top of page

Don't become collateral damage in cyberwars

  • Mar 9, 2022
  • 3 min read

Updated: Mar 24, 2022

For most large organisations, the critical consideration is not whether or not they have been targeted (they will have been), but whether or not they have been able to identify and neutralise the intrusion.


Cybercrime is a serious issue but, in the longer run, may be a lesser danger to organisations than the effects of what is called 'cyberwar'. It is believed that every significant terrorist or criminal organisation has cyber-capabilities and has become very sophisticated in its ability to plan and execute digital attacks. More significantly, many nation states now see cyberwar as an alternative - or an essential precursor to - traditional warfare.


Eliza Manningham-Butler, the then director-general of the UK security service MIS, said this at the 2004 CBI annual conference:


“A narrow definition of corporate security including the threats of crime and fraud should be widened to include terrorism and the threat of electronic attack. In the same way that health and safety and compliance have become part of the business agenda, so should a broad understanding of security, and considering it should be an integral and permanent part of your planning and statements of internal control; do not allow it to be left to specialists. Ask them to report to you what they are doing to identify and protect your key assets, including your people.”


A decade later, Sir lan Lobban said much the same thing in an open letter to CEOs and Chairs of FTSE 350 companies, encouraging them to undertake a 'cyber health check' after a KPMG security survey found that all of them were leaking data, such as employee usernames, email addresses and sensitive internal file location information online.


Certainly, businesses appear to have got this message, with 97 per cent of them claiming to be concerned at board level about cyberwar. They should be More than 400 million computers are linked to the internet; many of them are vulnerable to indiscriminate cyber-attack. The critical infrastructure of the First World is subject to the threat of cyber-assaults ranging from defacing websites to undermining critical national infrastructure.


A growing number of countries are at last putting cyber security strategies in place. The UK government's 2010 national security strategy recognised cyber risk as a Tier 4 national security risk and, in 2011, it launched a national cyber security strategy with the objective of making the UK one of the most secure places in the world to live and work online. The EUs 2013 cyber security strategy (‘An Open, Safe and Secure Cyberspace’) has similar objectives.


In 2009, President Obama accepted that cybersecurity was one of the most serious economic and national security challenges faced by the United States, but that neither the government nor the country was ready to counter. In the United States announced a ten-point cyber security plan and, in the US Department of Defence released a Strategy for Operating in Cyberspace', in which it identified cyberspace as another operational theatre.


While organisations that are part of the Critical National Infrastructure (CNI) clearly have a significant role to play in preparing to defend their national cyberspace against cyberattack, all organisations should take appropriate steps to defend themselves from being caught in the digital crossfire.


Advanced persistent threat


The term advanced persistent threat (APT) usually refers to a national government - or state-level entity that has the capacity and the intent to persistently and effectively target - in cyberspace - another entity that it wishes to disrupt or otherwise compromise. While cyberspace is the most common theatre of attack, other vectors include social engineering, infected media and malware and supply chain compromise. Attackers usually have the resources, competence and available time to focus on attacking one or more specific entities.


The Stuxnet worm is an example of one such attack, but there are many others. For most large organisations, the critical consideration is not whether or not they have been targeted (they will have been), but whether or not they have been able to identify and neutralise the intrusion.


 
 
 

Recent Posts

See All

Comments


bottom of page