HomeSecurityWeaknesses in public cybersecurity in the United Kingdom

Weaknesses in public cybersecurity in the United Kingdom

safety

When the UK introduced the Freedom of Information Act, some data and statistics that were state secrets were exposed to the general public. This practically opens the way for anyone to have access to matters concerning the government itself and how it handles various state affairs. It also allows private companies to also request information from the UK government that was considered “security sensitive”, making it a public document that anyone can see.

Recently, a private IT company called SolarWinds requested access to some government information and revealed that there were a large number of cyberattacks on the public sector in the year 2018. 18% of public services fell victim to some form of ransomware, phishing attack and other viruses, especially those interacting with foreign/diplomatic entities. The results of the report also show that the effectiveness of available antimalware products on the market reaches 96% to 98%. Firewall hardware was also at the center of the report, as it was able to successfully prevent unauthorized access in 98% of cases.

Unfortunately, statistics show that the public sector is not able to conduct proper audits after an attack. This is due to the fact that only 73% of the public sector has a reliable log management system in place on its network premises. The same organisations also lack reliable network analytics, which would be useful for authorities’ investigations after a cyberattack. These results highlight the importance of finding easy-to-use, affordable and scalable solutions for additional security, which can operate in different environments, such as those of the NHS and central government, to ensure a more comprehensive protection for these vital services, as stated by Sascha Giese from SolarWind.

As in the rest of Europe, the UK public sector is run and funded by taxpayers. Funding for better internet security is therefore not an easy task. To provide adequate security against cyber risks, the right hardware and software are required to support the infrastructure, as well as staff, IT specialists, developers, etc.

However, what is most worrying is that a significant proportion of the UK public sector has no organised way of training employees to deal with cyber risks. While in other cases they simply leave employees to their own devices, ignoring the risks of new vulnerabilities, exploits and social engineering techniques that may one day affect one of them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS