TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Case Studies

Cyber surveys

by Mark Rowe

Most, 59 per cent of organisations hit by ransomware in the last 12 months recovered from their back-ups and did not pay, according to an annual survey of 500 IT decision-makers across UK businesses by the IT continuity services company Databarracks.

That compared with 18 per cent hit by ransomware that did pay the ransom. Among other findings; one in five said they have chosen not to report a serious cyber incident to avoid the legal or other fallout; regardless of UK data protection law that they have to notify the information security regulator the ICO once they become aware of a personal data breach that is likely to put people at risk. Most, 76pc of organisations believe they are more resilient than they were 12 months ago; yet only 43pc of organisations who describe themselves as “very confident” in their ability to respond to a ransomware attack have tested recovery from a cyber attack in the last 12 months.

Comment

The business continuity specialist and trainer Charlie Maclean-Bristol, Deputy Resilience Director at Databarracks, said: โ€œItโ€™s concerning to see how many cyber incidents are kept behind closed doors. Staying quiet about a cyber attack is rarely a wise idea. Besides any legal implications, by not informing the police, NCSC or other relevant authorities, you may also be obscuring a wider attack on a sector or region. Authorities cannot identify the pattern if incidents are not reported to them.

โ€œCovering up an incident can also do lasting damage to trust. If information is withheld from people affected by an attack, especially when they could have acted to protect themselves, the cover-up may ultimately cause more damage than the original incident. Prioritise crisis communications efforts on those who need to be informed, then concentrate on mitigating the impact, managing the response and protecting your reputation.

โ€œOne thing organisations can do when developing and testing cyber playbooks is identify the right law enforcement and regulatory contacts. Establishing those relationships in advance can improve the speed and effectiveness of reporting and support when an incident occurs.โ€

Insurance policy

Nearly one in five (18pc) organisations do not have cyber insurance, according to the study. A study for the data protection and security platform Cohesity, by OnePoll among 100 UK CEOs of large enterprises, found that only 22pc believe their cyber-insurance policy would cover both the additional costs and lost revenue resulting from a cyberattack. A third (33pc) believe their policy would only cover additional cost; and also one third (33pc) expect it to make up lost revenue only. One in ten (10pc) do not expect it to cover both additional costs and lost revenue fully. ย CEOs identified their top five risks following a cyberattack as:

  • Data breach:โ€ฏ49pc
  • Brand and reputational damage:โ€ฏ38 pc
  • High recovery costs:โ€ฏ36 pc
  • Revenue loss:โ€ฏ34 pc and
  • Production downtime:โ€ฏ30 pc.

Fraser Hutchison, VP UK and Ireland at Cohesity said: โ€œCyber insurance should not be treated as a get-out-of-jail-free card when it comes to cyber breaches. As the threat landscape becomes increasingly complex, organisations cannot treat an insurance policy as a substitute for resilience. Organisations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.โ€

Related News