{"id":32608,"date":"2019-08-06T15:19:33","date_gmt":"2019-08-06T14:19:33","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=32608"},"modified":"2019-08-13T09:06:21","modified_gmt":"2019-08-13T08:06:21","slug":"industry-expert-on-building-the-foundations-to-support-every-cybersecurity-strategy","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/08\/06\/industry-expert-on-building-the-foundations-to-support-every-cybersecurity-strategy\/","title":{"rendered":"Industry expert on building the foundations to support every cybersecurity strategy"},"content":{"rendered":"\n<p><em>The Minimum Cyber Security Standard defines the minimum security measures organisations and agencies must implement. But while awareness of this standard is high (98%), organisations have not seen the dip in cyberattacks that you would expect, as more had experienced over 1,000 attacks in 2018 than in 2017, according to the findings of an FOI request conducted by SolarWinds. Sascha Giese, Head Geek at SolarWinds, talks through the key findings from the survey and identifies how the public sector can manage the ever-increasing cybersecurity challenge in three points.<\/em><\/p>\n\n\n\n<p>Public sector organisations are now\nworking to meet the new standards released last year by the National Cyber\nSecurity Centre. The <a href=\"https:\/\/www.gov.uk\/government\/publications\/the-minimum-cyber-security-standard\">Minimum Cyber Security Standard<\/a> defines the minimum security measures\norganisations and agencies must implement with regard to protecting\ninformation, technology, and digital services. <\/p>\n\n\n\n<p>With the standard marking its one-year\nanniversary this summer, it\u2019s good for UK government departments and public\nsector organisations to evaluate their progress in meeting this standard, what\nchallenges they\u2019re facing and what priorities they still need to monitor. <\/p>\n\n\n\n<p>This is the first technical\nstandard issued and is designed to continually \u2018raise the bar\u2019 and address new threats or classes of\nvulnerabilities that can cause chaos for organisations and constituents alike.<\/p>\n\n\n\n<p><strong>Awareness doesn\u2019t equate to action<\/strong><\/p>\n\n\n\n<p>In a recent <a href=\"https:\/\/www.solarwinds.com\/company\/press-releases\/2019-q2\/nearly-a-fifth-of-uk-public-sector-organisations-reported-over-1000-cyberattacks-in-2018\">FOI request<\/a>,\n98% of respondents from central government and NHS\norganisations noted they\u2019re aware of the Minimum Cyber Security Standard, which\nis positive. However, this awareness doesn\u2019t seem to correlate with as\nmuch of an anticipated dip in cyberattacks. <\/p>\n\n\n\n<p>While the overall percentage of public\nsector respondents who experienced a cyberattack in 2018, compared to 2017,\ndecreased (38% experienced no cyberattacks in 2018, while 30% experienced none\nin 2017), more organisations experienced over 1,000 cyberattacks \u2013 18% in 2018\ncompared to 14% in 2017. <\/p>\n\n\n\n<p>Similarly, there could be another risk\nthat the standard will only be seen as a collection of checkboxes to tick,\nwithout thinking further ahead, or customising it to the organisation&#8217;s needs.<\/p>\n\n\n\n<p>Despite the positivity that can be drawn\nfrom the lowered percentages, these figures played out very differently in NHS\norganisations and central government agencies. <\/p>\n\n\n\n<p>Almost three-quarters (74%) of NHS\norganisations experienced less than 50 cyberattacks in 2018, slightly less than\nin 2017 (75%). <\/p>\n\n\n\n<p>On the other hand, over 80% of\ncentral government organisations reported almost the exact opposite by\nindicating they experienced in excess of 1,000 attacks in 2018, up from 67% in\n2017. <\/p>\n\n\n\n<p>This suggests that although the most\ntalked about cyberattack in recent memory, WannaCry, cost the NHS \u00a392m and caused 19,000\nappointments to be cancelled, central government agencies find themselves under more frequent attack than\nthe NHS. <\/p>\n\n\n\n<p><strong>Managing\nthe cybersecurity challenge<\/strong><\/p>\n\n\n\n<p>The results of the FOI suggest\npublic sector organisations are aware of the cybersecurity challenges they face\nand the rapid rate of evolution.\nHowever, it\u2019s also evident that the rate at which public sector organisations\nare facing cyberattacks is on the rise and simply setting out a security\nstandard may not be enough to stop it.<\/p>\n\n\n\n<p>While it\u2019s clear based on the establishment of the Minimum Cyber Security Standard that the regulatory bodies are taking the matter seriously, it\u2019s now a case of this way of thinking trickling down to each individual organisation or agency and implementing the tools to meet it. To form a successful strategy for this, there are three key areas to consider.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Knowing who <\/strong><\/li><\/ul>\n\n\n\n<p>A key\npart of cybersecurity is knowing who has access to systems and data. Through the right access management\nsystem, public sector organisations can improve security posture and mitigate\nany insider threats by identifying insecure accounts. Automating access rights\nmanagement, analysis and enforcement also enables quick demonstration of\ncompliance, easy permissions management and ultimately enhanced productivity of\nthe IT team. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Knowing\nwhat<\/strong><\/li><\/ul>\n\n\n\n<p>Visibility into\nwhat\u2019s happening within an IT environment is also key to strengthening security\nposture, so implementing security information and event management (SIEM) is\nanother crucial piece of the puzzle. SIEM tools enable IT teams to collect and\nnormalise logs generated across networks and systems to detect and protect\nagainst advanced cyberthreats, respond to cyber-incidents with unique\nuser-defined actions and help demonstrate regulatory and industry compliance. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Looking\nforward <\/strong><\/li><\/ul>\n\n\n\n<p>Every\npublic sector entity is unique and the velocity, variety and volume of\ncyberattacks they experience will provide new, evolving challenges. IT teams need to be ready and agile in\nadopting new techniques and learning from past experiences to ensure their\norganisations are constantly protected. <\/p>\n\n\n\n<p>Building\na roadmap for future testing, re-evaluation of tools and security posture and\nthe ability to think ahead to potential new threats will be key. A critical part of this will be\nunderstanding how to get visibility of the entire infrastructure and getting\neveryone who has access to use IT monitoring tools to provide the right\ninformation to put the right protections in place.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Minimum Cyber Security Standard defines the minimum security measures organisations and agencies must implement. But while awareness of this standard is high (98%), organisations have not seen the dip in cyberattacks that you would expect, as more had experienced over 1,000 attacks in 2018 than in 2017, according to the findings of an FOI [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":32826,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,497,1489,6617,93],"tags":[183,564,13083,8837,91,1032,13084],"class_list":["post-32608","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-government","category-insights","category-research","category-top-stories","tag-cyberattacks","tag-cybersecurity","tag-head-geek-at-solarwinds","tag-national-cyber-security-centre","tag-nhs","tag-public-sector","tag-sascha-giese"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=32608"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32608\/revisions"}],"predecessor-version":[{"id":32629,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32608\/revisions\/32629"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/32826"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=32608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=32608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=32608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}