Site navigation

NCSC Warns UK Business to Prepare for Iranian Cyber-attacks

Elizabeth Greenberg

,

iran cyber-attacks
The emerging conflict in the Middle East is likely to spill into the cyber realm, the UK’s cybersecurity centre warns.

The National Cyber Security Centre is uring UK businesses to shore up their cyber defenses due to the continuously destabilising conflict currently rocking the Middle East.

While the NCSC says that the current conflict does not mean there is any current significant change in the direct cyber threat from Iran to the UK, the fast-evolving nature of the conflict may see conditions shift dramatically.

As such, there is a heightened risk of indirect cyber threat for those organisations and entities who have presence, or supply chains, in the Middle East.

Iranian state and Iran-linked cyber actors almost certainly currently maintain at least some capability to conduct cyber activity, the NCSC said.

Iran suffered hundreds of casualties due to bombs launched by the US and Israel. The operation killed Iran’s long-time leader, Ayatollah Ali Khamenei, as well as hundreds of civilians, including children at a girls’ school which was bombed.

Following the attacks, Iran launched retaliatory missiles, including one that hit a hotel in Dubai. Flights in the region have been grounded, delayed, or diverted. Cyprus was also targeted by Iran, marking one of the first times the country directly targeted a European nation with military aggression.

The destabilisation of the region may spill into the cyber realm, as the NCSC’s warning echoes that of Google Threat Intelligence Group’s chief analyst, John Hultquist, who said that Iran will “absolutely” launch cyber-attacks in response to the US and Israeli air strikes.

How Should Organisations Prepare?

Organisations should prepare to respond to the risk of collateral impacts in the UK from Iran-linked hacktivists by reading previously issued advisories on DDoS attacks, phishing activity and ICS Targeting.

For organisations exposed to higher risk, for example with those with offices or supply chains in the region, you should adjust your cyber security posture accordingly. You should take the steps outlined in our actions to take when threat is heightened guidance, and consider proportionate action to increase monitoring and review your external attack surface.

The NCSC continues to encourage UK organisations to sign up to its Early Warning service, to receive timely notifications of security issues affecting their networks.

In addition, given this is an evolving situation, CNI organisations may wish to pre-emptively review the NCSC’s recently published guidance on actions to take now to prepare CNI organisations for severe cyber threat.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data