Cyberattack on Heathrow: What SMEs Need to Know
Over the weekend of 19 September 2025, passengers at Heathrow and several other European airports were greeted with long queues and slower-than-usual check-ins. The culprit wasn’t a strike or bad weather, but a cyberattack on Muse — the check-in and boarding software supplied by Collins Aerospace (part of RTX).
Heathrow was quick to reassure travellers that most flights were still operating, though check-in and boarding were slower than normal. Other airports, such as Brussels, were hit much harder, with widespread cancellations while they waited for a secure version of the software to be restored. Both the Guardian and AP News reported that staff were forced to dust off old manual processes — from handwritten boarding passes to manual baggage handling — just to keep passengers moving.
Investigations are ongoing, with Europe’s cyber agency ENISA confirming the disruption stemmed from a third-party software compromise. The source and motive remain unclear, though Reuters suggests ransomware could be involved.
Why this matters for small businesses
It’s easy to dismiss this as an “aviation problem,” but the parallels for SMEs are striking. Heathrow itself wasn’t directly hacked — their supplier was. The same principle applies when small businesses rely on cloud apps, payroll software, or even outsourced IT. If one of your partners is compromised, your operations could grind to a halt.
The chaos at check-in also shows why fallback plans matter. Airports with staff ready to switch to manual processes managed better than those that froze until systems came back online. For SMEs, this could mean having a way to take orders offline, process payments by alternative methods, or keep essential records accessible even if a system goes down.
Communication played a big role, too. Airports quickly deployed more staff and urged travellers to check flight statuses before heading to the terminal. In a business context, that translates into being able to update your customers, suppliers and staff when disruption strikes — even if the news isn’t good. Clear, honest communication can protect your reputation just as much as cybersecurity tools can protect your data.
What can SMEs take away from this?
First and foremost, supplier risk is business risk. Just as Heathrow relied on Collins Aerospace, you rely on cloud platforms, SaaS tools and service providers. Make sure you know how they handle security, how quickly they patch vulnerabilities, and what their incident response looks like.
Second, resilience is about more than technology. Heathrow’s ability to keep planes moving with manual workarounds is a reminder that people and processes are just as important. Could your team switch to an alternative way of working if your systems were locked or unavailable?
Not sure your team would spot a cyber threat in time? Browse our Threat Awareness articles.
And finally, don’t underestimate the importance of guidance from trusted authorities. The UK National Cyber Security Centre (NCSC) publishes practical, jargon-free resources for small businesses that cover everything from patching to backup planning. Building even a handful of their recommended practices into your daily operations could save you a major headache later.
The bottom line
The Heathrow cyberattack shows how fragile modern business can be when third-party systems fail. For airports, it meant handwritten boarding passes and frustrated passengers. For SMEs, the same kind of disruption could mean missed orders, angry clients, or lost revenue.
By reviewing your suppliers, building a simple incident plan, and training your staff to handle disruption calmly, you can turn an unexpected outage into a manageable inconvenience rather than a full-blown crisis.
If you’d like to explore how Novo IT can help strengthen your cybersecurity and resilience plans, have a look at our Cybersecurity Services.
Disclaimer: This article was created with the assistance of AI tools based on prompts and guidance provided by Novo IT Ltd.

Comments are closed