The Scottish Environmental Protection Agency (SEPA) is still feeling the effects of a major 2020 cyber attack, according to a new report.
So far, the agency has been unable to provide evidence of finances through bank statements and HMRC records, according to Audit Scotland.
More than 12 months on from the attack, SEPA is still rebuilding its computer systems after hackers crippled its network. The full financial impact of the incident is still unknown, said the report.
According to the Auditor General for Scotland, Stephen Boyle, the SEPA 2020 cyber attack has meant that accounting records have had to be recreated, leaving auditors unable to fully examine its finances.
Commenting on the attack, Boyle said the incident “highlights how no organisation can fully defend itself against the threat of today’s sophisticated cyber-attacks” and it is “crucial that organisations are as well-prepared as possible”.
He added: “SEPA was in a solid starting position but it will continue to feel the consequences of this attack for a while to come.”
The ransomware attack, which occurred on Christmas eve in 2020, hit critical services across the organisation and was carried out by a highly organised, international cybercrime group.
The week before the attack was announced, SEPA revealed that business continuity arrangements had been enacted and that it was working closely with the Scottish Government and law enforcement to resolve the issue.
Hackers subsequently went on to publish the stolen data online. Supposedly around 4,000 files were circulated on the dark web – a common tactic of cybercriminals.
Since the attack, the organisation has “a number of areas of good practice” the report said, including the agency’s “quick response and business continuity arrangements”, which helped it to continue delivering critical services. The report also praised SEPA for its “open and transparent communication with staff and wider public”.
The report stated that SEPA “recognises that the cyber-attack has increased the medium to longer term financial pressures on the organisation” and that “key systems have been rebuilt, such as SEPA’s financial accounting system, with others being built from new and data recovered or recreated securely, and this will take time”.
Recommended
- Contributed | How to define the scope of an MVP
- Business support comes as 32% of Scots firms face financial fears
- Treasury committee report: Stronger action needed for online fraud
Since the attack, SEPA said it has committed time and funding to reinforcing its systems from scratch, rather than to try and recover the old ones. However, the short-term impact has left the agency reeling.
Audit Scotland reported that since December 2020, it has received “limited financial information” from the agency in which monitor its performance and make decisions as it re-establishes its systems.
Boyle said: “What happened to SEPA could happen to any public sector body. It was well-prepared for a cyber-attack, best practice had been followed and staff had been trained. But, despite all that, SEPA couldn’t fully defend itself against a sophisticated attack.
“A year on, it is still counting the cost. Systems are being rebuilt from scratch and more cyber-security measures are planned, and that’s a lesson for everyone in the public sector.”
Scot-Secure 2022 | Scotland’s Largest Annual Cyber Security Summit
The 8th annual Scot-Secure Summit will take place on 23rd March at Dynamic Earth in Edinburgh, and streamed live through our virtual conference platform.
The programme will focus on promoting best-practice cyber security; looking at the current trends, key threats, and offering practical advice on improving resilience and implementing effective security measures.
For more information, visit www.scot-secure.com.





