Cyber security
We help organisations safeguard against cyber risk by raising technical resilience and building leadership confidence.
In recent years the growing number of serious cyberattacks on UK businesses and public services has been well publicised. The impacts have been significant, including hospitals unable to provide vital health care (with at least one death attributed to the effects of an attack), impacts on vital public services such as benefits payments and people being unable to buy and sell homes, and huge economic impact on businesses and their suppliers which has been estimated to run into billions. Alongside the impacts on citizens, customers and businesses, responding to a cyberattack also takes a huge toll on employees and leaders.
If you’ve not yet experienced a cyberattack in your own organisation, it’s easy to assume that the people affected weren’t taking their cyber defences as seriously as you do, and that holding up to date assurances like an ISO27001 accreditation or other compliance certificates will mean that your organisation is safe. That would be a serious mistake.
A pattern that we see time and again is that attacks occur when apparently simple controls haven’t worked. That could be a computer which is missing a critical security patch, a member of the IT support team being tricked into providing access to a malicious actor, or a failure with any number of other measures that your regular audits will have reassured you are well covered. It’s rare that the victims had been ignoring these.
Your certificates will confirm you have the right controls and processes in place. But you need to be 100% confident that those are 100% effective, 100% of the time. Your attacker only needs that to not be true once. They won’t care about the certificates you’ve earned if they can find a gap that is ready to exploit. And the impacts when that happens can be devastating.
Rapid innovation in AI is only going to make this harder, giving attackers ever more powerful tools to find the gaps that they need and helping them exploit vulnerabilities even faster than before. And an increasingly volatile world means that the potential threat is increasing every day. The only safe bet is to assume that your controls won’t work.
Too often conversations about cyber risks concentrate on technical threats and defences, with an emphasis on compliance and the certificates that demonstrate assurance. These are fundamental, but there is a much broader strategic focus that boards need to have to make sure that their organisations can have real confidence that they understand their cyber risks and are taking a genuinely strategic approach to mitigate them.
Some key steps that boards must take are:
Don’t treat cyber risks as an ‘IT thing’
Cyber can often feel very ‘techy’, and it’s easy to treat it as something for the IT team to look after. But the reality is that the actions needed to reduce cyber risks, the impacts of an attack, and the work needed to respond to and recover, involve every part of the organisation at every level.
Being well prepared against the risks and impacts of cyber threats is also an important part of making sure that your organisation is resilient to the demands of an increasingly volatile world. So treating cyber resilience as a core strategic capability has broader benefits beyond protecting your data and computer systems.
Organisations that take cyber resilience seriously are much more likely to be the organisations who are able to adapt and respond successfully to other risks too.
Invest in your defences
This is non-negotiable. Do your technology team have the investment and support they need to make your defences as strong as possible? Where do they need additional backing to retire legacy technology that could be your organisation’s weak point? Where do they need senior support to make sure that everyone who uses your systems is aware of and following your security processes?
And don’t assume that your controls are working the way that you expect - find out where they’re failing before the attackers do. Use approaches like investing in a ‘Red Team’ to help you find the inevitable gaps in your defences and act quickly to address those.
Make the strategic shifts needed to reduce risk
Defending your legacy technology is necessary, but not sufficient. It’s all too common to find business critical systems and infrastructure which have elements that are largely unchanged from the early 2000s, with security design and applications that present significant risks when faced with the threats of the modern internet and AI era. Take a look under the hood of your IT estate and you’ll probably be shocked by what you find.
As a board, challenge yourselves by asking how well you understand the legacy technology that you are still relying on and whether you’ve made the investments needed to design greater security and resilience into your systems. Are you using modern approaches like zero trust security and scalable cloud technology to reduce the likelihood of a breach and reduce the impact if an attacker is successful? Are you investing in the skills and capacity that you need to manage your technology estate effectively? Are you weighing the costs of modernisation against the (potentially huge) costs of disruption if an attack is successful?
Plan for resilience
All too often, business resilience plans assume that the impacts of a cyberattack will be measured in hours and days. But the reality is that it’s far more common for recovery to take months and even years. You should not assume that your plans will stand up to the challenges that you’d face if you experience a successful cyberattack - you should treat this as a case of ‘when?’, not ‘if?’.
Complex systems, processes and data, combined with the need to ensure that systems are properly clean before they are returned to use, mean that there is rarely a rapid path to recovery. Questions you should be asking before, not after, an attack include:
The first thoughts for most boards are likely to be very similar: are we covered? are we compliant? Do we have the certificates? Those are important questions. But it’s vital to not stop there - attackers won’t care about the certificates you’ve earned if they can find a gap in your defences which they can exploit.
Some practical steps you should take now are:
None of this is easy, especially in large, complex organisations that are having to balance competing priorities and which rely on large estates of complex, legacy technology. But that's the point. An organisation willing to sit with that discomfort now and make clear choices on how to make progress, before an attacker forces the question, is already doing something most never get around to.
If your organisation is thinking about how you can build your cyber resilience, and where to start, we'd be glad to talk it through. public.digital/cyber
Senior Director, Technology