- Security TWENTY
- Women in Security
The latest NHS hack has again shown the vulnerability of the public sector to cyber-crime. This is according to Secure Cloudlink, a cloud service provider, who argues that no organisation is immune to a data breach, but the public sector in particular must be endlessly diligent and maintain strict control over their digital information assets, the firm says, due to the highly sensitive nature of the data involved.
Details of thousands of medical staff in Wales were stolen from a private contractor’s computer server. The information included names, dates of birth, radiation doses and National Insurance numbers. A recent Freedom of Information (FoI) request, conducted by Secure Cloudlink, suggested that 64 per cent of London’s councils had experienced a data beach in the last four years.
Dave Worrall, CTO at Secure Cloudlink, said: “There is a mass market for stolen data and the public sector in particular is a vulnerable target. This recent attack is by no means an isolated incident; we demonstrated back in November that the security hygiene of the majority of local authorities in London is not up to scratch. Despite the clear and present danger and with cyber-crime starting to creep higher up on the government’s agenda, the public sector is still failing to fully grasp the scale of the threat right on its doorstep.
“The public sector cannot blindly allow these events to continuously occur and organisations need to be endlessly diligent in their approach to security to alleviate the growing security risks present. No one is immune so all organisations need to understand what is needed to navigate today’s increasingly vulnerable security landscape. Businesses must keep informed of the latest developments in security and train all staff accordingly. This is critical in the public sector, as the risk of not doing so puts not only the organisation in danger, but also individual citizens.
“Instilling a security mind-set throughout an organisation is half the battle. Greater strides also need to be made in managing security processes. Designs that were once suitable have not been updated to keep up with the increasing digital economy of today and because of this, hackers are able to capitalise and steal information much more easily. It’s therefore important to address the threat landscape by working closely with experts in security to adopt new tools and practices that offer the utmost resilience against cyber-crime. This latest hack demonstrates how fallible current solutions are. Technology needs to adapt to an ever-changing industry and the security mind-set needs to be adjusted as well.”