Site navigation

Comment: Boosting Online Resilience to Cyber-threats

Doug Cunningham

,

streaming services dark web
In a contributed piece for DIGIT, Doug Cunningham, CTO of Forrit, discusses the alarming rise in cyber-attacks and what businesses can do to defend themselves.

Recently, the firm that supplies software to 85% of NHS services fell victim to a massive cyber-attack, bringing its online systems to a grinding halt and leaving pharmacists, hospitals and thousands of people without access to vital services, including NHS 111.

Alarmingly, this was not an isolated incident.

Latest research from Accenture has highlighted how cyber-attacks soared 125% between 2020 to 2021. And, according to new figures published in the government’s Cyber Security Breaches Survey 2022 report, a third (31%) of UK businesses experience a cyber-attack or breach at least once a week.

What is behind the rise in attacks?

Whilst cyber threats have been steadily increasing for years, undoubtedly the pandemic has played a major part in accelerating attacks.

With thousands of physical premises closing from March 2020, most businesses brought forward their digital transformation initiatives to ensure day-to-day operations continued unaffected.

And this undoubtedly led to corners being cut, best practices not being followed, and due diligence – ordinarily completed during normal working conditions – scaled back.

How can businesses shore up their defences?

There is no one-size-fits-all approach to boosting cyber resilience. But there are new and emerging processes and technologies that businesses can employ at an early stage to protect themselves and identify threats.

These include:

  • Using artificial intelligence (AI) and machine learning (ML) tools to enable teams to focus on red-hot areas of concern and not be distracted by “noise”.
  • Ensuring data is secure at all stages, either during a data migration to the cloud or during day-to-day operations, to protect sensitive information including customer details.
  • Website: considering built-in application security from the design and development phases through to deployment and maintenance.
  • Improving identity/access management to ensure users of a company’s systems and associated services follow a ‘least privilege’ approach, giving them restricted access to do their jobs – and nothing more.

Next-generation, cloud-based tools

PaaS (Platform-as-a-Service) and SaaS (Software-as-a-Service) models – based in the cloud and allowing third-party providers to deliver software tools to users over the internet – also provide businesses of all sizes with increased cyber threat protection.

PaaS and SaaS may not be a new IT terms, but both are growing in popularity as businesses see increased value in streamlining their CMS.

PaaS, for example, was worth $3.2 billion in UK revenue in 2021, and according to the Technology Market Outlook, is expected to swell to $5.29bn by 2026.

Microsoft Azure PaaS is one platform that frees up time and expertise by automatically patching, upgrading, and migrating systems. With multiple layers of protection, small businesses can protect themselves as well as larger enterprises.

It also increases a business’s ability to create flexible and integrated systems due to the vast range of tools, services, and policies that can be applied to services configured within the cloud environment.

Azure Sentinel, for example, provides intelligent security analytics at scale across an entire business, making it easier to collect security data from devices to users, and apps to servers on any cloud. It uses the power of AI to ensure businesses are identifying real threats, and helps IT teams focus on responding to those threats.

In practice, these features offer developers and IT teams huge advantages in rapidly dealing with cyber-attacks.

We recently discovered one of our customer’s new websites had been badly compromised without their knowledge and damaging content was displaying on its homepage.

Unable to reach the client by phone due to the time difference – it’s based on the west coast of the USA – we shut the old site down and migrated content quickly to a PaaS-based web application hosting some of the site that was unaffected.


Recommended


Little damage was done, largely because they already had a system in place, primed to deal with the issue rapidly. The ability to identify threats early and react at speed are the keys to boosting cyber resilience.

As companies continue to add layers to already complex, non-integrated systems – including their CMS – the chances of attack increase, and the more attractive cloud-based tools begin to look.

If companies really want to get serious about defending their organisation against attack, everyone from the board down needs to be thinking in ‘cyber’ terms to ensure security is baked into a company’s systems – from development to deployment.

Doug Cunningham

Doug Cunningham

Chief Technology Officer, Forrit

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data