Site navigation

‘International Organised Criminals’ Likely Culprits Behind SEPA Cyber-Attack

Ross Kelly

,

SEPA Ransomware Attack
SEPA’s culture of cyber-resilience played a key role in its effective response.

Hackers displayed “significant stealth and malicious sophistication” during a ransomware attack on the Scottish Environment Protection Agency (SEPA), according to a series of audits published today.

Investigations into SEPA’s response to last year’s cyber-attack, which saw more than 4,000 files stolen by hackers, found that the agency responded well to the incident.

An audit conducted by Azets ruled SEPA’s response to the incident was highly effective, with staff dedication playing a key role in preventing further disaster.

“Staff have worked well beyond their normal hours and have demonstrated considerable flexibility, have worked through or given up annual leave, and public holidays,” the Azets audit found.

Meanwhile, Police Scotland noted that the agency boasted a “strong culture of resilience, governance, incident and emergency management” and regularly tested its response capabilities.

This strong focus on resilience meant SEPA was able to maintain key critical services in the wake of the attack.

Detective Inspector Michael McCullagh, Cybercrime Investigations at Police Scotland said SEPA “is not a poorly protected organisation” and showed “real leadership” following the incident.

SEPA ransomware attack

Launched on Christmas Eve, 2020, the SEPA ransomware attack was likely the work of an international organised crime group, according to the Police Scotland investigation.

In the wake of the incident, SEPA refused to respond to a ransom request from the group responsible and emphasised that it would not use public finances to pay organised criminals.

SEPA was hailed for its steadfast response to the attack, and the agency has since restored the majority of its services, which includes critical flood forecasting and its pollution hotline.

Terry A’Hearn, Chief Executive at SEPA, said: “In the face of this awful crime, I am immensely proud of the way our team has coped and responded. We have delivered high-priority services to protect Scotland’s environment and started building all our services up in new and better ways.

“In the end, we will have fast-tracked major reforms we had set out to do anyway. In all this work, as CEO of SEPA, I want to acknowledge and thank the outstanding efforts of our workforce and the assistance we have received from partners and all those we regularly work with.”

A’Hearn insisted that a “key element” of the agency’s recovery was due to the “high level of transparency” in its response. SEPA has been highly vocal since the incident unfolded last year, introducing weekly service updates to inform the public and stakeholders.


Recommended


A separate audit carried out by the Scottish Business Resilience Centre (SBRC) revealed that backups were taken in line with NCSC best practice.

In total, there were three copies of SEPA data located at two separate locations – one of which was stored offline. However, the audit noted that SEPA’s network design meant both sites were affected.

SBRC also found that while staff worked to recover and restore systems, a secondary attempt to compromise the agency’s systems was made.

Jude McCorry, Chief Executive at SBRC, commented: “The fact that SEPA’s cyber maturity assessment was high and sophisticated defence and detection mechanisms were implemented and operating correctly prior to the incident is a reminder to us all how real the risk is.

“For organisations in Scotland today, the question is when, not if you’re organisation will be subject to attack and how well it will respond and recover.”

Lessons learned

Lessons learned from the SEPA ransomware attack could help prevent a similar incident occurring in future. Police Scotland, Azets and SBRC investigations all recommended key actions to be implemented across the public sector.

SBRC and Azets both recommended that SEPA explore options for the creation of a 24-hour Security Operations Centre (SOC) while Police Scotland suggested the wider public sector should consider retaining a Cyber Incident Response (CIR) company to ensure rapid access to necessary expertise.

Additionally, Police Scotland also recommended that the Scottish Government’s Cyber Resilience Unit consider the development of an “Organisational Learning and Development process” across the public sector.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

Click here to subscribe.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data