public digitalThe public digital logo
View all insights

Cyber risk: why audit reports won't save you

October is cyber awareness month. This is an important opportunity to reflect on cyber risks and the steps that every business and institution should take to make sure they are as well protected as possible, and (critically) to be ready for when the worst happens.

In recent years the growing number of serious cyberattacks on UK businesses and public services has been well publicised. The impacts have been significant, including hospitals unable to provide vital health care (with at least one death attributed to the effects of an attack), impacts on vital public services such as benefits payments and people being unable to buy and sell homes, and huge economic impact on businesses and their suppliers which has been estimated to run into billions. Alongside the impacts on citizens, customers and businesses, responding to a cyberattack also takes a huge toll on employees and leaders.

If you’ve not yet experienced a cyberattack in your own organisation, it’s easy to assume that the people affected weren’t taking their cyber defences as seriously as you do, and that holding up to date assurances like an ISO27001 accreditation or other compliance certificates will mean that your organisation is safe. That would be a serious mistake.

A pattern that we see time and again is that attacks occur when apparently simple controls haven’t worked. That could be a computer which is missing a critical security patch, a member of the IT support team being tricked into providing access to a malicious actor, or a failure with any number of other measures that your regular audits will have reassured you are well covered. It’s rare that the victims had been ignoring these.

Your certificates will confirm you have the right controls and processes in place. But you need to be 100% confident that those are 100% effective, 100% of the time. Your attacker only needs that to not be true once. They won’t care about the certificates you’ve earned if they can find a gap that is ready to exploit. And the impacts when that happens can be devastating.

Rapid innovation in AI is only going to make this harder, giving attackers ever more powerful tools to find the gaps that they need and helping them exploit vulnerabilities even faster than before. And an increasingly volatile world means that the potential threat is increasing every day. The only safe bet is to assume that your controls won’t work.

What should leaders and boards be doing to manage cyber risks?

Too often conversations about cyber risks concentrate on technical threats and defences, with an emphasis on compliance and the certificates that demonstrate assurance. These are fundamental, but there is a much broader strategic focus that boards need to have to make sure that their organisations can have real confidence that they understand their cyber risks and are taking a genuinely strategic approach to mitigate them.

Some key steps that boards must take are:

Don’t treat cyber risks as an ‘IT thing’

Cyber can often feel very ‘techy’, and it’s easy to treat it as something for the IT team to look after. But the reality is that the actions needed to reduce cyber risks, the impacts of an attack, and the work needed to respond to and recover, involve every part of the organisation at every level.

Being well prepared against the risks and impacts of cyber threats is also an important part of making sure that your organisation is resilient to the demands of an increasingly volatile world. So treating cyber resilience as a core strategic capability has broader benefits beyond protecting your data and computer systems.

Organisations that take cyber resilience seriously are much more likely to be the organisations who are able to adapt and respond successfully to other risks too.

Invest in your defences

This is non-negotiable. Do your technology team have the investment and support they need to make your defences as strong as possible? Where do they need additional backing to retire legacy technology that could be your organisation’s weak point? Where do they need senior support to make sure that everyone who uses your systems is aware of and following your security processes?

And don’t assume that your controls are working the way that you expect - find out where they’re failing before the attackers do. Use approaches like investing in a ‘Red Team’ to help you find the inevitable gaps in your defences and act quickly to address those.

Make the strategic shifts needed to reduce risk

Defending your legacy technology is necessary, but not sufficient. It’s all too common to find business critical systems and infrastructure which have elements that are largely unchanged from the early 2000s, with security design and applications that present significant risks when faced with the threats of the modern internet and AI era. Take a look under the hood of your IT estate and you’ll probably be shocked by what you find.

As a board, challenge yourselves by asking how well you understand the legacy technology that you are still relying on and whether you’ve made the investments needed to design greater security and resilience into your systems. Are you using modern approaches like zero trust security and scalable cloud technology to reduce the likelihood of a breach and reduce the impact if an attacker is successful? Are you investing in the skills and capacity that you need to manage your technology estate effectively? Are you weighing the costs of modernisation against the (potentially huge) costs of disruption if an attack is successful?

Plan for resilience

All too often, business resilience plans assume that the impacts of a cyberattack will be measured in hours and days. But the reality is that it’s far more common for recovery to take months and even years. You should not assume that your plans will stand up to the challenges that you’d face if you experience a successful cyberattack - you should treat this as a case of ‘when?’, not ‘if?’.

Complex systems, processes and data, combined with the need to ensure that systems are properly clean before they are returned to use, mean that there is rarely a rapid path to recovery. Questions you should be asking before, not after, an attack include:

  • How well do you understand what is most critical to your business, customers and suppliers so you know what to prioritise in the event of an attack?
  • How will you continue to deliver your most critical work without your usual systems being available while recovery is taking place? How will you function if key suppliers are impacted by a cyberattack?
  • How will you make sure that your continuity arrangements will stand up to the pressures of a sustained and extended outage (you can’t be certain exactly how long this could be, but we suggest using six months as a reasonable guide for the potential timescale you should plan for)?
  • How will you manage culture, communications and rebuilding trust within the organisation, in the public media and with your customers, partners, investors/funders, regulators and suppliers? Are you prepared for the challenges that this will bring for you and your teams?

Where to start?

The first thoughts for most boards are likely to be very similar: are we covered? are we compliant? Do we have the certificates? Those are important questions. But it’s vital to not stop there - attackers won’t care about the certificates you’ve earned if they can find a gap in your defences which they can exploit.

Some practical steps you should take now are:

  1. Start by using the headings above to build a broad and strategic focus on cyber resilience. Ask yourselves how confident you are in each of the themes and consider your relative maturity across those - and make sure you challenge your assumptions (watch out for false confidence and dig deeper if you don’t have convincing evidence to support your level of confidence).
  2. Once you’ve got a clear view of where you need to act, take stock of your action plans. Test whether these are addressing your critical priorities, and look carefully at the progress you’re making. Is there clear evidence that you’re increasing your cyber resilience at the pace that is needed, or are there projects which are stuck and in need of support? 
  3. Where work feels stuck, how can you break work down into smaller chunks that will let you speed up progress? In particular, look for tangible steps that can help you learn about what works, how to address the more complex challenges, and start to deliver meaningful progress that reduces risk and increases resilience. (For example, proving a model for zero trust access to one critical system might only be one step on a longer journey, but if it means that critical system is itself more secure and less likely to be impacted if other systems are attacked, that will in and of itself be a material improvement to your cyber resilience. And once you’ve done that it will become easier for other systems.)

None of this is easy, especially in large, complex organisations that are having to balance competing priorities and which rely on large estates of complex, legacy technology. But that's the point. An organisation willing to sit with that discomfort now and make clear choices on how to make progress, before an attacker forces the question, is already doing something most never get around to.

If your organisation is thinking about how you can build your cyber resilience, and where to start, we'd be glad to talk it through. public.digital/cyber 

Written by