A new report from Big Brother Watch, privacy campaign organisation, has revealed that between 2013 and 2017, UK councils faced nearly 100 million cyberattacks, meaning there were an estimated 37 attempted breaches every minute.
Analysis in the report has shown that one in four UK local authorities have experienced an actual security breach in the past five years, a total of 376 cyber security incidents.
The report suggests that in fact, these numbers do not reflect the true scale of the problem as many councils do not report such incidents to the police. The report revealed that 56% of councils who failed to protect data from cyber security threats did not even report the incidents. As such, the findings are a serious wake-up call to the increasing threat of cybercrime – and the public sector’s inability to deal with it effectively.
Nowadays local authorities store vast amounts of sensitive information about UK citizens, with councils providing 80% of all local public services. A hack of this information and resulting data misuse would have a significant impact on both victims and the public’s trust in these organisations.
With experts predicting that the number of cyberattacks will increase in the near future, this number could become much worse. With the introduction of GDPR in May 2018, the situation may become critical, as council’s find themselves facing huge fines for breaches of the much tighter regulations.
Lack of Cybersecurity Education
Lack of action by local authorities in regards to cybersecurity awareness and education has been blamed for the poor results. 75% of local authorities do not provide mandatory training in cybersecurity awareness for staff and 16% do not provide any training at all.
The 2017 PwC Global CEO survey report found that only 53% of councils in the UK felt they were prepared to deal with cyber attacks and only 35% of council leaders felt confident that their staff had the necessary skills to deal with such threats.
Jennifer Krueckeberg, lead researcher at Big Brother Watch, said: “With councils hit by over 19m cyber attacks every year, one would assume that they would be doing their utmost to protect citizens’ sensitive information.
“We are shocked to discover that the majority of councils’ data breaches go unreported and that staff often lack basic training in cyber security.
“Local authorities need to take urgent action and make sure they fulfil their responsibilities to protect citizens.
“Whether they are council, government or business owned, websites are being constantly bombarded by cyberattacks every single day, and protecting against and responding to attacks is a part of everyday digital life.”
The new report comes after another disappointing recent revelation that showed that 200 NHS Trusts failed basic cybersecurity tests for similar reasons.





