Story image

Attacks on UK's critical infrastructure to skyrocket 100% over next 2 years

08 Dec 2017

Thought 2017 was bad? Well according to cybersecurity expert Huntsman Security, it’s going to get a whole worse.

The UK’s critical infrastructure faces an increase in cyberattacks of up to 100 percent over the next two years – at the same time as it faces a critical shortage of security analysts.

“With the ISACA predicting a global shortage of two million cybersecurity jobs by 2019, there simply aren’t enough security analysts in the UK, or even the world, to cope with the growing threat that critical infrastructure faces,” says Peter Woollacott, CEO of Huntsman Security.

“National agencies are already reporting a significant increase in reported attacks, let alone those that pass undetected.”

Critical infrastructure systems are increasingly being connected to the Internet and customers’ homes to gain efficiencies, which consequently has multiplied the opportunities to compromise them.

Woollacott asserts the consequences range from critical services being held for ransom, to service outages, economic chaos and even disruption, injury or death to citizens.

“As more elements of services move online, so there are many more opportunities for attackers of any size or capability to try their luck. As a result, our critical infrastructure faces a blizzard of attacks of varying sophistication – any one of which could be as damaging as WanaCry or Stuxnet,” says Woollacott.

“Even a simple DDoS attack has brought services such as Sweden’s trains to their knees recently. There’s no way to block all of these potential attacks at the walls of an organisation, and security analysts will soon be overwhelmed by the sheer volume they face. If organisations can’t address these challenges, the danger to the public, and the harm to the organisation itself, will be unacceptable.” 

2017 saw a number of high profile attacks on power plants in the Ukraine and USA, and significant threats to UK and European transport infrastructure.

Woollacott says attacks on national infrastructure have been increasing steadily. In the US for example, reported cyber incidents against critical infrastructure increased by 49 percent between 2012 and 2015 – with a potentially larger number of unreported or unnoticed incidents yet to be discovered.

In the UK, the introduction of the NIS Directive in May 2018 will place additional pressure on critical infrastructure organisations. Under NIS, companies could face fines of up to 4% of turnover or £17m, whichever is greater, if they can’t prove they have taken sufficient steps to “prevent and minimise” the impact of security incidents.

According to Woollacott, the greatest challenges for all businesses regardless of industry will be the sheer volume of potential and actual attacks they face.

“The fact that NIS is making organisations think about these dangers is important, but these thoughts have to be matched with the right action. When connections were entirely physical, it was relatively simple to prevent and stop attacks – in the online world, this is nowhere near enough,” says Woollacott.

“Without the ability to automatically triage potential threats and take the appropriate action – whether that’s simply logging the incident, alerting security teams, or quarantining the danger – organisations will find themselves overwhelmed and the odds of being victim to a major attack with serious consequences will increase accordingly. The internet as a means of communication is here to stay, meaning organisations will ultimately be judged by how they react to it. By accepting that they can’t stop every attack at the walls, critical infrastructure organisations are safeguarding not only themselves, but the UK as a whole.”

Nuance biometrics fight back against fraud
Nuance Communications has crunched the numbers and discovered that it has prevented more than US$1 billion worth of fraud from being passed on to users of its Nuance Security Suite.
Attacks targeting Cisco Webex extension explode in popularity - WatchGuard
WatchGuard's Internet Security Report for Q4 2018 also finds growing use of a new sextortion phishing malware customised to individual victims.
Developing APAC countries most vulnerable to malware - Microsoft
“As cyberattacks continue to increase in frequency and sophistication, understanding prevalent cyberthreats and how to limit their impact has become an imperative.”
Worldwide spending on security to reach $103.1bil in 2019 - IDC
Managed security services will be the largest technology category in 2019.
Privacy: The real cost of “free” mobile apps
Sales of location targeted advertising, based on location data provided by apps, is set to reach $30 billion by 2020.
Forrester names Crowdstrike leader in incident response
The report provides an in-depth evaluation of the top 15 IR service providers across 11 criteria.
Norwegian aluminium manufacturer hit hard by LockerGoga ransomware attack
“IT systems in most business areas are impacted and Hydro is switching to manual operations as far as possible.”
Slack doubles down on enterprise key management
EKM adds an extra layer of protection so customers can share conversations, files, and data while still meeting their own risk mitigation requirements.