How to Conduct a Security Audit Before Attackers Find the Gap
Knowing how to conduct a security audit is no longer optional after this week’s news out of the UK. Manchester Airports Group, which runs Manchester, Stansted, and East Midlands airports, disclosed a data breach affecting roughly 8.7 million customers, discovered on August 25, 2026, with the underlying access to data having occurred over the prior weekend.
The exposed data included email addresses, phone numbers, vehicle registrations, and postcodes tied to car park bookings, airport lounge access, Fast Track passes, and in-airport Wi-Fi sign-ups. No payment card data was involved, and flight operations and safety systems were unaffected. Attackers reportedly demanded a ransom, which MAG did not pay, and security researchers immediately flagged the real risk: targeted phishing and impersonation attempts against the millions of people whose contact details are now exposed. If a group running critical infrastructure like three major airports can get hit this way, the odds that your business has an unpatched gap somewhere are worth taking seriously.
What You Need Before You Start
You do not need an enterprise security team to run a meaningful audit. You need three things: a current inventory of where customer data actually lives (databases, third-party booking systems, marketing tools, Wi-Fi sign-up forms), a list of everyone who has access to each of those systems, and roughly half a day of uninterrupted time from whoever manages your IT. If you use third-party vendors for bookings, loyalty programs, or guest Wi-Fi, as MAG did, add their security posture to your scope too, because breaches increasingly start in a vendor system rather than your own. It also helps to have a rough sense of your regulatory exposure going in: a small local business handling a few hundred customer records has very different obligations than one operating across the UK and EU with tens of thousands of records on file, and knowing which bracket you fall into shapes how much of this audit you can reasonably run yourself versus when it makes sense to bring in outside help.
Step 1: Map Every Place Customer Data Lives
Start with a simple spreadsheet, not fancy software. List every system that touches customer data: your CRM, your website’s contact and booking forms, your Wi-Fi captive portal if you offer guest internet, your payment processor, and any spreadsheets or exports your team has generated over the years and forgotten about. Manchester Airports Group’s breach specifically involved data tied to routine services like parking and Wi-Fi sign-ups, the kind of “low-stakes” touchpoints most businesses do not think to lock down as tightly as their core systems. Those secondary systems are exactly where audits find the biggest gaps.
Step 2: Test Who Can Actually Access What
For each system on your list, check who currently has login access and whether that access still matches their job. Former employees and old vendor accounts are a classic weak point, and multi-factor authentication should be mandatory on anything touching customer data, not optional. Review your third-party integrations specifically: a Wi-Fi sign-up vendor or a car park booking platform often has broader data access than most businesses realize, since these tools were set up years ago and never re-audited as the relationship grew.
Step 3: Build (or Update) Your Incident Response Plan
A security audit without a response plan just tells you what is broken without telling you what to do when it breaks anyway. Write down, in plain language, who gets notified first if you suspect a breach, how you will determine what data was accessed, your legal obligation to notify affected customers and regulators (in the UK and EU, this generally means the ICO or the relevant data protection authority within 72 hours under UK GDPR and the EU GDPR), and a draft customer communication you can adapt quickly. MAG’s decision not to pay the ransom and its relatively fast public disclosure are worth studying as a template, even though the breach itself should not have happened. Paying a ransom does not guarantee data is deleted or that attackers will not resell it anyway, which is part of why most security agencies, including the UK’s NCSC, discourage payment as a default response.
Step 4: Train Your Team on the Phishing Fallout
A breach involving emails, phone numbers, and postcodes might sound less severe than one involving payment data, but security researchers flagged exactly the right concern after the MAG disclosure: this is prime material for targeted phishing and impersonation. Attackers who have someone’s name, phone number, and the fact that they recently booked airport parking can craft a convincing “your booking has an issue, click here” message that a generic phishing email never could. If your business handles any comparable customer data, whether it is bookings, sign-ups, or loyalty programs, brief your customer-facing staff now on what a plausible impersonation attempt looks like, and consider a short customer-facing notice reminding people you will never ask for payment details by phone or SMS.
This is also a good moment to check your own outbound communication habits. If your business routinely emails customers links to click or asks them to confirm details over the phone, you are training your customers to comply with exactly the kind of message a scammer would send after a breach like this one. Simplifying how you communicate sensitive requests, always through a verified account portal rather than email links, makes it much easier for your customers to spot the fake version when it eventually arrives.
Common Mistakes to Avoid
The first mistake is auditing only your “important” systems, like the main database, while ignoring supporting tools like guest Wi-Fi portals or loyalty programs, which is exactly where the Manchester Airports Group breach originated. The second is treating an audit as a one-time event rather than a quarterly habit, since new vendors, new employees, and new integrations all open fresh gaps. The third is having no communication plan ready before a breach happens, which forces a business to draft customer notifications and legal disclosures under pressure, often making the response look worse than the breach itself.
Key Takeaways
- Secondary systems are high risk: Wi-Fi portals, booking tools, and loyalty programs often hold more customer data than businesses realize.
- Access reviews matter as much as firewalls: Former employees and old vendor logins are a common entry point.
- Have a response plan before you need it: Know your notification obligations and draft communications in advance.
- Audit quarterly, not once: New vendors and integrations reopen gaps that a single audit closed.
Need Expert Help?
If this feels like a lot to manage alone, TecniForge can handle the heavy lifting. Our team specializes in custom software development and AI integration, including security reviews for customer-facing systems. Get in touch with our experts.
Also read: Manchester Airport Cyberattack: 6 Hard Lessons for Every Business, our earlier coverage on why this matters today.
For further reading, see Help Net Security’s report on the breach, Cybernews’ technical breakdown, and the UK ICO’s guidance on reporting a data breach if you need to understand your own notification obligations. The NCSC’s board toolkit is also a solid starting point for framing this conversation with leadership.
Run this audit before an incident forces your hand. The businesses that come out of a breach looking competent are the ones who already knew where their data lived.