British National Cyber Security Guidance

Most organisations rely on their IT systems to carry out business and to control critical functions, using various types of digital technology to manage their safety, security and engineering systems. As a result, businesses can become vulnerable to hacking and threats that undermine their confidentiality, integrity or accessibility. 

The consequences of such incidents can be significant to organisations, leading to loss of reputation, damage to assets, regulatory fines or result in physical injury.

To understand the cyber risk to your business, you should conduct a Cyber Risk Assessment. This will help to ensure that your approach to cyber security is proportionate.  Here is the UK Government’s outline of cyber security information for organisations:

Whilst there is no prescribed format for this, it should be based on the Risk Management processes detailed below. Note that the risk assessing is a continuous, on-going process which you will need to revisit as your business changes and / or threats evolve.

Assessing The Risk

The following three step process will help you identify:

  • The digital technologies and systems which are critical to your business
  • Who might attack them
  • How they might be vulnerable

This information will allow you to narrow down what you must protect.

Impact: What Your Want To Avoid

Your approach to cyber risk management should be driven by the ‘Impacts’ you are trying to avoid. Start by identifying the systems, data and technologies on which your business relies. The type of questions you might want to ask are:

  • Is there technology that must be available for the business to function? (e.g. payment systems, access controls)
  • Do physical security systems rely on digital technology? How are they protected?
  • Are you processing sensitive data? (personal, financial) If so, what if this data is lost, stolen or unavailable?
  • Are you reliant on third-party systems? If so, which systems are central to your business?

If you take a systematic approach, you should be able to produce a prioritised list. You then need to consider the impact of these systems being compromised or becoming unavailable. This basic understanding of what you care about and why it’s important, will help you identify what you must protect.

Threats: What Type of Attacks To Expect

A ‘Threat’ is the individual, group or circumstance, which could cause a given impact to occur. It can be challenging to develop an accurate assessment of the threat to your business without undertaking an appropriate analysis. The following will help you develop a baseline threat picture:

  • Commodity Attacks: All organisations and events, regardless of profile and size, are at risk from commodity attacks that exploit basic vulnerabilities using readily available hacking tools and techniques. Mass phishing campaigns are one example of such an attack.
  • Targeted Attacks: Some businesses will be targeted by cyber criminals who, for example, intend to steal financial or personal information e.g. spear phishing.
  • Methodology: Most attacks are preventable and use well-known techniques.
  • Insider Threat: Not all threats are external. It is essential that internal threats are incorporated into your assessment.
  • Learn from Experience: Has your business or similar businesses previously experienced cyber-attacks? How could those attacks have been prevented?
  • With some research, you should be able to develop a baseline threat assessment. For example, you may decide that your business is unlikely to be deliberately targeted, therefore commodity attacks exploiting basic vulnerabilities are the main threat.
  • Alternatively, you may discover that businesses of similar profile have been targeted by organised crime groups, therefore the threat is heightened and specific defensive measures are required.
  • It should be noted that most targeted attacks still use basic techniques, such as phishing emails, to enable attacks. Good basics are always the first layer of defence 

Vulnerabilities: How Secure Are The Networks & Systems That You Rely On?

A ‘Vulnerability’ is a weakness that would enable an impact to be realised, either deliberately, or by accident. The final stage of the process is identifying your vulnerabilities. You should start by overlaying your critical systems (see ‘Impact’, above), with the expected capabilities of any attackers.

Next, focus on establishing whether the security controls for each critical system are appropriate for the threat. Remember, most cyber-attacks are preventable if basic controls are in place. Identify who is supplying your critical systems and establish a clear picture of each supplier’s cyber security posture.

A good starting point is to ask whether your suppliers hold any existing security certifications (e.g. Cyber Essentials, Cyber Essentials Plus, ISO 27001). Holding a certification indicates that the supplier has a proactive approach to cyber security. If suppliers do not hold any certifications you will need to invest time to understand more about their security posture.

From an IT infrastructure perspective, you may wish to use the Cyber Essentials themes as discussion points:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Patch Management

For providers of online services, you may wish to focus your discussion on the common web application security issues and for further information:

Almost every business relies on the confidentiality, integrity and availability of its data and cyber security measures should form a critical part of a multi-layered approach that includes physical and personnel security. 

GovUK:          Centre for Protection of National Infrastructure:

For cost effective advice and recommendation on Cyber Security and Training for your organisation, please contact Cyber Security Intelligence.

You Might Also Read: 

Directors Must Understand Their Organisation’s Cyber Risks:

 

« The Data Center Containment Solution Market is Growing
Fake PayPal Emails Cost £8million In Theft »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Exodus Intelligence

Exodus Intelligence

Exodus Intelligence are an industry leading provider of exclusive zero-day vulnerability intelligence, exploits, defensive guidance, and vulnerability research trends.

INSUREtrust

INSUREtrust

INSUREtrust is a pioneer in the industry, inventing the concept of cyber insurance.

Robert Bosch Centre for Cyber-Physical Systems (RBCCPS)

Robert Bosch Centre for Cyber-Physical Systems (RBCCPS)

RBCCPS is an interdisciplinary research and academic centre within the Indian Institute of Science focused on research in cyber-physical systems.

SecLytics

SecLytics

SecLytics is the leader in Predictive Threat Intelligence. Our SaaS-based Augur platform leverages behavioral profiling and machine learning to hunt down cyber criminals.

Zymbit

Zymbit

Zymbit provides hardware security modules (HSM) for IoT devices, including Raspberry Pi and other single board computers.

Jobsora

Jobsora

Jobsora is an innovative job search platform in the UK and more than 35 other countries around the world. Sectors covered include IT and cybersecurity.

iZOOlogic

iZOOlogic

iZOOlogic protects hundreds of the world’s leading brands, across banking, finance and government from cybercrime. We provide strong cyber defence solutions to protect client digital assets.

Guidehouse

Guidehouse

Guidehouse is a leading global provider of consulting services to the public and commercial markets with broad capabilities in management, technology, and risk consulting.

SolCyber

SolCyber

SolCyber, a Forgepoint company, is the first modern MSSP to deliver a curated stack of enterprise strength security tools and services that are accessible and affordable for any organization.

Cyber Chasse

Cyber Chasse

Cyber Chasse is an IT consulting and staffing company offering a full range of cybersecurity solutions, contract staffing services and online training courses.

MailChannels

MailChannels

MailChannels protects companies against malicious email threats. Used by 750+ hosting providers around the world.

Cyber Unit

Cyber Unit

Cyber Unit offer next level protection from cyber attacks in packages and pricing options that are accessible to smaller organizations.

8com

8com

8com is an established Managed Security Service Provider (MSSP) with over 75 employees and customers in over 40 countries.

Sec3

Sec3

Sec3 is a security and research firm providing bespoke audits and cutting edge tools to Web3 projects.

SolidityScan

SolidityScan

SolidityScan is an advanced smart contract scanning tool designed to uncover vulnerabilities and proactively address risks within your code.

Cloud Native Computing Foundation (CNCF)

Cloud Native Computing Foundation (CNCF)

CNCF seeks to drive adoption of cloud native technologies by fostering and sustaining an ecosystem of open source, vendor-neutral projects.