With cyber attacks now affecting almost every government organisation, the challenge is no longer whether an incident will occur, but how prepared those affected are to respond.
A recent breach affecting the Department for Education has highlighted the scale of the threat facing the public sector, with a report by cyber security services provider Bridewell finding that 93% of government organisations experienced a cyber attack in the past year.
The impact of these incidents has been significant, with IT disruption and outages affecting 43% of organisations and 34% reporting operational disruption as a consequence of these attacks.
Sam Thornton, Chief Operating Officer at Bridewell, spoke to Government Transformation Magazine about the barriers the public sector faces in improving its cyber security, and what steps leaders should take to address them.
___
Central and local government face a number of challenges when seeking to improve their cyber security defences, according to Thornton. One such challenge relates to developing and retaining key skills and capabilities, with local government in particular often lacking the funding to invest in cyber expertise, and central government finding it difficult to retain top talent, increasing reliance on third-party providers.
Another relates to the move to cloud, which has opened up new vulnerabilities, and a shift in how hackers exploit stolen data, with information increasingly being used as leverage in ransomware and extortion attacks.
However, against this backdrop, there are still a number of practical and immediate steps government organisations can take to strengthen their security.
According to Thornton, one of the most common mistakes public sector organisations make is believing that creating action plans and running tabletop exercises means they are prepared for a real-world incident.
“It’s not as simple as that,” he said. “Most of the time when there is an attack in progress, or you're actively responding to something, the documentation side of things doesn't really get pulled out.
“It's too frantic at the time, you end up just trying to firefight and you're making decisions on the fly that wouldn't necessarily be made in a calmer kind of tabletop exercise.”
Instead Thornton suggests running more in-depth, realistic simulations, such as red team exercises, to help staff members become accustomed to acting under pressure. He also emphasises the importance of raising awareness of social engineering attacks, explaining that, despite the growing focus on AI-powered cyber threats, some of the most effective methods still involve phishing or impersonation.
Yet fostering the correct behaviours is not sufficient on its own; organisations must also have the correct technological foundations in place. While the latest advances in technology draw much attention, Thornton argues that leaders should not lose sight of the fundamental need to “do the basics right”.
This involves building new services with secure by design principles in mind from the outset, such as vulnerability management, identity and access control, and privilege access management, and consideration of the OWASP Top 10 security risks.
“It’s nothing revolutionary,” he said. “[While] the world's moved on and is talking a lot about AI, the reality is a lot of these basic controls and security mechanisms are still as prevalent today as they were 20 years ago, and they are the things that unfortunately are getting missed at times”.
Thornton remains optimistic about the future of cyber security in government, highlighting the "strides" government organisations have made in strengthening their cyber defences.
Indeed, his comments come as the government seeks to strengthen the UK's cyber resilience through measures including the Cyber Security and Resilience Bill, which aims to improve protections for critical infrastructure and organisations providing essential services.
“We work with a lot of government entities, and we can see that there is investment, there is a willingness and a want to do the right thing,” he said.