Sir Paul Grice the Clerk/Chief Executive of the Scottish Parliament has issued an update on yesterday’s Holyrood cyberattack.
While the attack is ongoing, all of the systems within the parliament appear to be fully functional and there’s no evidence the attack has been successful or that defences have been breached.
The statement issued to all members of the Scottish Parliament and staff reads:
Dear colleagues,
As you are aware, our security and monitoring systems yesterday identified that the Parliament had been targeted in a brute force cyber-attack. Various cyber security measures were quickly deployed to combat this and, as a result, we have seen the frequency of failed log-ins and account lockouts decrease.Â
At this point there is no evidence to suggest that the attack has breached our defences and our IT systems continue to be fully operational. Users should be aware, however, that this attack remains ongoing. It is not uncommon for brute force attacks to be sustained over a period of days so it is essential that IT account users are vigilant and report any suspicious issues.
Staff from the BIT Office are working closely with the National Cyber Security Centre (NCSC) and our suppliers to put in place additional security measures to continue to contain the incident and mitigate against any future attacks. In addition analysis is taking place to better understand the origin of the attack and to assess its overall impact.
I am grateful for the ongoing work of BIT staff as we respond to this incident and I am satisfied that our systems have performed well to date. I would also like to thank users across the organisation for their assistance yesterday in strengthening passwords. Advice from the NCSC has reinforced the importance of this measure.
Kind regards
Paul Grice
Clerk/Chief Executive





