UK businesses shockingly unaware of how to handle security threats
- Reference: 1712666474
- News link: https://www.theregister.co.uk/2024/04/09/uk_biz_response_to_cybercrime/
- Source link:
The report from the Department for Science, Innovation and Technology (DSIT), released today, painted security as more of an afterthought for UK businesses, especially when considering the figures about how breaches are handled.
Some of the figures are remarkably low. For example, only 22 percent of 2,000 businesses have a formal incident response plan in place, which has "astounded" experts.
[1]
"Only a fraction of UK businesses have any kind of formalized incident response plan, which I find astounding," said Andy Kays, CEO at Socura. "Businesses will always have a plan in case of a fire, but will not apply the same due care for a data breach – which is statistically much more likely. It flies in the face of common sense."
[2]
[3]
The reporting of breaches to external authorities and organizations is also low. Only 10 percent of businesses ring the police when they detect the most disruptive breach in the previous 12 months – a stat that's halved when looking at who reports incidents to the [4]National Cyber Security Centre (NCSC).
Reporting rates to arguably the most important entity, the [5]Information Commissioner's Office (ICO), weren't even included in the report since the watchdog didn't make the top ten organizations that receive reports of breaches. Banks, building societies, and credit card issuers, on the other hand, placed first – 32 percent of businesses reported incidents to them.
[6]
Clients and customers were only alerted 5 percent of the time.
In most cases (68 percent), organizations don't deem the incidents significant enough to report to anyone. Other excuses included not knowing where to report incidents (13 percent of businesses), thinking a report would make no difference (9 percent), and incidents being too recent to allow time to report (4 percent).
As for the action taken, as many as 39 percent of businesses took no action following their most disruptive breach in the previous 12 months. Most defaulted to delivering more training to staff (23 percent), with a much smaller proportion making any changes to [7]firewalls (9 percent) or anti-malware solutions (8 percent).
[8]
Small and micro businesses appear to be pulling the figures down considerably. Overall, 59 percent of businesses enacted some sort of organizational change following a breach, but medium and large businesses were much more likely to take action, with 74 and 86 percent of each respectively doing something to prevent further intrusions.
Breaches that resulted in material outcomes for victims, such as the theft of data, led to slightly different results. A greater diversity of measures were enacted by businesses and charities in this case, such as introducing new security tools, but still, 18 percent of businesses did absolutely nothing in response, even after a material breach.
"In the event of a breach, businesses are not keeping records, not informing the police or regulators, not assessing the scale and impact of the incident," said Kays.
"They are failing to do the bare minimum. It's also important to note that businesses are doing very little to prevent or detect breaches in the first place."
Figures from DSIT's survey also showed a general decrease in awareness of security initiatives and willingness to seek support.
Just 41 percent of businesses sought cybersecurity information from outside their organization over the previous 12 months – a decline from 49 percent the previous year. It represents a steady, continued downward trend since the early GDPR days when, naturally, the proportion of businesses seeking outside help was high at 59 percent.
The overall figures were largely driven by micro businesses, since only 39 percent sought outside expertise compared to 70 percent of medium companies. The figures for charities also stand at 39 percent but have remained largely unchanged since 2018, give or take a few percentage points each year.
IT consultants appear to be favored heavily compared to the services provided by "official sources" such as the UK's NCSC, especially by medium businesses that may not be able to hire their own internal talent.
[9]Puppies, kittens, data at risk after 'cyber incident' at veterinary giant
[10]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack
[11]Google sues app devs, claims they're Play Store crypto scammers with 100k+ victims
[12]Ransomware gang did steal residents' confidential data, UK city council admits
Only 1 percent of businesses and 2 percent of charities mentioned the NCSC by name when searching for security guidance, down from 2 percent each last year, suggesting the costly alternatives make a more convincing business case.
Awareness of the information campaigns run by the NCSC has also been in continued decline for the past two to three years, according to [13]today's survey .
Cyber Aware, the general online safety advice book from the NCSC, plus the 10 Steps to Cyber Security guide and its Cyber Essentials assessment are all gradually falling off businesses' radars, although the drop is only slight from last year. The multi-year downward trend may give cause for concern, however.
"The decline in awareness for Cyber Aware since 2022 is driven by a decline among micro and small business," the survey reads. "There was a significant decline in awareness for Cyber Aware among micro businesses since 2021 from 34 percent to 24 percent in 2024 and a similar, and significant, decline among small business since 2021 from 38 percent to 28 percent in 2024.
"Similarly, the decline in awareness seen for 10 Steps to Cyber Security is driven by a decline in micro and small business, but to a lesser extent."
Cost of a UK breach
According to DSIT's data, the average business that suffered any kind of security breach took a financial hit of £1,206 ($1,529). For medium and large businesses, this was predictably much higher than any micro and small organizations at £10,830 ($13,731).
The median cost of these breaches, both in the short and long term, stands at £0, though, which indicates that in the vast majority of cases, no material outcome is identified and no action needs to be taken.
But with incidents that do lead to material outcomes such as data theft, it becomes much costlier – the average cost soared to £6,940 ($8,799) with an average high of £40,400 ($51,221) for medium and large businesses. The costs were fairly evenly split between short-term and long-term outlays for the larger organizations, but those on the smaller side typically reported larger short-term costs, such as those related to the engagement of outside experts or paying sums to attackers.
Long-term costs refer more to things like replacing hardware or software, legal fees, and hiring new talent.
Attacks targeting the UK
It's estimated that around 312,000 registered business in the UK were targeted by some flavor of cybercrime in the past year, and 27,000 registered charities – 22 percent and 14 percent of the total respectively.
It may come as little surprise that [14]phishing leads the way as the most common type of cybercrime affecting UK businesses, with 90 percent of respondents saying they had identified attempts in the past 12 months.
Large businesses were the biggest reporters of cybercrime attempts against them at 58 percent, and they were also the primary targets of non-phishing crimes such as unauthorized access attempts, malware, and [15]ransomware .
They were "significantly" more likely to be targeted by cybercrime than smaller businesses – a trend that's also true for charities. Those with an income of more than £500,000 ($633,935) (37 percent) were more than twice as likely to be targeted compared to the average (14 percent). ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZhVmHl-iCBXwrmjWvGUNagAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhVmHl-iCBXwrmjWvGUNagAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhVmHl-iCBXwrmjWvGUNagAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2023/11/14/ncsc_cyber_readiness/
[5] https://www.theregister.com/2024/01/22/ico_fines_spam_slinging_financial/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhVmHl-iCBXwrmjWvGUNagAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/03/05/cloudflare_firewall_ai/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhVmHl-iCBXwrmjWvGUNagAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/04/08/cyber_incident_strikes_veterinary_services/
[10] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[11] https://www.theregister.com/2024/04/05/google_sues_alleged_play_store/
[12] https://www.theregister.com/2024/04/04/ransomware_gang_did_in_fact/
[13] https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024#summary
[14] https://www.theregister.com/2024/03/23/russia_cozy_bear_german_politicians_phishing/
[15] https://www.theregister.com/2024/04/04/ransomware_gang_did_in_fact/
[16] https://whitepapers.theregister.com/
Shocker
SMEs can barely keep their head above water, having yet another thing to add to the pile of things would likely have sunaked them.
So most just predictably decide to wing it and hope it will all somehow work itself out.
In the meantime policymaker just ticked another box.
Happy clappy Britain.
"Wot? Cybersecurity? Incident response?"
"We weren't taught anything about this in business school!"
Re: "Wot? Cybersecurity? Incident response?"
Every business has always been run by people determined to make the business work well ... that's been the business environment for hundreds of years with very little security threats until recent years. "Easy" data access everywhere has changed the safety world everywhere, currently data security is pretty much like "vaccinations" ... total effective this week, but the risks then evolve to cause problems again.
The environment has had a huge change so we need to make a tremendous change in the way everything is done ... it a bit like the pandemic, we're all wearing masks but we get infected occasionally.
Re: "Wot? Cybersecurity? Incident response?"
that's been the business environment for hundreds of years with very little security threats until recent years.
Really? What about having to pay protection money to the local gangs or competitors getting corrupt government to close you down or let your business experience mysterious fire.
Today is even worse, as common crimes against business are pretty much legal. Anyone can go to your company, take whatever they want and leave. If you are SME, all you can do is get crime ref number (and if officer has a bad day you will probably have to explain to him why you think any crime happened at all and that you have not imagined it) and frame it.
Then you have cyber crime on top of all that.
"It flies in the face of common sense"
Yup.
Time to redefine "common" sense, 'cause it ain't so common no more.
Re: "It flies in the face of common sense"
Never was.
why bother doing anything...
When the worst that happens is a slap on the wrist and a public telling off... especially when a mealy-mouthed "Sorry we got caught with our pants down, security is really our top priority, honest guv!" press release seems to be a get out of jail free card.
"Businesses will always have a plan in case of a fire"
It probably extends to having fire doors, a designated rendezvous point, extinguishers, evacuating the building, dialling 999 and having a roll-call. Beyond that it's hard to plan, partly because the extent of damage would be unknown.
If a business can't plan for something unknown but physical that the managers can understand, how can it plan for an unknown that most of the business managers don't understand?
I've certainly had the experience of a workplace fire. Any advance planning would have been above my pay grade but I doubt there was any at all. AFAICS the response was improvised based on the actual damage and the circumstances. My wing of the building was burned to a crisp but we needed to be in the security perimeter. The occupants of the surviving wing who didn't need the security were decanted to other premises - how they coped I've no idea. Space allocation had to be based on what was available and what could be found by getting in portacabins.
Individual groups took their own decisions as to what to do - one group gathered their surviving equipment in their allocated space and, as far as I could make out, just sat there for some days waiting to be told what to do next. Personally, I spent part of the Sunday* on the phone to our Leitz contact getting some microscope deliveries prioritised and on the Monday a couple of us drove up to the local laboratory supplier and went round the warehouse with lab. trolleys rather like a supermarket and buying in supplies on the principle that "We'll need some of those and some of that and that one, there". Someone else got in touch with other labs to rebuild the methods notes etc that we'd lost. Each group rearranged their allocated space as best they could with the help of builders brought in to tidy up the gap left by the missing wing. I managed to turn a section of corridor which now went nowhere into a microscope room so successful that we replicated it in the rebuilt wing.
Has anyone else had to deal with the aftermath of a fire and how did it differ in essentials?
* The fire happened on a Friday night and, as I was taking an OU field trip on the Saturday, didn't immediately find out about it.
Progress
So, no change there then, that most businesses do not have an incident response plan. After all that would require thinking about your business risks, and making a mature, cost-based decision on how to prepare and what to do, instead of - doing whatever the business was set up to do to make money.
Reminds me of a joke from the Goon Show :
Major Bloodknock: What's happening back in England?
Minnie Bannister: Nothing's happening back in England.
pause
Major Bloodknock; Well, there's progress for you.