Tag Archives: Business

Major life-threatening cyber attack on UK “in little doubt”

The National Cyber Security Centre (NCSC) has published its second Annual Review, in turn revealing that the organisation has prevented Britain from falling victim to nearly 1,200 attacks in the past two years. The NCSC has also warned of the likelihood of a major life-threatening cyber attack on the UK in the near future.

The NCSC states that the UK is hit by ten serious cyber attacks every week. 70% of these attacks are “undertaken by groups of computer hackers directed, sponsored or tolerated by the Governments of [hostile] countries”.

Commenting on these figures, Mishcon de Reya’s cyber security lead Joe Hancock informed Risk Xtra: “1200 attacks may seem like a large number, but the reality is that this is the tip of the iceberg. The majority of these attacks on business, Government and third sector organisations go unreported and often undetected. Behind these high profile attacks there are the millions of online crimes that affect individuals every day.”

NCSCLogoWeb

Focusing on that last point, Hancock continued: “We routinely deal with the often unreported issues. More needs to be done to back law enforcement in supporting both victims and responders to better detect and recover from cyber episodes. A focus on critical infrastructure is welcomed by everyone, but it doesn’t help the millions of victims of cyber fraud. The recent Facebook breach shows the potential downsides of large-scale data collection and reliance on single points, provided by social media to access a wide variety of services across the Internet which can act as a gateway for attackers to further data and services.”

Further, Hancock observed: “Cyber security practices are not consistent globally and an attack against a weaker link in the supply or data chain can have unanticipated consequences for companies and individuals. More is needed to help protect everyday victims of these crimes, and especially so in the international arena. It’s difficult to see how mass cyber crime can be tackled without an international consensus and consequences for nations that turn a blind eye.”

Also, Hancock outlined: “Many of the cyber incidents we deal with have a financial component, often involving the traditional banking system and not only cryptocurrencies such as Bitcoin. Driving cyber criminals out of the financial system will have an impact on cyber crime levels.”

Actions and behaviours

There are specific actions and behaviours that should be adopted now to aid readiness for inevitable cyber attacks. Steve Mulhearn, director of enhanced technologies for the UK and Ireland and DACH at Fortinet, has listed them as prevention, the harnessing of Artificial Intelligence (AI) and adaptive technology and better visibility across the network.

Prevention

Prevention is easier when all employees in the business, not just the IT Department, take responsibility for the security of the business. For example, breaches like the Bupa or Waymo hacks have raised the appreciation of the number of breaches that occur because employees are targeted. The Fortinet Global Enterprise Security Survey 2017 found that 67% of businesses say they’re planning IT security and awareness training for employees in 2018.

Harness AI and adaptive technology

Harnessing the power of AI to learn from breaches, as well analyse data and automate reactions to shut down breaches when they occur, are vital actions. Threats evolve and adapt over time as applications, technologies, configurations, controls and behaviours change, making security an arms race wherein a static solution simply will not do.

Better visibility across the network

A vital tool in this struggle is visibility. You cannot secure what you cannot see. This means control across the distributed network, including endpoints, the Internet of Things and the cloud. According to the Fortinet 2017 Survey, only a small cohort of respondents feel confident that they have full visibility and control of employee access.

*The National Cyber Security Centre’s Annual Review can be accessed online at https://www.ncsc.gov.uk/news/annual-review-2018

Leave a comment

Filed under Risk Xtra

BT to lead creation of 2017 Cyber Security Challenge UK Masterclass

Cyber security experts from BT, Airbus, the National Crime Agency, the Bank of England, Cisco, McAfee, Checkpoint, De Montfort University’s Cyber Technology Institute and 4PumpCourt have announced that they will stage “the most advanced Cyber Security Challenge UK Masterclass ever” on 12-14 November in London.

Spanning two-and-a-half days, Masterclass is the culmination of a year’s worth of nationwide face-to-face and online competitions designed to unearth and nurture new talent for the cyber security industry and address a critical skills shortage that affects Government, businesses and the public.

Led by BT in partnership with Airbus, the competition will see dozens of the UK’s top cyber enthusiasts face each other in a battle that will test their capabilities to deal with cyber attacks and their understanding of business know-how. The challenges will evaluate contestants’ technical, business and soft skills, in turn mirroring the different ways in which professionals communicate today.

This year’s Masterclass will demonstrate how cyber security can be an accessible career choice that has a number of different facets and pathways. BT recently identified 87 different roles in the cyber security industry, each requiring a different skill set, which will be reflected in this year’s competition.

CyberSecurityChallengeUKLogoWeb

Highly experienced professionals from Government as well as public and private sector organisations across the country will judge the contestants for a number of aptitudes that will rank their suitability for jobs in the sector. The best performing candidate will be crowned Cyber Security Challenge UK Champion.

Thousands of pounds’ worth of career-enabling prizes will be issued to those who take in the finale including training courses, tech equipment and even a fully paid-for Master’s degree sponsorship at De Montfort University, allowing one lucky contestant the chance to study for an MSc in Cyber Security.

Over the years, more than half of the contestants in the Challenge’s face-to-face and Masterclass competitions have moved into jobs in the industry after demonstrating their skills in front of assessors.

Competitions like this are crucial for identifying top quality recruits that could reduce the skills deficit. Industry association (ISC)2 predicts the skills gap will reach 1.8 million unfilled positions by 2022, leaving a lack of professionals able to defend our infrastructure from hackers.

Nigel Harrison, acting CEO at Cyber Security Challenge UK, said: “This year’s consortium of sponsors is working on taking Masterclass to the next level, adding new dimensions and levels of game-play that we’ve yet to see in our competitions to date. We’re always trying to match our challenges to the way in which industry is evolving and ensure that they test for the skills industry requires. We look forward to seeing how the finalists fare in a modern cyber security scenario.”

Rob Partridge, head of BT’s Cyber Academy, added: “Filling the cyber security skills deficit is immensely important for the long-term safety of the UK’s digital economy. We need to make sure that industry and Government are collaborating such that young people are engaged and switched on to the breadth of roles in cyber security and the various career paths available to them. These competitions are vitally important for unearthing hidden talent and helping to develop the next generation of UK cyber talent to the standard being set in many other countries.”

Kevin Jones, head of cyber security architecture and innovation at Airbus, explained: “In order to continue protecting vital UK infrastructure and businesses from both current and future cyber threats, it’s particularly important that we address the skills shortage. Competitions such as Cyber Security Challenge UK help to provide a safe and representative environment for contestants to gain experience and learn from industry experts, which in turn will help them understand the variety of skills needed and the careers available within the cyber security sector.”

Leave a comment

Filed under Risk UK News