Calendar An icon of a desk calendar. Cancel An icon of a circle with a diagonal line across. Caret An icon of a block arrow pointing to the right. Email An icon of a paper envelope. Facebook An icon of the Facebook "f" mark. Google An icon of the Google "G" mark. Linked In An icon of the Linked In "in" mark. Logout An icon representing logout. Profile An icon that resembles human head and shoulders. Telephone An icon of a traditional telephone receiver. Tick An icon of a tick mark. Is Public An icon of a human eye and eyelashes. Is Not Public An icon of a human eye and eyelashes with a diagonal line through it. Pause Icon A two-lined pause icon for stopping interactions. Quote Mark A opening quote mark. Quote Mark A closing quote mark. Arrow An icon of an arrow. Folder An icon of a paper folder. Breaking An icon of an exclamation mark on a circular background. Camera An icon of a digital camera. Caret An icon of a caret arrow. Clock An icon of a clock face. Close An icon of the an X shape. Close Icon An icon used to represent where to interact to collapse or dismiss a component Comment An icon of a speech bubble. Comments An icon of a speech bubble, denoting user comments. Comments An icon of a speech bubble, denoting user comments. Ellipsis An icon of 3 horizontal dots. Envelope An icon of a paper envelope. Facebook An icon of a facebook f logo. Camera An icon of a digital camera. Home An icon of a house. Instagram An icon of the Instagram logo. LinkedIn An icon of the LinkedIn logo. Magnifying Glass An icon of a magnifying glass. Search Icon A magnifying glass icon that is used to represent the function of searching. Menu An icon of 3 horizontal lines. Hamburger Menu Icon An icon used to represent a collapsed menu. Next An icon of an arrow pointing to the right. Notice An explanation mark centred inside a circle. Previous An icon of an arrow pointing to the left. Rating An icon of a star. Tag An icon of a tag. Twitter An icon of the Twitter logo. Video Camera An icon of a video camera shape. Speech Bubble Icon A icon displaying a speech bubble WhatsApp An icon of the WhatsApp logo. Information An icon of an information logo. Plus A mathematical 'plus' symbol. Duration An icon indicating Time. Success Tick An icon of a green tick. Success Tick Timeout An icon of a greyed out success tick. Loading Spinner An icon of a loading spinner. Facebook Messenger An icon of the facebook messenger app logo. Facebook An icon of a facebook f logo. Facebook Messenger An icon of the Twitter app logo. LinkedIn An icon of the LinkedIn logo. WhatsApp Messenger An icon of the Whatsapp messenger app logo. Email An icon of an mail envelope. Copy link A decentered black square over a white square.

Kevin Hancock: Cyber attack threat has never been so great

Kevin Hancock is regional director, Highlands and Islands, for Marsh Commercial.
Kevin Hancock is regional director, Highlands and Islands, for Marsh Commercial.

The threat of cyber attacks is the strongest it has ever been for business leaders and public bodies in advanced global economies.

While many organisations make the decision to try to deal with attacks internally, their increased frequency, severity and sophistication mean that more and more are entering the public consciousness.

They point to the growing vulnerability of organisations and the subsequent need for a smarter approach towards cyber risk management.

Hackers, once seen as rogue criminals acting alone, are today well-organised groups that can orchestrate their activity with precision, a trend which skyrocketed after 2018.

Organised hacking has skyrocketed

Before 2017, there were relatively few large-scale attacks and ransomware demands were moderate, around £300.

Following the global impact of the 2017 Petya incidents in Ukraine, hacker groups such as DarkSide came to the fore which allowed users to sign up for an account with ease and take advantage of services such as payment gateways and even media relations support for press coverage.

Greater accessibility to knowledge and intelligence, combined with an ability to mobilise have given rise to methods such as double extortion ransomware where hacking groups steal an organisation’s data and threaten to leak it unless a ransom is paid.

Risk heightened during pandemic

The “digital-first” mentality of almost all organisations, heightened during the pandemic, means that cyber criminals are able to exploit gaps in IT systems and cloud infrastructure in order to access valuable data.

It is no surprise then that during 2020 the number of ransomware incidents went up by 148%. In the last quarter of the year, 70% of all ransomware attacks included the threat to leak exfiltrated data.

As more people worked from home, the number of ransomware incidents went up by 148% in 2020.

In addition to protecting sensitive data, the business challenges fuelled by the pandemic included securing connections for remote working and educating employees on good cyber hygiene, such as how to avoid email phishing scams.

Eighteen months on, these objectives continue to require constant, proactive effort as part of effective risk management, especially with the expansion of remote workforces.

Furthermore, if the pandemic has taught us anything, it is how fragile supply chains can be without appropriate safeguards.

Modern supply chains are incredibly complex and it is difficult to determine their overall level of cyber resilience; all the more reason for greater vigilance when it comes to an organisation’s internal programs and processes.

Insurance no panacea

Cyber insurance, while being a vital piece of the puzzle when it comes to ensuring comprehensive protection, is not a panacea.

The cyber insurance market continues to go through significant transitions. The pace of innovation is such that opportunities for new business efficiencies are unbounded.

However, with these opportunities come novel exposures which summon insurers to review their capacity and limits, more recently around ransomware.

Organisations must work with their brokers to fully understand the insurability of their exposures or risk being left with vulnerabilities that bear the potential to disrupt the whole value chain if exploited.

Mitigate risk

There are a number of steps organisations can take to mitigate the risk of attack and enable more competitive terms with insurers.

Certain security controls are starting to be requirements for cyber insurance coverage, namely multi-factor authentication.

First and foremost, however, organisations should review their backup strategy.

This includes examining what is backed up, where it’s hosted, how often backups occur, and who is responsible for execution of the backup strategy.

Organisations should also look to systematically upgrade remote desktop protocols, establish a cyber incident response plan and ensure that employees are being provided with up-to-date information on how to stay safe when connected to any enterprise system.

Next big threat – deepfakes

As modern technology continues to shock and awe with its evolution, the next big cyber threat may be something as pernicious as deepfakes.

A deepfake is a sophisticated digital forgery of an image, sound, or video.

The forgery may be so good that a human is unlikely to detect the manipulation.

The goal is to mislead and deceive, making it appear as though a person has said or done something when that is not the case.

This can cause serious material damage to organisations.

Hackers are aware that reputation is far tougher to regain than loss of capital and as access to such technology widens, the use of deepfakes to bring down an organisation has the potential to snowball.

Despite the resources organisations are committing to cyber risk and a strengthening national cyber security ecosystem in Scotland, gaps remain in understanding preparedness in this current climate of uncertainty.

With the pervasive and accelerating nature of attacks, in whichever form they manifest, organisations across Scotland run afoul of building resilience if they do not take the necessary precautions to defend their assets.

Kevin Hancock is regional director, Highlands and Islands, for Marsh Commercial.