Attacks On UK Critical Infrastructure Will Double

The UK’s critical infrastructure faces an increase in cyber-attacks of up to 100% over the next two years at the same time as it faces a critical shortage of security analysts, cyber security expert Huntsman Security has warned.

With critical infrastructure systems increasingly connected to the Internet and customers’ homes, the opportunity to compromise them has also grown; with consequences ranging from critical services being held for ransom, to service outages, economic chaos and even disruption, injury or death to citizens.

This year alone has seen high-profile attacks on power plants in the Ukraine and USA, and significant threats to UK and European transport infrastructure. The risk for critical infrastructure businesses is compounded by the upcoming NIS Directive, as companies that fail to meet security standards will face fines in the tens of millions of pounds. 

“With the ISACA predicting a global shortage of two million cyber security jobs by 2019, there simply aren’t enough security analysts in the UK, or even the world, to cope with the growing threat that critical infrastructure faces,” said Peter Woollacott, CEO of Huntsman Security.

“National agencies are already reporting a significant increase in reported attacks, let alone those that pass undetected. 
“As more elements of services move online, so there are many more opportunities for attackers of any size or capability to try their luck. As a result, our critical infrastructure faces a blizzard of attacks of varying sophistication, any one of which could be as damaging as WanaCry or Stuxnet. 

“Even a simple DDoS attack has brought services such as Sweden’s trains to their knees recently. There’s no way to block all of these potential attacks at the walls of an organisation, and security analysts will soon be overwhelmed by the sheer volume they face. If organisations can’t address these challenges, the danger to the public, and the harm to the organisation itself, will be unacceptable.”

Attacks on national infrastructure have been increasing steadily. In the US, reported cyber incidents against critical infrastructure increased by 49% between 2012 and 2015, with a potentially larger number of unreported or unnoticed incidents yet to be discovered.

In the UK, the introduction of the EU Directive on Security of Network and Information Systems NIS Directive in May 2018 will place additional pressure on critical infrastructure organisations. Under NIS, companies could face fines of up to 4% of turnover or £20 million, whichever is greater, if they can’t prove they have taken sufficient steps to “prevent and minimise” the impact of security incidents.  To date energy, transport, health, drinking water supply and distribution and digital infrastructure have been proposed as the industries NIS covers.

Regardless of industry, the greatest challenge to organisations will be the volume and diversity of potential and actual attacks they face. In this environment, it will be critical to be able to identify, triage and respond to potential threats before they have an opportunity to cause damage. 

Ideally these tasks should be automated, so that security teams only need to take action on those attacks which present the highest risk, instead of being distracted by false alarms.

 “The fact that NIS is making organisations think about these dangers is important, but these thoughts have to be matched with the right action,” continued Woollacott. “When connections were entirely physical, it was relatively simple to prevent and stop attacks, in the online world, this is nowhere near enough. 
“Without the ability to automatically triage potential threats and take the appropriate action, whether that’s simply logging the incident, alerting security teams, or quarantining the danger, organisations will find themselves overwhelmed and the odds of being victim to a major attack with serious consequences will increase accordingly. 
“The Internet as a means of communication is here to stay, meaning organisations will ultimately be judged by how they react to it. By accepting that they can’t stop every attack at the walls, critical infrastructure organisations are safeguarding not only themselves, but the UK as a whole.”

Information Age

Britain Bombarded With High Level Cyber Attacks:

Which Countries Are Ready For Cyberwar?:

Some Observations On Britain's New Cyber Security Strategy:

 

« Cisco & INTERPOL: Working Against Cybercrime
10 Things About The Network and Information Security Directive (NIS) »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

British Assessment Bureau

British Assessment Bureau

The British Assessment Bureau is an ISO certification body. We check conformity and compliance of companies to recognised ISO standards including ISO 27001.

Robert Half Technology

Robert Half Technology

Robert Half Technology offers a full spectrum of technology staffing solutions to meet contract and full-time IT recruitment needs.

Networkers

Networkers

Networkers is a global recruitment consultancy helping unite job-seekers and hiring companies across the technology industry.

Codified Security

Codified Security

Codified is a testing platform for mobile application software. We make it easier than ever for companies to detect and fix security vulnerabilities and ensure their applications are compliant.

Cybrary

Cybrary

Cybrary is an open-source cyber security and IT learning and certification preparation platform.

HoxHunt

HoxHunt

HoxHunt is an automated cyber training program that transforms the way your employees react and respond to the growing amount of phishing emails.

The Cyber Security Expert

The Cyber Security Expert

The Cyber Security Expert delivers cyber security consultancy, website and cloud security monitoring services, and specialist training services.

IAmI Authentications

IAmI Authentications

IAmI is a first in Tokenization Cloud-based IAM Security Services, delivering the most advanced form of Two-Factor Authentication.

Swiss Accreditation Service (SAS)

Swiss Accreditation Service (SAS)

SAS is the national accreditation body for Switzerland. The directory of members provides details of organisations offering certification services for ISO 27001.

Fingent

Fingent

Fingent develops strategic software solutions for businesses across the globe in areas including Network Security, Infrastructure Security, Application Security, Risk and Compliance.

Elpha Secure

Elpha Secure

Elpha Secure provides a comprehensive cybersecurity solution, combining technology and insurance to protect against cyber threats.

RapidScale

RapidScale

RapidScale’s managed cloud solutions provide reliable, innovative, and secure services, all complete with white-glove service and full management options.

Soliton

Soliton

Soliton is a leading Japanese technology company and a pioneer in IT security solutions for protecting company resources and data from external IT security threats.

Epiphany Systems

Epiphany Systems

Epiphany enhances your defensive security controls by providing you with an offensive perspective. We expose the most likely attack paths to your most critical IT assets and users.

BigBear.ai

BigBear.ai

BigBear.ai delivers high-end analytics capabilities across the data and digital spectrum to deliver information superiority and decision support.

Brennan IT

Brennan IT

For over 25 years, Brennan’s expert team has helped businesses achieve real success through innovative and secure technology solutions.