
These days it’s no longer a case of IFyour firm will be the target of a cyber attack but WHEN. The cyber threat to firms is increasing daily with attacks becoming ever more sophisticated targeting people, networks and devices.
In 2015 the UK government published the results of a survey into information security breaches:
74% of small businesses reported a security breach
63% of businesses provide security awareness training to their staff. Unsurprisingly 72% of the companies where the security policy was poorly understood had staff-related breaches.
Only 27% of small businesses and 39% of large organisations have insurance that would cover them in the event of a breach.
32% of firms hadn’t carried out any form of security risk assessment.
The NCA Strategic Cyber Industry Group warned in their Cyber Crime Assessment 2016 that “the accelerating pace of technology and criminal cyber capability development currently outpaces the U.K.'s collective response to cybercrime. […]it is a major and growing threat to UK businesses.”
The long-term impacts of a cyber attack include substantial loss of revenue, data and other company assets; the impact of litigation costs and potential fines that new regulations could impose as well as the loss of confidence from reputational damage. These would all seriously impact the trading performance of a business. The report also reminds us that firms have an important role in educating and encouraging their customers and suppliers to improve their own cyber security since vulnerabilities within supply chains can be exploited and targeted by criminals.
Firms need to understand the risks and take appropriate action in order to demonstrate that threats have been assessed and it has policies and procedures in place to mitigate and manage those risks
The starting point for developing a cyber strategy and producing policies and procedures is a risk assessment. This should be regularly audited.
Whilst the report acknowledges that perfect security is almost impossible “…substantial and much greater risk mitigation by business is possible.”
The Cyber Essentials Scheme
The Cyber Essentials Scheme was developed by government and industry to fulfil two functions: it provides a clear statement of the basic controls all organisations should implement to mitigate the risk for common Internet-based threats within the context of the government's 10 Steps To Cyber Security and, through the Assurance Framework, it offers firms a mechanism to demonstrate to customers, investors, insurers and others that they have taken these essential precautions.
The Assurance Framework
The Assurance Framework leads to the awarding ofCyber Essentials and Cyber Essentials Pluscertificates.
Roz Woodward, Director of Securious, a Cyber Essentials Certification body and chair of the South West Cyber Security Cluster told us: "We’ve seen a welcome and significant increase in solicitors adopting Cyber Essentials Plus in order to demonstrate that they’ve taken appropriate steps to protect their client data."
Have you completed Cyber Essential or Cyber Essentials Plus? If not, why not?.
Alchemy Systems have 19 years of IT systems experience and are a Microsoft Partner. Alchemy Systems Designs, Supplies, Installs, Supports and Protects clients’ IT systems. The legal sector has always been a strategic focus. Our staff are experienced in the specific needs and challenges of law firms from service desk to strategy to protection services.
Tel. 0330-043-080198 email. sales@alchemysys.co.uk