EU Crackdown On Cyber Crime

Cyber-risks facing businesses today are significant and only increasing. With many welcoming the European Union’s recent announcement that cyber criminals will face tough sanctions under a new regime agreed by member states. 

In April 2019, cyber security firm Malwarebytes reported that the number of cyber threats to businesses has increased 235 per cent over 2018-19. Insurance firm Hiscox recently reported that more than 60% of British businesses have been the victim of one or more cyber-attacks in 2019 already.

Good News
Under the measures, people and organisations could be given travel bans and have their assets frozen if they are found to be responsible for cyber-attacks or to have provided financial, technical or other assistance in connection with a cyber-attack. Significantly, sanctions may also be imposed on people or organisations associated with them.

Limited Protection
There is no doubt the EU’s recent announcement marks a step forward in the battle against cyber-crime. The measures provide potentially powerful sanctions against cyber-criminals. However, it is important not to overplay the impact of these measures. Whilst the new EU sanctions will provide some potentially helpful tools for fighting security at an international level, their benefit is unlikely to be felt equally by all organisations.

The new EU measures only apply to cyber-attacks which have a ‘significant effect’. Guidance is yet to be released on the types of attacks that will fall into this category. However, it is possible that an isolated attack against an SME may not be included.

It is more likely that the new regime of measures is aimed at countering attacks on organisations and infrastructure on a national and international scale. 

One cannot help thinking of the worldwide WannaCry ransomware attack which took a particularly heavy blow to NHS hospitals in England and Wales back in May 2017. Further, in March 2019, the ten Healthcare Minister Jeremy Hunt warned of the growing vulnerability of democratic elections to interference. It is against these sorts of public targets that these sanctions are likely to be focused.

Even then, there are inherent difficulties associated with law enforcement of cybercrime. Locating and identifying perpetrators, with hackers regularly employing secure software to remain anonymous by hiding their location and routing their communications through multiple countries in order to evade direct detection.

Easy Target
Whilst the introduction of international sanctions against those involved in cyber-crime is a positive step, their direct impact on most businesses is likely to be limited. It is therefore important that businesses do not first look to government and international organisations for cyber-protection but rather develop robust cyber security strategies of their own.The number of cyber-attacks against businesses is increasing at an alarming rate. But what maybe more surprising for SMEs is that size offers no protection to cyber-attacks. Whilst we may be more familiar with stories of large attacks against well-known organisations, it is often SMEs that are most vulnerable to a breach.

Size does not make data any less valuable to criminals.

Sensitive information such as customer bank details or staff log-ins are desirable to criminals whether you are an small or medium sized enterprise (SME) SME or a public company (PLC). In light of robust regulation such as GDPR, their legal obligations in relation to the protection of that data may be the same. In fact, SMEs can be particularly attractive to hackers precisely because of their size.

Smaller businesses often do not have in place the mechanisms necessary to resist an attack. Therefore, attackers see them as easy targets.

In April, the government published the results of its latest annual cyber security survey. Whilst the survey encouragingly reported an increase in the proportion of SMEs who see cyber security as high priority (74%), there is still cause for concern. 
Smaller businesses are less likely to seek information, advice or guidance about cyber security compared to larger businesses.

Only a quarter of small business have cyber security policies in place and even less have received any cyber security training.

Urgent Action
Organisations of all sizes need to implement measures to effectively manage growing cyber-security risks. These are likely to include ongoing assessment of current security capability and implementation of appropriate upgrades, training to minimise human error and the taking out cyber-liability insurance to cover the costs of when things go wrong.

Cyber security is now a key business risk and it is not going to go away. This is reflected in the EU’s recent measures. The sooner SMEs are alive to these risks, the better.

SME Web:

You Might Also Read:

Hackers Don't Only Target Big Business:

UK Cyber Crime Is Increasing In 2019:

 

 

« US Power Grid Attack – No Harm Done. This Time
Smart Cities Call For Mobile Solutions »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Securezoo

Securezoo

Securezoo's mission is to simplify and enhance information security by providing trusted security guidance, products, and information to small and mid-sized businesses and security professionals.

Security Stronghold

Security Stronghold

Security Stronghold is focused on protecting computers from malicious programs like viruses, Trojans, spyware, adware, trackware, keyloggers and other kinds of online threats.

Thales

Thales

Thales provides solutions, services and products that help its customers in the defence, aeronautics, space, transportation and digital identity and security markets to fulfil their critical missions.

AppViewX

AppViewX

AppViewX is a global leader in the management, automation and orchestration of network services in data centers.

Government CSIRT - Chile

Government CSIRT - Chile

Government CSIRT is the Computer Security Incident Response Team for State networks and government cyberspace in Chile.

Elemendar

Elemendar

Elemendar Artificial Intelligence reads cyber threat reports written by humans and translates them into industry-standard, machine-readable and machine-actionable data.

Prove Identity

Prove Identity

Prove (formerly Payfone) is a leader in mobile & digital identity authentication for the connected world.

Nitrokey

Nitrokey

Nitrokey is the world-leading company in open source security hardware. Nitrokey develops IT security hardware for data encryption, key management and user authentication.

CERT.JE

CERT.JE

CERT.JE is responsible for promoting and improving the cyber resilience across the critical national infrastructure, business communities and citizens in Jersey.

SecAlliance

SecAlliance

SecAlliance is a cyber threat intelligence product and services company.

Corsearch

Corsearch

Combining AI-powered technology and decades of industry expertise, Corsearch is revolutionizing how companies establish and protect their brands.

Rescana

Rescana

Rescana offers a cyber risk management platform with the vision to remove the security team bottlenecks, accelerating business processes that require risk assessment.

Defendis

Defendis

Defendis develops AI-powered cybersecurity solutions for Government Agencies, Banks, and Businesses, designed to helps them contain data leaks, minimise damage, and proactively hunt for new threats.

Cyber Advisors

Cyber Advisors

Cyber Advisors offers customizable cyber security solutions and IT services for businesses of all sizes across the nation from experts you can trust.

Transcendental Technologies

Transcendental Technologies

Transcendental is a consulting organization which specializes in customized assurance services in the fields of Localization, Mobile Software Solutions, Web Design, Cyber Security & Cyber Forensics.

International Maritime Cyber Security Organisation (IMCSO)

International Maritime Cyber Security Organisation (IMCSO)

The IMCSO mission is to be the standard in the maritime cyber security industry, a collective voice, working towards alignment and standardisation.