British companies told to use pen and paper as serious hacks forcing them offline soar

M&S. Jaguar Land Rover. Legal Aid. Does it feel like the UK is being hit by a serious cyber attack every month?

Youโ€™re wrong โ€“ itโ€™s actually four major security incidents every single week.

Thatโ€™s according to the National Cyber Security Centre, which handled 204 โ€œnationally significantโ€ attacks in the year to September. That’s up from 89 over the previous year, with 18 deemed serious enough to impact essential services. Those are the serious ones: a total 429 were reported to the NCSC, which is part of GCHQ.

โ€œWith over half the incidents handled by the NCSC deemed to be nationally significant, and a 50% rise in highly significant attacks on last year, our collective exposure to serious impacts is growing at an alarming pace,โ€ noted Dr Richard Horne, Chief Executive of the NCSC, in a statement.

None of this will come as a surprise given the headlines this year: M&S, Co-op and Harrods all hit by ransomware; JLR bailed out with a government loan after a hacking incident shutdown production; a breach of Legal Aid that leaked serious data, and so on.

Whatโ€™s going on?

The NCSC noted that a โ€œsubstantial proportionโ€ of the incidents it saw last year were linked to Advanced Persistent Threat (APT) actors, which is industry jargon for technically capable, well resourced hackers who are either working for a country, part of a major criminal group, or both.

โ€œWe are seeing nation state actors target further down supply chains in order to breach high value targets to conduct espionage or cause destruction, plus cyber crime operations are targeting organisations of all sizes seeking significant ransom demands,โ€ noted Simon Phillips, CTO of Engineering at CybaVerse.

โ€œHowever, it doesnโ€™t matter what side of the fence an attacker sits on, we are also witnessing a new ecosystem, where threat actors unite on varying parts of the attack chain, taking advantage of the expertise of others to improve success rates,โ€ Phillips added. โ€œThis is a huge ecosystem, built on collaboration and designed to cause destruction.โ€

How can British companies fight the hackers?

To inspire companies to fight back, the UK Government has written a letter to all CEOs of major UK businesses, including all of the FTSE350, nagging them to get their act together when it comes to security.

โ€œThe best way to defend against these attacks is for organisations to make themselves as hard a target as possible,โ€ Horne said. โ€œThat demands urgency from every business leader: hesitation is a vulnerability, and the future of their business depends on the action they take today. The time to act is now.โ€

The NCSC advised companies to take part in the Cyber Essentials certification scheme, which includes liability insurance for smaller companies. Beyond its existing resources, NCSC has unveiled a new toolkit for small organisations and sole traders to help introduce some basic protections.

Would you pass a Cyber Essentials audit? Hereโ€™s why hackers hope not

Resilience means pen and paper

One key piece of advice is resilience โ€“ and that includes the ability to maintain operations without digital systems if needed. In other words, plan for pen and paper.

The NCSC suggested finding ways to store key plans offline and figure out in advance of an attack how teams will communicate without email. โ€œThe call for pen and paper might sound old-fashioned, but itโ€™s practical,โ€ Graeme Stuart, Head of Public Sector at cyber-security firm Check Point, told the BBC.

The BBC quoted the NCSCโ€™s Horne as saying companies need to โ€œhave a plan for how they would continue to operate without their IT, (and rebuild that IT at pace), were an attack to get throughโ€.

If you donโ€™t have such a plan in place, better hope the government will bail you out as it did JLR.

Nicole Kobie
Nicole Kobie

Nicole is a journalist and author who specialises in the future of technology and transport. Her first book is called Green Energy, and she's working on her second, a history of technology. At TechFinitive she frequently writes about innovation and how technology can foster better collaboration.