Published September 8, 2023
Read Time Mins
In this article, our CISO, Paul Jenkins, discusses the 2021-22 breach of the UK’s Electoral Commission’s systems, which he says, “underlines the growing importance of robust cybersecurity measures for public institutions.” It also brings to the forefront several critical issues and lessons, which should be carefully noted – not only by governmental bodies but by any organisation entrusted with sensitive data.
In this incident, which occurred between August 2021 and October 2022, the data of 40 million voters was compromised.
The Cyber Essentials audit, which the Commission failed, was not merely a procedural hurdle but a clear indicator of potential vulnerabilities.
“Ignoring these audits or not taking them seriously jeopardises the integrity and security of the entire system.”
The mention of the failed Cyber Essentials audit by the Commission underscores that audits are not just bureaucratic checkpoints but essential tools that identify potential weaknesses in an organisation’s cybersecurity posture. Neglecting or trivialising audits can have severe repercussions for the overall integrity and security of an organisations information systems.
Tips:
The revelation about the use of outdated software on staff laptops and unsupported iPhones is alarming.
“Such outdated systems can easily become the weakest link, making the entire infrastructure vulnerable to attacks.”
Outdated hardware and software pose a significant risk to an organisations most critical systems and potentially exposes their entire network to potential cyber-attacks. Infrastructure that lacks essential security updates and patches makes an attractive target for malicious actors who are seeking weak points in an organisation’s defences. Addressing and modernising outdated systems is critical to maintaining an effective security posture that minimises the risk of a breach.
Tips:
The fact that unauthorised access persisted for over a year indicates a lack of effective intrusion detection mechanisms.
“The longer a malicious entity has undetected access, the more data they can compromise, and the more they can understand the organisation’s internal structures.”
Tips:
Undetected access by malicious actors over an extended period poses a growing threat. Deep infiltration into an organisation’s systems leads to more extensive data breaches as an attacker gains more understanding of an organisations internal structures and systems, and swift detection and remediation are essential to minimise the damage from compromise.
Downplaying the significance of a breach, especially one of this magnitude, is not just a PR risk but also a massive trust risk.
“Transparency in handling and reporting such incidents is paramount for maintaining public trust.”
Handling data breaches in a transparent and responsible way, particularly in the context of large-scale incidents, is critically important. Downplaying the impact and severity of a breach not only harms an organisation’s reputation but also often irreparably undermines the trust that stakeholders have in its ability to protect their data.
Tips:
The Commission’s decision not to reapply for Cyber Essentials certification in 2022 certainly raises eyebrows.
“While certifications are vital, the commitment to cybersecurity should be continuous and not just based on external validations.”
Certification should not be seen as the only indicator of an organisation’s commitment to cyber security, and indeed, the Commission’s decision not to pursue certification may reflect a shift towards a more comprehensive and internally-driven cyber security approach.
It is essential for organisations to strike a balance between internal cyber security practices and external validation and, while certifications can provide a valuable benchmark and help maintain a strong security posture, cybersecurity is an ongoing and dynamic process that should be a constant and integral part of an organisation’s culture and operations.
Tips:
So, what can we learn from this?
This incident serves as a rallying call to all organisations. As cyber threats evolve, so should our defences.
Adopting a proactive and continuous approach to cybersecurity is not just a necessity; it is an imperative as our world becomes increasingly interconnected.