Story image

UK most breached country in EU but businesses are blissfully naïve

30 May 2018

The United Kingdom has won an award after taking out Europe’s most breached country of last year – and perhaps the most unaware.

This was after the 2018 Thales Date Threat Report (European Edition) noted a year-on-year increase in the number of attacks to the UK from 43 percent to 67 percent.

Despite this spike, British businesses claim to feel less vulnerable to data threats when compared to those across Germany, Sweden, and the Netherlands.

2017 saw a number of high-profile cyberattacks across Europe with ransomware cryptoworm, WannaCry and wider-reaching malware, Bad Rabbit, crippling thousands of systems including the UK’s National Health Service (NHS).

In terms of organisations, large-scale names like Equifax, Accenture, and T-Mobile all painted the headlines as victims of cybercrime. While more organisations across Sweden and the Netherlands admitted to being breached in the past (78 percent and 74 percent respectively, as opposed to 67 percent in the UK), the last 12 months was a very different story:

  • 37 percent of businesses across the UK were breached
  • 33 percent of German respondents were breached
  • 30 percent of organisations in Sweden were breached
  • 27 percent of respondents across the Netherlands were breached

Despite these findings, just 31 percent of UK organisations said they feel ‘very’ or ‘extremely’ vulnerable to data threats, leaving the majority at 69 percent to feel ‘somewhat’ or ‘not at all’ vulnerable. In contrast, businesses in Sweden claimed to feel the most vulnerable with 49 percent, followed by the Netherlands on 47 percent and Germany on 36 percent.

While 7 in 10 British businesses have upped their cybersecurity spending from the previous year (with 15 percent stating it to be ‘much higher’), the report reveals the UK is still falling behind its European counterparts. For example, three quarters of businesses in Sweden have increased their budgets, while 39 percent say it is ‘much higher’.

In spite of all these findings, the UK it seems is actually in good stead when it comes to GDPR compliance when compared to its European neighbours.

Businesses had around two years to prepare for the implementation data of GDPR, but there have still been high rates of failure for compliance audits, especially in the last year.

Swedish businesses ranked the highest for failure, with 49 percent missing the bar compliance audits. Next up was the Netherlands with 38 percent, followed by Germany with 33 percent. Meanwhile, just 19 percent of UK organisations reported failed data security audits within the last year.

Furthermore, all European countries – aside from the UK – showed decline in their efforts to meet compliance. Despite the drop, all respondents cited compliance as being effective when it comes to preventing data breaches.

Thales eSecurity chief strategy officer Peter Galvin says a tidal wave of data breaches is rolling across Europe, with three in every four organisations now a victim of cybercrime.

“As a result, people are feeling more vulnerable than ever before, worried about where the next threat will come from, and in what form. To stand the best chance of success against these advanced attacks, businesses need to dedicate the appropriate level of attention, budget and resource into safeguarding their sensitive data, wherever it happens to be created, shared or stored,” says Galvin.

“The deployment of encryption is a well-recognised strategy to mitigate the risk of data breaches and cyber-attacks as well as protect an organisation’s brand, reputation and credibility.”

Veeam releases v3 of its MS Office backup solution
One of Veeam’s most popular solutions, Backup for Office 365, has been upgraded again with greater speed, security and analytics.
Too many 'critical' vulnerabilities to patch? Tenable opts for a different approach
Tenable is hedging all of its security bets on the power of predictive, as the company announced general available of its Predictive Prioritisation solution within Tenable.io.
Industrial control component vulnerabilities up 30%
Positive Technologies says exploitation of these vulnerabilities could disturb operations by disrupting command transfer between components.
McAfee announces Google Cloud Platform support
McAfee MVISION Cloud now integrates with GCP Cloud SCC to help security professionals gain visibility and control over their cloud resources.
Scammers targeting more countries in sextortion scam - ESET
The attacker in the email claims they have hacked the intended victim's device, and have recorded the person while watching pornographic content.
Cryptojacking and failure to patch still major threats - Ixia
Compromised enterprise networks from unpatched vulnerabilities and bad security hygiene continued to be fertile ground for hackers in 2018.
Princeton study wants to know if you have a smart home - or a spy home
The IoT research team at Princeton University wants to know how your IoT devices send and receive data not only to each other, but also to any other third parties that may be involved.
Organisations not testing incident response plans – IBM Security
Failure to test can leave organisations less prepared to effectively manage the complex processes and coordination that must take place in the wake of an attack.