On Thursday, two young hackers were sentenced at Woolwich Crown Court for the 2024 attack on Transport for London — five and a half years each. What made the case notable wasn’t just the sentence length. It was the law used to secure it: Section 3ZA, and this is the first successful prosecution brought under it. For UK business owners, the sentencing is a timely reminder of just how expensive — and how avoidable — an attack like this can be.

The numbers are the real story here. The attack knocked out 148 TfL systems and forced all 27,000 staff into the office in person to get their passwords reset by hand, because remote reset wasn’t safe to trust. The National Crime Agency and Crown Prosecution Service put the total cost of the incident, including recovery, at £29 million. That’s not a fine or a ransom — that’s the bill for cleaning up after the fact, at an organisation with far more security resource than the average SME will ever have.

Why this matters if you’re not TfL

It’s tempting to read this as a story about a giant public body and move on. Don’t. The pattern behind attacks like this — credential theft, weak points in identity and access systems, lateral movement once inside — is exactly the pattern hitting small and mid-sized UK businesses every week. The NCSC has been explicit that state-linked and criminal groups are increasingly targeting the contractors, suppliers and smaller firms around bigger organisations, precisely because their controls are weaker and their access is still useful.

The TfL case is also a signal on the legal side. New prosecution powers mean law enforcement now has a stronger hand to go after attackers, but that’s cold comfort if your business is the one that gets hit first. Prevention and fast detection still do far more for you than the prospect of a conviction two years later.

Three things worth checking this week

Password reset processes. TfL had to bring 27,000 people into a building because remote resets weren’t trustworthy. Ask yourself: if your identity system was compromised tomorrow, could you reset access for your whole team safely, and how long would it take?

Third-party and contractor access. Most breaches like this start with a foothold that shouldn’t have existed — an old account, a supplier login, a forgotten integration. A basic audit of who and what has access to your systems, run quarterly, catches most of this before it becomes a headline.

Monitoring, not just prevention. TfL’s systems were down for an extended period partly because the scale of the intrusion wasn’t obvious immediately. Continuous monitoring that flags unusual account activity early is the difference between an incident that costs a few hours and one that costs weeks.

This is exactly the gap services like KeepSafe are built to close for smaller businesses — ongoing monitoring for the kind of early warning signs that, in the TfL case, took far too long to surface. For a business without an in-house security team, that kind of outside monitoring is often the only realistic way to get enterprise-grade visibility without an enterprise-grade budget.

What the new law actually changes

Section 3ZA gives prosecutors a clearer route to charge people who cause serious disruption to essential systems, rather than relying solely on older computer misuse legislation that wasn’t written with modern, large-scale attacks in mind. That’s good news for deterrence over time, but it’s a legal remedy that arrives after the damage is done. Nothing about a stronger prosecution regime reduces the odds that your business gets targeted in the first place, or shortens the days of disruption if it happens. The practical lesson for SMEs sits entirely on the prevention side, not the legal one.

The takeaway

You will never have TfL’s budget, and you don’t need it. What you need is the basics done consistently: multi-factor authentication everywhere, a tested process for revoking access fast, and someone actually watching for the early signs of compromise. The hackers in this case are going to prison. The £29 million bill still got paid. Prevention is cheaper than either outcome.