6 June 2024
Implications of Cyber Attacks
By Becky Hall, Information Governance Manager
Recently several cyber-attacks have been reported on in the news, highlighting the disruptive impact that these attacks have on the services that organisations provide.
A cyber-attack that took place over the recent half term resulted in a school in Essex having to close to some of their year groups for the day as all their IT systems were inaccessible due to complex encryption. The school also believes that names, addresses, and medical notes of students, as well as parent and career contact details, may have been accessed as part of the breach. This incident highlights not only the immediate impact of a cyber-attack innot being able to open the school to the full capacity, but also the longer term, unknown impacts that cyber-attacks can have on individuals if their data is shared for malicious purposes.
A number of major hospitals in London have also been affected by a cyber-attack impacting blood transfusion, test results, and resulting in procedures being cancelled or being carried out elsewhere. This is the result of one of the service providers to the hospitals suffering a cyber-attack leading to the widespread impact on hospital services and highlighting the need for robust business continuity planning.
These incidents illustrate that an organisation may be directly targeted or that they may suffer as the result of an attack on one of their suppliers. Being able to cope with the disruption and minimise the impact for those involved are core parts of the response, as well as maintaining transparency and clear communications with individuals who have been affected by such attacks.
While cyber-attacks may never be completely preventable, organisations can implement some essential tasks to reduce their risk of suffering an attack and helping them to recover afterward. These include:
- Ensuring that all relevant technical security measures are in place and are up to date, including applying updates and patches;
- Ensuring that organisational measures are used such as role-based access controls;
- Carrying out staff training to make sure that staff are aware of the risks and know what to look out for. The National Cyber Security Centre provides free e-learning; and round table exercises for organisations to access http://www.ncsc.gov.uk
- Carrying out data processor due diligence to ensure that suppliers have appropriate technical and organisational measures in place;
- Understanding where information is stored to help understand the impact of any incident, this most commonly is done in an Information Asset Register;
- Ensuring that the business continuity plan and disaster recovery plan are kept up to date and regularly reviewed.
If these are areas that might affect you and your organisation, Naomi Korn Associates offers specialist services to support organisations including:
- Data protection audits
- Project based support
- Policy and procedure support
- CPD accredited staff training
Naomi Korn Associates also runs a public training programme covering a variety of topics. Relevant topics include:
Privacy by Design: Data Protection Impact Assessments18th June, 9.30am-1.00pm
Information Security and Data Breach Management 9 July, 1.00-4.30 pm