From Resilience to Ruin: What the Knights of Old Cyber Attack Teaches Us About Crisis Preparedness

Written by: Piers Shearman

Categorised: Cyber Resilience, Ransomware

Cyber crises land on real organisations, with real people, and real consequences. The collapse of Knights of Old, a 158-year-old British logistics company, is a sobering reminder that even the most established businesses can be brought down by a cyber-attack. At Red Goat Cyber Security, we believe the most valuable lessons come from honest reflection on what went wrong, and how leaders can prepare for the unpredictable.

What happened at Knights of Old

A 158‑year‑old British logistics group, KNP Logistics trading as Knights of Old, suffered a ransomware attack in June 2023. The attackers from the Akira group allegedly got in by guessing an easy password on an externally exposed service that did not have multi‑factor authentication. Once inside, they deployed ransomware, destroyed backups and disaster recovery tooling, and left a note inviting “constructive dialogue.” The estimated demand was about £5 million. Without viable backups or the funds to pay, operations stalled, 500 lorries were effectively immobilised, and more than 700 people ultimately lost their jobs as the company entered administration. 

Those are stark facts. Yet the real value for leaders is not just knowing what went wrong, but how to think and act when a cyber crisis is messy, fast moving and information poor. That is where adopting the pillars we use in exercises helps.

Pillar 1: Roles and responsibilities that work under pressure

Crisis management benefits from clear levels of responsibility. In the UK emergency services this is often framed as strategic, tactical and operational. In cyber incidents, that separation keeps directors focused on outcomes and priorities while technical teams contain, investigate and restore. In Knights of Old’s case, specialist responders were brought in through the insurer and took point on the technical work, while directors managed business decisions. The public record suggests reliance on external responders rather than a rehearsed internal command structure, which limited options once the blast radius became clear. 

Incident takeaway. Decide in advance who chairs the strategic group, who owns tactical co‑ordination, and who runs the operational workstreams. Write it down, rehearse it, and empower people to act within defined thresholds when minutes matter. This mirrors how we frame crisis roles in our briefings. 

Pillar 2: Communication that is timely, honest and consistent

In our engagements we say communication is the second most important function in a cyber incident after technical response. When it is slow, inconsistent or overly optimistic, trust erodes and reputational damage compounds. Strong examples exist, Ferrari’s transparent, CEO‑fronted updates as a benchmark, whereas others who have opted for the “IT outage” framing, have ended up creating a credibility gap. 

Knights of Old communicated that there had been a cyber attack, and colleagues recall being told things were getting back to normal a month later. In reality, recovery was not on track. Many employees reported feeling blindsided when the closures and redundancies came at short notice. That gap between internal sentiment and external reality possibly made a hard situation worse. 

Incident takeaway. Prepare plain‑language templates for internal updates, customer notifications, regulator engagement and media holding lines. Set a cadence for updates, even if the update is “no change.” Align every message with legal advice and a single source of truth. This is exactly the pattern we practise in exercises. 

Pillar 3: Important business services and their dependencies

In crisis we anchor on what the organisation must keep doing to survive, and what technology those services rely on. Logistics is heavily dependent on routing, order management, billing and communications. When ransomware encrypts those systems and backups are gone, you are effectively running blind. Knights of Old allegedly attempted manual workarounds for a period, but it was claimed that without reliable finance data the company could not meet lender reporting obligations and ran out of room to manoeuvre. 

Incident takeaway. Identify your important services and enumerate the minimum viable technology they rely on. Decide how you would continue if those systems vanish for days, weeks or months. Put that plan in a pack that the crisis team can actually use. 

Pillar 4: Containment decisions under uncertainty

Containment is about “stopping the bleeding.” Sometimes that means pulling networks offline fast, accepting short‑term pain to prevent long‑term ruin. In recent UK retail cases, disconnecting at scale limited damage but created a complex and costly recovery. We emphasise in exercises that you may have to empower operational leads to make that call in minutes, not hours. 

In this case, it is possible that by the time responders were engaged, encryption and backup destruction meant traditional containment options were spent.

Incident takeaway. Pre‑agree triggers for aggressive containment and who can pull them. Practise what happens next so you understand the knock‑on effects on restoration. Fast, proactive decision making in the case of the Co-op meant they were able to stop the detonation of the payload across their estate.

Pillar 5: Recovery that accepts the timeline

Restoration takes time. We coach leaders to ask: in what order do we bring systems back, how do we validate they are clean, and what is our honest recovery window. In major incidents, months is common. For Knights of Old, with backups destroyed and limited resources, there was no viable route to rebuild at pace. 

Incident takeaway. Invest in offline or immutable backups and test restores routinely. Build recovery plans and communicate realistic timelines. 

Why this case matters beyond logistics

Ransomware groups target known weak points and predictable pressure windows. Universities near term start, hospitals in winter, game studios pre‑launch, retailers at Christmas. The pattern we stress in briefings is consistent: attackers only need to be lucky once; your teams need to be effective every time. That is why we push the combination of prevention, detection, communication and continuity rather than a single silver bullet. 

Closing thought

Ransomware is not just an IT problem. It is a leadership, communication and continuity problem. Knights of Old did many things right and made some mistakes that many organisations would also make. They believed they were in a good place, had insurance and compliance boxes ticked, and made heroic efforts to keep going once hit. Ultimately they were unlucky.

Learn from it now, not later. 

Related Content

Menu