first, how long it takes, and what "back to normal" actually looks like long before they ever need to do it for real.

Transparency with customers. MAG notified affected customers, was upfront about what data was and wasn't taken, and kept services like Manage My Booking running with clear guidance. Contrast that with breaches where organisations downplay, delay or bury disclosure — those are the ones that end up dominating the news cycle for the wrong reasons, facing regulatory penalties, and losing customer trust for years. Being straight with people when things go wrong isn't just a compliance obligation; it's reputational insurance.

The cost of getting it wrong. Delayed detection, unclear data ownership, no tested recovery plan, and vague or defensive communication that combination is what turns a cyber incident into a full-blown crisis. Regulatory fines, customer churn, and the drawn-out reputational damage of "the company that didn't come clean" usually cost far more than the incident itself.

Being prepared isn't optional anymore

Every business now holds customer data somewhere a booking form, a WiFi sign-up, a loyalty scheme. That makes every business a target, regardless of size or sector. The organisations that fare best aren't the ones that never get attacked; they're the ones that assume they will be, and have already answered the hard questions before an attacker forces them to.

Where Synapse fits in

This is exactly the ground Synapse works on every day. We help organisations get a genuine handle on where their data lives, put immutable backup and cyber vault protection in place so recovery doesn't depend on an attacker's terms, and build tested, workable recovery plans so "we've contained it" is followed by "and we're back up"  not weeks of uncertainty.

Protecting data isn't just about keeping attackers out. It's about making sure that when something does happen and increasingly, it's a case of when, not if you can recover quickly, keep operating, and be straight with the people whose data you hold.

If you're not confident you could answer those questions today, that's the conversation worth having before an incident forces it.

Get in touch with Synapse to talk about protecting, and backing up your data.

Share this post