M&S. Jaguar Land Rover. Legal Aid. Does it feel like the UK is being hit by a serious cyber attack every month?
Youโre wrong โ itโs actually four major security incidents every single week.
Thatโs according to the National Cyber Security Centre, which handled 204 โnationally significantโ attacks in the year to September. That’s up from 89 over the previous year, with 18 deemed serious enough to impact essential services. Those are the serious ones: a total 429 were reported to the NCSC, which is part of GCHQ.
โWith over half the incidents handled by the NCSC deemed to be nationally significant, and a 50% rise in highly significant attacks on last year, our collective exposure to serious impacts is growing at an alarming pace,โ noted Dr Richard Horne, Chief Executive of the NCSC, in a statement.
None of this will come as a surprise given the headlines this year: M&S, Co-op and Harrods all hit by ransomware; JLR bailed out with a government loan after a hacking incident shutdown production; a breach of Legal Aid that leaked serious data, and so on.
Whatโs going on?
The NCSC noted that a โsubstantial proportionโ of the incidents it saw last year were linked to Advanced Persistent Threat (APT) actors, which is industry jargon for technically capable, well resourced hackers who are either working for a country, part of a major criminal group, or both.
โWe are seeing nation state actors target further down supply chains in order to breach high value targets to conduct espionage or cause destruction, plus cyber crime operations are targeting organisations of all sizes seeking significant ransom demands,โ noted Simon Phillips, CTO of Engineering at CybaVerse.
โHowever, it doesnโt matter what side of the fence an attacker sits on, we are also witnessing a new ecosystem, where threat actors unite on varying parts of the attack chain, taking advantage of the expertise of others to improve success rates,โ Phillips added. โThis is a huge ecosystem, built on collaboration and designed to cause destruction.โ
How can British companies fight the hackers?
To inspire companies to fight back, the UK Government has written a letter to all CEOs of major UK businesses, including all of the FTSE350, nagging them to get their act together when it comes to security.
โThe best way to defend against these attacks is for organisations to make themselves as hard a target as possible,โ Horne said. โThat demands urgency from every business leader: hesitation is a vulnerability, and the future of their business depends on the action they take today. The time to act is now.โ
The NCSC advised companies to take part in the Cyber Essentials certification scheme, which includes liability insurance for smaller companies. Beyond its existing resources, NCSC has unveiled a new toolkit for small organisations and sole traders to help introduce some basic protections.
Would you pass a Cyber Essentials audit? Hereโs why hackers hope not
Resilience means pen and paper
One key piece of advice is resilience โ and that includes the ability to maintain operations without digital systems if needed. In other words, plan for pen and paper.
The NCSC suggested finding ways to store key plans offline and figure out in advance of an attack how teams will communicate without email. โThe call for pen and paper might sound old-fashioned, but itโs practical,โ Graeme Stuart, Head of Public Sector at cyber-security firm Check Point, told the BBC.
The BBC quoted the NCSCโs Horne as saying companies need to โhave a plan for how they would continue to operate without their IT, (and rebuild that IT at pace), were an attack to get throughโ.
If you donโt have such a plan in place, better hope the government will bail you out as it did JLR.
More articles by Nicole Kobie