What is a cyber-attack?
An attempt by a hacker to damage, destroy or obtain information from a computer network or system.
Cyber threats
There are a number of cyber threats to members, many of which hackers will use in tandem to obtain their goal. We list the most common types below:
Phishing attacks
Where an e-mail is sent impersonating a business or individual tricking the victim to give out personal information or providing an entry point to deposit malware (hostile software) on the victim’s computer or network. Similar scams can be applied over the phone (vishing) and through text messages (smishing).
Spear-phishing attacks
These are common attacks on businesses whereby the fraudster will send an e-mail impersonating usually senior staff authorising the victim to disclose sensitive information or make payment (to account details specified by the fraudster).
Ransomware
A form of malicious software that is often deployed through a phishing attack. Once a computer or system is infected it will ask the victim to make payment in return for restoring the system/files to the same state before the attack.
Advanced Persistent Threat Attack
Where the attacker gains access to a network and remains undetected over a long period of time extracting valuable information. These attacks are often associated with Organised Crime Gangs (OCGs) and provide a means with which to harvest data that can be used to commit other types of cyber-attack.
Distributed Denial of Services (DDoS)
A DDoS attack infects multiple systems in order to overwhelm an online service. This can lead to websites crashing and restricting the ability for new information to be published.
Drive-by Download
Malicious programmes automatically downloaded without consent or prior knowledge, usually when a link is clicked. These types of threat can be focused on both unsecured and secured website traffic. It is therefore important for businesses to have in place appropriate security measures that monitors secured traffic to ensure any viruses are not admitted to the site.
The risks
Data breaches
If personal data is lost, altered or accessed by a hacker the ICO could levy a fine of up to £500,000 depending on the seriousness of the breach. Transposition of General Data Protection Regulation (GDPR) in May 2018 increased the maximum fine to €20m or 4% of annual global turnover – whichever is higher.
FCA enforcement action
Although the ICO is the regulator responsible for data security, data breaches and systems failures reported to the FCA could result in closer supervision and (in extreme cases) enforcement activity due to inadequate protection of clients’ assets (PRIN 10) and systems and controls failures.
Additional costs
Cyberattacks can be costly. Phishing and ransomware attacks have resulted in cases where businesses have paid hackers large sums of money. There may also be a need to replace damaged software and appoint solicitors, consultants or other professional advisers following the attack.
Reputational damage and associated loss of revenue
High profile cyberattacks can result in lack of confidence in the products and services that affected businesses provide, resulting in loss of sales and revenue.
Guidance, prevention and reporting
- The FCA’s Good cyber security guide and operational resilience web page – provide a concise overview of what the regulator sees as good cyber security practice and the organisations that attacks and data breaches should be reported to.
- The National Cyber Security Centre (NCSC) is a government funded intelligence agency set up to protect critical services from cyber-attacks, manage major incidents and improve underlying cyber security in the UK. NCSC provides guidance for industry and information on current threats including weekly threat reports. NSCC is also responsible for the Cyber Security Information Sharing Partnership (CiSP) set up to exchange cyber threat information in real-time. The FLA can sponsor members that would like to join CiSP.
- The UK Gov provides a cyber security sign-posting web page with a number of useful websites and publications which can be found here.
- Cyber Essentials is a certification scheme that allows businesses to demonstrate that they have met a government endorsed cyber security standard through a verified self-assessment process. Certification can be used to give customers and suppliers the assurance that they are handling their data securely and improve the cyber awareness of staff.
Training
Please e-mail training@fla.org.uk for further information including upcoming dates of when the course will take place.