UK Emergency Services at risk of major cyber-attack, overall infrastructure resilient
• Diversification of businesses and industry in the UK increases resilience to targeting of key sectors
• Emergency services upgrade to android devices leaves UK vulnerable to attack due to UK having one of highest rates of Malware attacks
• Intelligence sharing key to preventing a major cyber or hybrid attack
London, UK. [27 February 2018] The UK’s emergency services are at risk of a major cyber-attack. This is the finding of a new landscape analysis, issued this morning by leading threat intelligence provider, Anomali.
The UK Threat Landscape report, which explores the UK’s Critical National Infrastructure against threats and possible vulnerabilities, points to a number of weak spots in the UK which could attract an attack. One of the most notable, in addition to the emergency services, is the Defence Equipment and Supply Organisation which presents a prime target for actors seeking to disrupt defence procurement.
Other key findings of the analysis include the vulnerability of the UK’s energy infrastructure. 21% of all electricity is generated by 15 nuclear reactors, all of which are owned by EDF. This combination of monopoly of ownership and geographic clustering means that the civil nuclear sector is constantly on a high state of alert for a terrorist and cyber-attack.
Commenting on the findings, Hugh Njemanze, CEO of Anomali said, “The UK presents a complex cyber risk picture – previous foreign policy commitments and current tensions between NATO and other nation states make it a target for international terror organisations.
Within the UK, the nature of the economy and industry present a combination of opportunity and risk to those looking to plan a hybrid attack. The network of small and medium enterprises which support Critical National Infrastructure strengthens its resilience, whereas the geographical clustering of industries can weaken the system leaving them vulnerable to attack.
The UK’s emergency services are a prime example of this – the breadth and complexity of the organisations which comprise this mean there are a number of points of potential weakness. The number of notable attacks over the past few years are testament to this weakness. It is clear that the UK’s emergency services need to take action to stop this heightened risk becoming a reality. One of the best means of preventing these attacks is ensuring that knowledge of cyber threats is shared between emergency services operators so all can ensure the resilience of their networks.”
In addition to this, the UK’s Financial Services sector, which is a key pillar of the economy is highly vulnerable to cyber-attacks – it is subject to regular and significant stress tests by the Bank of England to prevent a major disruption to the economy.