Co-op Chair Resigns as the Cost of the 2025 Cyberattack Reaches the Boardroom
The Co-op chairwoman Debbie White has stepped down with immediate effect, months after the resignation of chief executive Shirine Khoury-Haq. The mutual is still absorbing the fallout from a 2025 cyberattack that cost it more than 200 million pounds in lost revenues.
Article record
Why it matters
What this means for organisations holding critical data
The Co-op chairwoman Debbie White has stepped down with immediate effect, months after the resignation of chief executive Shirine Khoury-Haq. The mutual is still absorbing the fallout from a 2025 cyberattack that cost it more than 200 million pounds in lost revenues.
The Co-op chairwoman Debbie White has stepped down with immediate effect after two and a half years in the role, the latest in a growing list of senior departures from the mutual. Her exit was reported by The Times on 10 August 2026.
What Happened
White became chair in February 2024, succeeding Allan Leighton. She will be replaced on an interim basis by Moni Mannings, a senior independent director. Her departure follows the resignation of Shirine Khoury-Haq, who stepped down in March after four years as chief executive, and the exit of managing director Matt Hood earlier this summer as part of a wider shake-up. The Co-op is now searching for both a permanent chair and a permanent chief executive.
The mutual had faced allegations of a toxic executive culture, which it did not accept, and was still absorbing the fallout from the 2025 cyberattack that cost it more than 200 million pounds in lost revenues. During that incident, shelves in Co-op stores were left empty as ordering and replenishment systems were taken offline.
Why It Matters
A cyberattack is no longer contained inside an IT function. It removes trading capacity, empties shelves, damages supplier confidence and eventually reaches the board. The Co-op case shows the full arc: an intrusion in 2025, a nine figure revenue impact, a period of cultural and operational strain, and by 2026 the departure of both the chief executive and the chair.
The financial figure is the part that gets quoted, but the operational detail is the more instructive one. The business was not stopped because money was stolen. It was stopped because the data that tells a retailer what to order, where to send it and at what price was reachable from a compromised network. Once that data was unavailable or untrusted, thousands of stores could not trade normally.
The Firevault View
Retail runs on a small set of data that must be correct and available: supplier and contract records, product and pricing files, warehouse and logistics configuration, system images and backups. Almost none of that needs to be permanently reachable from a connected estate. It needs to be reachable by authorised people, at the moment they need it, and to be provably intact.
Offline Secure Storage® keeps those gold copies physically disconnected at the hardware level. There is no network path to encrypt, exfiltrate or quietly corrupt, so an attacker who is already inside cannot reach them. Recovery becomes a controlled restore from a clean, verified copy rather than a negotiation conducted while stores stand empty.
Boards should be asking a simpler question than which tool to buy next. Which of our data has no reason to remain permanently connected, and what happens to trading if the connected copy is lost tomorrow? Disconnect to Protect® is the answer to both.
Written by Mark Fermor, Director and Co-Founder of Firevault.
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






