<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/national-cyber-security-centre-ncsc" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in National-cyber-security-centre-ncsc ]]></title>
                <link>https://www.itpro.com/tag/national-cyber-security-centre</link>
        <description><![CDATA[ All the latest national-cyber-security-centre-ncsc content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 24 Jul 2026 08:23:13 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NCSC issues alert over 'zero-click' phishing campaign hitting enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises</link>
                                                                            <description>
                            <![CDATA[ Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TBMSiPEYprpUySAU2QTRDj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 08:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.</p><p>The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors. </p><p>This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies. </p><p>Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted. </p><p>Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised. </p><p>The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”. </p><p>Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations. </p><p>“This <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.</p><h2 id="ukrainian-organizations-used-in-testing">Ukrainian organizations used in testing </h2><p>According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.</p><p>Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations. </p><p>Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities. </p><p><a href="https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/" target="_blank"><u>Analysis from Rapid7</u></a> found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks. </p><p>More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors. </p><p>“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted. </p><p>Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails. </p><p>“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”</p><p>Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey. </p><p>“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said. </p><p>“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC issues warning over Russian intelligence-backed threat group ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-issues-warning-over-russian-intelligence-backed-threat-group</link>
                                                                            <description>
                            <![CDATA[ The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ecBtbkHCFUTQLq8qjGpdG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 11:25:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:description>                                                            <media:text><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Insignia of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a smartphone screen with blurred blue, green, and orange coloring in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MT5985QZfigcxyG6ydBAiR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has urged UK organizations to remain vigilant for attacks waged by Russian state-backed hackers. </p><p>As part of an advisory published in collaboration with 18 other agencies, the cybersecurity center specifically highlighted techniques employed by Russian FSB’s Centre 16 threat actors. </p><p>The group has been “opportunistically” targeting vulnerable routers and critical national infrastructure globally in recent months, the advisory warns. </p><p>Centre 16 goes by a number of names, including Berserk Bear, Static Tundra, and Ghost Blizzard, according to the NCSC. The group primarily uses SNMP (Simple Network Management Protocol) scans to locate and compromise vulnerable routers. </p><p>The group has also been observed <a href="https://www.itpro.com/security/cyber-attacks/cisco-asa-customers-urged-to-take-immediate-action-as-ncsc-cisa-issue-critical-vulnerability-warnings">exploiting vulnerabilities in Cisco devices</a>, web portal flaws, and vulnerabilities in Cisco’s Smart Install (SMI) feature to seize network devices.</p><p>The advisory comes as the UK government implements sanctions against 24 individuals and entities behind “destructive cyber and hybrid operations” which have employed criminal groups via proxy networks. </p><p>Jonathon Ellison, NCSC Director of National Resilience, said these activities require organizations to remain in a heightened state of vigilance moving forward. </p><p>“The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter,” he said.</p><p>“Today’s joint advisory provides decisive, actionable directions from the global security community that network defenders should implement to protect against Russian Intelligence operations and secure the UK’s critical infrastructure.”</p><h2 id="russian-hackers-targeting-key-sectors">Russian hackers targeting key sectors</h2><p>Organizations across a host of sectors worldwide are at risk from the group, according to the advisory. </p><p>Those operating in the communications, energy, healthcare, defense, and financial services industries in particular are firmly in Centre 16’s crosshairs. </p><p>The security agency urged organizations in these domains to take action immediately. This includes disabling the use of legacy SNMP versions and switching to SNMPv3 to lower their risk of compromise.</p><p>Similarly, organizations are advised to implement “strong and unique passwords for network devices, and restrict access to management protocols”. </p><h2 id="call-to-action">Call to action</h2><p>In addition to basic defensive measures, the NCSC also encouraged at-risk organizations to obtain <a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank"><u>Cyber Essentials</u></a> certification. </p><p>This is a government-backed initiative for organisations to show they meet the recognized minimum standards for cybersecurity. </p><p>Organizations can also make use of the <a href="https://www.ncsc.gov.uk/collection/cyber-assessment-framework" target="_blank"><u>Cyber Assessment Framework</u></a>, allowing them to audit their security capabilities, operational maturity, and bolster cyber resilience techniques.</p><p>“I’d strongly encourage all organisations, especially those entrusted with UK critical networks, to adopt these recommended measures immediately, thereby reducing the risk of compromise,” Ellison commented. </p><h2 id="repeated-warnings">Repeated warnings</h2><p>This isn’t the first warning issued by the NCSC over Centre 26 activities in recent years. The security agency, alongside international counterparts, attributed the December 2025 attack on Poland’s energy grid to the unit. </p><p>Various subunits and techniques employed by Centre 16 have also been exposed over the last three years.  The security agency called out a Centre 16 unit known as ‘Turla’ in 2023 over the deployment of Snake malware, for example. </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>strain has been a key component of Russian-backed espionage campaigns for nearly two decades, the NCSC said at the time. </p><p>A similar advisory that year also shed light on a group known as Star Blizzard. The NCSC said this particular subunit of Centre 16 was actively interfering in UK politics and democratic processes. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/uks-cyber-resilience-pledge-gathers-momentum-as-60-firms-sign-up-to-bolster-capabilities</link>
                                                                            <description>
                            <![CDATA[ The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">85jHtazzwahdKRi23Ynkk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 09:41:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:description>                                                            <media:text><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:text>
                                <media:title type="plain"><![CDATA[UK tech map with Great Britain and Northern Ireland pictured on a screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8Y8QhNNiBqk9AccuYbNHH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government said more than 60 businesses have signed up for its Cyber Resilience Pledge so far, including <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">M&S</a>, Nationwide, ITV, Microsoft UK, and Cloudflare.</p><p><a href="https://www.itpro.com/security/uk-government-calls-on-firms-to-sign-cyber-resilience-pledge-as-security-sector-booms"><u>Announced in May</u></a>, the voluntary scheme sees businesses committing to three concrete actions to improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>capabilities.</p><p>They must commit to making cyber security a board-level responsibility, by implementing the Cyber Governance Code of Practice and ensuring all board members complete the NCSC’s Cyber Governance Training.</p><p>They must also register for the NCSC’s free Early Warning service, a tool that alerts organizations to potentially suspicious activity on their networks, and commit to taking a risk-based approach to requiring the government-backed Cyber Essentials certification across their supply chain. </p><p>The pledge has been designed primarily for medium and large organizations, with other signatories including Deloitte, Accenture UK, Vodafone Group, and VodafoneThree, but is open to businesses of all sizes and from all sectors.</p><p>"Today, some of Britain’s biggest businesses are taking action to strengthen their cyber defences and setting a powerful example for others to follow. By signing this pledge, they are showing that cyber resilience is no longer just an IT issue - it is a business imperative," said technology secretary Liz Kendall.</p><p>"The steps in this pledge are practical, achievable and proven to make a difference. Today’s signatories are leading the way, and I encourage organizations across the UK to follow their example."</p><h2 id="cyber-charter-to-beef-up-critical-services">Cyber Charter to beef up critical services</h2><p>Alongside the pledge, the government has been developing a Cyber Charter for 39 companies designated as strategic suppliers for delivering critical services to the government. </p><p>These organizations have been invited to sign the pledge as an initial commitment to bolstering their cyber resilience, although so far only a little more than half have done so.</p><p>"We have long held the view that cyber resilience is a critical business and organizational enabler. It underpins our growth, our economic security, and the safety and security of our people," said Julian David, CEO of techUK. </p><p>"With the average cost of significant cyber-attacks to the UK economy recently estimated to be £14.7 billion annually – the equivalent of 0.5% of our GDP – it’s clear that cyber security and resilience must be recognised as a leadership responsibility and should no longer be viewed as an IT issue alone."</p><h2 id="pledge-targets-national-resilience">Pledge targets national resilience</h2><p>Moves to bolster national resilience capabilities come amidst an increase in malicious cyber activity in the UK. </p><p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> recently confirmed it handled 204 nationally significant incidents in the year to September, up from 89 the year before. </p><p>The average cost of an attack on an individual UK business now stands at almost £195,000, with the annual cost to organizations estimated at £14.7 billion - and that’s in addition to the costs of wider economic disruption. </p><p>Last year, experts estimated that the attack on <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre"><u>Jaguar Land Rover (JLR) cost the UK economy roughly £1.9 billion</u></a>, making it the most costly cyber incident in British history. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hostile states behind three-quarters of UK critical infrastructure attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hostile-states-behind-three-quarters-of-uk-critical-infrastructure-attacks</link>
                                                                            <description>
                            <![CDATA[ NCSC CEO warns that with the rise of AI, the danger is only set to get worse ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q5cNNxjBujgjgEiQ8ucRod</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 11:55:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:description>                                                            <media:text><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:text>
                                <media:title type="plain"><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The overwhelming majority of cyber attacks on critical infrastructure are coming from hostile states, the UK's cyber chief has warned.</p><p>Speaking at the Royal United Services Institute's (RUSI) Annual Security Lecture, Richard Horne, CEO of the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre </a>(NCSC), said the organization had handled more than 200 cyber incidents affecting the UK's critical national infrastructure and its supporting ecosystem over the last year. Around 75% were believed to be linked to state actors, particularly Russia, China, and Iran. </p><p>"We know that adversaries are prepositioning today, establishing footholds within technology that underpins critical national infrastructure that could enable rapid exploitation, to cause mass disruption in a time of conflict," he said.</p><p>"The highest profile example of this was a campaign often referred to as <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid">Volt Typhoon</a> against largely US critical national infrastructure, which was attributed in 2024. And we are seeing our critical infrastructure being targeted, regularly finding and stopping breaches, before their intent becomes clear."</p><p>Horne broke the threat down into 'near', 'mid,' and 'far' spaces, with the far space representing the adversary's home turf, systems, tooling, and networks. Here, he said, the UK and its allies bring pressure to bear through intelligence collection, sanctions, law enforcement action , and offensive cyber operations to disrupt and degrade their capability at source.</p><p>In the mid space, efforts are concentrated on hardening cloud, technology, and telecommunications infrastructure, and by disrupting adversary positions within those environments.</p><p>"The reality is much of this space is in private hands," he said. "Which means success here demands genuine collaboration between government and private sector, which is at the heart of our approach in the NCSC."</p><p>But, he said, it's the near space – the defense and resilience of the organizations and systems being targeted – where most action is probably required. <a href="https://www.itpro.com/technology/artificial-intelligence-ai/358279/why-it-professionals-are-concerned-about-the-rise-of">The rise of AI</a> is an important factor here, he said.</p><p>"Recent developments of frontier AI models have demonstrated their effectiveness at finding inherent vulnerabilities in the technology we rely on," he said.</p><p>"Our latest assessment shows that by 2028, it is highly likely that AI-Cyber capabilities will be used by attackers against known vulnerabilities in legacy technology in our critical national infrastructure."</p><p>British organizations should take note, said James Neilson, SVP of global at OPSWAT.</p><p>"The daily scale of hostile activity against the UK is vast, and until the NCSC revealed those figures, the threat and danger facing critical infrastructure was far greater than most businesses realized," he said. </p><p>"Many organizations neglect to secure data that moves in and out of their OT networks. By controlling data flows and scanning files in transit, organizations can detect and neutralise hidden malicious payloads before they infiltrate critical systems."</p><p>Horne called on organizations to strengthen cyber resilience by focusing on three core capabilities: understanding their exposure to threats, building stronger defences based on proven security fundamentals, and ensuring they can continue operating and recover quickly after an attack.</p><p>"By making our environment harder for adversaries to operate in, and engaging in the contest better, we can play an important part in altering potential adversaries' options and deterring conflict," he said.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC urges organizations to shore up supply chain security practices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-urges-organizations-to-shore-up-supply-chain-security-practices</link>
                                                                            <description>
                            <![CDATA[ With attackers increasingly compromising open source packages to spread malware, organizations need to be on their guard ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4yLzX53j8ACVTzWTEUk9LP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jun 2026 11:27:36 +0000</pubDate>                                                                                                                                <updated>Fri, 05 Jun 2026 11:27:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has urged organizations to review their dependencies in light of an increasing number of supply chain attacks.</p><p>Recent attacks, the agency noted, have included <a href="https://www.itpro.com/security/cyber-attacks/the-build-pipeline-is-becoming-the-new-frontline-axios-npm-compromise-highlights-growing-software-supply-chain-risks-experts-warn">maintainer account compromise</a>, where attackers steal credentials or tokens that allow a malicious actor to update a trusted package. </p><p>Attackers are also taking over ownership of expired domains connected to package maintainers, or otherwise transferring ownership of a previously legitimate package.</p><p>Meanwhile, typosquatting is on the rise, with packages published using similar names to the genuine article, or with the misspelling of popular legitimate packages in the hope they are installed by mistake. </p><p>Threat actors are also using credentials or tokens stolen from a previous attack to access or modify additional packages.</p><p>These risks arise because one single application may rely on a large number of third-party packages – including libraries, frameworks, snippets, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-agentic-ai-development-tools">software development kits</a> - some of which may not be entirely trustworthy. </p><p>Node.js, Rust and Python, for example, are unusually exposed as they have minimal standard libraries, boosting the use of third-party dependencies and delegation of basic functionalities, and leading to a heavy reliance on external registries. </p><p>Many of these components are retrieved automatically through <a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">continuous integration and continuous delivery (CI/CD)</a> pipelines, often without human intervention. </p><p>"It is this combination of automation, trust and scale which means that malicious code introduced into a single package can spread rapidly across many organisations and services before detection," the NCSC warned.</p><p>The NCSC warned that threat groups are actively targeting developer environments, which are usually less tightly controlled than managed corporate devices, making it easier to compromise and steal the credentials of shared code or package registries. </p><p>A single malicious package can spread quickly across downstream software products and services. Indeed, the impact of compromising a lesser known, but critical, software component can have a significant and far-reaching impact for many organizations and systems. </p><p>The NCSC highlighted Node.js in particular, as its highly modular packages depend on many smaller components.</p><h2 id="ci-cd-threats-are-rising">CI/CD threats are rising</h2><p>Meanwhile, recent attacks have exploited the implicit trust in CI/CD and automation pipelines, where the automation of updates, installation, and execution of scripts and packages allows attackers to execute malicious code. </p><p>"For example, Node.js and Python support scripts that execute on installation, and allow a malicious package to be run immediately. Without human intervention or approval, the code can simply propagate," the NCSC warned.</p><p>Open publishing models increase exposure, with security controls for maintainer registry accounts not currently enforced by all registry providers.</p><h2 id="check-your-dependencies">Check your dependencies</h2><p>The NCSC outlined a series of actions organizations are advised to take, including:</p><ul><li>Pause automatic dependency updates where compromise may be present</li><li>Review and approve new updates, dependencies, or versions manually</li><li>Rotate exposed or potentially exposed credentials</li><li>Enforce MFA for developer and package registry accounts</li><li>Use private or trusted registries where appropriate</li></ul><p>"These attacks highlight the need to revisit how dependencies are introduced and managed, as part of a secure development lifecycle (SDLC)," the NCSC said. </p><p>"Whilst Node.js, Python and Rust are considered higher risk for these attacks, it’s important to be aware that other languages, tools, and package repositories are also at risk."</p><p>Developers should also make use of the Software Security Code of Practice, reviewing how dependencies are introduced and updated, avoiding automatically adopting new dependency versions without review, and striking a balance between deploying patches quickly and updating dependencies slowly. </p><p>This will help minimize the potential impact of compromise, according to the NCSC.</p><p>Elsewhere, they should also ensure deployments occur through controlled CI/CD pipelines rather than developer devices and store sensitive credentials securely, avoiding exposure on developer workstations.</p><p>"Modern software development has transformed how software is created, shared and reused – but recent attacks on these tools highlight the rapidly growing risks of using modern software ecosystems," the NCSC said.</p><p>"Whilst Node.js, Python and Rust are considered higher risk for these attacks, it’s important to be aware that other languages, tools, and package repositories are also at risk."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/a-perfect-storm-ncsc-chief-issues-warning-over-quantum-threats-nation-state-hackers-and-the-dangers-of-global-hacktivism</link>
                                                                            <description>
                            <![CDATA[ NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jkUTJkTdCc6AQEQJN3uNAB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u6Lpwu2Ps7tF8A9vNo4Q5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 12:25:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u6Lpwu2Ps7tF8A9vNo4Q5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dr Richard Horne, CEO of the UK&#039;s National Cyber Security Centre (NCSC) speaking on stage at the CyberUK conference in Glasgow, Scotland.]]></media:description>                                                            <media:text><![CDATA[Dr Richard Horne, CEO of the UK&#039;s National Cyber Security Centre (NCSC) speaking on stage at the CyberUK conference in Glasgow, Scotland.]]></media:text>
                                <media:title type="plain"><![CDATA[Dr Richard Horne, CEO of the UK&#039;s National Cyber Security Centre (NCSC) speaking on stage at the CyberUK conference in Glasgow, Scotland.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u6Lpwu2Ps7tF8A9vNo4Q5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Iran, Russia, China and other nation states represent the most serious cybersecurity threats to the UK today, according to Richard Horne, the CEO of the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>.</p><p>Speaking at the CyberUK conference in Glasgow, Horne said that technological change and geopolitical tensions make for 'tumultuous uncertainty', with the agency already handling  an average of four nationally significant incidents a week.  </p><p>"Criminal activity such as ransomware remains the most prevalent threat to the vast majority of organizations, but the majority of the nationally significant incidents that my teams are handling now originate directly or indirectly from nation states," he said.</p><p>Horne warned that China’s intelligence and military agencies in particular now display an 'eye-watering' level of sophistication in their cyber operations, while Iran is almost certainly using cyber activity to support the repression of British individuals. </p><p>Russia, meanwhile, is using the tactics and techniques that it's honed in conflict against states it considers hostile, making cyber security the new 'home front'.</p><p>"We know that, were we to be in, or near, a conflict situation, the UK would likely face hacktivist attacks at scale. With similar effects and sophistication to the ransomware attacks we see today but no option to pay a ransom to help recover," he said.</p><p>These threats are combining with others to create a 'perfect storm', with frontier AI capabilities now rapidly enabling discovery and exploitation of existing vulnerabilities at scale. </p><p>Attackers are exposing gaps in the fundamentals of cybersecurity, such as code shipped by tech producers with significant vulnerabilities, organizations' failure to patch with the completeness or urgency they should, and a failure to <a href="https://www.itpro.com/business/digital-transformation/banks-are-persisting-with-the-patch-and-upgrade-approach-to-legacy-systems-and-its-swallowing-up-it-budgets">replace legacy systems</a>.</p><h2 id="ncsc-sounds-alarm-on-quantum-threats">NCSC sounds alarm on quantum threats</h2><p>Meanwhile, quantum is a looming threat, Horne told attendees. The warning comes amid rising concerns about ‘Q-Day’, the point at which quantum computers can crack traditional encryption methods. </p><p>Google, for example, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready">recently revised its timeline for this tipping point</a> to within just three years. Predictions on this front vary wildly, however, ranging from within a few years to decades. </p><p>"We don’t know when a quantum computer will be able to break the widely used cryptography that we rely on in everything we do. But we do know it is in our gift to be ready for that point," he said.</p><p>He advised organizations to <a href="https://www.itpro.com/business/get-started-on-post-quantum-encryption-organizations-warned">refer to NCSC guidance</a> setting out what they need to do over the coming years to ensure successful migration to post-quantum cryptography.</p><p>More broadly, as the technology landscape develops the definition of cybersecurity expands with it. Efforts to shore up protections across a wider array of areas are being made globally, such as in <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">operational technology (OT)</a>, typically used to control energy systems and production lines – both key targets for state-backed threat groups and <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivists</a>. </p><p>Ric Derbyshire, principal security researcher at Orange Cyberdefense, echoed Horne's concerns about politically-motivated hacktivist groups. </p><p>"Escalatory hacktivism is a phenomenon we are seeing in which groups align with state-backed narratives and contribute to their host state’s hybrid warfare efforts. This trend is set to become more pervasive and more impactful," he said.</p><p>"This is about societal resilience as much as cyber resilience. It will require stronger global collaboration, closer public-private coordination, and sustained legislative action, such as the <a href="https://www.itpro.com/business/policy-and-legislation/cyber-security-and-resilience-bill-security-experts-question-practicality-scope-of-new-legislation">Cyber Security and Resilience Bill</a>, with a focus on protecting critical services and maintaining continuity in the face of disruption.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC says it’s time to switch to passkeys ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-says-its-time-to-switch-to-passkeys</link>
                                                                            <description>
                            <![CDATA[ UK security organization calls for companies to step up and offer more secure ways to login ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jaYhRKhMTS3hbYHkehkCrY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 11:21:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:description>                                                            <media:text><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:text>
                                <media:title type="plain"><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's time to finally kill off passwords in favour of passkeys – and companies need to start offering them to login. </p><p>That's according to the UK's National Cyber Security Centre (NCSC), which is now advising consumers to use passkeys where available because they offer "stronger resilience" to cyber attacks and are easier to use. </p><p>Passkeys tie credentials to a specific device, including a smartphone or laptop, removing the need for text messages or email verification codes. </p><p>The NCSC sees this as more secure as hackers would need to intercept the code or steal the device itself for access. In a <a href="https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services" target="_blank"><u>blog post</u></a>, the security agency said this makes passkeys "phishing-resistant" by design. </p><p>While the NCSC has long persisted with passwords as its official preference, <a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc"><u>last year it began recommending</u></a> users switch to passkeys or a password manager. </p><p>In a statement, the NCSC said it had stopped short of fully endorsing passkeys due to "some key implementation challenges", but pointed to progress within the industry. </p><p>Indeed, the <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>shift to passkeys</u></a> is well underway. As the agency noted, passkeys are widely supported and half of Google users in the UK have one set up.</p><p>"Adopting passkeys wherever you can is a strong step towards a safer, simpler login experience and I am pleased that we can now support uptake," said Jonathon Ellison, Director for National Resilience at the NCSC. </p><p>"The headaches that remembering passwords have caused us for decades no longer need to be a part of logging in where users migrate to passkeys – they are a user-friendly alternative which provide stronger overall resilience."</p><p>The NCSC said beyond better security and lower costs for companies, passkeys save a minute per login versus a username, password, and text verification code. </p><h2 id="industry-push-needed-for-passkeys">Industry push needed for passkeys</h2><p>Of course, for that shift to happen, organizations need to step up and ditch passwords and SMS verification with passkeys. </p><p>“We strongly advise all organizations to implement passkeys wherever possible to enhance security, provide users with faster, frictionless logins and to save significant costs on SMS authentication," NCSC Chief Technical Officer Ollie Whitehouse said.</p><p>The government is hoping to achieve this later in the year across its own digital services. The NHS was one of the first government organizations in the world to offer passkeys for logins.</p><p>“The rollout of passkeys across GOV.UK services marks another major step forward in strengthening the UK’s digital defences while improving the user experience for millions," said AI and Digital Government Minister Feryal Clark.</p><h2 id="why-passkeys">Why passkeys?</h2><p>Passkeys are framed as a key weapon in the fight against phishing attacks. Beyond being more resistant to these attempts, it will also help reduce the number of texts users have to wade through. </p><p>This has become a major problem, and one exacerbated by the rise of <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platforms like <a href="https://www.itpro.com/security/cyber-crime/tycoon-2fa-phishing-risk-takedown-barracuda">Tycoon 2FA</a>, as well as the rise of <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026">AI-generated phishing campaigns</a>. </p><p>To help with passkey rollout, the NCSC has joined forces with the FIDO Alliance, which is working towards password-free authentication. </p><p>“We’re also very pleased that the NCSC has joined the FIDO Alliance, which allows agencies across the UK government to collaborate with other thought leaders in the Alliance to advance the development and deployment of foundational technologies that will strengthen our collective cyber resilience," said Executive Director and CEO of the FIDO Alliance Andrew Shikiar.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC issues alert over Russian hacker campaign targeting SOHO routers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-issues-alert-over-russian-hacker-campaign-targeting-soho-routers</link>
                                                                            <description>
                            <![CDATA[ The APT28 group has exploited vulnerable internet routers to covertly reroute internet traffic through malicious servers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zMzke9FPNtPBx5CW9Pdyrb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Apr 2026 09:46:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has uncovered two new Russian-linked campaigns aimed at harvesting login credentials from personal web and email services.</p><p>The APT28 group, also known as Fancy Bear or Forest Blizzard, has exploited vulnerable internet routers to enable Domain Name System (DNS) hijacking - allowing it to intercept traffic and steal sensitive data including passwords and access tokens.</p><p>In an <a href="https://www.ncsc.gov.uk/sites/default/files/2026-04/NCSC_APT28-exploit-routers-to-enable-DNS-hijacking-operations.pdf" target="_blank"><u>advisory </u></a>on 7 April, the security agency said the activity appears to be opportunistic in nature, starting with a scattergun approach to reach large numbers of potential victims. Thereafter, threat actors then narrow in on targets of interest as the attack develops.</p><p>Attackers redirect traffic through DNS servers under their control, with the resulting malicious DNS resolutions enabling <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AitM)</a> attacks that harvest passwords, OAuth tokens, and other credentials for web and email related services.</p><p>The NCSC said it believes APT28 is almost certainly the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Centre Military Intelligence Unit 26165.</p><p>This group is believed to have been behind an attack against the German parliament in 2015, which led to data theft and disrupted the email accounts of German members of parliament and the vice chancellor, as well as an attempted attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) in 2018. </p><p>That particular attack was aimed at disrupting the independent analysis of chemicals weaponized by the GRU in the UK.</p><h2 id="microsoft-issues-separate-alert">Microsoft issues separate alert</h2><p>In a <a href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/"><u>separate alert</u></a>, Microsoft has issued a similar warning, saying that the group has been carrying out this activity since at least August 2025.</p><p>"By compromising edge devices that are upstream of larger targets, threat actors can take advantage of less closely monitored or managed assets to pivot into enterprise environments," it said. </p><p>"Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard’s malicious DNS infrastructure."</p><h2 id="soho-routers-targeted-in-campaign">SOHO routers targeted in campaign</h2><p>The first cluster of activity identified by the NCSC saw the DHCP DNS server settings of compromised small office/home office (SOHO) routers modified to include IP addresses owned by the attackers. </p><p>These settings were subsequently inherited by downstream devices such as laptops and phones.</p><p>Lookups for domain names containing key terms associated with particular services - frequently email applications or login pages - would be resolved by the malicious DNS servers to further IP addresses controlled by the group. </p><p>DNS requests that don't match the actor’s targeting criteria would instead be resolved to the legitimate IP addresses for the services being requested.</p><p>The group would then attempt to conduct AitM attacks against both user browser sessions and desktop applications, aiming to harvest user account credentials.</p><p>In the second cluster of activity, some servers received DNS requests via compromised devices including models of MikroTik and <a href="https://www.itpro.com/security/tp-link-hits-back-at-us-ban-proposals">TP-Link routers</a>. The DNS requests were forwarded from these servers to other servers under the group's control, the NCSC noted.</p><p>This cluster of infrastructure was also involved in interactive operations against a small number of MikroTik routers, mostly located in Ukraine, and probably of intelligence value to the actor.</p><p>"This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors," said Paul Chichester, NCSC director of operations.</p><p>"We strongly encourage organizations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice."</p><p>The NCSC advises organizations to protect the management interfaces of their systems, keep devices, networks, and software up to date, set up a security monitoring capability, and add applications to an allowlist.</p><p>They should also deploy a host-based intrusion detection system and use <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/ncsc-names-and-shames-pro-russia-hacktivist-group-amid-escalating-ddos-attacks-on-uk-public-services</link>
                                                                            <description>
                            <![CDATA[ Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jqeUd8AcbExEp3jjXdxNS4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jan 2026 10:55:05 +0000</pubDate>                                                                                                                                <updated>Tue, 20 Jan 2026 10:55:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Pro-Russia hacktivists</a> are targeting local government and critical infrastructure in the UK, the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has warned.</p><p>In an advisory this week, the security agency issued an alert over increased <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a> by state-aligned groups. These attacks are driven by ideology over Western support for Ukraine, rather than financial gain, and aren't directly controlled by the state.  </p><p>"We continue to see Russian-aligned hacktivist groups targeting UK organizations, and although denial-of-service attacks may be technically simple, their impact can be significant," said NCSC director of national resilience Jonathon Ellison. </p><div class="product"><a data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>“By overwhelming important websites and online systems, these attacks can prevent people from accessing the essential services they depend on every day."</p><p>In particular, the NCSC cites the NoName057(16) group, active since March 2022, and operating mainly through Telegram channels. It uses GitHub, along with other websites and repositories, to host the proprietary DDoS tool, DDoSia, and to share tactics, techniques, and procedures (TTPs) with its followers.</p><p>NoName057(16) has carried out numerous attacks against government bodies and the private sector in countries perceived as hostile to Russian geopolitical interests, including frequent DDoS attempts against UK local authorities.</p><p>“NoName057(16) consistently targets organisations where availability is closely tied to public trust, particularly local government websites, civic services, and other public-facing infrastructure," said Christiaan Beek, senior director of threat intelligence and analytics at Rapid7.</p><p>"While the group presents itself as a grassroots hacktivist collective, the timing of its campaigns and the close alignment of its targeting with Russian geopolitical objectives mean we cannot rule out some level of state encouragement, coordination, or tacit approval."</p><h2 id="russian-hacktivists-are-an-ever-present-threat">Russian hacktivists are an ever-present threat</h2><p>Russian hacktivism isn't a new problem. In 2023, the NCSC published an alert on the risk posed by state-aligned adversaries following the Russian invasion of Ukraine. </p><p>In December, alongside international partners, it co-sealed an advisory which called out pro-Russian hacktivist groups for targeting government and private sector entities.  </p><p>The NCSC <a href="https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations&site=ncsc" target="_blank"><u>advises</u></a> organizations to take preventative action – with the first steps being to discover weak points and look for help from upstream service providers. </p><p>To deal with attacks which can’t be handled upstream – or only once detected and blocked – they should make sure their service can rapidly scale.</p><p>Similarly, the agency said organizations should define a response plan, covering graceful degradation of services, dealing with changing tactics, retaining administrative access during an attack and having a scalable fallback plan for essential services. </p><p>Gary Barlet, public sector CTO at Illumio, welcomed the focus on mitigation as well as prevention.</p><p>"We need a new way of dealing with DoS attacks. For too long, we have focused solely on prevention, and this approach has not worked," he said.</p><p>"The NCSC’s advice signals a change by recommending that plans include retaining administrative access and implementing full-scale backup plans. However, there needs to be an entire mindset shift within critical infrastructure organizations to focus on prioritizing impact mitigation and maintaining service and operational uptime.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK government launches industry 'ambassadors' scheme to champion software security improvements ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/uk-software-security-ambassadors-ncsc-code-of-practice</link>
                                                                            <description>
                            <![CDATA[ The Software Security Ambassadors scheme aims to boost software supply chains by helping organizations implement the Software Security Code of Practice. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hhoFwaLxMzvGZkMHzAcDMd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ZT5mU7YeSN7Bg7YHh2LxX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Jan 2026 10:47:23 +0000</pubDate>                                                                                                                                <updated>Mon, 19 Jan 2026 10:47:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ZT5mU7YeSN7Bg7YHh2LxX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female software developer coding in dark room with screen reflecting on glasses.]]></media:description>                                                            <media:text><![CDATA[Female software developer coding in dark room with screen reflecting on glasses.]]></media:text>
                                <media:title type="plain"><![CDATA[Female software developer coding in dark room with screen reflecting on glasses.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ZT5mU7YeSN7Bg7YHh2LxX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has launched a new scheme to boost adoption of the <a href="https://www.gov.uk/government/publications/software-security-code-of-practice" target="_blank"><em>Software Security Code of Practice</em></a> by appointing a series of industry champions. </p><p>Under the plans, a cohort of ‘Software Security Ambassadors’ will promote the code of practice across various different sectors, showcasing examples of practical implementation and giving feedback to inform future policy improvements.</p><p>The first batch of participating organizations includes the Department for Science, Innovation, and Technology (DSIT) itself, along with the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>. </p><div class="product"><a data-dimension112="09d3756b-f11b-4f40-b164-50861fe20284" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="09d3756b-f11b-4f40-b164-50861fe20284" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="09d3756b-f11b-4f40-b164-50861fe20284" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>Accenture, <a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco</a>, ISACA, Lloyds Banking Group, Sage, Palo Alto Networks, and others have also backed the scheme. </p><p>"By acting as ambassadors, signatories are committing to a process of transparency, development and continuous improvement. The implementation of this code of practice will take time and, in doing so, may bring to light issues that need to be addressed," DSIT said in a statement confirming the announcement. </p><p>"Signatories and policymakers will learn from these issues as well as the successes and challenges for each organization and, where appropriate, will share information to help develop and strengthen this government policy."  </p><h2 id="what-is-the-software-security-code-of-practice">What is the Software Security Code of Practice?</h2><p>The Software Security Code of Practice was <a href="https://www.itpro.com/software/software-security-code-of-practice-ncsc-announcement"><u>unveiled by the NCSC</u></a> in May last year, setting out a series of voluntary principles defining what good <a href="https://www.itpro.com/software/software-security-flaws-remediation">software security</a> looks like across the entire <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">software lifecycle</a>. </p><p>Aimed at technology providers and organizations that develop, sell, or procure software, the code offers best practices for secure design and development, build-environment security, and secure deployment and maintenance.</p><p>The code also emphasizes the importance of transparent communication with customers on potential security risks and vulnerabilities. </p><p>Developed with the NCSC, the code is designed to reflect internationally recognized best practices, such as the US Secure Software Development Framework (SSDF) and the EU’s <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">Cyber Resilience Act (CRA)</a>.</p><h2 id="software-security-in-the-spotlight">Software security in the spotlight</h2><p>The launch of the code came in direct response to growing concerns surrounding software security on both sides of the Atlantic. In the US, for example, the <em>Secure by Design Pledge</em> was <a href="https://www.itpro.com/software/software-vendors-are-flocking-to-cisas-secure-by-design-pledge"><u>launched by CISA in 2023</u></a>. </p><p>This voluntary scheme asks software developers and providers to place a stronger emphasis on product security. </p><p>According to figures from the DSIT, more than half (59%) of organizations experienced <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">software supply chain attacks</a> in the past year, underlining the growing risks faced by UK enterprises and consumers alike. </p><p>In a separate <a href="https://www.isc2.org/Insights/2025/11/2025-isc2-supply-chain-risk-survey" target="_blank">survey from ISC2</a>, more than half of respondents identified software vulnerabilities in supplier products as the most disruptive <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threat to their organisation’s supply chain.</p><p>ISC2 said it plans to help drive adoption of the code by promoting awareness through educational and thought leadership content, and referencing it in relation to certifications, training, and guidance that support secure software development.</p><p>It will also work with organizations across the software supply chain to encourage practical implementation and require its own partners to incorporate it.</p><p>“Promoting secure software practices that strengthen the resilience of systems underpinning the economy, public services and national infrastructure is central to ISC2’s mission,” said Tara Wisniewski. ISC2 EVP for advocacy and strategic engagement. </p><p>“The code moves software security beyond narrow compliance and elevates it to a board-level resilience priority. As supply chain attacks continue to grow in scale and impact, a shared baseline is essential and through our global community and expertise, ISC2 is committed to helping professionals build the skills needed to put secure-by-design principles into practice.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC touts honeypots and ‘cyber deception’ tactics as the key to combating hackers — but they could ‘lead to a false sense of security’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-touts-honeypots-and-cyber-deception-tactics-as-the-key-to-combating-hackers-but-they-could-lead-to-a-false-sense-of-security</link>
                                                                            <description>
                            <![CDATA[ Trials to test the real-world effectiveness of cyber deception solutions have produced positive results so far ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AJVXYsVaQTvRxuHhuK2NXN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kXhTUASnqmZC3EaLXqGUyb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Dec 2025 11:45:49 +0000</pubDate>                                                                                                                                <updated>Mon, 15 Dec 2025 11:46:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kXhTUASnqmZC3EaLXqGUyb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female cybersecurity workers using AI tools on a desktop computer in a dimly-lit office space.]]></media:description>                                                            <media:text><![CDATA[Male and female cybersecurity workers using AI tools on a desktop computer in a dimly-lit office space.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female cybersecurity workers using AI tools on a desktop computer in a dimly-lit office space.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kXhTUASnqmZC3EaLXqGUyb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/20178/sweet-smell-it-security-understanding-honeypots">Honeypots </a>and cyber detection tools can be highly effective at disrupting cyber attacks, according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, but enterprises should prepare for serious risks.</p><p>Over the last year, the <a href="https://www.itpro.com/security/the-ncsc-wants-to-know-how-your-business-is-using-honeypots-to-combat-hackers">NCSC has run a series of cyber deception trials</a>, speaking to users, and analyzing the results to try and work out whether such tactics can increase observability, improve <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">threat hunting</a>, and even influence how attackers behave. </p><p>The trials involved 121 organizations from across the UK, 14 commercial providers of cyber deception solutions, and 10 product trials across different environments, from cloud deployments to operational technology.</p><p>So far, the NCSC said it's clear that cyber deception can work - but it’s not always easy. While most organizations reckoned that cyber deception could offer real value, particularly in detecting novel threats and enriching threat intelligence, there was a lack of outcome-based metrics. </p><p>"As with any observability and threat hunting methods, the effectiveness of cyber deception depends on having the right data and context," said the NCSC. </p><p>"We found that cyber deception can be used for visibility in many systems, including legacy or niche systems, but without a clear strategy, organizations risk deploying tools that generate noise rather than insight."</p><p>Terminology is also a bit of a problem, with vocabulary across the industry often inconsistent, making it harder for organizations to understand what’s on offer or even what they’re trying to achieve. The NCSC said it now plans to standardize its cyber deception vocabulary. </p><p>Similarly, organizations may be missing a trick by failing to publicly announce that they use cyber deception - only 10% do. Some research suggests that when attackers believe cyber deception is in use, they are less confident in their attacks. </p><p>"This can impose a cost on attackers by disrupting their methods and wasting their time, to the benefit of the defenders," said the NCSC.</p><p>Notably, the NCSC’s research indicated that many organizations don't know where to start, and could really benefit from impartial advice, real-world case studies, and reassurance that the tools they’re using are effective and safe – something the agency said it will aim to provide. </p><h2 id="cyber-deception-is-risky-business">Cyber deception is risky business</h2><p>The NCSC warned that the trial scheme also highlighted significant risks, particularly the danger of misconfiguration. </p><p>If cyber deception tools aren’t properly configured, they may “fail to detect threats or lead to a false sense of security”. </p><p>Worse still, these tools could create openings for attackers, the agency noted. </p><p>"As networks evolve and new tools are introduced, keeping cyber deception tools aligned requires ongoing effort. It is important to consider regular updates and fine-tuning cyber deception solutions."</p><p>Regardless, the NCSC said there's still a strong case for the use of cyber deception – particularly its potential to impose cost on adversaries. </p><p>By forcing attackers to spend time and resources navigating false environments, chasing fake credentials, or second-guessing their access, it can slow down attacks and increase the chances of detection.</p><p>"Cyber deception isn’t new, but neither is it widely used, and that’s a missed opportunity," the NCSC concludes. "When done well, it can provide early warning of attacks, generate high-quality intelligence, and shape how our adversaries operate. But it’s not a magic fix; it requires planning, strategy, and support." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know">NCSC issues urgent warning over growing AI prompt injection risks – here’s what you need to know</a></li><li><a href="https://www.itpro.com/business/business-strategy/ransomware-victims-are-refusing-to-play-ball-with-hackers-just-17-percent-of-enterprises-have-paid-up-so-far-in-2025-marking-an-all-time-low">Ransomware victims are refusing to play ball with hackers</a></li><li><a href="https://www.itpro.com/security/government-urges-large-enterprises-to-shore-up-defenses-as-ncsc-warns-uk-faces-four-nationally-significant-cyber-attacks-every-week">Government urges large enterprises to shore up defenses as NCSC warns UK faces four 'nationally significant' cyber attacks every week</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government urges large enterprises to shore up defenses as NCSC warns UK faces four 'nationally significant' cyber attacks every week ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/government-urges-large-enterprises-to-shore-up-defenses-as-ncsc-warns-uk-faces-four-nationally-significant-cyber-attacks-every-week</link>
                                                                            <description>
                            <![CDATA[ UK enterprises of all sizes face escalating cybersecurity threats, ministers have warned ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">52u76yJ7hRScQpLdyQhN5n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Oct 2025 10:31:43 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Oct 2025 10:32:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:description>                                                            <media:text><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:text>
                                <media:title type="plain"><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK government ministers have written to some of the country’s largest companies, urging them to shore up cybersecurity capabilities amidst a surge in high-profile attacks. </p><p>The <a href="https://www.gov.uk/government/publications/ministerial-letter-on-cyber-security-to-leading-uk-companies/ministerial-letter-on-cyber-securityhttps:/www.gov.uk/government/publications/ministerial-letter-on-cyber-security-to-leading-uk-companies/ministerial-letter-on-cyber-security" target="_blank"><u>letter</u></a>, sent to the CEOs of all companies in the FTSE100 and FTSE250, as well as a number of other leading UK firms, calls on them to make cybersecurity a board responsibility.</p><p>Signed by technology secretary Liz Kendall, chancellor Rachel Reeves, business secretary <a href="https://www.itpro.com/business/policy-and-legislation/who-is-peter-kyle-the-uks-new-technology-secretary-and-what-are-his-plans-for-the-future-of-the-sector">Peter Kyle</a>, security minister Dan Jarvis, and the heads of the NCSC and National Crime Agency, it points out that hostile cyber activity in the UK is becoming more intense, frequent, and sophisticated.</p><p>"The government is taking significant action to counter the cyber threat and has developed tools to help businesses to defend themselves, but we cannot do this alone," it reads. </p><p>"We ask you and the CEOs and chairs of other leading UK companies to take the necessary steps to protect your business and our wider economy from cyber attacks."</p><p>According to the letter, organizations should make cyber risk a board-level priority using the <a href="https://www.gov.uk/government/publications/cyber-governance-code-of-practice" target="_blank"><u>Cyber Governance Code of Practice</u></a> and sign up to the NCSC’s <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning" target="_blank"><u>Early Warning Service</u></a>.</p><p>They should also implement Cyber Essentials and require it in their supply chain. </p><p>Notably, this certification scheme comes with an incentive: it includes automatic cyber liability insurance for any UK organization that certifies the whole organization and has less than £20 million annual turnover.</p><p>The advice comes as the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> revealed it dealt with a record 204 nationally significant cyber attacks in the year to September – more than twice as many as the 89 it handled in the previous 12 months.</p><p>n its latest <a href="https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025" target="_blank"><u>Annual Review</u></a>, the cyber agency said it dealt with 429 incidents in all, and that many were linked to Advanced Persistent Threat (APT) actors – either nation-state actors or highly-capable cyber criminal groups.  </p><p>"The best way to defend against these attacks is for organisations to make themselves as hard a target as possible," said Dr Richard Horne, chief executive of the NCSC.</p><p>"That demands urgency from every business leader: hesitation is a vulnerability, and the future of their business depends on the action they take today. The time to act is now."</p><h2 id="uk-facing-an-onslaught-of-cyber-threats">UK facing an onslaught of cyber threats</h2><p>Over the last year, high-profile attacks have caused huge problems for firms including Marks and Spencer (M&S), the Co-op Group, Harrods, and Jaguar Land Rover (JLR).</p><p>As part of the NCSC report, Shirine Khoury-Haq, CEO of the Co-op Group, warned businesses to do all they can to avoid falling victim to the same fate.</p><p>"The attack has had a significant impact on me, my colleagues and on our members. I will never forget the strain it put on those people making it right, or the concern it has given our members, to whom I answer," she wrote.</p><p>"While the security of your systems will no doubt remain on your radar, please continue to account for the fact that the timing and nature of a <a href="https://www.itpro.com/security/cyber-attacks">cyber attack</a> like this is unpredictable. New challenges will always emerge and threats to corporate infrastructures will never stop."</p><p>Backing up the government's advice, the NCSC is urging smaller firms to take action too. Its new <a href="https://cybertoolkit.service.ncsc.gov.uk/?utm_source=NCSC&utm_medium=AnnualReviewDigitalCopy&utm_campaign=PublicBeta" target="_blank"><u>Cyber Action Toolkit</u></a> is designed to help sole traders and small organizations put in place some of the basic <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>measures that help guard against the most common cyber threats.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/how-to-choose-the-best-cyber-security-vendor-for-your-business">How to choose the best cyber vendor for your business</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">The best online cybersecurity courses</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/357296/the-ultimate-guide-to-landing-a-cybersecurity-career">The ultimate guide to starting a career in cybersecurity</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Industry welcomes the NCSC’s new Vulnerability Research Initiative – but does it go far enough? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/industry-welcomes-the-ncscs-new-vulnerability-research-initiative-but-does-it-go-far-enough</link>
                                                                            <description>
                            <![CDATA[ The cybersecurity agency will work with external researchers to uncover potential security holes in hardware and software ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">awQdzykcVf8Xojd7LjFFCA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Jul 2025 14:36:54 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Jul 2025 14:37:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:description>                                                            <media:text><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> is extending its vulnerability research capabilities by partnering with external partners rather than relying entirely on its own analysts.</p><p>Dubbed the Vulnerability Research Initiative (VRI), the new initiative builds on existing external relationships and has been largely welcomed by the industry.</p><p>The agency <a href="https://www.ncsc.gov.uk/information/engaging-the-vulnerability-research-community-through-the-vulnerability-research-initiative" target="_blank"><u>explained</u></a> it already works closely with the UK government, technology companies, and wider public to discover flaws, provide advice on staying safe online, and respond to cyber incidents.</p><div class="product"><a data-dimension112="db30d2c7-76f2-4b2e-9178-c78457c4ed93" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="db30d2c7-76f2-4b2e-9178-c78457c4ed93" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="db30d2c7-76f2-4b2e-9178-c78457c4ed93" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>The Vulnerability Research Initiative (VRI), however, is a more collaborative affair that brings in specialist <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>expertise.</p><p>“The VRI’s mission is to strengthen the UK’s ability to carry out VR,” the NCSC said in a statement announcing the scheme. </p><p>“We work with the best external vulnerability researchers to deliver deep understanding of security on a wide range of the technologies we care about. The external VRI community also supports us in having tools and tradecraft for vulnerability discovery,” it added.</p><p>The agency also outlined who is in the core VRI team, including technical experts, relationship managers, and project managers. Additional details, including what external partners are involved, remain vague. </p><p>Kevin Robertson, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>of Acumen Cyber, said the project “sounds promising in theory” but claimed the NCSC has a “track record of largely ineffective and self-serving programs [and] it could end up as another flop that delivers little real value”.</p><p>Others in the industry were more positive about the announcement, however. </p><p>Kev Breen, senior director of cyber threat research at Immersive, welcomed the decision as a proactive step to identifying and tackling security threats. </p><p>“There is a great deal of capability in the public domain, especially in more niche areas of research,” he said. </p><p>“It is not practical for the NCSC to maintain the necessary skills, time, and resources to effectively hunt for bugs across all of these domains.</p><p>“Extending the VRI to include the wider community, via invitation or application, is an excellent way to broaden that knowledge base.”</p><h2 id="will-the-ncsc-scheme-go-far-enough">Will the NCSC scheme go far enough?</h2><p>Notably, Breen warned that the lack of financial reward, as seen in a bug bounty program, may reduce the number of researchers willing to get involved.</p><p>Google, for example, offers between $100 and $31,337 for a qualifying bug, <a href="https://www.geeksforgeeks.org/blogs/bug-bounty-programs/" target="_blank"><u>according to Geeks for Geeks</u></a>. </p><p>Microsoft, meanwhile, has several <a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program">bug bounty programs</a>, offering up to $300,000 for vulnerabilities found in Azure or up to $30,000 for issues in Windows Insider Preview as just two examples. </p><p>On the hardware side, Intel offers between $500 and $100,000 for valid reports, depending on the risk level and nature of the bug. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/windows/the-ncsc-just-urged-enterprises-to-ditch-windows-10-heres-what-you-need-to-know">The NCSC just urged enterprises to ditch Windows 10 – here’s what you need to know</a></li><li><a href="https://www.itpro.com/software/software-security-code-of-practice-ncsc-announcement">The NCSC wants developers to get serious on software security</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy">NCSC expert urges businesses to follow geopolitics as defensive strategy</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC just urged enterprises to ditch Windows 10 – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/windows/the-ncsc-just-urged-enterprises-to-ditch-windows-10-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The UK cyber agency says those that haven’t migrated to Windows 11 should do so immediately ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rBm57cuojr5CvowLhHaU6N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kNXojsonrZEBVQCVPPxCw6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Jul 2025 10:43:28 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Jul 2025 10:43:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kNXojsonrZEBVQCVPPxCw6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 and Windows 11 logos pictured on laptop screens sitting side by side on a desk.]]></media:description>                                                            <media:text><![CDATA[Windows 10 and Windows 11 logos pictured on laptop screens sitting side by side on a desk.]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 and Windows 11 logos pictured on laptop screens sitting side by side on a desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kNXojsonrZEBVQCVPPxCw6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Center (NCSC)</a> has urged organizations to <a href="https://www.itpro.com/software/windows/how-long-does-it-take-to-upgrade-to-windows-11">upgrade to Windows 11</a> before the <a href="https://www.itpro.com/software/windows/windows-10-end-of-life-how-to-prepare-for-the-deadline">end of support deadline for Windows 10 </a>hits in October. </p><p>In a blog post, the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> body pointed out there are significant security risks for those who do not choose to upgrade. </p><p>Beyond the difficulties linked to being out of a dedicated support period, out-of-date operating systems are prime targets for cyber criminals – and the NCSC said the risks simply aren’t worth it. </p><div class="product"><a data-dimension112="02fdaa18-71d1-43dc-ad7a-f4b64081d748" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="02fdaa18-71d1-43dc-ad7a-f4b64081d748" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="02fdaa18-71d1-43dc-ad7a-f4b64081d748" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Take the<a href="https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-021?redirectedfrom=MSDN"><u> IE 6-11</u></a> vulnerability from the end of support for Windows XP as an example. </p><p>Organizations have until October 2025 to update their devices and hardware before Windows 10 reaches end-of-life status. Despite Windows 11 being almost four years old, many have still not made the switch. </p><p>“While Windows 10 was released more than a decade ago, it is still used widely by enterprises and not upgrading is akin to incurring a debt at a high interest rate – with the threat of forced repayment at a future date,” NCSC chief technical officer, Ollie Whitehouse, warned.</p><p>“The NCSC implores any organisation that has not already migrated to a more modern system to do so to help address security vulnerabilities in your devices and ensure overall cyber resilience. This is essential as demonstrated by the requirement to maintain supported software in <a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank"><u>Cyber Essentials</u></a>.”</p><h2 id="what-s-holding-up-the-shift-to-windows-11">What’s holding up the shift to Windows 11?</h2><p>One reason for companies holding on to Windows 11 could be the necessary hardware requirements. </p><p>Requirements such as TPM 2.0, UEFI, and support for Secure Boot may mean upgrading to more modern laptops, which might be a cost headache in the short term. </p><p>However, the cost of a cyber incident might be far worse in the long run. </p><p>As part of its guidance, the NCSC also released updated configuration packs for Microsoft Windows, with selected group settings to make it easier to deploy. </p><p>The requirements have led to suggestions that it could lead to a global torrent of e-waste, with millions of devices scrapped. </p><p>Research from Canalys suggested that up to <a href="https://www.itpro.com/software/windows/windows-10-end-of-life-could-prompt-torrent-of-e-waste-as-240-million-devices-set-for-scrapheap">240 million PCs around the world could be terminated</a> as a result of the shift to Windows 11.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy">NCSC expert urges businesses to follow geopolitics as defensive strategy</a></li><li><a href="https://www.itpro.com/software/software-security-code-of-practice-ncsc-announcement">The NCSC wants developers to get serious on software security</a></li><li><a href="https://www.itpro.com/security/ransomware/what-you-need-to-know-about-the-new-ncsc-ransomware-guidance">What you need to know about the new NCSC ransomware guidance</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘States don’t do hacking for fun’: NCSC expert urges businesses to follow geopolitics as defensive strategy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy</link>
                                                                            <description>
                            <![CDATA[ Paul Chichester, director of operations at the UK’s National Cyber Security Centre, urged businesses to keep closer tabs on geopolitical events to gauge potential cyber threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tWmWKKmQCWqZdQFyWWxsaA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jun 2025 09:01:08 +0000</pubDate>                                                                                                                                <updated>Thu, 05 Jun 2025 09:01:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Russian hacker concept image showing a skulls and crossbones colored like the Russian Federation flag, made up of binary code, and imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLqJdzSrYCkAScByVUwGaF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Business leaders need to stay up to date with geopolitics to keep their cybersecurity strategies up to date and mitigate the risks posed by state-backed hacker groups. </p><p>This is the message that Paul Chichester, director of operations at the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, delivered to attendees at a keynote session of Infosecurity Europe 2025.</p><p>The call to action from Chichester came as states known to support threat actors and engage in cyber attacks of their own step up efforts to disrupt critical infrastructure</p><p>Chichester said Russia’s cyber capabilities in particular have improved in recent years, with its invasion of Ukraine used as an opportunity to hone offensive cyber techniques. Along with Russia, Chichester focused on the threat <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats"><u>China-backed groups</u></a> pose to both public and private organizations.</p><p>“I'll come back to this a few times, but states don't do hacking for fun,” Chichester said.</p><p>“They do not do things for the sake of it. There is always a reason. We might not know the reason sometimes and that's quite a challenge for us, but we shouldn't assume that they're just doing it because they can.”</p><p>Chichester urged businesses who are being targeted by a state APT to carefully consider why and to assess how geopolitics feeds into their defensive strategies.</p><p>“At the end of the day, cyber isn't really just, or even, a technical thing. It's a tool that somebody uses, be it a criminal, be it a state. How does that risk manifest itself for you?”</p><p>The past few years have seen a number of high-profile attacks by <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored groups</u></a> on organizations to achieve ideological and military aims. Chichester said Russia is increasingly targeting supply chains which feed into Ukraine, with defense, energy, and logistics companies firmly in its crosshairs.</p><p>In 2022, for example, Microsoft warned the Russia-backed group Seashell Blizzard was using the Prestige <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware strain</u></a> to target organizations involved in the supply or transport of humanitarian aid and military shipments to Ukraine. </p><p>This is also coming from within the GRU military intelligence service, and Chichester cited the example of Unit 29155. This Russian military sabotage unit is known for its role in the 2018 Skripal poisonings, but it is now using cyber attacks to carry out its aims.</p><p>“Ultimately, if you want to target something in the real world, you need to understand them in the cyber world. You need to understand how they operate, you need to understand their movements, you need to understand what's going where,” Chichester explained.</p><p>“And we're seeing that merger of that real world sabotage being joined with that cyber espionage piece as well – and also cyber sabotage.”</p><p><a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks"><u>Russia launched a major cyber attack on Viasat</u></a>, a US communications company, on 24 February 2022, the same day it invaded Ukraine. This triggered a widespread outage, impacting Ukrainian military command and control and causing knock-on outages for several thousand internet-connected German wind turbines. </p><p>Chichester said the attack was carefully-timed to hit hardest in the first 24-48 hours of the invasion and “might have been a deciding factor” in the war had events on the ground gone differently.</p><p>Despite the apparently unintentional effects on EU-based companies, Chichester used the attack as an example of how states are increasingly targeting private businesses to achieve military or ideological aims.</p><p>China is also heavily implicated in attacks on critical national infrastructure, with cyber experts Kevin Mandia and Nicole Perlroth having recently warned the nation state has <a href="https://www.itpro.com/security/china-has-almost-doubled-their-aggression-in-cyber-kevin-mandia-and-nicole-perlroth-warn-organizations-arent-waking-up-to-growing-apt-threats"><u>ramped up its cyber aggression</u></a>.</p><p>Chichester said attacks by Volt Typhoon, an <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> that <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid"><u>successfully breached the US electric grid</u></a> for almost a year, as well as Salt Typhoon which <a href="https://www.itpro.com/security/fcc-tells-telcos-to-sharpen-up-security-after-salt-typhoon-chaos"><u>carried out major attacks on US telcos in 2024</u></a>, show groups ‘pre-positioning’ themselves inside critical infrastructure.</p><p>As <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a"><u>warned by CISA</u></a>, this could enable undetected groups to carry out devastating attacks in the event of conventional war in the long-term.</p><h2 id="for-profit-attacks-remain-king">For-profit attacks remain king</h2><p>Despite the growing threat posed by state-backed groups pursuing ideological and military aims, evidence suggests that businesses will still largely contend with traditional threat actors.</p><p>In a separate keynote talk at the event, James Lyne, office of the CEO at the SANS Institute and Ciaran Martin, director of CISO network at the SANS Institute and former head of the NCSC, balanced the real threat of state-backed groups with those of profit-motivated groups.</p><p>“Most people are interested in fraud,” said Lyne. “Most of this stuff is about making money, the average obsession of the average criminal gang is far more mundane.”</p><p>“I think that's probably largely going to continue to be the case,” he added.</p><p>Lyne noted that, like the German wind farm operators inadvertently impacted by Russia’s attack on Viasat, some serious cyber attacks are mere “collateral damage” from campaigns aimed at other targets.</p><p>Martin said this was seen in the worst period of his time at the NCSC: the six-week period in 2017 in which <a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst"><u>North Korea</u></a> launched the <a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two/2"><u>WannaCry</u></a> ransomware attack, while suspected Russian groups hit Ukrainian banks and other organizations with the <a href="https://www.itpro.com/malware/34381/what-is-notpetya"><u>NotPetya</u></a> malware.</p><p>“Between them, they [did] north of $10 billion of destruction and in my, sadly, favorite example from NotPetya, they’re attacking Ukrainian tax software and they end up stopping production at Cadbury’s chocolate factory in Tasmania, off the south coast of Australia.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">The Iran cyber threat: Breaking down attack tactics</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li><li><a href="https://www.itpro.com/security/state-sponsored-cyber-crime-is-officially-out-of-control">State-sponsored cyber crime is officially out of control</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber attacks have rocked UK retailers – here's how you can stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cyber-attacks-have-rocked-uk-retailers-heres-how-you-can-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Following recent attacks on retailers, the NCSC urges other firms to make sure they don't fall victim too ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yvkJobyXPrCgsC3VwGxzXR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 May 2025 09:45:09 +0000</pubDate>                                                                                                                                <updated>Tue, 06 May 2025 09:45:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:description>                                                            <media:text><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:text>
                                <media:title type="plain"><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Centre (NCSC) has warned organizations to tighten up their security practices following the recent cyber attacks on M&S, Co-op, and Harrods.</p><p>The security agency is calling on firms to review their password reset policies, and in particular how IT help desks authenticate workers when they make a reset request. </p><p>Organizations should be particularly cautious in the case of senior employees with escalated privileges, such as Domain Admin, Enterprise Admin and Cloud Admin accounts. </p><p>Similarly, the advisory noted that businesses should make sure that they're using <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> across the board.</p><p>Notably, the agency warned organizations should be constantly on the lookout for ‘risky logins’ within <a href="https://www.itpro.com/cloud/cloud-security/the-biggest-cloud-security-risk-in-2024-will-be-stolen-and-exposed-credentials">Microsoft Entra ID Protection</a>, where sign-in attempts are flagged as potentially compromised due to suspicious activity or unusual behaviour. </p><p>"Preparation and resilience does not mean just having good defences to keep out attackers. No matter how good your defences are, sometimes the attacker will be successful," <a href="https://www.ncsc.gov.uk/blog-post/incidents-impacting-retailers" target="_blank"><u>wrote</u></a> NCSC national resilience director Jonathon Ellison and chief technology officer Ollie Whitehouse.  </p><p>"It also means detecting threat actors when they are using your employees’ legitimate access (or are on your network, or in your cloud services) whilst being able to contain attackers to prevent damage, and to respond and recover when an attack has got through your defences."</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has similar advice warning organizations to make sure that accounts are protected by a strong password, and that passwords aren't being reused across multiple accounts. </p><h2 id="what-happened-with-the-retail-attacks">What happened with the retail attacks?</h2><p>Attacks against UK retailers have rocked the industry in recent weeks. M&S was the first to be hit, followed by the Co-op and <a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack">Harrods </a>at the end of April.</p><p>The attacks have caused <a href="https://www.itpro.com/business/m-and-s-calls-in-ncsc-after-cyber-incident-disrupts-customer-payments-online-orders">lasting disruption for M&S in particular</a>, which has been unable to provide <a href="https://www.itpro.com/security/marks-and-spencer-cyber-incident-update">contactless payment, click-and-collect services, or online sales</a>.</p><p>While the Co-op attack was initially thought to have been limited in its impact, the <a href="https://www.bbc.co.uk/news/articles/crkx3vy54nzo" target="_blank"><u>retailer told </u><u><em>BBC News</em></u><u> last week</u></a> that hackers had “accessed data relating to a significant number” of current and past members. </p><p>The threat actors behind the <a href="https://www.itpro.com/security/co-op-cyber-attack">Co-op attack</a>, who are going by the name ‘<em>DragonForce</em>’, told the broadcaster they are also responsible for the incidents at M&S and Harrods. </p><h2 id="attacks-are-a-wake-up-call-for-uk-businesses">Attacks are a ‘wake-up call’ for UK businesses</h2><p>In a speech at CyberUK this week, chancellor of the Duchy of Lancaster Pat McFadden is expected to describe the attacks as 'a wake-up call for every business in the UK', and to call on firms to treat <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>as an 'absolute priority'.</p><p>"We are ready to support you," he will say. "The National Cyber Security Centre is standing ready to support businesses and provide advice, and guidance, on how to raise the cyber security bar."</p><p>Small businesses are being encouraged to engage with the NCSC’s Small Business Guide to help bolster their defences and support through the Cyber Local scheme, which provides tailored funding to boost regional cyber skills.  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/2024-was-a-record-year-for-commercial-cyber-attacks">2024 was a record year for commercial cyber attacks</a></li><li><a href="https://www.itpro.com/security/data-breaches/cyber-attacks-against-uk-firms-dropped-by-10-percent-last-year-but-experts-say-dont-get-complacent">Cyber attacks against UK firms dropped by 10% last year, but experts say don't get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/global-cyber-attacks-jumped-44-percent-last-year">Global cyber attacks jumped 44% last year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five Eyes cyber agencies issue guidance on edge device vulnerabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/five-eyes-cyber-agencies-issue-guidance-on-edge-device-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity agencies including the NCSC and CISA have issued fresh guidance on edge device security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">44gupsKEJXkvZessyUyQnN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Feb 2025 08:20:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Feb 2025 14:34:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:description>                                                            <media:text><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:text>
                                <media:title type="plain"><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> agencies have teamed up to offer guidance on how to secure edge devices from ever-increasing threats.</p><p>The advice covers network edge devices and appliances, such as firewalls, routers, <a href="https://www.itpro.com/security/27098/best-vpn-services">virtual private networks (VPN)</a> gateways, <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things (IoT)</a> devices, internet-facing servers and internet-facing <a href="https://www.itpro.com/security/364189/from-it-to-ot-whats-the-partner-opportunity">operational technology (OT)</a> systems. </p><p>Issued by the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, <a href="https://www.itpro.com/security/what-is-cisa">CISA</a>, and agencies in Australia, Canada, New Zealand, and the US, the guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default. </p><p>This, the NCSC points out, should make it easier for network defenders to detect malicious activity and investigate following an intrusion. </p><p>The <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring"><u>guidelines</u></a> also set out a set of minimum standards for forensic visibility to help network defenders secure organizational networks, both proactively and when responding to a compromise.</p><p>"In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat," said NCSC technical director <a href="https://www.itpro.com/business/public-sector/uks-ncsc-names-ollie-whitehouse-as-its-new-cto">Ollie Whitehouse</a>.</p><p>"In doing so, we are giving manufacturers and their customers the tools to ensure products not only defend against <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> but also provide investigative capabilities post-intrusion."</p><p>The NCSC said malicious actors are increasingly exploiting vulnerabilities and insecure design features to gain and maintain valuable accesses. Devices often aren't secure by design or by default, aren't given regular firmware updates, or have weak authentication measures with limited logging, making it hard to detect suspicious activity. </p><p>Similarly, many may not be configured securely, lack proper network segmentation, and use unsupported or <a href="https://www.itpro.com/software/windows/windows-10-end-of-life-could-prompt-torrent-of-e-waste-as-240-million-devices-set-for-scrapheap">end-of-life (EOL) hardware</a>, thereby increasing their vulnerability to exploitation. </p><p>Last summer, a report from WithSecure identified the mass exploitation of edge services as the year's prevailing trend for attackers.</p><p>The year saw a sharp rise in security incidents caused by the mass exploitation of edge devices, including such as <a href="https://www.itpro.com/security/a-new-critical-moveit-vulnerability-is-being-exploited-by-hackers-heres-what-you-need-to-know">MOVEit</a>, CitrixBleed, Cisco XE, Fortinet’s <a href="https://www.itpro.com/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited">FortiOS</a>, <a href="https://www.itpro.com/security/ivanti-connect-secure-flaws-have-been-targeted-250000-times-a-day-since-january-and-hackers-show-no-signs-of-stopping">Ivanti ConnectSecure</a>, Palo Alto’s PAN-OS, Juniper’s Junos, and Con<a href="https://www.itpro.com/security/ransomware/screenconnect-vulnerabilities-are-incredibly-trivial-to-exploit-researchers-warn">nectWise ScreenConnect</a>.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nMPk3hYgRaNUm4dqd8ZtSQ" name="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission" caption="" alt="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission." src="https://cdn.mos.cms.futurecdn.net/nMPk3hYgRaNUm4dqd8ZtSQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ABB)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/discover-how-these-data-centers-from-germany-and-australia-became-more-resilient-to-disruption-while-also-lowering-operating-costs-and-co2-emission"><em>Data centers fortified with robust maintenance</em></a></p></div></div><p>The number of edge service and infrastructure Common Vulnerabilities and Exposures (CVEs) added to the Known Exploited Vulnerability Catalogue (KEV) was 22% higher than in 2023.</p><p>Juliette Hudson, CTO of CybaVerse, said the new guidance is much needed given the scale of threats facing edge devices currently.</p><p>"These are guidelines that shouldn't be ignored, because when edge devices are insecure, the entire networks they run within are at heightened exposure to attack. Today, all businesses are digital businesses, where they rely on smart devices and the internet to deliver services, but this expands the enterprise attack surface," she said.</p><p>"Having good visibility across network assets and running proactive monitoring for threats are essential, but device manufacturers also have a key role to play, and it is essential they practice good security hygiene in the development process."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks">Five Eyes raises alarm over 'living off the land' attacks</a></li><li><a href="https://www.itpro.com/internet-of-things-iot/34509/how-edge-computing-can-benefit-businesses">How edge computing can benefit businesses</a></li><li><a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368117/best-enterprise-vpn-of-2022">Check out the best VPNs for enterprises</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Thinly spread": Questions raised over UK government’s latest cyber funding scheme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/thinly-spread-questions-raised-over-uk-governments-latest-cyber-funding-scheme</link>
                                                                            <description>
                            <![CDATA[ The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sFJaLxh7kPdjUAGtcGH4HB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jan 2025 11:50:28 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Jan 2025 13:53:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of the Houses of Parliament, London, UK.]]></media:description>                                                            <media:text><![CDATA[View of the Houses of Parliament, London, UK.]]></media:text>
                                <media:title type="plain"><![CDATA[View of the Houses of Parliament, London, UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government plans to spend £1.9 million on cyber resilience projects across the country, the <a href="https://www.gov.uk/government/news/new-regional-skills-projects-to-bolster-uk-cyber-defences-and-deliver-on-plan-for-change"><u>Department for Science, Innovation and Technology (DSIT) has revealed</u></a>. </p><p>With planned investment in more than 30 projects, the money will help improve the UK’s cyber resilience for both businesses and consumers, and boost national <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge">cyber skills</a>. </p><p>Some projects set to receive funding include ‘CyberSecurityAId: Empowering Small Businesses with Cyber Security Skills,’ ‘Cybersecurity Angel Investor Network,’ and ‘First Steps to a Cyber Security Career - North West.’</p><p>The funding boost comes amid growing concerns over <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cybersecurity skills shortages</a> across the country. Almost half of UK firms report a deficit in this regard, according to the DSIT, and these projects will help fill current gaps and meet growing demand. </p><p>Under the scheme, people across the country will be able to pursue new, high-level career opportunities as a result, DSIT added. </p><p>“By <a href="https://www.itpro.com/business-strategy/training/358122/upskilling-a-remote-workforce">upskilling</a> small businesses and individuals, investing in workforce development, and encouraging neurodiverse talent, government and industry partners are fostering robust and diverse cyber communities for the future,” said Jonathan Ellison, director for national resilience and future technology at the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>. </p><p>“This is vital for protecting our digital economy, creating new opportunities for secure innovation, and helping make the UK the safest place to live and work online,” Ellison added. </p><p>The UK’s minister for cybersecurity, Feryal Clark, also commented, saying strong defenses are needed for the country’s growing digital economy, which is worth billions of pounds. </p><p>“Attempts to disrupt the technologies and services we rely on daily continue to grow, so we’re leaving no stone un-turned to make sure our communities have the skills to rise to the challenge,” Feryal said. </p><h2 id="cyber-investment-is-a-good-start-but-does-it-go-far-enough">Cyber investment is a good start, but does it go far enough?</h2><p>While the move has been welcomed by industry stakeholders, some experts have questioned the scope of the initiative. </p><p><a href="https://www.itpro.com/security/uks-first-national-security-center-to-open-in-wales">Socura</a> CEO Andy Kays said a key concern is the “size of investment relative to the scale of its ambition”, suggesting that the volume of projects set to be awarded funding could dilute the overall investment. </p><p>“30 new projects slated for 2025 and beyond across multiple regions means that this money will be thinly spread across the UK,” Kays said. </p><p>“The concern is that this money won’t go far enough to have the level of impact needed. It is, however, a good start,” he added. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QG6vhN3APSsV7GwFnj5f3o" name="Discover the six superpowers of Dell PowerEdge servers.jpg" caption="" alt="Discover the six superpowers of Dell PowerEdge servers" src="https://cdn.mos.cms.futurecdn.net/QG6vhN3APSsV7GwFnj5f3o.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell & AMD)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/discover-the-six-superpowers-of-dell-poweredge-servers"><em>Transform your data center</em></a></p></div></div><p>Kays said it was “only right” that the UK invest more money to develop its regional <a href="https://www.itpro.com/business/370195/welsh-startups-isolated-over-lack-of-diverse-funding-routes">cyber skills in places like Wales</a>, the North East of England, and Northern Ireland. </p><p>Jake Moore, global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> advisor at ESET, welcomed the investment scheme, adding that the initiative will help strengthen the country’s overall cyber resilience and futureproof communities.  </p><p>“Upskilling workforces is crucial for safeguarding our digital economy, unlocking opportunities to secure innovation, and ensuring the UK remains protected from constant attacks,” Moore said.</p><p>“However, this isn’t the first time we have seen a shake-up in the UK’s skills shortage so it is vital that the initiative will continue to be funded and pushed to the next level where more roles are filled,” he added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ State-sponsored cyber crime is officially out of control ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/state-sponsored-cyber-crime-is-officially-out-of-control</link>
                                                                            <description>
                            <![CDATA[ North Korea is the most prolific attacker, but Russia and China account for the most disruptive and tightly-targeted campaigns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MSC4TVH5sKyCNLV7UsKLPS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x36eFsVMn7zTT8Pg9QZZhm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Oct 2024 11:56:56 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Oct 2024 10:41:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x36eFsVMn7zTT8Pg9QZZhm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing a digitized padlock symbol on a digital interface.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing a digitized padlock symbol on a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing a digitized padlock symbol on a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x36eFsVMn7zTT8Pg9QZZhm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two-thirds of attributable cyber attacks now come from state-backed attackers, lending weight to warnings from national security agencies about the scale of the threats faced by enterprises and public services alike.</p><p>Analysis from Netskope shows a marked escalation in state-sponsored attacks in recent years, with the company warning this trend shows no sign of slowing down. </p><p>Sanjay Beri, CEO and co-founder of Netskope, said cyber attacks waged by nation state actors now represent a form of ‘quiet war’. </p><p>"Under the surface of this worldwide escalation is a varied picture of different states pursuing widely divergent cyber attack strategies,” he said. </p><p>While attention has largely focused on the risks from Russia, China and Iran, data from Netskope indicates that North Korea is currently the world's biggest offender in terms of the number of victims.</p><p>It's been targeting victims en-masse through cyber crime and cryptocurrency theft, with the goal of stealing money to fund its military.</p><p>China and Russia, meanwhile, account for the second and third greatest number of attacks. Unlike North Korea, however, their goal is to disrupt and damage highly targeted pieces of critical national infrastructure, leading to a smaller number of higher impact, more targeted attacks.</p><p>Examples include the targeting of NHS England and the Electoral Commission, both of which were highly disruptive.</p><p>"The difference between North Korea’s cyber ‘carpet bombing’ and Russia’s ‘precision strikes’ means that if you’ve fallen victim to an online phishing attack, it’s unlikely that Russian government-backed actors were the cause," said Beri. </p><p>"If, however, a critical piece of national infrastructure is down, then it’s more likely that they are. Understanding these nuances is critical for businesses and individuals operating in today’s connected world - because the first and most important step in putting in place the best cyber defense strategy is understanding who is targeting you, what their goals are, and how they’re trying to achieve them."</p><h2 id="state-sponsored-cyber-attacks-are-wreaking-havoc">State sponsored cyber attacks are wreaking havoc</h2><p>Earlier this summer, the UK’s National Cyber Security Centre (NCSC), along with US and South Korean authorities, warned that a North Korea-linked threat group known as Andariel was compromising organizations around the world to steal sensitive and classified technical information and intellectual property data.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VCH845ZhDV5hUdMBUUxXBg" name="The revolutionary content supply chain (1).jpg" caption="" alt="The revolutionary content supply chain" src="https://cdn.mos.cms.futurecdn.net/VCH845ZhDV5hUdMBUUxXBg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/the-revolutionary-content-supply-chain"><em>Reinvent and optimize content supply chains</em></a></p></div></div><p>While it mainly targeted defense, aerospace, nuclear, and engineering entities, it also hit organizations in the medical and energy sectors to a lesser extent, stealing information such as contract specification, design drawings, and project details. </p><p>In March this year, the UK government warned that the Chinese state-sponsored attacks on parliamentarians and on the Electoral Commission would not be tolerated. </p><p>This particular incident prompted the government to summon the Chinese Ambassador and sanction a front company and two individuals identified as members of the APT31 hacking group. </p><p>Similarly, late last year, Russian-backed threat actors were thrust into the spotlight after the NCSC exposed a campaign by Russian Intelligence Services to interfere in UK politics and democratic processes.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>More from ITPro</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">The Iran cyber threat: Breaking down attack tactics</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">State-sponsored cyber attacks: The new frontier</a></li><li><a href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">What threat do nation state hackers pose to businesses?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC and FBI just issued a major alert over a state-backed hacker group – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-and-fbi-just-issued-a-major-alert-over-state-backed-hacker-groups-here-s-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ State-affiliated attackers are targeting individuals via spear-phishing techniques, according to the NCSC ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UsVi3w8ceTLy5HupueDrm9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rfyesh66wgmmCbpkKKZrYW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Sep 2024 11:50:13 +0000</pubDate>                                                                                                                                <updated>Mon, 30 Sep 2024 13:19:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rfyesh66wgmmCbpkKKZrYW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Iran]]></media:description>                                                            <media:text><![CDATA[Iran]]></media:text>
                                <media:title type="plain"><![CDATA[Iran]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rfyesh66wgmmCbpkKKZrYW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has warned that Iran-linked hackers are using <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> to target government officials, lobbyists, and others.</p><p>In a joint advisory with the FBI, the NCSC said hackers working for <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">Iran's Revolutionary Guard Corps (IRGC)</a> are carrying out <a href="https://www.itpro.com/security/29093/what-is-phishing">spear phishing</a> attacks against people with links to Iranian and Middle Eastern affairs.</p><p>They've been impersonating victims' contacts via email and messaging platforms, thereafter asking them to share user credentials via a false email account login page. This allows the attacker to gain access to victims’ accounts, exfiltrate and delete messages, and set up email forwarding rules. </p><p>They tailor their approach on an individual basis, according to the NCSC, impersonating business associates or family members, journalists purportedly looking for interviews, conference organizers, embassy staff, and others.</p><p>"The spear-phishing attacks undertaken by actors working on behalf of the Iranian government pose a persistent threat to individuals with a connection to Iranian and Middle Eastern affairs," said NCSC director of operations Paul Chichester.</p><p>"With our allies, we will continue to call out this malicious activity, which puts individuals’ personal and business accounts at risk, so they can take action to reduce their chances of falling victim."</p><h2 id="fbi-ncsc-offer-advice-for-potential-targets">FBI, NCSC offer advice for potential targets</h2><p>The FBI said signs to look out for include suspicious logins from foreign or domestic IP addresses; the creation of message handling rules to forward emails and prevent victims from receiving notifications of the compromise; the connection of unknown devices, applications, or accounts to a victim account; exfiltration and deletion of messages; and attempts to access other victim accounts.</p><p>Meanwhile, the NCSC is advising potential victims to follow its guidance for high-risk individuals, adding that anyone facing a higher risk of targeting due to their work or public status can sign up for two opt-in cyber defense services managed by the center.</p><p>These are an Account Registration service that alerts individuals if the NCSC becomes aware of a cyber incident impacting a personal account, and a Personal Internet Protection service that helps prevent spear-phishing by blocking access to known malicious domains.</p><p>"I strongly encourage those at higher risk to stay vigilant to suspicious contact and to take advantage of the NCSC’s free cyber defense tools to help protect themselves from compromise," Chichester said.</p><p>Back in 2019, the US Department of State designated the <a href="https://www.itpro.com/cyber-warfare/33895/president-trump-authorises-cyber-attack-on-iran">IRGC as a foreign terrorist organization</a> that aimed to steal US policy information and weaken confidence in the country's electoral processes.</p><p>And alongside this alert, the FBI also said that it had indicted three IRGC cyber actors for a 'hack-and-leak' operation which stole material from the Trump presidential campaign and leaked it to the Democratic campaign in an attempt to influence the upcoming presidential election.</p><p>"The conduct laid out in the indictment is just the latest example of Iran’s brazen behavior," said FBI director Christopher Wray. "So today the FBI would like to send a message to the government of Iran – you and your hackers can’t hide behind your keyboards."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>More from ITPro</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/ncsc-identifies-china-linked-botnets-targeting-thousands-of-devices-worldwide">NCSC identifies China-linked botnets targeting thousands of devices worldwide</a></li><li><a href="https://www.itpro.com/security/cisa-breached-a-federal-agency-as-part-of-its-red-team-program-and-nobody-noticed-for-five-months">CISA breached a federal agency as part of its red team program — and nobody noticed for five months</a></li><li><a href="https://www.itpro.com/security/the-ncsc-wants-to-know-how-your-business-is-using-honeypots-to-combat-hackers">The NCSC wants to know how your business is using honeypots to combat hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK's data protection watchdog deepens cooperation with National Crime Agency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/uk-s-data-protection-watchdog-deepens-cooperation-with-national-crime-agency</link>
                                                                            <description>
                            <![CDATA[ The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">575tSDTARjuuKo7qW4Paib</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Pz3CFWeJxcZh89pBoB28YV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Sep 2024 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Pz3CFWeJxcZh89pBoB28YV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mockup image with padlocks to symbolise a cyber security vulnerability]]></media:description>                                                            <media:text><![CDATA[Mockup image with padlocks to symbolise a cyber security vulnerability]]></media:text>
                                <media:title type="plain"><![CDATA[Mockup image with padlocks to symbolise a cyber security vulnerability]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Pz3CFWeJxcZh89pBoB28YV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> and National Crime Agency (NCA) are planning to improve the support they give to organizations experiencing <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a>.</p><p>In a Memorandum of Understanding (MoU), the two agencies set out plans to make sure that victims are signposted to relevant bodies, such as the National<a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"> Cyber Security Centre (NCSC)</a>, and are empowered to report cyber crime at the earliest opportunity.</p><p>“Unfortunately, we’ve seen cyber crime costing UK firms billions over the past years. That’s why it’s crucial that relevant bodies work together to boost the <a href="https://www.itpro.com/security/kings-speech-cybersecurity-in-the-spotlight-as-government-promises-new-efforts-to-lock-down-insecure-it-supply-chains">UK’s cyber resilience</a>," said Stephen Bonner, ICO deputy commissioner - regulatory supervision.</p><p>"This new memorandum of understanding builds on our existing relationship with the NCA and will help improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> standards across the board, while respecting each other’s remits."</p><p>The MoU commits the ICO and NCA to encourage organizations to engage with the NCA on cybersecurity matters, including the response to cyber crime, promising that the NCA will never pass on information shared in confidence without having first received the organization's consent. </p><p>The ICO will also share information about cyber incidents with the NCA on an anonymized, systemic, and aggregated basis - and on an organization-specific basis where appropriate - to help protect the public from serious and organized crime.</p><p>Where the ICO and NCA are both engaged in a cyber incident, they'll work together to minimize disruption to the organization’s efforts to contain and mitigate harm.</p><p>Similarly, the two agencies will also work together to promote learning, provide consistent guidance, and improve standards on cyber-related matters while continuing to work closely with the National Cyber Security Centre (NCSC).</p><p>The NCA noted that organizations have a legal responsibility – under both data protection law and the <a href="https://www.itpro.com/policy-legislation/it-regulation/369630/uk-updates-nis-regulations-bringing-stricter-rules-for-msps">Network and Information Systems Regulations</a> – to report incidents that meet a certain threshold. </p><p>There’s a huge amount of assistance on offer, the crime agency added, including tailored technical advice, the creation of secure communication channels, insight into an attacker’s possible motivations, and strategic advice on how to engage with the rest of government, regulators, and the media.</p><p>"The NCA leads a whole-system response to cyber crime, disrupting cyber criminals and putting them before the courts wherever possible," said NCA deputy director Paul Foster, head of the National Cyber Crime Unit. </p><p>"Organizations who are vulnerable to imminent attack or find themselves a victim also need support and guidance, and we work closely with our partners to provide this."</p><p>"We are pleased to be making this commitment with the Information Commissioner’s Office; this agreement signifies our common goal of establishing and maintaining a secure and resilient cyber ecosystem for all."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC wants to know how your business is using honeypots to combat hackers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-wants-to-know-how-your-business-is-using-honeypots-to-combat-hackers</link>
                                                                            <description>
                            <![CDATA[ The NCSC hopes to encourage the use of cyber deception techniques within the UK, across government and critical national infrastructure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S3nkgiMWnRvgrJTEjRvWEF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Aug 2024 08:50:50 +0000</pubDate>                                                                                                                                <updated>Wed, 14 Aug 2024 10:07:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:description>                                                            <media:text><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:text>
                                <media:title type="plain"><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK&apos;s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> is calling for industry comment on the use of cyber deception in cyber defense.</p><p>The center said it recognizes the potential value of using cyber deception technologies and techniques to support cyber defense in certain situations. And as a result, it&apos;s aiming to establish an evidence base for use cases on a national scale, in support of its <a href="https://www.itpro.com/security/ncscs-active-cyber-defence-20-refresh-looks-to-tailor-services-to-the-evolving-security-market-and-threat-landscape">Active Cyber Defence 2.0 initiative</a>.</p><p>As a starting point, the NCSC sees two main use cases. The first is low-interaction solutions such as digital tripwires and honeytokens to alert organizations of all types to unauthorized access.</p><p>The second is both low-interaction and high-interaction <a href="https://www.itpro.com/cloud/362460/how-to-use-the-cloud-as-a-honeypot">honeypots</a> to collect threat intelligence both at a large scale and as one-off instances, which it sees being deployed by organizations with mature security capabilities, as well as managed cyber security service providers.</p><p>"During discussions, it became clear that ‘deception’ has connotations which can be uncomfortable for some," the NCSC explained.</p><p>"It is important to acknowledge this, and although there are wider definitions of <a href="https://www.itpro.com/security/29500/setting-a-trap-for-hackers">cyber deception</a> in military and other contexts, they differ to the technology we are referring to here."</p><p>By tripwires, it means components and systems designed to detect a threat actor by interacting with them to disclose their unauthorized presence in an environment which include honeytokens.</p><p>Honeypots, meanwhile, it defines as "components and systems designed to allow a threat actor to interact with them, allowing observation of their techniques, tactics, and procedures (TTPs), as well as the capability and infrastructure they use – with the aim of collecting cyber threat intelligence".</p><p>Finally, breadcrumbs are described as digital artifacts distributed in a system that entice a threat actor to interact with a tripwire and/or honeypot.</p><h2 id="the-ncsc-wants-to-see-more-honeypots-and-deception-techniques-xa0">The NCSC wants to see more honeypots and deception techniques </h2><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X9SNJ3pkpC6GvUhHDV2bfP" name="Patch Management Buyer’s Guide.jpg" caption="" alt="Patch Management Buyer’s Guide" src="https://cdn.mos.cms.futurecdn.net/X9SNJ3pkpC6GvUhHDV2bfP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: NinjaOne)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/patch-management-buyers-guide"><em>Evaluate your patch readiness and assess potential solutions</em></a></p></div></div><p>The NCSC said it plans to collect existing evidence, but also to encourage the use of these techniques across the UK, including in government security operations and critical national infrastructure.</p><p>It&apos;s aiming for 5,000 instances on the UK internet of low and high interaction solutions across IPv4 and IPv6, 20,000 instances within internal networks of low interaction solutions, 200,000 assets within cloud environments of low interaction solutions and 2,000,000 tokens deployed.</p><p>There are three core research questions it aims to examine:</p><ul><li>How effective are deployments at supporting the discovery of latent compromises within organization estates</li><li>How effective are deployments at supporting the enduring discovery of new compromises by threat actors</li><li>Does knowledge of the presence of such technologies at a national level actually affect the behavior of threat actors?</li></ul><p>Honeypots are already being deployed across the UK, allowing organizations to detect where cybercriminals are coming from, the level of threat, their preferred tactics, and the data or applications they&apos;re interested in - as well as how well existing <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> measures are working.</p><p>Last year, for example, the <a href="https://www.itpro.com/security/national-grid-exploring-cyber-honeypots-in-bid-to-mitigate-rising-threats">National Grid said it was looking to award a £1 million contract for honeypot technology</a>, and it&apos;s widely used by law enforcement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC Active Cyber Defence 2.0 refresh looks to tailor services to the security market and threat landscape ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncscs-active-cyber-defence-20-refresh-looks-to-tailor-services-to-the-evolving-security-market-and-threat-landscape</link>
                                                                            <description>
                            <![CDATA[ The NCSC plans to update its Active Cyber Defence program, introducing a refresh to keep the initiative up to date with the current threat landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mDdA2fiEPpWthnJKbw8Ns4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Aug 2024 11:34:49 +0000</pubDate>                                                                                                                                <updated>Mon, 05 Aug 2024 15:28:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:description>                                                            <media:text><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:text>
                                <media:title type="plain"><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre</a> (NCSC) has announced it will refresh its <a href="https://www.itpro.com/security/27236/national-cyber-security-centre-to-fight-hackers-with-dns-filtering">Active Cyber Defence</a> (ACD) program, with a second iteration of the initiative to help organizations stay secure in a new era of cyber threats.</p><p>The first generation of the Active Cyber Defence program was launched in 2016, seeking to reduce the harm caused by cyber criminals leveraging prepackaged malicious tools and services available on <a href="https://www.itpro.com/security/hacking/360395/number-of-hacking-tools-increasing-as-cyber-criminals-become-more-organized">underground hacking forums</a>, known as commodity attacks.</p><p>The ACD comprises a collection of technical services and capabilities aimed at tackling a large swath of the cyber threats UK organizations face everyday, providing self-service checks, <a href="https://www.itpro.com/security/29061/three-reasons-why-cyber-threat-detection-is-still-ineffective">threat detection tools</a>, and more.</p><p>The program was initially targeted specifically at developing services for the protection of government organizations.</p><p>But in its annual review for 2023, the NCSC said the ‘whole of society’ approach that defines the UK’s national <a href="https://www.itpro.com/security/cyber-security/361043/uks-upcoming-national-cyber-strategy-to-reflect-need-for-cyber">cyber strategy</a> meant it broadened the utility of ACD products and services to a wider range of users, from small business to the education sector.</p><p>The initiative also wanted to make it easier for users to find, sign up to, and manage the services provided in ACD, using its <em>My NSCS</em> platform to help bring various ACD products and services together into a single experience. </p><p>ACD 2.0 will encompass the next generation of products and services the cyber agency will provide to UK entities to help neutralize new dangers posed by a fast <a href="https://www.itpro.com/security/ransomware/life-after-lockbit-a-fragmented-landscape-and-wayward-affiliates-will-still-cause-chaos-for-enterprises">developing threat landscape</a>.</p><h2 id="ncsc-acd-2-0-will-strategically-divest-where-is-sees-the-market-stepping-up">NCSC ACD 2.0 will strategically divest where is sees the market stepping up</h2><p>The second generation of the ACD will also reflect how the NCSC is divesting in certain areas as it sees the <a href="https://www.itpro.com/640255/viasat-raps-ico-for-going-easy-on-private-sectorhttps://www.itpro.com/629068/private-sector-to-use-gchq-tech">private sector</a> catching up. </p><p>The increased availability and maturity of analogous services from private service providers means the agency can step back and focus on areas where it is uniquely positioned to provide <a href="https://www.itpro.com/security/enterprise-security/357374/trend-micro-extends-cyber-protection-for-large-scale-industrial">protection at scale</a>.</p><p>Ollie Whitehouse, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a> at the NCSC said the services included in the second generation of the ACD will be delivered where the market is not able to, be that because of the NCSC’s unique position in government, ability to scale, cyber capabilities, or authority.</p><p>“It’s important that the UK’s National Cyber Security Centre focuses its efforts where we can make a uniquely valuable contribution – where we see a gap in the commercial market, or where being part of GCHQ presents a unique opportunity to drive up resilience at scale,” he wrote in his <a href="https://www.ncsc.gov.uk/blog-post/introducing-active-cyber-defence-2">blog</a> introducing the program.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tvawFkCaNr5vdotoTDCE6Z" name="The life sciences guide to AI-driven innovations.jpg" caption="" alt="The life sciences guide to AI-driven innovations" src="https://cdn.mos.cms.futurecdn.net/tvawFkCaNr5vdotoTDCE6Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-life-sciences-guide-to-ai-driven-innovations"><em>Reinvent your business with data and AI</em></a></p></div></div><p>“The NCSC will look to divest most of our new successful services within 3 years – to another part of government or the private sector to run on an enduring basis”.</p><p>The agency will continue to work with industry partners to deliver a number of the core services offered in the ACD package, such as its attack surface management suite, comprising its Web Check, Mail Check, and Early Warning products.</p><p>Helping organizations understand and reduce their attack surface and associated vulnerabilities is one of the most efficient ways of driving up external resilience nationwide, Whitehouse stated in his blog, urging <a href="https://www.itpro.com/security/22502/why-security-vendors-need-a-red-card-during-the-world-cup">security vendors</a> with ideas for future products to get in touch with the agency.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the National Cyber Security Centre (NCSC) and what does it do? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do</link>
                                                                            <description>
                            <![CDATA[ The NCSC plays a critical role in keeping the UK safe from cyber attacks, but can also help businesses get ahead of attacks through strategic changes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9nbCkmpygLhsnZkuSZujyB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 May 2024 12:11:46 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Jun 2024 11:44:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:description>                                                            <media:text><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:text>
                                <media:title type="plain"><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Whenever you’ve heard about a cyber attack on a UK institution, be it public, private, or third sector, you’ve likely also heard that the National Cyber Security Centre (NCSC) is involved in providing support. </p><p>That’s because the center is the UK’s dedicated organization charged with protecting the country from cyber security threats. Acting as a bridge between industry and government, the NCSC provides vital security advice, support, and information on best practice for the public and private sector. </p><p>Formed to act as a ‘technical authority’ for issues related to cyber security,  the NCSC is part of GCHQ, the UK’s intelligence and security agency. The NCSC was <a href="https://www.itpro.com/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre"><u>formally established in 2016</u></a>, absorbing existing organizations such as the Computer Emergency Response Team (CERT-UK) and Communications-Electronic Security Group (CESG).</p><p>Since then, the NCSC’s responsibilities and scope have expanded significantly, largely due to the continually escalating <a href="https://www.itpro.com/security/ransomware/life-after-lockbit-a-fragmented-landscape-and-wayward-affiliates-will-still-cause-chaos-for-enterprises">cyber threat landscape</a> that UK businesses and organizations are forced to contend with. </p><p>Here’s everything you need to know about the NCSC. </p><h2 id="what-does-the-ncsc-do">What does the NCSC do?</h2><p>By <a href="https://www.ncsc.gov.uk/section/about-ncsc/what-we-do" target="_blank"><u>its own definition</u></a>, the NCSC provides a “single point of contact” for small businesses, large enterprises, government agencies, and the general public for all cyber-security-related issues or incidents. </p><p>When a UK organization falls victim to a cyber attack, the NCSC provides critical <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response</a> support to help alleviate the impact of an incident, coordinating with the affected business, law enforcement, and other UK authorities to assist with recovery. </p><p>This support is provided through the Cyber Incident Response (CIR) scheme, originally aimed at assisting organizations operating in <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>critical national infrastructure (CNI)</u></a>. It has since been <a href="https://www.itpro.com/security/ncsc-expands-incident-response-scheme-to-support-smaller-at-risk-organizations"><u>expanded to include support for smaller enterprises</u></a>. </p><p>With <a href="https://www.itpro.com/security/cyber-crime/cyber-crime-cost-uk-businesses-more-than-pound30-billion-in-2023-and-small-businesses-were-among-the-worst-hit"><u>small businesses and charities ranked among the most targeted organizations</u></a> in the UK, the NCSC has expanded the scope of this program to provide more comprehensive support. <a href="https://www.itpro.com/security/ransomware/why-ransomware-attacks-happen-to-small-businesses-and-how-to-stop-them"><u>Ransomware attacks against small businesses</u></a> by groups such as <a href="https://www.itpro.com/security/ransomware/lockbit-leader-revealed-what-it-means-for-ransomware"><u>LockBit</u></a> are specifically <a href="https://www.itpro.com/security/ransomware/ransomware-groups-are-once-again-targeting-smaller-businesses-for-more-lucrative-payouts"><u>on the rise</u></a> and the NCSC has demonstrated a focus on alleviating this threat.</p><p>Recent instances of this support include the <a href="https://www.itpro.com/security/british-library-cyber-attack-fallout-highlights-public-sector-security-weaknesses"><u>British Library ransomware attack</u></a>, which saw the NCSC provide response and advice. </p><h2 id="ncsc-training-schemes">NCSC training schemes</h2><p>The agency provides more than just incident response support. A key focus for the NCSC centers around proactive actions to protect institutions across the country. </p><p>This includes the publication of frequent threat advisories aimed at providing vital information for businesses to stay ahead of the curve and defend themselves. IN 2024 alone, the NCSC has published <a href="https://www.itpro.com/cloud/cloud-security/state-linked-threat-actors-are-ramping-up-attacks-on-cloud-services-heres-what-you-need-to-know"><u>advisories on state-linked threat actors</u></a>, so-called <a href="https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks"><u>‘living off the land attacks’</u></a>, and <a href="https://www.itpro.com/security/cyber-attacks/security-agencies-warn-of-heightened-threat-to-critical-national-infrastructure"><u>attacks against CNI</u></a>. </p><p>The agency also provides best practice advice for businesses of all sizes across the UK. For example, the NCSC’s <a href="https://www.itpro.com/security/ransomware/what-you-need-to-know-about-the-new-ncsc-ransomware-guidance"><u>recent ransomware guidance</u></a> urges organizations to <a href="https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight"><u>cease ransomware payments</u></a> to remove the incentive for threat actors to conduct these attacks.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=60068497&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>In addition to its reactive and advisory roles, the NCSC provides educational programs to arm workers with the knowledge to spot and counter cyber threats. This includes its <a href="https://www.ncsc.gov.uk/information/certified-training"><u>NCSC Certified Training</u></a> program, which offers skills training for professionals already working in – or just joining – the cyber security industry. </p><p>The NCSC runs practical training too, such as the <a href="https://www.ncsc.gov.uk/information/exercise-in-a-box"><u>Exercise in a Box</u></a> scheme. This free-to-use exercise allows organizations to test their <a href="https://www.itpro.com/security/seven-things-every-chief-exec-needs-to-know-in-the-event-of-a-cyber-attack"><u>response to a cyber attack</u></a> and fine-tune their processes in the event of an incident. </p><p>In December 2023, the <a href="https://www.itpro.com/security/ncsc-cyber-incident-exercising-scheme-looks-to-fine-tune-incident-response"><u>NCSC expanded this program</u></a> in collaboration with CREST and certification organization, IASME. The Cyber Incident Exercising scheme gives users access to approved service providers from the security industry and provides bespoke, real-time cyber incident exercises. </p><h2 id="supporting-the-cyber-workforce-of-the-future">Supporting the cyber workforce of the future</h2><p>With the UK contending with the well-publicized <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing"><u>cyber security skills shortage</u></a>, the NCSC has become a leading voice in the drive to encourage young people to take up careers in the industry. </p><p>This includes the <a href="https://www.itpro.com/national-cyber-security-centre-ncsc/34640/exciting-expansion-on-the-horizon-for-girls-cyber-security"><u>CyberFirst program</u></a>, which aims to support students aged 11-17 to develop computing science and cyber skills with bursaries, free courses, and competitions. </p><p>According to the NCSC, this program “provides opportunities for young people to explore their passion for tech by introducing them to the fast-paced world of cyber security”. </p><p>The NCSC also runs the <a href="https://www.itpro.com/business-strategy/careers-training/358601/scottish-pupils-strong-showing-cyberfirst"><u>CyberFirst Girls competition</u></a>, a competition for schoolgirls aged 12-13 intended to encourage more girls to aim for careers in tech and improve the share of <a href="https://www.itpro.com/business/careers-and-training/women-in-cyber-security-closing-the-gender-divide"><u>women in cyber security</u></a> in the long term.</p><h2 id="who-leads-the-ncsc">Who leads the NCSC?</h2><p><a href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni"><u>Ciaran Martin</u></a> served as the first chief executive of the NCSC upon its formation in 2016. Martin had previously served as director of security and intelligence at the UK Cabinet Office from 2008-2011 and head of cyber security at GCHQ, a position from which he advocated for the creation of the NCSC. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sa9dAsAFwtdAiiPrUQkz2X" name="Driving Employee Experience and Productivity across Industries.jpg" caption="" alt="Man working on his desk" src="https://cdn.mos.cms.futurecdn.net/sa9dAsAFwtdAiiPrUQkz2X.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/iaas/driving-employee-experience-and-productivity-across-industries"><em>Discover how monitors impact employee productivity</em></a></p></div></div><p>Throughout his tenure as CEO at NCSC, Martin oversaw the establishment of many of the programs and procedures the agency follows today and saw the UK’s cyber security preparedness ranking raised to first in the International Telecommunications Union (ITU)’s yearly index.</p><p>Martin left in August 2020 and has since <a href="https://www.itpro.com/security/cyber-attacks/369375/ncsc-founder-regrets-underestimating-organised-cyber-crime"><u>expressed regret</u></a> over the NCSC’s initial focus on <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored cyber attacks</u></a> at the expense of tackling organized cyber crime.</p><p>Since then, the agency has had several CEOs. <a href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/356598/ncsc-appoints-lindy-cameron-as-new-ceo"><u>Lindy Cameron succeeded Martin in 2020</u></a> and during her time in the role highlighted the immediate <a href="https://www.itpro.com/security/ransomware/361201/ransomware-presents-the-most-immediate-danger-to-the-uk-warns-ncsc-ceo"><u>threat ransomware poses to the UK</u></a> and how <a href="https://www.itpro.com/security/ncsc-ai-will-increase-speed-and-scale-of-critical-infrastructure-attacks"><u>AI could increase the speed of CNI attacks</u></a>.  </p><p>After Cameron announced her departure in December 2023, the post was filled by interim CEO Felicity Oswald, who continues to hold the role ahead of <a href="https://www.itpro.com/security/ncsc-appoints-new-ceo"><u>new chief executive Richard Horne</u></a> taking the reins in the autumn of 2024.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC CTO says what everyone is thinking about software security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/the-ncscs-cto-just-said-what-is-thinking-about-software-security</link>
                                                                            <description>
                            <![CDATA[ UK tech firms are building secure software products, but the current state of the market means they're not fully rewarded for doing so ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8Nq5gu9ukQk2nFmPbFmYej</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 May 2024 13:00:16 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 12:46:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:description>                                                            <media:text><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:text>
                                <media:title type="plain"><![CDATA[Digitized padlock with binary code placed over a circuit board signifying secure software development and security pratices.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2GhNhXCSPdGYMPqCL4uMS9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK tech sector is failing to incentivize companies to build and roll out secure software products, according to NCSC chief technology office Ollie Whitehouse. </p><p>In a keynote address at the <em>CYBERUK</em> conference in Birmingham, Whitehouse highlighted the steep rise in <a href="https://www.itpro.com/software/development/new-secure-software-development-rules-mean-us-tech-execs-will-have-to-sign-safety-guarantees">software product vulnerabilities</a> in recent years, warning that the scale of the issue is placing businesses and individuals across the country at risk.</p><p>But the current state of the market means that companies building resilient products aren’t fully rewarded for their efforts. Firms across the country “know how to design and build resilient, secure technology,” he said, but the next key focus must be to build a market that “supports and rewards it”.</p><p>"We have security products which contain vulnerability classes that we have known about for over 70 years or 24 years, depending on how you count them, being discovered and exploited in our edge perimeters in 2024.</p><p>"For the last four years, the numbers of &apos;22 to &apos;23, we saw a 14% increase in disclosed vulnerabilities, bringing us to 29,000 but in addition to that what we saw was 40,000 vulnerabilities registered, which is also similarly a 14% increase."</p><p>Whitehouse described what he called a ‘thousand Band-Aid’ approach to cyber security - the tendency for organizations to layer sticking plasters over security cracks in an attempt to address technical debt. For the UK to become a truly cyber resilient nation, that approach needs to fundamentally change, he said.</p><p>Concerningly, Whitehouse warned that current legal frameworks are not keeping up with the pace of technological change, and is likely never to do so.</p><p>He called for developers to be honest about the profound challenges they are facing, in order to develop products and services that are fit for purpose and for a resilient future.</p><p>"The world is changing, fast, and we are facing a fundamental challenge: we don’t have the evidence for how to build a resilient country writ large," he said.</p><p>"The challenges ahead of us are the horse-sized ducks of states with strategic intentions, and the duck-sized horses of criminal actors out for financial gain. And the reality is that we don’t get to choose which one we’d rather counter, because we have to be able to face both with confidence."</p><h2 id="candid-remarks-welcomed-by-industry">Candid remarks welcomed by industry</h2><p>Gareth Pritchard, CTO at security firm Sapphire, welcomed Whitehouse’s comments, adding that if boards continue to only see cyber as a ‘one and done’ transformation program, commercial market forces won’t fix the lingering <a href="https://www.itpro.com/business/digital-transformation/it-leaders-need-to-accept-theyll-never-escape-technical-debt-but-that-doesnt-mean-they-should-down-tools">technical debt</a> and problems cited in his keynote. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x2wBwuD5AyBXVM42w9cj8W" name="Sustainable devices for positive impact_listing.jpg" caption="" alt="Whitepaper cover with top image of trees and blue screen from the ground looking up" src="https://cdn.mos.cms.futurecdn.net/x2wBwuD5AyBXVM42w9cj8W.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell Technologies)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/sustainable-devices-for-positive-impact"><em>Push for sustainability in your organization</em></a></p></div></div><p>There must be a steadfast focus on cyber security as a cultural foundation for businesses of all shapes, sizes and sectors, Pritchard noted.</p><p>"Taking an evidence-based approach to <a href="https://www.itpro.com/security">security</a> whilst implementing good security hygiene is vital to our continued fight against cyber threats," he said.</p><p>"We all must take on the challenge posed by Ollie as it is through collaboration and collective action that we will drive the market to make <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> a core foundation of our business operations, products, and services that we all rely on.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What you need to know about the new NCSC ransomware guidance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/what-you-need-to-know-about-the-new-ncsc-ransomware-guidance</link>
                                                                            <description>
                            <![CDATA[ The new ransomware guidance from the NCSC has been developed in collaboration with major insurance bodies, and warns against paying up in the event of an attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">E3TU6SaJeQ3S6DVcXDsRPH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 May 2024 10:05:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:description>                                                            <media:text><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:text>
                                <media:title type="plain"><![CDATA[A logo is displayed on a television screen in the National Cyber Security Centre (NCSC) on February 14, 2017 in London, England]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QyZfGkLbNUbuuxodAzsuFU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Centre (NCSC) has teamed up with insurance bodies to try and reduce the amount being paid by <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> victims.</p><p>Concerned that too many <a href="https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight">organizations are paying ransoms</a>, the NCSC, along with GCHQ and the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and International Underwriting Association (IUA), said they want their guidance to help victims make informed decisions.</p><p>Considerations include the thorough assessment of business impact, reporting protocols, and where to access sources of support.</p><p>"The NCSC does not encourage, endorse or condone paying ransoms, and it’s a dangerous misconception that doing so will make an incident go away or free victims of any future headaches. In fact, every ransom that is paid signals to criminals that these attacks bear fruit and are worth doing," said NCSC CEO Felicity Oswald.</p><p>"This cross-sector initiative is an excellent next step in foiling the ransom business model: we’re proud to support work that will see cyber criminals’ wallets emptier and UK organizations more resilient."</p><p>Ransomware remains the biggest day-to-day cyber security threat to UK organizations, and the number of attacks is rising, the agency warned. Paying a ransom doesn&apos;t guarantee the end of an incident nor the removal of malicious software from victims’ systems.</p><p>However, it does provide incentives for criminals to continue and expand their activities. Even following payments, cyber criminal groups will lie about having deleted the data, the guidance points out.</p><p>The NCSC advises reviewing all the options - including not paying, keeping careful records of decision-making, and where possible consulting experts as well as staff.</p><p>Victims should assess the impact on business operations and data, as well as the financial implications, and should investigate the root cause of the incident to avoid a repeat attack.</p><p>If organizations do pay up, they should make sure it&apos;s legal to do so, and should be aware that paying a ransom does not fulfill their regulatory obligations. Similarly, they must make sure they report the incident to the authorities.</p><h2 id="ncsc-guidance-welcomed-by-industry">NCSC guidance welcomed by industry</h2><p>Helen Dalziel, IUA director of public policy, said that the payment of ransoms in response to <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> is on a downward trend globally.</p><p>"Businesses are realizing that there are alternative options and this guidance further illustrates how firms can improve their operational resilience to resist criminal demands," she commented.</p><p>Raghu Nandakumara, head of industry solutions at security firm Illumio, said he welcomes the advice, adding he&apos;d like to see more guidance to help businesses build resilience and contain attacks.</p><p>"More often than not, recovery plans are inadequate or have not been properly tested, which makes them unviable when a real incident does occur. As a result, organizations are left with no choice but to pay the ransom to restore operations and productivity levels as quickly as possible," he said.</p><p>"The NCSC should encourage businesses to adopt an ‘assume attack’ mindset. This is not admitting defeat - instead it focuses on preparing to respond effectively to a cyber incident and building resilience."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is hackbot as a service and are malicious LLMs a risk? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk</link>
                                                                            <description>
                            <![CDATA[ As threat actors begin to use malicious chatbots, hackbot as a service groups are helping affiliates launch tailored attacks via subscription ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">coL7zwZtofgEvqeFSkjCmL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kx7LDWje6sTgxesFZVxQZV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 May 2024 12:17:26 +0000</pubDate>                                                                                                                                <updated>Thu, 09 May 2024 16:56:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kx7LDWje6sTgxesFZVxQZV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An orange, fragmented digital avatar representing hackbots and the hackbot as a service model. Hexagonal lens flares and strands representing connections with users are splintering around the avatar.]]></media:description>                                                            <media:text><![CDATA[An orange, fragmented digital avatar representing hackbots and the hackbot as a service model. Hexagonal lens flares and strands representing connections with users are splintering around the avatar.]]></media:text>
                                <media:title type="plain"><![CDATA[An orange, fragmented digital avatar representing hackbots and the hackbot as a service model. Hexagonal lens flares and strands representing connections with users are splintering around the avatar.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kx7LDWje6sTgxesFZVxQZV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The explosion of interest in <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> since 2022 has not been limited to those with pure intentions, with many in the sector now warning that threat actors are adopting malicious <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today"><u>LLMs</u></a> or ‘hackbots’ via subscription.</p><p>Threat actors have been just as eager to leverage <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today"><u>AI tools</u></a> in their attack chains as defenders have in their security stack, raising the importance of a <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks"><u>concrete strategy for AI threats</u></a> among security teams.</p><p>The UK’s <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> has claimed AI, “will almost certainly increase the volume and heighten the impact of cyber attacks over the next two years” in a <a href="https://www.ncsc.gov.uk/report/impact-of-ai-on-cyber-threat" target="_blank"><u>report</u></a> released in January 2024.</p><p>Hackers have already been using LLMs to refine <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> attacks, matching the tone and style of an executive for <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> or using <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected"><u>deepfake attacks</u></a> to circumvent identity systems.</p><p>Vasu Jakkal, corporate vice president of security at Microsoft, has taken to the stage at RSA Conference 2024 to warn that AI is already being used to <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>crack passwords</u></a> and linked the availability of the technology to a 10x increase in <a href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them"><u>identity-based attacks</u></a>.</p><p>Experts have also suggested that chatbots could be used to create bespoke <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> strains. Publicly available models like ChatGPT and Gemini have anti-blackhat guardrails built in to prevent them from being used to produce malicious content, but hackers have been able to bypass many of these protections through <a href="https://www.itpro.com/security/jailbreaking-chatgpt-researchers-swerved-gpt-4s-safety-guardrails-and-made-the-chatbot-detail-how-to-make-explosives-in-scots-gaelic"><u>sophisticated prompt engineering</u></a> techniques.</p><p>But recent research suggests that publicly-available LLMs are <a href="https://www.itpro.com/security/ais-use-as-a-hacking-tool-has-been-overhyped"><u>largely unable to exploit vulnerabilities</u></a>, with only OpenAI’s GPT-4 having been able to produce <a href="https://www.itpro.com/security/zero-day-exploits-how-risky-are-they-for-businesses"><u>exploits</u></a> for known flaws. These limitations appear to have fed into the production of bespoke, malicious <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-difference"><u>chatbots</u></a> designed specifically to assist threat actors with their nefarious activities. </p><h2 id="wormgpt-and-fraudgpt-x2013-the-birth-of-hackbot-as-a-service">WormGPT and FraudGPT – the birth of hackbot as a service</h2><p>These tools are being advertised on marketplaces and forums across the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a>, and are available for threat actors to rent as and when they need them to enhance their attacks, spawning the hackbot as a service model.</p><p>Cyber security specialists Trustwave SpiderLabs published a <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/wormgpt-and-fraudgpt-the-rise-of-malicious-llms/" target="_blank"><u>blog</u></a> in August 2023 outlining the rise of malicious LLMs being pushed on underground message boards across the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>.</p><p>One such malicious LLM, WormGPT, was first discovered being touted on popular hacking platforms hosted on the dark web in June 2021, according to Trustwave’s research. Another is FraudGPT, first discovered by threat researchers at Netenrich being circulated on Telegram in July 2023.</p><p>Both of these tools allow attackers to design assets used in social engineering attacks such as phishing emails, deepfakes, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369857/microsofts-valle-cyber-crime-deepfakes"><u>voice cloning</u></a>, and more but their creators claim their real value comes in <a href="https://www.itpro.com/security/cyber-attacks/top-12-most-exploited-security-vulnerabilities-revealed-by-national-cyber-security-agencies"><u>exploiting vulnerabilities</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cR79xdx35hpP8v9w73TdbQ" name="Customer Experience (CX) Trends (1).jpg" caption="" alt="Woman's hand touch a laptop screen" src="https://cdn.mos.cms.futurecdn.net/cR79xdx35hpP8v9w73TdbQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/customer-experience-cx-trends"><em>An overview of the current state of CX</em></a></p></div></div><p>Hackers can feed code pertaining to a specific vulnerability into these malicious models, which in theory could produce a number of <a href="https://www.itpro.com/security/poc-exploits-for-jenkins-vulnerability-are-being-targeted-in-the-wild-researchers-reveal"><u>proof of concept (PoC) exploits</u></a> for an attacker to try.</p><p>Speaking to <em>ITPro </em>Jack Peters, customer solutions architect at cloud services company M247, describes the recent surge in these types of tools and how they can be used to assist in cyber attacks.</p><p>“Using the same user-friendly prompts akin to other generative AI chatbots, ‘FraudGPT’ and other tools are flooding the dark web, allowing hackers to take similar shortcuts to create malware, malicious code, and phishing emails to steal data and create havoc for businesses”, Peters explained.</p><p>“As with any sophisticated language model, one of FraudGPT’s biggest strengths is its ability to produce convincing emails and documents in order to gain access to a business’ systems.”</p><p>These tools are available through underground marketplaces on the dark web where hackers can pay for a monthly license to use the hackbot. In this sense, they are similar to the <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service (RaaS)</a> model, which experts have directly linked to the <a href="https://www.itpro.com/security/ransomware/the-big-three-ransomware-groups-are-losing-their-grip-on-the-industry-as-gangs-begin-to-fracture-study-shows">diversified ransomware industry</a> that plagues businesses today.</p><p>The research from Trustwave listed the price range for a monthly subscription for FraudGPT as between $90 and $200, whereas the first version WormGPT is available for €100 per month. </p><p>Several new malicious LLMs have entered the market since the arrival of WormGPT, including BlackHatGPT, XXXGPT, WolfGPT, and more, forming a new segment of the cyber black market.</p><h2 id="a-blackhat-alternative-to-chatgpt-but-are-they-really-worth-it">A blackhat alternative to ChatGPT, but are they really worth it?</h2><p>Trustwave’s research attempted to test the efficacy of these tools by comparing the outputs of the hackbots to those produced by a legitimate chatbot.</p><p>The results showed that with the right prompts, ChatGPT could be made to produce some <a href="https://www.itpro.com/software/development/python-stretches-its-lead-as-the-most-popular-programming-language-but-why-does-it-have-such-widespread-appeal"><u>Python</u></a> malware. But users had to first claim the code was to be used for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat</a> purposes and before it could be deployed the output code required further tweaking.</p><p>Ultimately, ChatGPT was able to produce a malicious Python script to the same requirements as WormGPT, but ChatGPT included a disclaimer urging the user to “use this script responsibly” etc. </p><p>In a similar fashion, ChatGPT is also able to create very realistic exchanges that could be used for phishing but the prompts required to produce these outputs need to be very specific. In most circumstances, ChatGPT will refuse to comply with malicious requests.</p><p>As such, these malicious chatbots may simply offer cyber criminals an easier route to using AI for attacks compared to spending time trying to jailbreak their instance of ChatGPT or craft the phishing page or malware they require.</p><p>Etay Maor, senior director of security strategy at Cato Networks, tells <em>ITPro </em>he had doubts about the coding capabilities of these tools early on, citing the Python code included in the listing for WormGPT.</p><p>“I’m not impressed with the example that they gave here of a Python script that knows how to create a DDoS attack," Maor says. "Looking at this, it is pretty lame, I don’t know who it’s supposed to impress”.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=59776785&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Camden Woollven, group head of AI at GRC International Group, expresses similar skepticism and argues that the adversarial capabilities of these tools do not appear to be vastly superior to anything proficient hackers can already achieve.</p><p>“From what I can tell, these tools seem to be fairly rudimentary – generating simple malware code, phishing schemes, stuff a decent hacker could pull off without an AI assistant,” Woollven tells <em>ITPro</em>.</p><p>“There’s an element of ‘overhype’ at play, as seems to be the case with anything AI-related.”</p><p>Cyber criminals themselves have expressed their discontent with the capabilities of these tools. Reviews for WormGPT contain frequent complaints about the tool’s limited functionality, with some threat actors even having accused the developer behind the hackbot of operating a scam.</p><p>One review warns would-be users that the tool is "just an old cheap version of ChatGPT", adding that it was just as restrictive as the original version of the chatbot.</p><h2 id="hackbot-as-a-service-as-a-shortcut-for-cyber-attacks">Hackbot as a service as a shortcut for cyber attacks</h2><p>Despite their limited malicious credentials, Maor believes the real threat posed by these rudimentary hackbots is that they can significantly reduce the time and work a threat actor needs to put in to launch a high volume of effective attacks.</p><p>Even if the success rate of attacks based on hackbot outputs is the same or lower than those completely crafted by human attackers, the improved consistency and volume of attacks backed by AI could nevertheless drive up the success rates of threat actors. Hackbot as a service can therefore be a tempting value proposition for attackers looking for a leg up in what is an increasingly <a href="https://www.itpro.com/security/ransomware/the-big-three-ransomware-groups-are-losing-their-grip-on-the-industry-as-gangs-begin-to-fracture-study-shows"><u>competitive</u></a> space.</p><p>Maor says he is particularly concerned that hackbot as a service models could lower the barrier to entry for cyber crime for individuals who would have previously lacked the <a href="https://www.itpro.com/business/careers-and-training/why-is-computer-literacy-still-an-issue-in-2023">digital literacy</a> to launch a cyber attack.</p><p>Simple attacks are likely to become easier for the scammers to pull off, while skilled hackers could see the scope of their capabilities increase dramatically when paired with malicious LLMs.</p><p>“Yes, it does lower the barrier for threat actors to do more and it makes life easier for those who are already proficient,” Maor explains.</p><p>This is a nascent market with new threats appearing all the time. In March, Maor published a <a href="https://www.catonetworks.com/blog/wanted-brilliant-ai-and-experts-needed-for-cyber-criminal-ring/">blog post</a> detailing a callout from a Russian group looking for engineers with a foundation in <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning (ML)</a> and AI to help them develop a malicious LLM.</p><p>Maor provides two reasons why he thinks the LLM in question, xGPT, could pose a far more serious threat to enterprises than WormGPT or similar ChatGPT variants:</p><p>“First, this is a known threat actor that has already sold credentials and access to US government entities, banks, mobile networks, and other victims,” he tells <em>ITPro</em>. “Second, it looks like they are not trying to just connect to an existing LLM but rather develop a solution of their own.”</p><p>As the hackbot as a service underground matures, businesses will need to carefully assess the protections they have in place. Strong <a href="https://www.itpro.com/technology/artificial-intelligence/what-good-ai-cyber-security-looks-like-today"><u>AI security systems</u></a> may become more necessary to counter the threat posed by corrupted LLMs, and controls such as <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity management</u></a> tools will be a boon against tailored social engineering attempts.</p><p>The efficacy of these tools is still in debate, but as security teams see with more and more advanced <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>strains of ransomware</u></a> there is always the potential for criminals to innovate at a pace approaching that of legitimate developers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security agencies warn of heightened threat to critical national infrastructure ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/security-agencies-warn-of-heightened-threat-to-critical-national-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The NCSC and CISA say that pro-Russia hacktivists are targeting under-protected industrial control systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ojLa3bMmXChk2Fk9wdFTkX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 May 2024 10:06:15 +0000</pubDate>                                                                                                                                <updated>Fri, 03 May 2024 10:06:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing digitized cloud symbol on a circuit board with data flowing out of the cloud.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYTQnscZmBWjF97ciGDC9T-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK and US authorities are warning that pro-Russian hacktivists have been targeting vulnerable, small-scale industrial control systems (ICS) in North America and Europe.</p><p>The UK’s National Cyber Security Centre (NCSC) and US Cybersecurity and Infrastructure Security Agency (CISA) say victims have seen &apos;some limited physical disruption&apos; to operations.</p><p>"The pro-Russia hacktivist activity appears mostly limited to unsophisticated techniques that manipulate ICS equipment to create nuisance effects," CISA said in an advisory.</p><p>"However, investigations have identified that these actors are capable of techniques that pose physical threats against insecure and misconfigured OT environments."</p><p>The <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivists</a> have targeted industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including water and wastewater systems, dams, energy, and food and agriculture.</p><p>The NCSC added that while they often align to Russian government interests, this isn&apos;t always the case - making them less predictable.</p><p>"While the cyber activity of these groups often focuses on DDoS attacks, website defacements and/or the spread of misinformation, some have stated a desire to achieve a more disruptive and destructive impact against western critical national infrastructure (CNI), including in the UK," the NCSC warned.</p><p>"We expect these groups to look for opportunities to create such an impact, particularly if systems are poorly protected."</p><p>The hackers&apos; techniques involve manipulating ICS equipment to create nuisance effects. However, CISA said its investigations have revealed they can also pose physical threats against insecure and misconfigured OT environments.</p><p>They have been spotted gaining remote access by exploiting publicly exposed internet-facing connections and outdated <a href="https://www.itpro.com/mobile/remote-access/368108/what-is-vnc">virtual network computing</a> (VNC) software, as well as by using the factory default passwords of human machine interfaces (HMIs) and <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">weak passwords</a>, without multifactor authentication.</p><p>Similarly, they’ve been able to alter the settings for water pumps and blower equipment to make them exceed their normal operating parameters, and were also able to max out set points, alter other settings, turn off alarm mechanisms, and change administrative passwords to lock out the WWS operators.</p><p>But while some victims experienced minor tank overflows, most victims reverted to manual controls in the immediate aftermath and were able to quickly restore operations.</p><p>"Without external assistance, we consider it unlikely that these groups have the capability to deliberately cause a destructive, rather than disruptive, impact in the short term," said the NCSC.</p><p>"But they may become more effective over time, and so the NCSC is recommending that organizations act now to manage the risk against successful future attacks."</p><p>Organizations should take immediate steps to improve their <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> capabilities, according to security experts, by following official guidance for heightened <a href="https://www.itpro.com/security">security</a> threats and advice on secure system administration.</p><p>"Cyber resilience should be the top priority for the NCSC, government and businesses, underpinning comprehensive cyber defense measures to combine reactive, preventative and recovery procedures," said Achi Lewis, area VP EMEA for Absolute Security.</p><p>"With cyber attacks being a case of when, not if, particularly when it comes to critical national infrastructure, it is vital that organizations ensure their endpoint devices are best protected against threats to best mitigate the threat and impact of a breach."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC appoints new CEO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-appoints-new-ceo</link>
                                                                            <description>
                            <![CDATA[ Richard Horne will join the organisation from PwC, where he currently chairs the company's cyber security practice ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lrjr4ud5dAYRDfERVP6Exi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mxa4MjpRrkEMJ948C9JDCo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Apr 2024 13:55:44 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Apr 2024 16:04:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mxa4MjpRrkEMJ948C9JDCo-1280-80.jpg">
                                                            <media:credit><![CDATA[National Cyber Security Centre (NCSC)]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A head and shoulders photo of Richard Horne, the new CEO of the NCSC]]></media:description>                                                            <media:text><![CDATA[A head and shoulders photo of Richard Horne, the new CEO of the NCSC]]></media:text>
                                <media:title type="plain"><![CDATA[A head and shoulders photo of Richard Horne, the new CEO of the NCSC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mxa4MjpRrkEMJ948C9JDCo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> has appointed Richard Horne as its new CEO, taking over from Lindy Cameron later this year.</p><p>As well as leading the NCSC, the UK’s national technical authority for <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>, he will also become a board member of the UK’s spy agency, <a href="https://www.itpro.com/tag/gchq">GCHQ</a>.</p><p>His mission, he said, will be to increase the UK’s cyber resilience, particularly in light of future technology challenges such as <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> and <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a>. He will also seek to make sure the NCSC can carry on managing the most critical cyber incidents affecting the UK.</p><p>"It is an honour to become CEO of the NCSC. Over the seven years since its establishment, the NCSC has repeatedly shown its world-leading understanding of technology and its unparalleled knowledge of the cyber threat we face in the UK," says Horne. </p><p>"I’m incredibly honoured and excited about leading a globally recognised organisation, its world class experts and leaders into the future whilst helping ensure that our mission is realised."</p><p>Unlike his predecessors, who both had a background in civil service, Horne has spent most of his professional life in cyber <a href="https://www.itpro.com/security">security</a>. Currently, he chairs the cyber security practice at PWC and before that he was managing director of cyber security for Barclays. It was in that role that he got his first taste of working in the public sector when, in 2011, he was seconded to the Cabinet Office. There he helped shape and drive the government’s <a href="https://www.itpro.com/637555/government-publishes-cyber-security-strategy">first Cyber Security Strategy</a> across government and the wider economy.</p><p>Horne holds a PhD in Mathematics and Cryptography from Royal Holloway, University of London, and has served on a number of advisory boards for academic institutions and cyber security <a href="https://www.itpro.com/business-strategy/startups/357974/so-you-want-to-work-for-a-tech-startup-its-not-all-ping-pong">startup</a> companies.</p><p>"I’m delighted that Richard Horne will become the next CEO of the NCSC. He brings with him a wealth of experience working with major companies and organisations to help them understand and manage their cyber security and respond to incidents when they occur," says GCHQ director Anne Keast-Butler. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GucKFGYi4KhzmTQ5VqSnBn" name="AMD Ryzen™ PRO processors and Windows 11 Pro.jpg" caption="" alt="AMD Ryzen™ PRO processors and Windows 11 Pro" src="https://cdn.mos.cms.futurecdn.net/GucKFGYi4KhzmTQ5VqSnBn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AMD)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/amd-ryzentm-pro-processors-and-windows-11-pro"><em>Unlock the power of AI</em></a></p></div></div><p>"Richard’s experience will ensure the NCSC continues to drive cyber security up the boardroom agenda and develop its world-leading partnerships to address the cyber security threats that the UK faces."</p><p>Recent initiatives from the NCSC include the release of <a href="https://www.itpro.com/security/ncsc-launches-new-cyber-guidance-for-smbs-as-threats-continue-to-surge"><u>new cyber guidance</u></a> for small and medium businesses on how to use cloud and online services more securely, with practical advice on basic security measures that small businesses can readily use.</p><p>Earlier this year, it issued an invitation to security professionals to sign up as members of its new <a href="https://www.itpro.com/security/inside-the-ncscs-plan-to-create-a-national-threat-tracking-a-team"><u>Cyber League initiative</u></a>. The group will work with NCSC analysts to share their specialist knowledge and understanding of the threat landscape to develop techniques and strategies to counter cyber attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SCADA is heading to the cloud — here's why security experts are worried ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/scada-is-heading-to-the-cloud-heres-why-security-experts-are-worried</link>
                                                                            <description>
                            <![CDATA[ SCADA systems are increasingly migrating to cloud environments, but the NCSC worries security is often an afterthought ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q7YVh4iDaFr7mfeS8zPKWb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NaiGBURS97tX5xnCYwTUt3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 Mar 2024 08:45:55 +0000</pubDate>                                                                                                                                <updated>Wed, 27 Mar 2024 15:31:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NaiGBURS97tX5xnCYwTUt3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT technician operating a SCADA industrial control system at a computer station.]]></media:description>                                                            <media:text><![CDATA[IT technician operating a SCADA industrial control system at a computer station.]]></media:text>
                                <media:title type="plain"><![CDATA[IT technician operating a SCADA industrial control system at a computer station.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NaiGBURS97tX5xnCYwTUt3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NCSC has issued guidance for organizations moving SCADA (Supervisory Control and Data Acquisition) systems into the cloud, as more companies are considering the shift.</p><p>These systems are used for running and monitoring industrial systems and processes everywhere from power stations to factory assembly lines and wind farms.</p><p>SCADA industrial control systems have been around for decades, but were rarely connected to the open internet, which kept them relatively protected from attack.</p><p>In recent years however, these systems have been connected to the internet to make them easier to access. With this shift, the NCSC believes there is evidence of a clear change in attitudes towards using <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a> for these industrial applications.</p><p>“Where this has previously been a commonly dismissed topic due to the potential risks, many operational technology (OT) organizations are now looking to the cloud for solutions,” the security agency said. Operational technology refers to any hardware or software that runs or monitors industrial systems.</p><p>As a result, the NCSC has published new guidance on cloud-hosted SCADA systems, and said that <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> should be a key consideration.</p><p>The agency said it would not dictate whether the cloud was the right or the wrong approach - but said cloud-hosted SCADA has some “unique” risks.</p><p>“The current state of play in OT can make the path to securely implementing a cloud migration challenging,” the NCSC warned.</p><p>Keeping SCADA systems safe is a particular concern because they often form the basis for control across critical national infrastructure (CNI) and other cyber-physical systems.</p><p>That means hacking into and meddling with a SCADA system can have dangerous real-world consequences, something that governments have been worried about for a number of years.</p><p><a href="https://www.itpro.com/cyber-attacks/32391/its-now-impossible-to-protect-critical-uk-infrastructure-from-cyber-attack">Critical infrastructure is at constant risk of targeted cyber attack</a>, something that’s increased in the last couple of years. Last year, the NCSC warned that hackers backed by China have been making efforts to target critical infrastructure in the UK and elsewhere.</p><p>“This persistent and elevated threat means cyber security needs to be at the forefront of all decisions in both CNI and wider cyber-physical systems, and you should understand the challenges that a shift to the cloud will involve,” the NCSC said.</p><h2 id="protecting-scada-systems">Protecting SCADA systems</h2><p>The guidance lists some of the key considerations for moving SCADA into the cloud.</p><p><br></p><p>Large industrial control systems are often put in place for 20 or more years. While a cloud migration project means a chance to re-think those systems and make them more secure, it can also introduce risks by exposing <a href="https://www.itpro.com/business/digital-transformation/legacy-it-infrastructure-accounts-for-more-than-a-third-of-enterprise-power-consumption-and-its-creating-a-sustainability-nightmare-for-it-leaders">legacy infrastructure</a> to external threats it was never designed to deal with.</p><p>SCADA systems were often designed to be ‘air-gapped’, disconnected from the public internet and broader enterprise networks.</p><p>The agency also warned that firms need to consider how critical functions would be recovered in the event of a cloud (or cloud connectivity) outage.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yiGvFdMfu4ZLjGahuS4tsB" name="Phish in a Barrel (1).jpg" caption="" alt="Illustration of a person working at a desk with a laptop open" src="https://cdn.mos.cms.futurecdn.net/yiGvFdMfu4ZLjGahuS4tsB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/phish-in-a-barrel"><em>Learn more about users’ dual role as top targets for attackers and frontline defenders</em></a></p></div></div><p>“As with safety critical functions, organizations will need to consider break glass recovery solutions to ensure local control can be regained,” it said.</p><p>“<a href="https://www.itpro.com/cloud/cloud-computing/inside-lambeth-councils-cost-cutting-cloud-migration">Cloud migration</a> should not be executed in isolation, and needs to be considered as part of the organization’s wider <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">cyber security strategy</a>.”</p><p>Organizations considering making the switch also need to consider the impact of other issues with operational technology, such as the reliance on legacy equipment, as well as on-premises and monolithic software packages.</p><p>They were urged to consider whether their SCADA <a href="https://www.itpro.com/software">software</a> is even supported in a cloud deployment, the trust model between <a href="https://www.itpro.com/cloud/hybrid-cloud/354545/why-enterprises-are-moving-back-to-on-premise-data-centres">on-premise</a> and cloud components and issues such as latency, as well as the sensitivity of the data that is being sent to the cloud.</p><p>“SCADA data is sensitive, and provides the necessary information required to control physical infrastructure. Ensuring that this data is adequately protected should be a priority both on-premises and in a cloud deployment,” the NCSC said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Seven things every chief exec needs to know in the event of a cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/seven-things-every-chief-exec-needs-to-know-in-the-event-of-a-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ New guidance from the NCSC aims to provide CEO's with vital learning materials to draw upon if their organization suffers a cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CgEfeQwsp2KXaHmSBhWeSH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RedwCmfxCPMtSW8N8UwyxY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Mar 2024 13:53:12 +0000</pubDate>                                                                                                                                <updated>Mon, 25 Mar 2024 16:09:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RedwCmfxCPMtSW8N8UwyxY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security leadership team discussing an incident in an open plan office space in low light.]]></media:description>                                                            <media:text><![CDATA[Cyber security leadership team discussing an incident in an open plan office space in low light.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security leadership team discussing an incident in an open plan office space in low light.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RedwCmfxCPMtSW8N8UwyxY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre</a> (NCSC) has released guidance specifically for CEOs aimed at helping them manage <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> incidents.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Jd3pxZCLYdY6GikcNyQbuT" name="GettyImages-1400779382-cyber-security-vendor-crop.jpg" caption="" alt="A digital shield logo on a screen, with code surrounding it to represent a cyber security vendor." src="https://cdn.mos.cms.futurecdn.net/Jd3pxZCLYdY6GikcNyQbuT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-to-choose-the-best-cyber-security-vendor-for-your-business" target="_blank">How to choose the best cyber security vendor for your business</a></p></div></div><p>According to the NCSC, resources and learning materials for executives on how to respond to a cyber attack are few and far in between, leaving many in the dark in the event of an incident.</p><p>The new guidance aims to provide detailed information on how executives can manage a cyber incident, as well as how to engage with staff and relevant authorities to remediate issues.</p><p>"If your organization is the victim of a significant cyber attack, the immediate aftermath will be challenging. You may find there is a lot of information in some areas, and none in others," the NCSC warns.</p><p>"There will be difficult risk-based decisions to make to protect your operations. Your aim will be to limit the impact on your business, clients and staff in the weeks and months which follow."</p><p>Here are seven things every CEO needs to know if their organization suffers a cyber attack. </p><h2 id="governance-is-critical">Governance is critical</h2><p>The NCSC says organizations should consider appointing a <em>Senior Responsible Officer</em>, or using a broader governance command structure such as the bronze, silver, and gold model to assign overall responsibility for an incident. </p><p>CEOs should make sure that there are structures in place to handle the full impact across the whole organization and make it easy for those managing the response to regularly come together to collaborate and confer on progress.</p><p>Similarly, the guidance recommended they should inform and empower senior decision-makers and work with regulators and insurers, providing updates to the board.</p><h2 id="bring-in-external-resources">Bring in external resources</h2><p>Organizations affected by a cyber attack often bring in third parties to help assess impact and identify key areas of focus during the remediation process, which the NCSC says is advised in most cases. </p><p>The security center says it strongly advises using a cyber incident response (CIR) company to help recovery management.</p><p>For companies that have <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance">cyber insurance</a> in place, their insurer may have in-house experts or preferred CIR firms that organizations can work with. The NCSC has its own <a href="https://www.ncsc.gov.uk/section/products-services/verify-suppliers?scheme=Cyber+Incident+Response+%28CIR%29" target="_blank">list</a> of approved companies, which executives can find via the center’s website.</p><h2 id="communicate-with-those-affected">Communicate with those affected</h2><p>ICO guidance makes it clear that notifiable breaches must be reported to them ‘without undue delay’ and not later than 72 hours after becoming aware of it. Risks to data must also be reported to the data owners.</p><p>In terms of public messaging, the NCSC says communications should be factual and clear, and the incident shouldn&apos;t be misrepresented or downplayed.</p><p>"You might need to give a different level of detail to different groups – key decision-makers and stakeholders in your organization, wider staff, your partner organizations or communications to the public," the NCSC warned.</p><p>"Make sure you know in advance who needs to be brought into your communications planning."</p><h2 id="think-twice-before-paying-a-ransom">Think twice before paying a ransom</h2><p>While it&apos;s tempting to just pay up in the event of a ransom demand, the NCSC advises against this. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AKV4FATYviEDsmrb4p5bc" name="Cloudflare's Cybersecurity Solutions for Public Sector Resilience_listing.jpg" caption="" alt="An orange webinar screen with contributor images, on security solutions for public sector resilience" src="https://cdn.mos.cms.futurecdn.net/AKV4FATYviEDsmrb4p5bc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/securing-europe-cloudflares-cyber-security-solutions-for-public-sector-resilience"><em>Enhance your security with a DDoS mitigation system</em></a></p></div></div><p>As it points out, there&apos;s no guarantee that paying up will mean getting access to data or networks back. Research <a href="https://www.itpro.com/security/ransomware/bowing-to-ransomware-demands-doesnt-guarantee-the-safety-of-your-data-or-exemption-from-future-attacks">published by Cybereason</a> earlier this year showed that companies who have previously paid ransoms are frequently targeted again as cyber criminals have evidence that they’re likely to comply.</p><p>The question of whether to pay a ransom has become a source of controversy across the security industry in recent months.</p><p>In January 2024, calls for an outright <a href="https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight">ban on ransom payments</a> by a major security vendor <a href="https://www.itpro.com/security/ransomware/a-ransomware-payments-ban-risks-criminalizing-victims">prompted backlash from some in the community</a>, with experts suggesting that it could risk “criminalizing victims”.</p><h2 id="consider-team-resilience-and-welfare">Consider team resilience and welfare</h2><p>It&apos;s important to bear in mind the effect an incident can have on staff morale, with stress and uncertainty likely, according to the NCSC. </p><p>Security incidents can take months to remediate, therefore it’s important to ensure that staff aren’t exhausted.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=58777296&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p><a href="https://www.itpro.com/security/surging-cyber-threats-exacerbating-security-staff-burnout">Stress and burnout among cyber security practitioners</a> have been a long-running issue across the industry. Research last year showed that <a href="https://www.itpro.com/security/cyber-security/370114/nearly-half-cyber-leaders-leave-roles-mounting-stress">nearly half of senior cyber security staff were considering leaving the profession altogether</a>.</p><p>Meanwhile, alternative research on working culture in the industry found that many practitioners frequently work longer hours, with some even missing important life events and canceling vacations due to work.</p><h2 id="review-the-lessons-learned">Review the lessons learned</h2><p>The NCSC advises holding a debrief after any cyber security incident to try and identify how it came about. </p><p>This, the guidance says, should be systemic in nature, rather than an exercise in assigning blame. Recent research specifically <a href="https://www.itpro.com/business/business-strategy/a-war-room-style-reaction-to-security-incidents-is-burning-out-it-staff">highlighted a ‘blame game’ culture as a leading cause of burnout and workforce discontent</a> in the immediate wake of a cyber attack. A clear set of rules ahead of a cyber attack such as a <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">data breach response</a> plan can help prevent these pressures from becoming too great.</p><p>The NCSC says organizations should carry out a general cyber security review to help understand and <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">manage vulnerabilities</a> that could lead to further attacks. Leaders can also implement specific steps to <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">protect against data breaches</a> and establish a <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks">strategy for AI threats</a>.</p><h2 id="report-incidents">Report incidents</h2><p>Finally, significant incidents should be reported to the NCSC and UK law enforcement who can provide support. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tjMUsHBxmAtXAghu2xs28E" name="Stressed_Worker_Stock_Image_GettyImages-962630998 (1).jpg" caption="" alt="Stressed and exhausted office worker sits behind desk at night in a darkened room" src="https://cdn.mos.cms.futurecdn.net/tjMUsHBxmAtXAghu2xs28E.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/fighting-the-always-on-culture-thats-savaging-mental-health-in-cyber-security">Fighting the ‘always on’ culture that’s savaging mental health in cyber security</a></p></div></div><p>The NCSC says this can be done using UK government signposting tools, which explain how organizations can notify relevant authorities based on the individual circumstances of the incident.</p><p>Law enforcement and agencies such as the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> and the NCSC frequently work with public and private sector organizations in the wake of a cyber attack or security incident.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Former NCSC chief calls for ransomware payments ban, but cyber security experts aren't keen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/former-ncsc-chief-calls-for-ransomware-payments-ban-but-cyber-security-experts-arent-keen</link>
                                                                            <description>
                            <![CDATA[ Ciaran Martin, former chief executive at the NCSC, said efforts to introduce a ransomware payments ban could help tackle the $20 billion industry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Sg6bemHkXAET7Gcp8q63UT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tZDrEXZkF2owJPisgEeQF6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Mar 2024 13:20:06 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Mar 2024 14:41:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tZDrEXZkF2owJPisgEeQF6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ciaran Martin, former head of the National Cyber Security Centre (NCSC), speaks during the 2018 Aspen Cyber Summit in San Francisco, California, U.S., on Thursday, Nov. 8, 2018]]></media:description>                                                            <media:text><![CDATA[Ciaran Martin, former head of the National Cyber Security Centre (NCSC), speaks during the 2018 Aspen Cyber Summit in San Francisco, California, U.S., on Thursday, Nov. 8, 2018]]></media:text>
                                <media:title type="plain"><![CDATA[Ciaran Martin, former head of the National Cyber Security Centre (NCSC), speaks during the 2018 Aspen Cyber Summit in San Francisco, California, U.S., on Thursday, Nov. 8, 2018]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tZDrEXZkF2owJPisgEeQF6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The former chief executive of the UK&apos;s National Cyber Security Centre (NCSC) has called for the government to ban organizations from making <a href="https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight">ransomware payments</a>.</p><p>Writing in <a href="https://www.thetimes.co.uk/article/ban-ransomware-payments-hackers-ciaran-martin-cybersecurity-gk3jh2vk0" target="_blank"><em>The Times</em></a>, Ciaran Martin, who served as the NCSC’s inaugural chief executive, suggested a ban could help put a stop to the ever-increasing proliferation of ransomware, referring to the &apos;apparently sanguine attitude&apos; of British policymakers to cyber criminals groups.</p><p>"Ransomware is by far the most damaging cyber threat to most businesses right now. We have to find a way of making a ransom payments ban work," he wrote.</p><p>Martin suggested that any ban would need a better support network for affected companies. However, the lack of such a policy is in part down to the US&apos; reluctance to introduce a ban amid concerns that it would unreasonably constrain businesses. </p><p>Similar concerns have been raised that this could be a particular problem for the country&apos;s hospitals, many of which are in the private sector.</p><p>Currently, many governments, including the UK, have a policy that they won&apos;t pay ransoms themselves. In October 2023, <a href="https://www.itpro.com/security/ransomware/coalition-of-nations-agree-to-end-ransomware-payments-to-hackers">40 countries pledged their support for the International Counter Ransomware Initiative</a> (CRI) as part of an effort to create a more aligned global approach to cyber crime.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UqcNuXS5DhrfeyKUzJsrU6" name="When it comes to cyber security, fight fire with fire_listing.jpg" caption="" alt="This CEO's guide from IBM shares how generative AI can fortify your business security" src="https://cdn.mos.cms.futurecdn.net/UqcNuXS5DhrfeyKUzJsrU6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://itpro.com/technology/artificial-intelligence/the-ceos-guide-to-generative-ai-when-it-comes-to-cyber-security-fight-fire-with-fire"><strong>Fortify your business defenses with generative AI</strong></a></p></div></div><p>Participating nations agreed not to make payments and pledged to share information and create a blacklist of digital wallets being used to deposit and move <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> payments.</p><p>The official advice for UK-based companies is that they should not pay ransoms under any circumstances. The NCSC suggests that even when companies do so, there&apos;s no guarantee that they will get access to their data or systems back, that computers will still be infected, and that those who pay are more likely to be targeted in the future.</p><p>Across the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> community, there are mixed feelings about whether or not a ban should be introduced.</p><p>Oliver Norman, vice president for UK and Ireland at data management firm Veritas, said that regardless of a ban, the outcome of incidents will remain the same, with organizations more likely to be targeted in future and given no guarantees of having data safely returned.</p><p>"Whether banned or not, paying not only puts a target on the organization’s back for future attacks," he said. "There’s also no guarantee all of the data will be returned even if a payment is made – we estimate that 32% of businesses that paid ransoms still lost over half their data."</p><p>Others, though, believe that a ban is impractical.</p><p>"Banning ransomware payments can often have further implications – and this is not the first time this idea has cropped up. Although prevention is better than cure, there are still multiple cases where the only option has been to pay," said Jake Moore, global cyber security advisor at security firm ESET.</p><p>"Being stuck between a rock and a hard place is no position any company wants to be in but if the law is directed only one way, then companies can easily fold and the potential of livelihoods lost can make this a damming and forced decision."</p><p>Moore warned there is also a danger that driving ransom payments underground could lead to further demands, as well as criminalizing victims.</p><p>"Although the long term effects of banning ransom payments may sound idyllic, the path needed to navigate all companies to this ideal is going to be challenging, if not impossible," he said.</p><p>Moore&apos;s comments follow hefty criticism for cyber security firm Emsisoft in January after it <a href="https://www.itpro.com/security/ransomware/a-ransomware-payments-ban-risks-criminalizing-victims">called for an outright ban on ransomware payments</a>. </p><p>Emsisoft urged lawmakers to introduce legislation aimed at preventing firms from engaging with cyber criminals, but critics argued it would “shift the focus of criminality” from perpetrators to victims.</p><p>Currently, according to a recent report from data security and management firm Cohesity, <a href="https://www.itpro.com/security/most-uk-firms-pay-ransom-pay-ransomware-demands-despite-do-not-pay-policies">more than nine-in-ten UK businesses have a no-pay policy</a> - but virtually all of those that have fallen victim to a ransomware attack have in fact paid out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ State-linked threat actors are ramping up attacks on cloud services - here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/state-linked-threat-actors-are-ramping-up-attacks-on-cloud-services-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Attacks on cloud-hosted environments are escalating rapidly, according to a new advisory from the NCSC and international partners ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q3B952TpVCJrZUsz8K2DzH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Feb 2024 11:05:37 +0000</pubDate>                                                                                                                                <updated>Tue, 27 Feb 2024 12:02:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:description>                                                            <media:text><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud security concept image showing a digitalized cloud symbol with a padlock sitting on a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6J7qLSiKJDwawdKHyL5x56-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Russian hacking group known as <a href="https://www.itpro.com/security/hacking/359478/russian-hackers-are-exploiting-these-11-flaws-to-attack-businesses">APT29</a>, Midnight Blizzard, the Dukes, or Cozy Bear is adapting its techniques to attack organizations&apos; cloud-hosted environments.</p><p>The UK&apos;s National Cyber Security Centre (NCSC), along with Five Eyes partners the US, Australia, Canada and New Zealand, has issued an advisory about the threat.</p><p>"We are resolute in our commitment to exposing malicious cyber activity, which includes raising awareness of changes in the behavior of groups which persistently target the UK," said NCSC director of operations Paul Chichester.</p><p>"The NCSC urges organizations to familiarize themselves with the intelligence and mitigation advice within the advisory to help defend their networks."</p><p>The group is best known for the <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">supply chain compromise of SolarWinds</a> software in 2020, as well as the targeting of organizations involved in the development of the Covid-19 vaccine in the same year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wJTa4C5M48quyZBahu2DXo" name="Security_GettyImages-1039289924.jpg" caption="" alt="Cyber security concept image with a digitalized padlock surrounded by digital interface" src="https://cdn.mos.cms.futurecdn.net/wJTa4C5M48quyZBahu2DXo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it">Hackers are lying low in networks to wage critical infrastructure attacks - here’s how they do it</a></p></div></div><p>Linked to Russia’s Foreign Intelligence Service (SVR), it has tended to target think tanks, healthcare, and education organizations, many of which have moved to <a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022">cloud-based infrastructure</a>.</p><p>NCSC analysis shows it’s now expanding operations to target aviation, education, law enforcement, local and state governments, government financial departments, and military organizations.</p><p>As organizations move to the cloud, the group has been forced to move beyond its traditional means of initial access, such as exploiting <a href="https://www.itpro.com/security/software-vulnerabilities-are-declining-but-third-party-risks-still-linger">software vulnerabilities</a> in an on-premise network.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UqcNuXS5DhrfeyKUzJsrU6" name="When it comes to cyber security, fight fire with fire_listing.jpg" caption="" alt="This CEO's guide from IBM shares how generative AI can fortify your business security" src="https://cdn.mos.cms.futurecdn.net/UqcNuXS5DhrfeyKUzJsrU6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/the-ceos-guide-to-generative-ai-when-it-comes-to-cyber-security-fight-fire-with-fire"><em>Spot threats as soon as they materialize</em></a></p></div></div><p>Instead, it&apos;s started targeting the cloud services themselves, which means successfully authenticating to the cloud provider.</p><p>Over the past 12 months, the NCSC said SVR-linked actors have been spotted stealing system-issuing access tokens to compromise victim accounts, enrolling new devices to the victim’s cloud environment via credential reuse from personal accounts, and targeting system accounts with password spraying and <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">brute forcing</a>.</p><p>Once initial access has been gained, the actor is then capable of deploying highly sophisticated capabilities, the NCSC warned, such as MagicWeb, spotted in 2022 targeting government organizations, NGOs, intergovernmental organizations, and think tanks across the US, Europe, and Central Asia.</p><p>These techniques are made possible by weak passwords and the absence of <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-step verification</a> - and the Five Eyes partners are advising organizations on how to stay safe.</p><p>Organizations should use <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication</a> (MFA) where possible, or failing that, strong, unique passwords; user and system accounts should be disabled when no longer required, and system and service accounts should implement the principle of least privilege.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=57223823&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>The NCSC also suggested creating &apos;canary service accounts&apos; that appear to be valid service accounts but are never used by legitimate services. In doing so, organizations can monitor these accounts to show if they’ve been compromised and are being used by threat actors.</p><p>Session lifetimes should be kept as short as practical, and device enrolment policies should be configured to only permit authorized devices to enroll.</p><p>"As the world modernizes their systems, we need to do all we can to reduce the attack surface for cyber actors to penetrate," said Rob Joyce, director of cybersecurity for the US National Security Agency (NSA).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five Eyes advisory raises alarm over state-backed 'living off the land' attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks</link>
                                                                            <description>
                            <![CDATA[ State-backed actors may be lurking in critical infrastructure systems, security agencies have warned ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JNHdk6EVRovNF4AYzoQUd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H3JvMkkKnU6yR4egdg39DW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Feb 2024 11:45:00 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Feb 2024 14:41:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H3JvMkkKnU6yR4egdg39DW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber criminal concept art featuring a digitized eye on a binary code background]]></media:description>                                                            <media:text><![CDATA[Cyber criminal concept art featuring a digitized eye on a binary code background]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber criminal concept art featuring a digitized eye on a binary code background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H3JvMkkKnU6yR4egdg39DW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre</a> (NCSC), along with its Five Eyes allies, has issued a new warning to critical infrastructure operators about ‘living off the land’ attacks.</p><p>Together with <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> agencies in the US, Australia, Canada, and New Zealand, the NCSC said in its advisory that state-sponsored actors have been exploiting native tools and processes built into computer systems to blend in with legitimate system and network behavior.</p><p>This, the NCSC said, can make their activity difficult to distinguish – even for organizations with more mature <a href="https://www.itpro.com/security">security</a> postures.</p><p>"In this new dangerous and volatile world where the frontline is increasingly online, we must protect and future proof our systems," said deputy prime minister Oliver Dowden. "By driving up the resilience of our critical infrastructure across the UK, we will defend ourselves from cyber attackers that would do us harm."</p><p>The new guidance - an update to a warning issued last May - warns that state-sponsored attackers from China and Russia have been observed living off the land on compromised critical infrastructure networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j3qKLuBJWSTwFybkYhYiMH" name="Security_Alert_Stock_Image_GettyImages-1403439566 (1).jpg" caption="" alt="Warning symbol in yellow pictured on a digital blue background signifying a security alert" src="https://cdn.mos.cms.futurecdn.net/j3qKLuBJWSTwFybkYhYiMH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/the-big-three-ransomware-groups-are-losing-their-grip-on-the-industry-as-gangs-begin-to-fracture-study-shows">The &apos;Big Three’ ransomware groups are losing their grip on the industry as gangs begin to fracture</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/office-staff-think-theyre-in-safe-hands-with-cyber-security-teams-but-communication-could-be-better">Office staff think they’re in safe hands with cyber security teams, but communication could be better</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/what-is-an-air-gap-and-why-do-security-teams-use-them">What is an air gap and why do security teams use them?</a></p></div></div><p>It gives advice on how to identify living off the land activity, and to mitigate and remediate if a compromise is detected.</p><p>Priorities, it said, should include implementing logging and aggregate logs in an out-of-band, centralized location and establishing a baseline of network, user, and application activity, with automation used to continually review all logs and compare activity.</p><p>Organizations should also work to reduce alert noise, implement application allow listing, enhance network segmentation and monitoring, implement authentication controls, and make use of user and entity behavior analytics (UEBA).</p><p>"It is vital that operators of UK critical infrastructure heed this warning about cyber attackers using sophisticated techniques to hide on victims’ systems. Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services," said Paul Chichester, NCSC director of operations.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CZjuxSoWvz8unNrpfyqQxf" name="Buyer’s Guide for Developer Security Tools 2022.jpg" caption="" alt="Dark background with white text that says Buyer’s Guide for Developer Security Tools 2022" src="https://cdn.mos.cms.futurecdn.net/CZjuxSoWvz8unNrpfyqQxf.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Synk)</span></figcaption></figure><p class="fancy-box__body-text"><em>What should you consider when evaluating a developer security platform?</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/buyers-guide-for-developer-security-tools">DOWNLOAD NOW</a></p></div></div><p>"Organizations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks."</p><p>Alongside this guidance, the five countries have also issued a separate advisory that shares specific details about China state-sponsored actor <a href="https://www.itpro.com/security/cyber-attacks/asus-cisco-netgear-devices-exploited-in-ongoing-chinese-hacking-campaign">Volt Typhoon</a>. This group has been observed using living off the land techniques to compromise US <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">critical infrastructure systems</a>, mainly in the communications, energy, transport and water and wastewater sectors.</p><p>"It’s clear the US has grown increasingly concerned about the threat Volt Typhoon exposes its critical infrastructure to and is working to disband the adversary," said Ian McGowan, managing director at Barrier Networks.</p><p>"All critical organizations across the world have migrated their operations to digital today, yet this has made them more vulnerable to attack. Gas facilities use automated tools to manage critical processes, while electrical plants rely on automated tools to control the electricity supply into peoples’ home.</p><p>“But, if attackers find a way to get access to these systems, they can shut down these key services, causing serious damage to a country and its citizens."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Struggling with mandatory password change policies? Here's the most effective way to get stubborn employees to comply ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/researchers-at-uc-san-diego-reveal-the-most-effective-way-to-get-stubborn-employees-to-change-their-passwords</link>
                                                                            <description>
                            <![CDATA[ The study involved monitoring email reminders and login prompts sent to almost 10,000 faculty and staff members ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">F3pHUR34byzmQFT2meUcE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xvgNnkx6pAN9JWe8n5vPu7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Feb 2024 11:27:03 +0000</pubDate>                                                                                                                                <updated>Wed, 14 Feb 2024 08:22:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xvgNnkx6pAN9JWe8n5vPu7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A login screen of an application showing empty username and password fields]]></media:description>                                                            <media:text><![CDATA[A login screen of an application showing empty username and password fields]]></media:text>
                                <media:title type="plain"><![CDATA[A login screen of an application showing empty username and password fields]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xvgNnkx6pAN9JWe8n5vPu7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A team of university computer scientists has analyzed the messaging for a campus-wide mandatory password change in what is considered the first study of its kind to look at effective communications around password policies.</p><p>Researchers at the University of California San Diego teamed up with the campus’ Information Technology Services team to analyze the messaging for a campus-wide mandatory password change affecting almost 10,000 faculty and staff members.</p><p>They believe this is the first time that an empirical analysis of a mandatory password update has been conducted on this large a scale and in the wild, rather than as part of a simulation or controlled experiment.</p><p>Over the first four weeks of the campaign, faculty and staff at UC San Diego received four emails at roughly weekly intervals prompting them to change their <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on</a> password. Those who still failed to act then got a prompt to do so as they logged in.</p><p>The emails were considered to be generally effective, with between 5% and 15% of users updating their passwords during each wave of emails. However, there were diminishing returns: even after four email prompts, a quarter of users still hadn&apos;t completed the update procedure.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Eight out of ten of these reluctant users, though, finally changed their passwords when they were prompted to do so at log-in.</p><p>"The active single sign on prompting was a big winner across the board," says <a href="https://dl.acm.org/doi/fullHtml/10.1145/3627106.3627198" target="_blank">the paper’s</a> first author, Ariana Mirian. "You managed to get people who are stubborn – and maybe not paying attention – to take action, and that’s huge."</p><p>In what must have come as a relief – and despite concerns from the campus – the campaign did not generate a significant increase in tickets to the IT help desk. While ticket volume did increase by three to four times, tickets related to the password update only represented 8% of all requests.</p><div  class="fancy-box"><div class="fancy_box-title">More on password use</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="63RKMivocG7x8LQgDmk6kF" name="GettyImages-1405668707.jpg" caption="" alt="A close-up of part of a login screen where the password field has been filled in and the curser is hovering over the Sign In button" src="https://cdn.mos.cms.futurecdn.net/63RKMivocG7x8LQgDmk6kF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">How do hackers get your passwords?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/lastpass-is-getting-stricter-on-master-passwords-in-the-wake-of-a-disastrous-2022-security-breach">LastPass is getting stricter on master passwords in the wake of a disastrous 2022 security breach</a></p></div></div><p>The users who were slowest to carry out the update were those working in areas where they weren&apos;t required to log in to their computers regularly, such as maintenance, recreation, and dining services.</p><p>"Targeting such users earlier, or forgoing email reminders and using login intercepts from the start, or even using a different notification mechanism such as text messages, may be more effective," the researchers write.</p><p>Mandatory password change programs aren&apos;t always a good idea, with the UK&apos;s <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> warning that it can be counterproductive. When users are forced to change their password, it says, the chances are that they&apos;ll pick something similar to the password they used before.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Q65i32qBV5ZTXznMxnpLeF" name="Understanding AI models to future-proof your AppSec program.jpg" caption="" alt="Dark background with light text that says Understanding AI models to future-proof your AppSec program" src="https://cdn.mos.cms.futurecdn.net/Q65i32qBV5ZTXznMxnpLeF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Synk)</span></figcaption></figure><p class="fancy-box__body-text"><em>Become more knowledgeable when talking to colleagues about AI<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/understanding-ai-models-to-future-proof-your-appsec-program">DOWNLOAD NOW</a></p></div></div><p>"The new password may have been used elsewhere, and attackers can exploit this too. The new password is also more likely to be written down, which represents another vulnerability," it says. </p><p>"New passwords are also more likely to be forgotten, and this carries the productivity costs of users being locked out of their accounts, and service desks having to reset passwords."</p><p>Instead, the NCSC recommends using system monitoring tools that present users with information about the last login attempt, so they can see if they’re responsible for failed login attempts and report any issues for investigation.</p><p>"Initiatives such as this are far more likely to help keep systems safe, and much more manageable for the user," says the NCSC.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A king's ransom-ware:Buckingham Palace is on the hunt for two cyber security pros to join the Royal Household ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/a-kings-ransom-ware-buckingham-palace-is-on-the-hunt-for-two-cyber-security-pros-to-join-the-royal-household</link>
                                                                            <description>
                            <![CDATA[ The Royal Household is looking for cyber security and information security managers to keep the Palace safe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gdGKNa3R3oMpWfNxN4RfLf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tTViZW3kqsoYoU4pvWf5xH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jan 2024 11:35:56 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Feb 2024 18:19:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tTViZW3kqsoYoU4pvWf5xH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photo of the Queen Victoria Memorial with Buckingham Palace in the background on a bright sunny day]]></media:description>                                                            <media:text><![CDATA[A photo of the Queen Victoria Memorial with Buckingham Palace in the background on a bright sunny day]]></media:text>
                                <media:title type="plain"><![CDATA[A photo of the Queen Victoria Memorial with Buckingham Palace in the background on a bright sunny day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tTViZW3kqsoYoU4pvWf5xH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two security jobs are up for grabs in possibly the poshest workplace in the UK - Buckingham Palace.</p><p>The Royal Household is advertising for a cyber security manager and an information security, privacy and records manager, working to reduce cyber risk and build resilience against cyber attacks.</p><p>Both jobs are based in the Privy Purse and Treasurer’s Office, and come with a good range of perks and benefits – including employee discounts at the royal shops.</p><p>"It’s developing your skills whilst pushing our systems forward," reads the <a href="https://theroyalhousehold.tal.net/vx/lang-en-GB/mobile-0/appcentre-1/brand-3/candidate/so/pm/1/pl/4/opp/3149-Cyber-Security-Manager/en-GB" target="_blank">cyber security manager ad</a>. "And it&apos;s being a part of the professional business behind the Monarchy. This is what makes working for the Royal Household exceptional."</p><p>The job pays a relatively modest £75,000 for a 37.5-hour week, and involves heading up the royal household&apos;s cyber risk management strategy and cyber security framework delivery.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=58079953&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>This means leading in-house teams working to reduce cyber risk and build resilience against cyber-attacks, as well as working with the enterprise architecture team to mature a secure by design culture.</p><p>Working with the <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a>, the successful applicant will also work to <a href="https://www.itpro.com/business-strategy/careers-training/369064/how-to-upskill-your-existing-workforce-to-beat-the-talent">upskill</a> the wider digital services team and keep all employees on their toes in terms of security best practice.</p><div  class="fancy-box"><div class="fancy_box-title">More on security training</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xXqApfaWjb4FwsP7HQiW3o" name="GettyImages-1248990543-cyber-employees-shortage-skills.jpg" caption="" alt="A top-down artwork showing businesspeople walking left and right across blocks with binary code on them, to represent the cyber security skills shortage. None of the businesspeople are on paths that will intersect, and as they walk the blocks change from light blue to dark blue." src="https://cdn.mos.cms.futurecdn.net/xXqApfaWjb4FwsP7HQiW3o.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">The cyber security skills shortage: What skills are missing?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/370058/how-it-professionals-can-get-into-cyber-security">How IT professionals can change careers to cyber security</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/370054/cyber-security-certification-vs-degree">Cyber security certification vs degree: Which is best for your career?</a></p></div></div><p>The royal household is looking for a strong track record, with "significant experience in a cyber security role, with an understanding of <a href="https://www.itpro.com/security/nist-announces-rare-overhaul-of-security-framework-focusing-on-organizational-leadership">information security frameworks</a> and a proven ability to lead a cyber function and execute an enterprise-level security strategy, preferably within UK HMG."</p><p>Candidates will also need to be "able to review complex information systems and web applications, identify risks and recommend appropriate, pragmatic (and cost effective) solutions to mitigate those risks, as well as provide clear and concise advice to senior management".</p><p>Meanwhile, the information security, privacy and records manager will pull a slightly smaller salary – £70,000. They&apos;ll be responsible for developing and enhancing strategy, policies, and practices for data protection, records management and information security.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FzDEWPg3WQaL7frXgSRaPo" name="A journey to cyber resilience_listing.jpg" caption="" alt="An eBook from SecurityScorecard on how to measure your business' cyber resilience" src="https://cdn.mos.cms.futurecdn.net/FzDEWPg3WQaL7frXgSRaPo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: SecurityScorecard)</span></figcaption></figure><p class="fancy-box__body-text"><em>Enhance your financial services firm&apos;s cyber resilience<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/a-journey-to-cyber-resilience">DOWNLOAD NOW</a></p></div></div><p>"With a relevant qualification in Information Security and Data/Records Management you’ll also have experience of managing a complex and varied portfolio of digital and physical records," <a href="https://theroyalhousehold.tal.net/vx/lang-en-GB/mobile-0/appcentre-1/brand-3/candidate/so/pm/1/pl/4/opp/3150-Information-Security-Privacy-and-Records-Manager/en-GB" target="_blank">reads the ad</a>.</p><p>"Experience of team leadership, strategy development, risk and business analysis, and a deep understanding of relevant technical best practice. Knowledge of ISO 27001 would be an advantage."</p><p>The Royal Household is, of course, a rather high profile target, and any breaches could be dangerous as well as embarrassing.</p><p>Last October, the Royal Family website went down for an hour and a half, thanks to a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">denial of service (DoS) attack</a>. No systems were compromised, nor any data breached, said the palace. The pro-Russian hacktivist group <a href="https://www.itpro.com/security/hacking/367685/russian-hackers-declare-war-on-10-countries-after-failed-eurovision-ddos">KillNet</a> took responsibility for the attack on its Telegram channel.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three Kent councils grapple with cyber incidents as services knocked offline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/three-kent-councils-grapple-with-cyber-incidents-as-services-knocked-offline</link>
                                                                            <description>
                            <![CDATA[ Affected local authorities said they have taken swift action to contain the incidents, but warned that services may be unavailable ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8pUZmvTWy9Geykk3gyiWo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q78FXEQYdWxt9sQ9poVpxb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jan 2024 12:53:09 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Jan 2024 12:53:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q78FXEQYdWxt9sQ9poVpxb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Binary digital security padlock and network data on a huge cyberspace]]></media:description>                                                            <media:text><![CDATA[Binary digital security padlock and network data on a huge cyberspace]]></media:text>
                                <media:title type="plain"><![CDATA[Binary digital security padlock and network data on a huge cyberspace]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q78FXEQYdWxt9sQ9poVpxb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three local councils in Kent have been hit by cyber attacks that have severely disrupted services for communities in the region. </p><p>Canterbury City Council, Thanet District Council, and Dover District Council confirmed they are investigating the incidents.</p><p>At present, it’s not known whether any personal data has been compromised in the incidents. However, all three local authorities said they have taken precautions to contain the incidents, which has made certain parts of their websites inaccessible.</p><p>"We are working to resolve this as soon as possible and apologise for any inconvenience caused," said Thanet District Council.</p><p>The councils say they are working with the National Cyber Security Centre (NCSC) to establish what happened.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j3qKLuBJWSTwFybkYhYiMH" name="Security_Alert_Stock_Image_GettyImages-1403439566 (1).jpg" caption="" alt="Warning symbol in yellow pictured on a digital blue background signifying a security alert" src="https://cdn.mos.cms.futurecdn.net/j3qKLuBJWSTwFybkYhYiMH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/four-in-ten-employees-sacked-over-email-security-breaches-as-firms-tackle-truly-staggering-increase-in-attacks">Four-in-ten employees sacked over email security breaches as firms tackle “truly staggering” increase in attacks</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/this-malware-is-trying-to-steal-your-aws-keys-and-more-heres-how-to-protect-yourself">This malware is trying to steal your AWS keys and more, here&apos;s how to protect yourself</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/inside-the-ncscs-plan-to-create-a-national-threat-tracking-a-team">Inside the NCSC’s plan to create a national threat tracking A-Team</a></p></div></div><p>"Our teams are taking a precautionary approach while we work hard to investigate the problem and to minimise any disruption to our services. Our email system and website have been available throughout although some parts of the website may not quite work as intended," said Canterbury City Council.</p><p>"We are sorry for any inconvenience people may have experienced over the past few days and will provide updates as and when we have them."</p><p>Cyber attacks on local authorities have grown in both frequency and intensity in recent years, according to Trevor Dearing, director of critical infrastructure at security firm Illumio.</p><p>In 2023, for example, Kent County Council’s children’s department fell victim to a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attack when an officer clicked on a link from an email to reset their password.</p><p>Gloucester City Council was also severely affected by a 2023 cyber attack which resulted in more than £1 million in recovery costs.</p><p>"Attacks on the public sector are becoming more frequent and more pervasive, but the problem is <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> funding isn’t rising in tandem,” he said.</p><p>“Investments in technologies that provide demonstrable gains in cyber resilience must be prioritized."</p><p>Last year, a report from software provider TechnologyOne found that six-in-ten senior leaders at UK councils said their approach to cyber security is &apos;outdated&apos;, but that they couldn&apos;t afford the cost of a security breach.</p><p>Leo Hanna, UK executive vice president at TechnologyOne, said a concerted national effort to improve cyber security among local authorities should be prioritized.</p><p>"Systems held together by gaffer tape and chewing gum still deliver mission-critical services at local authorities across the country but they need to be urgently overhauled if they are to remain secure," he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Inside the NCSC’s plan to create a national threat tracking A-Team ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/inside-the-ncscs-plan-to-create-a-national-threat-tracking-a-team</link>
                                                                            <description>
                            <![CDATA[ The NCSC Cyber League program looks to draw on the strengths of the country’s security industry and bolster national resilience ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MVnERSstz9CCVcT7Nm8CuK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vPCNaKE7odWDJST3pzLbAg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jan 2024 13:10:37 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Jan 2024 13:51:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vPCNaKE7odWDJST3pzLbAg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[National Cyber Security Centre (NCSC) logo displayed on a television screen.]]></media:description>                                                            <media:text><![CDATA[National Cyber Security Centre (NCSC) logo displayed on a television screen.]]></media:text>
                                <media:title type="plain"><![CDATA[National Cyber Security Centre (NCSC) logo displayed on a television screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vPCNaKE7odWDJST3pzLbAg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) is inviting security professionals to sign up as members of its new Cyber League, an initiative aimed at working on some of the biggest security threats currently facing the country. </p><p>The plan is to bring together a community of industry experts, working with NCSC analysts and with each other, to use their specialist knowledge and understanding of the threat landscape to develop techniques and strategies to counter future attacks.</p><p>Members will take part in a range of projects, the NCSC said, including <a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics">analytics</a> workshops and discussion groups on key trending issues.</p><p>Paul Chichester, director of operations at the security agency, said the initiative will draw on the combined strengths of the country’s cyber industry and institutions to improve national resilience.</p><p>"Cyber defence is a giant, complex and ever-changing puzzle, with critical knowledge, skills and innovation spread widely across industry and government,” he said. .</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2tJwSpj9g49CmTpeMXwCN4" name="security_GettyImages-1442484864.jpg" caption="" alt="Security concept art stock image featuring padlock on a blue background" src="https://cdn.mos.cms.futurecdn.net/2tJwSpj9g49CmTpeMXwCN4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ncsc-launches-new-cyber-guidance-for-smbs-as-threats-continue-to-surge">NCSC launches new cyber guidance for SMBs as threats continue to rise</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ncsc-cyber-incident-exercising-scheme-looks-to-fine-tune-incident-response">NCSC Cyber Incident Exercising scheme looks to fine-tune incident response</a><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ncsc-announces-global-guidelines-on-ai-security">NCSC announces global guidelines on AI security</a></p></div></div><p>"Only through working together can we achieve our collective aim of making the UK the safest place to live and work online."</p><p>Raj Samani, SVP and chief scientist at Rapid7 said the announcement marks a positive step for the UK <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> landscape, and could play a critical role in ensuring broader national resilience.</p><p>“With the current asymmetry of information among criminal threat groups and the cyber security industry, it’s great to see the NCSC taking proactive steps to promote the sharing of skills and information through the Cyber League initiative,” he said.</p><p>Samani said the industry has a tendency to get “bogged down too much in speculation about vulnerabilities and threats”, and therefore the launch of the scheme presents an opportunity for industry to collaborate more closely on mitigating threats.</p><p>“This new Cyber League will act as a great place to boost context-driven threat hunting and innovate how we tackle the rising problem of cyber security,” he added.</p><h2 id="how-the-ncsc-cyber-league-will-work">How the NCSC Cyber League will work</h2><p>To take part in the <a href="https://www.ncsc.gov.uk/information/cyber-league"><u>Cyber League</u></a>, an organization must have a &apos;substantial&apos; UK connection and be part of the cyber security or threat intelligence industry, according to the NCSC. </p><p>Up to three individuals in an organization can sign up to participate providing they have the “relevant cyber experience and knowledge".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9ziQWb9G9shLwqWMVyiGaU" name="9ziQWb9G9shLwqWMVyiGaU.jpg" caption="" alt="A close-up of Ciaran Martin, the first NCSC CEO, staring to the left" src="https://cdn.mos.cms.futurecdn.net/9ziQWb9G9shLwqWMVyiGaU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni">Former NCSC chief Ciaran Martin pinpoints critical national infrastructure (CNI) as the next big ransomware target</a></p></div></div><p>Participants will be required to pass security checks, and will also have to have been a resident in the UK for the last five consecutive years.</p><p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">NCSC</a> said the aim of the initiative is to be as flexible as possible when it comes to membership. Anyone can take part, even if they can&apos;t commit much time, as long as they still have experience and knowledge to share that can bring operational benefit.</p><p>Most members, though, are likely to come through the Industry 100 (i100) secondment program.</p><p>This involves secondees working across a wide range of placements on a part-time basis, ranging from one day a week to one day a month. Participating organizations continue to pay the salary of their staff members while on secondment, in order to maintain independence.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Ho7aXBGCg2UvD5yrJywpem" name="2023 Cybersecurity Insiders VPN Risk Report.jpg" caption="" alt="2023 Cybersecurity Insiders VPN Risk Report whitepaper" src="https://cdn.mos.cms.futurecdn.net/Ho7aXBGCg2UvD5yrJywpem.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Explore the complex world of today’s VPN management and understand its vulnerabilities<br><br></em><a data-analytics-id="inline-link" href="https://www.itpro.com/software/vpn/2023-cybersecurity-insiders-vpn-risk-report">DOWNLOAD NOW</a></p></div></div><p>There are currently 127 placements from 87 organizations, with 200 secondments to date. Participating organisations get the opportunity to challenge and help shape government thinking on cyber issues, build a network of professional contacts across government and the wider cyber security community, and gain a greater understanding of how a central government department works.</p><p>"i100 brings together public and private sector talent to challenge thinking, test innovative ideas and enable greater understanding of cyber security – one of the most important issues of our time," the NCSC said.</p><p>"In i100, we are bringing industry and government expertise together to help us all learn lessons, identify systemic vulnerabilities and reduce the impact of cyber attacks."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC launches new cyber guidance for SMBs as threats continue to rise ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-launches-new-cyber-guidance-for-smbs-as-threats-continue-to-surge</link>
                                                                            <description>
                            <![CDATA[ The NCSC said new cyber guidance for SMBs will help firms navigate an increasingly perilous threat landscape in which hackers are ramping up attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BS75N4pP4nrX2pdbarepQC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Jan 2024 13:06:02 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Jan 2024 15:13:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK&apos;s National Cyber Security Centre (NCSC) has released new cyber guidance for SMBs on how to use cloud and online services more securely.</p><p>Concerned that smaller businesses may be overwhelmed by its existing cloud security guidance - aimed squarely at IT professionals and containing a lot more technical details - the NCSC said it wants to help SMBs avoid falling victim to cyber attacks.</p><p>"Many SMEs already rely on online services for day-to-day tasks, even if they’re not aware of it. This includes email and instant message communications, cloud storage, website/shop hosting, online accounting and invoicing, or simply using social media to engage with customers," said Amelia H of the NCSC&apos;s economy and society team.</p><p>"If you rely on any of these services, it’s important that they are set up in such a way that they’re safe from online risks, whilst also reflecting your organization’s priorities."</p><p>The new <a href="https://www.ncsc.gov.uk/collection/using-online-services-safely">guidance</a> offers practical advice on basic cyber security measures that small businesses can employ to protect themselves amid heightened threats.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2tJwSpj9g49CmTpeMXwCN4" name="security_GettyImages-1442484864.jpg" caption="" alt="Security concept art stock image featuring padlock on a blue background" src="https://cdn.mos.cms.futurecdn.net/2tJwSpj9g49CmTpeMXwCN4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/uk-cisos-are-cowing-to-ransomware-demands-more-than-you-think-heres-why-they-shouldnt-pay-up">UK CISO’s are cowing to ransomware demands more than you think, here’s why they shouldn’t pay up</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/23andme-risks-public-relations-disaster-as-it-blames-customers-for-data-breach">23andMe data breach response has been a public relations disaster as it blames customers for data breach</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/babuk-tortilla-ransomware-dealt-major-blow-with-release-of-new-decryptor-heres-how-victims-can-recover-their-data">Babuk Tortilla ransomware dealt major blow with release of new decryptor</a></p></div></div><p>It recommends checking to make sure that cloud services are configured in such a way that they are safe from common cyber attacks. " Reputable service providers make it easy for you to do this," the NCSC said.</p><p>Organizations should make sure that all their essential data is exported and backed up, and that they know how to access and restore it. While some cloud services keep a copy of deleted files for a short period, this shouldn&apos;t be relied on, according to the NCSC, and organizations should keep their own independent copy.</p><p>The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> center also offered fresh advice on how to keep domain names secure.</p><p>"If your public domain name was set up with a personal email account, you should change this so that it is now managed by an account under your organization’s control, such as a work email account," the NCSC said.</p><p>Organizations are also warned not to allow staff to use personal accounts for work activities or the other way round, nor to allow accounts to be shared. Accounts should be secured using two-factor verification, with unique, unguessable passwords. Admin accounts should have similar protection, and should only be created when necessary.</p><h2 id="ncsc-warns-of-growing-malware-threats">NCSC warns of growing malware threats</h2><p>The NCSC also detailed additional advice on avoiding <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> for small businesses amid an uptick in incidents over the last year. Devices should be kept up to date and protected, the guidance reads, and only trusted devices should be used to log into work accounts.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xeaCHzH5iMdAxuAANusCzi" name="2023 ThreatLabz Enterprise IoT and OT Threat Report.jpg" caption="" alt="2023 ThreatLabz Enterprise IoT and OT Threat Report" src="https://cdn.mos.cms.futurecdn.net/xeaCHzH5iMdAxuAANusCzi.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler )</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover strategies that ensure the resilience of OT environments</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/internet-of-things/2023-threatlabz-enterprise-iot-and-ot-threat-report">DOWNLOAD NOW</a></p></div></div><p>"The amount of trust you want in a device should be based on what it will be able to do and access. For example, users should only use a device that they know has been kept up to date and protected when logging into admin and staff accounts," the guidance reads.</p><p>"Similarly, your organization may choose whether to allow users that only have limited access to log in from a personal device as long as you trust them and they trust their device."</p><p>Organizations should make sure they make full use of <a href="https://www.itpro.com/cloud">cloud services</a>&apos; built-in security features, such as filtering out malicious messages and files and accessing services via a web browser or a dedicated mobile or desktop app.</p><p>Finally, there&apos;s advice on how to spot the signs and compromise and how to recover a hacked account or service, including step-by-step guides for <a href="https://www.itpro.com/software/workspace/google-workspace-review-a-simple-aesthetic-with-productivity-in-mind">Google Workspace</a> and <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a>.</p><p>"Our new guidance will help SMEs use online services more securely, so that they’re less likely to be the victim of a cyber attack," said Amelia H.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What are the most-targeted industries for cyber attacks? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/what-are-the-most-targeted-industries-for-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ What makes the most-targeted industries for cyber attacks such common victims, and what can they do to shore up security? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VMSRAfWimDswsXm9yLaaeR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HEuPZ3MHXKEfCnnXvCLP2j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Dec 2023 14:40:40 +0000</pubDate>                                                                                                                                <updated>Mon, 18 Dec 2023 17:17:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HEuPZ3MHXKEfCnnXvCLP2j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An industrial engineer standing outdoors, his face is lit by the light from a laptop and a power station blurred in the background. He is wearing a hard hat and high-vis jacket over an orange jumper.]]></media:description>                                                            <media:text><![CDATA[An industrial engineer standing outdoors, his face is lit by the light from a laptop and a power station blurred in the background. He is wearing a hard hat and high-vis jacket over an orange jumper.]]></media:text>
                                <media:title type="plain"><![CDATA[An industrial engineer standing outdoors, his face is lit by the light from a laptop and a power station blurred in the background. He is wearing a hard hat and high-vis jacket over an orange jumper.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HEuPZ3MHXKEfCnnXvCLP2j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every business is a potential target for cyber attacks, but <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets"><u>hackers choose targets</u></a> in some industries more than others. The most targeted industries for cyber attacks often include firms operating in “critical” sectors like energy, health, and finance which are targeted by both for-profit hacking groups and state-backed adversaries aiming to do damage to international rivals.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M52ds9wEZCmgUf2Bzb8fkM" name="GettyImages-1426489732-ransomware-hand-key-binary-crop.png" caption="" alt="A black and white hand holding a drawing of a white, square-handled key. Instead of teeth, the key has the number "10110" representing binary code and encryption. The hand and key are set against a solid blue background." src="https://cdn.mos.cms.futurecdn.net/M52ds9wEZCmgUf2Bzb8fkM.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/why-ransomware-attacks-happen-to-small-businesses-and-how-to-stop-them" target="_blank">Why ransomware attacks happen to small businesses – and how to stop them</a></p></div></div><p>Other industries are targeted because of the lucrative information they hold – <a href="https://www.itpro.com/security/cyber-security/360747/why-retailers-are-the-most-targeted-sector-for-cyber-attacks"><u>retail is a top target for cyber attacks</u></a> and law firms are often singled out for the same reason. Meanwhile government agencies, councils, and educational establishments often find themselves in hot water due to under-investment and lack of understanding of the importance of security. </p><p>Three industries stand out as key targets in the first half of 2023: technology, energy and education, according to recent <a href="https://www.gatewatcher.com/en/ressource/cyber-threats-barometer-november-2023/"><u>analysis</u></a> by Gatewatcher. </p><p>Gatewatcher CEO Jacques de la Riviere tells <em>ITPro </em>that schools and universities “suffer from a significant and recurring lack of resources, investment, and staff – and they offer criminals a lot of return”. </p><p>“There is access to a database of student and teacher accounts, confidential information that could be resold and technological and engineering data at research establishments.”</p><h2 id="why-critical-national-infrastructure-is-targeted-for-cyber-attacks">Why critical national infrastructure is targeted for cyber attacks</h2><p>Firms operating in so-called critical national infrastructure (CNI) sectors such as energy, water, transport, and health can find themselves at the top of the cyber-attack target list, with former <a href="https://www.itpro.com/tag/national-cyber-security-centre"><u>National Cyber Security Centre (NCSC)</u></a> chief Ciaran Martin having warned that <a href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni"><u>CNI is the next big ransomware target</u></a> in March 2023. Financial institutions, <a href="https://www.itpro.com/technology/cryptocurrencies/361286/cryptocurrency-should-you-invest"><u>cryptocurrency</u></a> exchanges, and fintech organizations are also considered a prime target, says James McQuiggan, security awareness advocate at KnowBe4. “These organizations handle large amounts of financial information, including sensitive data such as credit card numbers.”</p><p>The healthcare industry is also a popular goal for hackers partly because it handles information including medical records. “Cyber-criminals recognize that healthcare systems are maintained by the government or regulatory bodies and are sometimes challenged by slow-moving technological and implementation processes,” McQuiggan adds. </p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=54751392&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Manufacturing and <a href="https://www.itpro.com/security/cyber-attacks/361142/why-is-the-energy-sector-so-vulnerable-to-hacking"><u>energy sectors are vulnerable to hacking</u></a> and McQuiggan describes how they are more likely to be singled out by hackers. “Year after year, manufacturing organizations are a top target for nation states as they work to disrupt, damage, or destroy manufacturing, energy, and other critical infrastructure organizations,” says McQuiggan.</p><p>Outside of CNI, online retailers and e-commerce sites also handle large amounts of sensitive customer data, making them vulnerable to attack. In some cases, the reason for attacks is obvious. Attacks on CNI sectors such as energy firms are “a very political act” that can cause physical damage, says Ian Thornton-Trump, CISO at Cyjax. </p><p>Sectors that fall under this header, including energy and water firms, often use technology that was never meant to be connected to the internet, increasing the risk. It’s this exposure and the legacy technology they use that can cause “spectacular impacts” such as shutting down a critical power system, Thornton-Trump says. </p><p><a href="https://www.itpro.com/security/32264/stuxnet-is-back-iran-admits"><u>Stuxnet</u></a>, the infamous computer worm that caused physical damage to Iran’s nuclear centrifuges in 2010, is a prime example. </p><h2 id="the-threat-state-sponsored-groups-xa0-pose-to-industries">The threat state-sponsored groups pose to industries</h2><p>Attackers themselves are a diverse bunch, spanning nation-states through to cyber-criminals and <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism"><u>hacktivism</u></a> groups. State-sponsored attackers are typically directed by national governments and often target “strategically essential industries”, such as manufacturing and energy organizations, says McQuiggan.</p><p>Philip Ingram MBE, a former senior British Military Intelligence officer, describes how different nation-state adversaries target businesses. “International entities linked to nation-state priorities are themselves a potential target.”</p><p>One nation-state adversary to look out for is Iran, says Ingram. “It has a huge cyber capability but this is focused on specific areas: the first is Saudi Arabia and any infrastructure linked to the Saudi government including large corporations such as the oil giant Aramco.“</p><p>Iran also focuses on US defense targets, as well as CNI and financial institutions, Ingram adds. Meanwhile, Russia aims to have a disruptive political impact, targeting CNI, healthcare and financial institutions, says Ingram. “The aim is to create upset and undermine current government activity, leading to political pressure being applied.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9jRiDv3ZrwPArvTWH6TC3Z" name="2023 ThreatLabz state of ransomware report.jpg" caption="" alt="2023 ThreatLabz state of ransomware report" src="https://cdn.mos.cms.futurecdn.net/9jRiDv3ZrwPArvTWH6TC3Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how you can safeguard your organization against ransomware attacks with a zero trust strategy<br><br></em><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/2023-threatlabz-state-of-ransomware-report">DOWNLOAD NOW</a></p></div></div><p><a href="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks">Chinese cyber attacks</a> tend to focus on victims that offer a technical and therefore economic advantage. “Universities, research institutes, large technology, pharma companies, defense industries, and economic institutions are all high priority targets for Chinese cyber activity”, Ingram explains.</p><p>At the same time, <a href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks">North Korean cyber attacks</a> typically aim for financial institutions and crypto firms, says Ingram. When it comes to individual North Korean groups, a famous example from is Lazarus, which targets organizations in the financial industry and is known for the <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a> cyber attack that <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack">laid waste to the NHS</a> and is <a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two">still wreaking havoc</a> today. </p><p>The BlackCat <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> gang, also known as <a href="https://www.itpro.com/security/ransomware/everything-we-know-so-far-about-the-rumored-alphv-takedown">ALPHV</a>,  is notorious for targeting companies in the financial, legal, and professional services industries, says Kevin Curran, senior IEEE member and professor of cyber security at Ulster University. “The group uses a combination of advanced techniques in attacks. They initially infiltrate networks using the <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet">Emotet botnet</a> and <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell vulnerability</a> and redirect users to <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>-laden pages via hijacked legitimate websites.”</p><h2 id="regulating-to-protect-the-most-targeted-industries-xa0">Regulating to protect the most-targeted industries </h2><p>Given the number of specific targets for attack, it’s no surprise that regulation is emerging covering the security of critical sectors. For example, firms operating in Europe should be looking out for the <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive"><u>Network and Information Security 2 (NIS2)</u></a> directive and the <a href="https://www.itpro.com/business/policy-legislation/368414/eu-digital-operational-resilience-act-dora"><u>Digital Operational Resilience Act (DORA)</u></a>. </p><p>“NIS2 focuses on stepping up <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference"><u>cyber security risk management</u></a> and incident reporting across critical sectors in the EU, while DORA zeroes in on the financial sector and its supply chain, demanding better handling and reporting of IT risks,” says Cliff Martin, head of cyber incident response at GRCI Law.</p><p>Among its stipulations, the NIS2 Directive places the onus on organizations to adopt protective measures, share information on cyber threats, and comply with stricter supervisory requirements, says McQuiggan.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="v274Th96q48snC6N7CoQVo" name="GettyImages-1426489734-hacking-hand-asterisks-crop.jpg" caption="" alt="A black and white hand outstretched, beneath five white asterisks representing a hacker seizing a password. Both are set against a solid  red background." src="https://cdn.mos.cms.futurecdn.net/v274Th96q48snC6N7CoQVo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/hacking-is-not-a-crime-criminal-activity-is" target="_blank">Hacking is not a crime, criminal activity is</a></p></div></div><p>Beyond regulation, highly-targeted industry sectors should implement a robust cyber security strategy to safeguard their organization against threats, says David Emm, principal security researcher at Kaspersky.</p><p>In addition, he says, organizations need to fortify network and endpoint security, <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypt</a> sensitive data, and “continuously monitor for potential threats, utilizing threat intelligence sources to stay informed”.</p><p>For high-risk sectors, a layered approach to security is crucial, agrees Martin. “It’s vital that organizations are confident in their ability to detect and handle incidents as well as to prevent them. This means regular risk assessments, thorough employee training, solid incident response strategies and investing in cutting-edge security tech.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The end of ransomware payments: How businesses fit into the fight ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight</link>
                                                                            <description>
                            <![CDATA[ Governments worldwide have determined to stop ransomware payments, but what does this mean for businesses? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cKtAaAcXzNALEYPpEMKnnG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ELrPPh37SP8EyPNn5MWMYT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Dec 2023 13:12:40 +0000</pubDate>                                                                                                                                <updated>Fri, 23 Feb 2024 09:15:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ELrPPh37SP8EyPNn5MWMYT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of a metal safe representing ransomware payments, viewed from an isometric angle and placed against a dark grey background resembling a motherboard. At the bottom of the safe, gold pins like on a chip can be seen, and four blue lines of light emanate from each side of the square safe.]]></media:description>                                                            <media:text><![CDATA[A CGI render of a metal safe representing ransomware payments, viewed from an isometric angle and placed against a dark grey background resembling a motherboard. At the bottom of the safe, gold pins like on a chip can be seen, and four blue lines of light emanate from each side of the square safe.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of a metal safe representing ransomware payments, viewed from an isometric angle and placed against a dark grey background resembling a motherboard. At the bottom of the safe, gold pins like on a chip can be seen, and four blue lines of light emanate from each side of the square safe.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ELrPPh37SP8EyPNn5MWMYT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A global crackdown on ransomware payments is underway after a <a href="https://www.itpro.com/security/ransomware/coalition-of-nations-agree-to-end-ransomware-payments-to-hackers"><u>coalition of forty nations signed an agreement</u></a> designed to stop digital extortionists. Part of the <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2023/11/01/international-counter-ransomware-initiative-2023-joint-statement/" target="_blank"><u>International Counter Ransomware Initiative</u></a>, the no ransoms pledge aims to address ransomware attacks globally, with plans to leverage <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>artificial intelligence (AI)</u></a> and enhance information-sharing capabilities among nations. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="v274Th96q48snC6N7CoQVo" name="GettyImages-1426489734-hacking-hand-asterisks-crop.jpg" caption="" alt="A black and white hand outstretched, beneath five white asterisks representing a hacker seizing a password. Both are set against a solid  red background." src="https://cdn.mos.cms.futurecdn.net/v274Th96q48snC6N7CoQVo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/hacking-is-not-a-crime-criminal-activity-is" target="_blank">Hacking is not a crime, criminal activity is</a></p></div></div><p>The Initiative will see countries designing platforms to share information on digital payment accounts and wallets associated with ransomware. The idea is to make it easier to trace the accounts used by criminals and prevent the transfer of funds.</p><p>Global organizations including the UK’s <a href="https://www.itpro.com/tag/national-cyber-security-centre"><u>National Cyber Security Centre (NCSC)</u></a> and US Federal Bureau of Investigation (FBI) already advise against paying ransoms, but <a href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up"><u>many firms still pay up</u></a>.</p><p>As the new crackdown on ransomware ramps up across the globe, what are the rules now – and what can firms do to avoid paying the ransom?</p><h2 id="crackdown-on-public-sector-ransomware-payments">Crackdown on public sector ransomware payments</h2><p>The Initiative does not directly impact private firms, as it focuses on government organizations and agencies. However, the overall aim is to increase collaboration between the public and private sectors and discourage payments by all organizations, says Javvad Malik, lead security awareness advocate at KnowBe4.</p><p>In doing so, the initiative hopes to make things difficult for <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware-as-a</u>-service</a> operators and their business model. The agreement sets the stage for governments to collaborate more closely with each other to attack the problem from multiple angles, says Daniel Clayton, VP of security operations at Expel. This includes measures such as analyzing the <a href="https://www.itpro.com/security/28031/what-is-blockchain"><u>blockchain</u></a> to identify funding for ransomware and track and capture extortionists. </p><p>The initiative also aims to boost information sharing between member governments, he says, a step towards the kind of <a href="https://www.itpro.com/security/cyber-attacks/standardized-information-sharing-framework-essential-for-improving-cyber-security"><u>information-sharing framework</u></a> for which experts in the space have long called. Recent developments such as the <a href="https://www.itpro.com/security/us-and-eu-cyber-agencies-strike-agreement-to-boost-global-threat-response"><u>information sharing agreement</u></a> between the European Union Agency for Cybersecurity (ENISA) and US Cybersecurity and Infrastructure Security Agency (CISA) may complement this.</p><p>Of course, no firm wants to pay the ransom but the reality is often complex. It is not illegal unless the payment is made to a sanctioned entity, says Picus researcher Huseyin Can Yuceel. “Many businesses weigh the financial losses and legal repercussions of the attack and choose to pay the ransom as an unforeseen cost.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z5o5av8Qme7nhYwTzVLsuC" name="Everything is connected_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/z5o5av8Qme7nhYwTzVLsuC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how the ransomware epidemic influences global supply chains<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370165/uncovering-the-ransomware-threat-from-global-supply-chains">DOWNLOAD NOW</a></p></div></div><p>But there are also multiple risks associated with paying ransoms. There is no way of knowing for certain if the attackers will honor the agreement and provide the decryption key, says Matt Roach, head of International information integrity institute (i-4) cyber security leaders community at KPMG UK. “Nor is there a guarantee that they won’t attack the company again. There are numerous instances of repeat victimization by different groups of cyber-criminals once word gets around that a particular company is a ‘cyber-soft touch’.”</p><p>At the same time, there are important ethical considerations to bear in mind, says Roach. “There is a risk that the money paid to cyber-criminals will be used for organized crime, human trafficking, terrorism, or other illegal activities.”</p><p>Recent Trend Micro <a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/understanding-ransomware-using-data-science?cjdata=MXxZfDB8WXww&PID=6361382&SID=itprous-gb-1349978003689107500&cjevent=357871d2981811ee820f03180a18b8f8" target="_blank"><u>research</u></a> found that <a href="https://www.itpro.com/security/ransomware/370132/paying-ransomware-gangs-fund-10-additional-attacks"><u>ransomware payments could fund up to ten new attacks</u></a>, with researchers warning that ransomware groups can escalate attacks using payments from just a few victims.</p><p>Roach adds that law enforcement is closing in on cyber crime and that this should also be something businesses take into consideration. “Several governments are now imposing sanctions on cyber criminals. Hence, you might be breaking the law if you intend to acquiesce to their demands for payment.”  </p><p>In February 2023 the UK government <a href="https://www.itpro.com/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown"><u>issued sanctions against members of Ryuk and Conti</u></a>, ransomware groups known for attacks victims including <a href="https://www.itpro.com/security/357525/sopra-steria-new-ryuk-variant-weeks-recover"><u>Sopra Steria</u></a> and the <a href="https://www.itpro.com/security/ransomware/367623/costa-rica-declares-state-of-emergency-following-conti-ransomware-attack"><u>government of Costa Rica</u></a> respectively. The US Department of Justice (DoJ) has also <a href="https://www.itpro.com/security/cyber-crime/latest-arrest-places-lockbit-firmly-in-the-crosshairs-of-international-cyber-police"><u>charged three members of Lockbit</u></a>, the group behind the <a href="https://www.itpro.com/security/ransomware/lockbit-remains-most-dangerous-ransomware-despite-fall-in-attacks"><u>most dangerous ransomware</u></a> strain and known for attacks such as the <a href="https://www.itpro.com/security/ransomware/370124/lockbit-leaks-44gb-royal-mails-data-sets-fresh-ps33-million-ransom"><u>February 2023 Royal Mail cyber attack</u></a> which cost the firm <a href="https://www.itpro.com/security/royal-mail-has-spent-pound10-million-in-remediation-costs-after-lockbit-cyber-attack"><u>£10 million ($12.58 million) in remediation costs</u></a>.</p><p>While you shouldn’t pay unless you have to, for private companies it is still a business decision. There is a need to weigh up the pros and cons of cost, <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations"><u>reputational damage linked to a data breach</u></a>, and <a href="https://www.itpro.com/business-strategy/disaster-recovery-dr/367961/how-much-is-99999-uptime-actually-worth"><u>downtime</u></a> with the risks associated with paying the ransom and the potential mitigation of <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance">cyber insurance</a>, says Clayton. “It is a reality that if a company has not been sufficiently diligent with response planning, they may have no choice but to make the payment.”</p><p>Richard Breavington, partner at international law firm RPC describes how his firm has dealt with cases where organizations have had to pay a ransom due to <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encryption</u></a> of their main servers. “This meant that they were unable to carry out business and as a result, were suffering ongoing and unsustainable losses to revenue and commercial reputation that could only be remedied through getting their data back.”</p><p>Another firm needed to delay the publication of sensitive commercial information.  “In one case, the publication of data relating to a sensitive corporate agreement could have jeopardized the deal at the time. Once the deal was complete, the sensitivity decreased considerably, but the ransom payment to delay imminent data release was considered necessary by the client.”</p><h2 id="negotiating-with-attackers-over-ransomware-payments">Negotiating with attackers over ransomware payments</h2><p>Whether a firm pays in the end or not, it is often necessary to negotiate with attackers. If they need to do so, organizations shouldn’t go it alone. First and foremost, consult with your legal team before and during any negotiation, says Clayton. He recommends using a well-regarded third-party ransomware negotiation service to interact with attackers, especially if you plan to pay. </p><p>Of course, the ideal outcome is to avoid paying the ransom at all – something backed up by all the advice from experts and governments. </p><p>Organizations are better off investing money that would be paid to a ransomware adversary in improving their security, says Allan Liska, threat intelligence analyst at Recorded Future. “Invest in better backup capabilities, as well as more effective data management. Because of the way ransomware attacks have evolved, where data exfiltration is integral to an attack it can be just as important to know where your data is, both locally and in cloud environments, and how it is being secured at all times good backups and other effective security steps.”</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=56509835&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Businesses should remember the basics to help mitigate ransomware risks, says Adam Harrison, managing director in the cybersecurity practice at FTI Consulting. “Identify what and where critical data is and make sure it is properly protected; ensure <a href="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy"><u>backups</u></a> are complete, offline, and tested; and employ <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA)</u></a> wherever possible.”</p><p>In addition, Malik advises patching vulnerable software and providing security awareness training to employees. No business can escape this threat altogether, with <a href="https://www.itpro.com/security/ransomware/why-ransomware-attacks-happen-to-small-businesses-and-how-to-stop-them"><u>small business ransomware attacks</u></a> on the rise as attackers exploit the lower security budgets and outdated software of smaller businesses for financial gain.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RUqRvKotEcdx7mncP2Vh2G" name="GettyImages-1365148935-cyber-padlocks-yellow.jpg" caption="" alt="A graphic of dozens of locked, gold padlocks on a pale yellow background, lined up in rows and viewed with an isometric view to represent cyber security. To the right of the frame there is one especially large, unlocked padlock. They are set against a pale yellow background." src="https://cdn.mos.cms.futurecdn.net/RUqRvKotEcdx7mncP2Vh2G.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-many-security-providers-is-the-right-amount" target="_blank">How many security providers do you really need?</a></p></div></div><p>The global ransomware crackdown is likely to expand as the data-locking <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> continues to be a part of many modern cyber-attacks. The new agreement is about discouraging payments, rather than banning them, to try and disrupt the ransomware business model for good. For now, experts agree that collaboration between companies and the public sector is key – and paying the ransom should only be a last resort.</p><p>As ransomware evolves, it is vital that organizations anticipate how stolen data could be used for secondary crime and fraud, says Roach. “Place additional cyber security measures around the data that would cause the greatest embarrassment or damage in the hands of enemies.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC Cyber Incident Exercising scheme looks to fine-tune incident response ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-cyber-incident-exercising-scheme-looks-to-fine-tune-incident-response</link>
                                                                            <description>
                            <![CDATA[ The NCSC Cyber Incident Exercising scheme will offer bespoke, structured table-top or live-play cyber incident exercises ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SXTLQeSEpLLY83Rthx9pg9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Dec 2023 13:11:07 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Jun 2024 11:45:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Centre (NCSC) has launched its new Cyber Incident Exercising scheme, with the aim of helping organizations to carry out cyber <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response</a> exercises. </p><p>First announced in August 2023, the scheme involves <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> not-for-profit CREST and certification organization IASME as the delivery partners for the scheme, managing assessments and bringing the assured exercising service providers on board.</p><p>"In some respects, there is no difference between our delivery partners – both will adhere to the NCSC’s strict standards for assessing technical and organizational capability," said Catherine H, NCSC&apos;s head of assured professional services schemes, industry assurance.</p><p>"However, the model each is using for the processes of onboarding, ongoing management and off-boarding of suppliers is different. Having two delivery partners means potential providers have two routes to apply for membership of the CIR Level 2 scheme and can choose whichever is best for their business."</p><h2 id="inside-the-ncsc-cyber-incident-exercising-scheme">Inside the NCSC Cyber Incident Exercising scheme</h2><p>The NCSC Cyber Incident Exercising scheme gives organizations access to approved service providers that will create bespoke, structured table-top or live-play cyber incident exercises. </p><p>It&apos;s designed to complement the NCSC’s free <em>Exercise in A Box</em> tool, which allows organizations to test their incident response against a host of generic cyber incident scenarios.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xVTMjZ6UmEQAhwxsGt2JDC" name="GettyImages-635260654.jpg" caption="" alt="NCSC logo superimposed with a translucent background in front of an office building" src="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ncsc-announces-global-guidelines-on-ai-security">NCSC announces global guidelines on AI security</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ncsc-warns-of-cyber-risk-to-the-uks-water-network">Cyber risk to the UK&apos;s water network, NCSC warns</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ncsc-ai-will-increase-speed-and-scale-of-critical-infrastructure-attacks">NCSC: AI will increase speed and scale of critical infrastructure attacks</a></p></div></div><p>"I’ve often said the first time you try out your cyber incident response plan shouldn’t be on the day you are attacked. So, if you do only one thing on a regular basis, incident exercising should be it," said NCSC director of operations Paul Chichester.</p><p>"Exercising in a safe and supportive environment will allow all the relevant teams and individuals to properly understand their roles and maximize their effectiveness during an incident. In turn this will help to minimize harm and improve the resilience of both individual organizations and the UK as a whole."</p><p>However, the scheme doesn&apos;t cover category 1 and category 2 incidents, as defined by the UK cyber incident categorization system.</p><p>Category 1 incidents are national cyber emergencies causing sustained disruption to the UK’s public services or affecting national security, and leading to severe economic and social impacts or deaths.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="A6eNTYJyPgtyLyTwa9UgCd" name="Beat cyber criminals at their own game_listing.jpg" caption="" alt="Red whitepaper cover with title and logo above circular images of colleagues using laptops, and servers" src="https://cdn.mos.cms.futurecdn.net/A6eNTYJyPgtyLyTwa9UgCd.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how you can protect your business from potential attacks<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/beat-cyber-criminals-at-their-own-game">DOWNLOAD NOW</a></p></div></div><p>Meanwhile, Category 2 incidents are those with a &apos;serious impact&apos; on central government, essential public services, a large proportion of the population, or the economy. In both these cases, there would be a coordinated government response.</p><p>Instead, the scheme is designed to simulate incidents that have a significant impact on a single client organization.</p><p>According to IASME, the scheme is primarily aimed at private sector organizations, charities, local authorities, and smaller public sector organizations which operate in the UK.</p><p>Companies can access services through a portal of approved providers, the NCSC said.</p><p>"We are determined that companies of any size can apply to join any of our schemes. We particularly welcome companies located in or serving geographically remote or under-represented areas," the NCSC said.</p><p>"Similarly, if your company is working hard to address issues of under-representation in the cyber security workforce, we’d love to see your application."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber risk to the UK's water network, NCSC warns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-warns-of-cyber-risk-to-the-uks-water-network</link>
                                                                            <description>
                            <![CDATA[ The cyber security agency is advising water companies to take action following an attack on a facility in the US ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P4rKbDTby8gbJn4R2td67A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A4izkxrQ38gsj4MhfU9t66-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Dec 2023 13:35:40 +0000</pubDate>                                                                                                                                <updated>Fri, 01 Dec 2023 17:11:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A4izkxrQ38gsj4MhfU9t66-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photo of the outside of Daveyhulme wastewater treatment plant showing a large building surrounded by large white pipes]]></media:description>                                                            <media:text><![CDATA[A photo of the outside of Daveyhulme wastewater treatment plant showing a large building surrounded by large white pipes]]></media:text>
                                <media:title type="plain"><![CDATA[A photo of the outside of Daveyhulme wastewater treatment plant showing a large building surrounded by large white pipes]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A4izkxrQ38gsj4MhfU9t66-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK&apos;s <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> has warned of the active exploitation of Unitronics programmable logic controllers (PLCs), used extensively across the water sector.</p><p>The <a href="https://www.ncsc.gov.uk/news/ncsc-statement-following-exploitation-of-unitronics-programmable-logic-controllers" target="_blank">statement</a> follows a <a href="https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems" target="_blank">similar alert</a> from the US Cybersecurity & Infrastructure Security Agency (CISA) earlier this week, with the NCSC recommending that organizations should follow its guidance.</p><p>"The NCSC has warned for some time of the enduring threat to the UK’s critical national infrastructure," says Jonathon Ellison, NCSC director for national resilience and future technology.</p><p>"Our US counterparts, CISA, have issued an advisory outlining a threat against the water sector. We are notifying UK providers of this threat, and recommend they protect consumers by following the mitigation advice set out by CISA."</p><p>Water and waste water facilities use PLCs to control and monitor various processes, including turning on and off pumps to fill tanks and reservoirs, flow pacing chemicals to meet regulations, gathering compliance data for monthly regulation reports, and announcing critical alarms to operations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sf5b5N6zXz9jW9fiJLCtaA" name="sf5b5N6zXz9jW9fiJLCtaA.jpg" caption="" alt="Graphic to represent digital water" src="https://cdn.mos.cms.futurecdn.net/sf5b5N6zXz9jW9fiJLCtaA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ncsc-announces-global-guidelines-on-ai-security">NCSC announces global guidelines on AI security</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368808/uk-water-supplier-confirms-hack-by-cl0p-ransomware-gang">UK water supplier confirms hack by Cl0p ransomware gang</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/369238/can-smart-water-fix-britains-broken-water-supply">Can &apos;smart water&apos; fix Britain&apos;s broken water supply?</a></p></div></div><p>While the NCSC says that the exploitation is of ‘limited sophistication’ and is highly unlikely to cause any disruption to water supplies, there is a potential risk to some small suppliers.</p><p>The CISA advisory follows an attack on an unidentified US water facility, in which the attackers appear to have accessed the affected device — a Unitronics Vision Series PLC with a Human Machine Interface (HMI) — by exploiting <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">poor password security</a> and exposure to the internet.</p><p>The facility, says CISA, immediately took the system offline and switched to manual operations, meaning that there was no known risk to the drinking water or water supply.</p><p>But to prevent other attacks, it says, users should change all default passwords on PLCs and HMIs, require <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multifactor authentication</a> for all remote access, including from the IT network and external networks, and disconnect the PLC from the open internet.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xVA2pNHKZj5x6aph2MKhhM" name="Three essential requirements for flawless data protection (1).jpg" caption="" alt="Three essential requirements for flawless data protection whitepaper" src="https://cdn.mos.cms.futurecdn.net/xVA2pNHKZj5x6aph2MKhhM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Want a better CASB and stronger DLP? Starts with the right foundation.</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/three-essential-requirements-for-flawless-data-protection">DOWNLOAD NOW</a></p></div></div><p>They should also back up the logic and configurations on any Unitronics PLCs to enable fast recovery, where possible utilize a TCP port other than the default TCP 20256 port and update PLC/HMI to the latest version.</p><p>The alert follows a recent <a href="https://www.ncsc.gov.uk/news/ncsc-warns-enduring-significant-threat-to-uks-critical-infrastructure" target="_blank">NCSC report</a> that warned that the UK’s critical sectors, including the water industry, are facing an &apos;enduring and significant’ threat.</p><p>"The last year has seen a significant evolution in the cyber threat to the UK – not least because of Russia’s ongoing invasion of Ukraine but also from the availability and capability of emerging tech," says NCSC CEO Lindy Cameron.</p><p>"Beyond the present challenges, we are very aware of the threats on the horizon, including rapid advancements in tech and the growing market for cyber capabilities."</p><p>In summer last year, South Staffs Water fell victim to hackers who were able to access the names and addresses of account holders, along with the sort codes and account numbers used for direct debit payments. Shortly after, a ransomware group claimed it was possible to tamper with water supplies.</p><p>And in the US, there have been a number of attacks, including the breach of a water authority near Pittsburgh which affected the water pressure in nearby towns. The attack is believed to have been carried out by hacktivists aligned with the government of Iran.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC: AI will increase speed and scale of critical infrastructure attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-ai-will-increase-speed-and-scale-of-critical-infrastructure-attacks</link>
                                                                            <description>
                            <![CDATA[ The NCSC Annual Review suggests AI-related threats to national infrastructure are growing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">V8Z4tXxm4PyKMgLBkvk98B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Nov 2023 12:36:29 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Nov 2023 16:45:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) has raised concerns over the rising possibility of AI-supported cyber attacks against critical national infrastructure (CNI) targets.</p><p>In its annual review, the security center warned that state-aligned threat actors are accelerating attempts to disrupt critical targets, such as hospitals or organizations operating in the energy sector. </p><p>The NCSC pointed toward a range of tactics employed by threat actors, including ransomware and DDoS attacks, as well as the spread of misinformation to create chaos across the UK. </p><p>“2023 has seen the addition of state-aligned actors to the ongoing threat from state actors, as a new and emerging cyber threat to CNI,” the review states. </p><p>“While the cyber activity of these groups often focuses on DDoS attacks, website defacements, and/or the spread of misinformation, some have stated a desire to achieve a more disruptive and destructive impact against western CNI.”</p><p>The report further warned that the use of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> tools among threat actors could pose heightened threats to infrastructure targets across the country. </p><p>“Our adversaries - hostile states and cyber criminals - will seek to exploit <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> technology to enhance existing tradecraft,” it said. </p><p>“In the short term, AI technology is more likely to amplify existing cyber threats than create wholly new ones, but it will almost certainly sharply increase the speed and scale of attacks.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="s96hutZKqthLgFMn3rBsbW" name="AI governance for responsible transparent and explainable AI workflows.jpg" caption="" alt="Managing Data for AI and Analytics at Scale with an Open Data Lakehouse Approach: IBM watsonx.data whitpaper" src="https://cdn.mos.cms.futurecdn.net/s96hutZKqthLgFMn3rBsbW.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about the key building block that comprise AI governance <br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ai-governance-for-responsible-transparent-and-explainable-ai-workflows">DOWNLOAD NOW</a></p></div></div><p>Threats to CNI have been rising in recent years. A UK government report in August suggested that a successful attack against a target could <a href="https://www.itpro.com/security/cyber-attacks/threat-of-cyber-attacks-to-national-security-compared-to-that-of-chemical-weapons"><u>wreak havoc on-par with a chemical or biological warfare attack</u></a>. </p><p>Andy Kays, CEO of Socura, a Cardiff-based security firm that works with CNI providers such as NHS trusts, said attacks on infrastructure targets have been escalating and have the potential to cause widespread national disruption. </p><p>"Attacks on UK banks, hospitals and energy providers have all increased in recent years, especially since the start of the Ukraine war," he said. </p><p>"These are typically well-resourced organizations, but they are prime targets for adversaries who are seeking to cause maximum disruption. The UK can always do more to protect these critical assets."</p><h2 id="ransomware-still-a-potent-threat">Ransomware still a potent threat</h2><p>Ransomware still remains a pervasive and potent threat to critical national infrastructure, according to the NCSC, with threat actors now switching tactics to include double extortion techniques. </p><p><a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">Double extortion</a> techniques differ from a traditional ransomware approach by both exfiltrating and encrypting stolen data, providing the threat actor with an additional degree of leverage to demand payments.</p><p>The NCSC warned that Russian-speaking threat actors have been observed conducting these style of attacks to great success in recent months.</p><p>Kevin Curran, IEEE senior member and professor of cyber security at Ulster University said the <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack">Colonial Pipeline attack</a> in May 2021 still serves as a reminder of the devastating impact such an attack could have on CNI. </p><p>"<a href="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware </a>remains one of the biggest threats to critical national infrastructure. Attacks have increased tenfold and in severity,” he said. </p><p>“Consider the more recent attack in May 2021 on the Colonial pipeline in the US which runs from Houston to New Jersey and controls 50% of the fuel supply in North America.</p><p>"It revealed the damage ransomware can pose to vital national infrastructure and public services, which seem to be the main target at present, as it causes the most disruption."</p><h2 id="ai-election-meddling-xa0">AI election meddling </h2><p>AI-based cyber threats were a common recurring talking point in the NCSC’s annual review, with the center warning that countries such as Russian, China, or Iran may use the technology to interfere in elections. </p><p>According to the report, the rise of AI and geopolitical pressures are putting UK electoral processes at risk. </p><p>NCSC chief executive Lindy Cameron said geopolitical threats have been rising rapidly since the Russian invasion of Ukraine in February 2023, and warned that the country can expect to see additional threats in the coming years. </p><p>"The last year has seen a significant evolution in the cyber threat to the UK – not least because of Russia’s ongoing invasion of Ukraine, but also from the availability and capability of emerging tech," she said.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V9HGm7YHJKhfpsykZVZXEU" name="AI for customer service.jpg" caption="" alt="AI for customer service whitepaper" src="https://cdn.mos.cms.futurecdn.net/V9HGm7YHJKhfpsykZVZXEU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI for customer service</strong></p><p class="fancy-box__body-text"><em>Get an overview of the conversational AI landscape and its three most common use cases<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/368445/ai-for-customer-service">DOWNLOAD NOW</a></p></div></div><p>"Beyond the present challenges, we are very aware of the threats on the horizon, including rapid advancements in tech and the growing market for cyber capabilities."</p><p>The UK government has said it&apos;s almost certain that Russian actors attempted to interfere with the 2019 general election. And, with the next set to take place before the end of January 2025, the NCSC warned that the changing geopolitical situation has made the prospect of influencing the political discourse ever more attractive.</p><p>The center warned threat actors will “almost certainly” harness <a href="https://www.itpro.com/technology/why-cutting-edge-innovation-is-killing-the-planet">large language models</a> (LLMs) to generate election disinformation, which could then be spread by AI-created hyper-realistic bots. </p><p>Simon Thompson, head of data science and AI at <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> firm GFT said the prospect of AI-generated misinformation is a serious concern given the current maturity of technologies designed to mitigate these threats.</p><p>"As it stands, the technology that is being used to assess and flag AI-made content, both positive and negative, has not yet matured as much as we would have hoped to prevent this content from reaching its intended audiences," he said.</p><p>"This means that election commissions and those charged with protecting the sanctity of the electoral process will have to focus on the impact that the technology could have on the democratic process and seek ways to combat it." </p><p>The review also highlights a new trend of malicious actors targeting the personal email accounts of high-profile and influential individuals involved in politics. </p><p>This warning from the NCSC follows a campaign conducted by Chinese-linked threat actors earlier this year which saw email <a href="https://www.itpro.com/security/microsoft-reveals-2021-crash-dump-led-to-us-state-department-hacks"><u>correspondence belonging to US State Department officials exposed</u></a>.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s NCSC names Ollie Whitehouse as its new CTO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/public-sector/uks-ncsc-names-ollie-whitehouse-as-its-new-cto</link>
                                                                            <description>
                            <![CDATA[ Whitehouse has called for better public-private information sharing over cyber threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GtoMS3QpLUY9SkURshLVcf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GgocSx85TsNe8XYXjMyQB7-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Aug 2023 23:01:00 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Sep 2023 10:03:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is a staff writer at ITPro. He is a subject expert on artificial intelligence and business networks and additionally covers a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs and extensive daily coverage of the most significant announcements, as well as analysis pieces and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/GgocSx85TsNe8XYXjMyQB7-1280-80.png">
                                                            <media:credit><![CDATA[UK NCSC]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC CTO Ollie Whitehouse headshot]]></media:description>                                                            <media:text><![CDATA[NCSC CTO Ollie Whitehouse headshot]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC CTO Ollie Whitehouse headshot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GgocSx85TsNe8XYXjMyQB7-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) has announced its new chief technical officer (CTO) as Ollie Whitehouse, a veteran of the cyber security sector.</p><p>Whitehouse has spent the past 27 years in the private sector, having most recently held the role of CTO at NCC Group. </p><p>Throughout his time at NCC Group Whitehouse stressed the importance of fruitful public-private partnerships when it comes to cyber security. </p><p>He praised the work of the NCSC in particular, describing it as a central player for the entire UK’s cyber resilience and the country’s place within the international cyber community. He also called for greater cross-sector information sharing, a goal he could pursue further in his new role.</p><p>"I’m honored to be starting as chief technology officer at the NCSC and look forward to supporting its world-class talent in their critical work keeping the UK safe online,” said Whitehouse.</p><p>“Having worked closely with the NCSC since its inception, I know how crucial its mission is and I am eager to contribute to our national security by addressing the collective challenges we face in maintaining our edge in cyberspace.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="87gaNQAGPvtMfF9usou6tG" name="Three steps to transforming security operations_listing.jpg" caption="" alt="Whitepaper cover with green title above image of business man holding a smart phone" src="https://cdn.mos.cms.futurecdn.net/87gaNQAGPvtMfF9usou6tG.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Three steps to transforming security operations</strong></p><p class="fancy-box__body-text"><em>Learn how to automate processes, save thousands of hours for your IT security staff, and stay ahead of the latest cyberthreats.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/three-steps-to-transforming-security-operations">DOWNLOAD FOR FREE</a></p></div></div><p>In 2017 and 2022 Whitehouse gave testimony to the UK Parliament Joint Committee on the National Security Strategy. The session was centered on the threat posed to the UK by ransomware, and the dividing lines between groups motivated by profit and those with state backing.</p><p>Among the expert areas of discussion Whitehouse offered testimony on the rise of <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware as a service</u></a> (RaaS), as well as the motivations for threat actors and how smaller groups can obtain <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> through the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a>.</p><p>Whitehouse will formally take up the role in October, at which point he will inherit responsibilities such as <a href="https://www.itpro.com/security/cyber-attacks/ncsc-sbu-reveal-overt-russian-cyber-campaign-as-cyber-war-continues-to-evolve"><u>ongoing cyber support for Ukraine</u></a> and <a href="https://www.itpro.com/security/ncsc-expands-incident-response-scheme-to-support-smaller-at-risk-organizations"><u>incident response for smaller groups</u></a> such as charities and other public sector organizations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC, SBU reveal overt Russian cyber campaign as cyber war continues to evolve ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/ncsc-sbu-reveal-overt-russian-cyber-campaign-as-cyber-war-continues-to-evolve</link>
                                                                            <description>
                            <![CDATA[ Sandworm-linked threat actors gained access to battlefield tablets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y82NppLgZ7zP4DpTwWToDc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EmPpjivS5QagLQf2iQgm9n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Aug 2023 11:59:01 +0000</pubDate>                                                                                                                                <updated>Thu, 31 Aug 2023 12:44:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is a staff writer at ITPro. He is a subject expert on artificial intelligence and business networks and additionally covers a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs and extensive daily coverage of the most significant announcements, as well as analysis pieces and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EmPpjivS5QagLQf2iQgm9n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Ukrainian military member holds a smartphone, with a residential building in the background. They are based in Donetsk Oblast, Ukraine.]]></media:description>                                                            <media:text><![CDATA[A Ukrainian military member holds a smartphone, with a residential building in the background. They are based in Donetsk Oblast, Ukraine.]]></media:text>
                                <media:title type="plain"><![CDATA[A Ukrainian military member holds a smartphone, with a residential building in the background. They are based in Donetsk Oblast, Ukraine.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EmPpjivS5QagLQf2iQgm9n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) and joint partners have issued a report into a new malware linked to the Sandworm group openly targeting Ukrainian military devices.</p><p>‘Infamous Chisel’ is an infostealer malware that was found targeting Android devices in use by Ukrainian military personnel on the front lines as a possible first step towards a wider-scale compromise of Ukrainian military networks.</p><p>Though the malware largely contains standard components implemented with intermediate sophistication, and was easily discovered via an investigation, researchers noted that Android has no automatic detection for attacks of this kind.</p><p>The authors also noted the overt nature of the campaign was matched by the serious danger associated with any exfiltration of sensitive Ukrainian military data. </p><p>According to the NCSC, Infamous Chisel made little attempt to obscure its activities from security services but had been specially crafted to establish persistence on victims’ devices. </p><p>The Security Service of Ukraine (SBU) discovered and eradicated the <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> on Android tablets, and shared its findings with international partners.</p><p>“Since the first days of the full-scale war, we have been fending off cyber attacks of Russian intelligence services aiming to break our military command system and more,” said Illia Vitiuk, head of the SBU’s cyber security department.</p><p>“The operation we have carried out now is the cyber defense of our forces.”</p><p>The SBU first published a report on Infamous Chisel on 8 August, in which it stated that it was confident the APT group Sandworm was behind the malware campaign.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TUHb3DrtXpm3KwkkJUCCS6" name="Choosing_right_technology to strengthen cloud security_listing.jpg" caption="" alt="A whitepaper from ServiceNow covering how to lay a strategic foundation for cloud security that protects what matters to your business" src="https://cdn.mos.cms.futurecdn.net/TUHb3DrtXpm3KwkkJUCCS6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><em>Choose the optimal cloud security platform and discover what the right solution should enable you to do.</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/choosing-the-right-technology-to-strengthen-cloud-security-and-risk-management">DOWNLOAD FOR FREE</a></p></div></div><p>In the weeks after, the NCSC worked on analyzing the threat with international partners including the US Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA), New Zealand’s National Cyber Security Centre (NCSC-NZ), and the Canadian Centre for Cyber Security.</p><p>Paul Chichester, director of operations at the NCSC, noted that the campaign represents a new evolution in Russia’s ongoing cyber campaigns against Ukraine and its allies.</p><p>“The exposure of this malicious campaign against Ukrainian military targets illustrates how <a href="https://www.itpro.com/security/ransomware/off-the-shelf-ransomware-is-spurring-a-new-era-in-the-ukraine-war"><u>Russia’s illegal war in Ukraine</u></a> continues to play out in cyberspace,” he said.</p><p>“Our new report shares expert analysis of how this new malware operates and is the latest example of our work with allies in support of Ukraine’s staunch defense. The UK is committed to calling out Russian cyber aggression and we will continue to do so.”</p><p>The NCSC has linked Sandworm to Russia’s Main Intelligence Directorate (GRU), specifically its Unit 74455 which is otherwise known as the Main Centre for Special Technologies GTsST.</p><p>Previously tracked by Microsoft as IRIDIUM, and now known under the name Seashell Blizzard, Sandworm is the main suspect behind the <a href="https://www.itpro.com/malware/34381/what-is-notpetya"><u>NotPetya</u></a> attacks that in 2017 <a href="https://www.itpro.com/ransomware/34749/microsoft-cut-off-entirety-of-ukraine-from-its-network-during-notpetya-attacks"><u>encrypted Ukrainian financial, energy, and government systems</u></a>. </p><p>The NCSC has also credited Sandworm with a 2018 attempt to breach UK Defence and Science Technology Laboratory (DSTL) systems, as well as widespread description of Georgian government websites.</p><p>In November 2022 the UK government specifically named Sandworm’s ‘Industroyer2’ malware as a strain of concern, and <a href="https://www.itpro.com/security/369438/uks-6m-cyber-support-package-for-ukraine-revealed-for-first-time"><u>pledged to provide Ukraine with £6.35 million</u></a> ($8 million) for cyber defense which has since been increased to up to £25 million ($32 million).</p><p>The Industroyer family targets industrial control systems (ICS) and is part of a wave of new threats against critical national infrastructure (CNI).</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="how-does-infamous-chisel-operate">How does Infamous Chisel operate?</h2><p>Infamous Chisel is made up of several main components named ‘netd’, ‘killer’, ‘blob’, and ‘td’ which all perform different functions.</p><p>‘Netd’ replaces the default binary of the same name within Android’s system directory, which allows it to achieve persistence. Its main function is to exfiltrate data, which it performs approximately once per day. It collects a wide range of file types, including .dat, .bat, .txt, and .xml. </p><p>The component collects device information as well as any network and application data specific to the Ukraine military. It scans all networks available via the <a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">Transmission Control Protocol (TCP)</a> ports approximately every two days, and collects network information as .tmp and .csv text files for exfiltration.</p><p>The SBU described some of its behavior as consistent with Russian intelligence activities, and the NCSC noted that network scanning of this kind suggests an intent for lateral attacks down the line.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about the benefits AI brings to cyber security landscape.</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security">DOWNLOAD FOR FREE</a></p></div></div><p>Once collected, the malware uses the ‘blob’ and ‘td’ components to establish a connection with a hard-coded local IP via the <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open-source</u></a> anonymous browser <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>The Onion Router (Tor)</u></a>. The software package ‘dropbear’ maintains the threat actor’s remote access to the infected device via port 34371.</p><p>‘Killer’ is simply used to end ‘netd’ by remote threat actor command.</p><p>The SBU additionally identified a component named ‘stl’, through which the malware collects data on the device’s connection to the <a href="https://www.itpro.com/infrastructure/network-internet/368407/spacex-given-fcc-provide-starlink-wifi-moving-vehicles"><u>Starlink satellite constellation</u></a>, as well as two components used to download additional <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>Trojans</u></a>.</p><p>Ukrainian forces have made extensive use of SpaceX’s Starlink since Russia’s invasion, to stay connected in areas with poor traditional connectivity. Its fleet of <a href="https://www.itpro.com/infrastructure/mobile-networks/uk-government-eyes-pound160-million-satellite-fund-to-boost-5g-and-broadband"><u>low-earth orbit (LEO) satellites</u></a> has been a reliable platform for crucial networks, amid Russian <a href="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine"><u>missile and cyber attacks</u></a> on other communications networks.</p><p>Initially provided to Ukraine for free, the <em>New York Times</em> has since <a href="https://www.nytimes.com/interactive/2023/07/28/business/starlink.html?p=cur" target="_blank"><u>reported</u></a> that SpaceX has requested funds from the Department of Defense (DoD) to subsidize its operating costs and that Elon Musk has personally intervened to ‘geofence’ Starlink access within Ukraine. </p><p>It’s possible that this has curtailed Ukrainian troops from accessing the internet via Starlink in regions under Russian occupation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Expert: UK cyber security programme for students is “excellent” introduction to the field ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/expert-uk-cyber-security-programme-for-students-is-excellent-introduction-to-the-field</link>
                                                                            <description>
                            <![CDATA[ Through Cyber Explorers, DSIT and the NCSC aim to empower youths and prevent them from going down the path of hacking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qsjqHckcXiMdaDr2VBUmy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HzGWXS8b5hdkqT9oha5JvA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Aug 2023 12:40:11 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Aug 2023 15:22:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is a staff writer at ITPro. He is a subject expert on artificial intelligence and business networks and additionally covers a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs and extensive daily coverage of the most significant announcements, as well as analysis pieces and podcasts.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HzGWXS8b5hdkqT9oha5JvA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two students with headphones in leaning in to look at laptop screens in an IT lesson, with more laptops closer to the camera but out of focus.]]></media:description>                                                            <media:text><![CDATA[Two students with headphones in leaning in to look at laptop screens in an IT lesson, with more laptops closer to the camera but out of focus.]]></media:text>
                                <media:title type="plain"><![CDATA[Two students with headphones in leaning in to look at laptop screens in an IT lesson, with more laptops closer to the camera but out of focus.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HzGWXS8b5hdkqT9oha5JvA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than 50,000 students have been signed up for a UK government-run programme that aims to boost the cyber workforce by providing children with engaging courses on digital skills and cyber security.</p><p>Cyber Explorers is a series of free lesson plans and learning materials for young students run by the Department for Science, Innovation and Technology in collaboration with the National Cyber Security Centre (NCSC).</p><p>Webinars with prominent experts within the sector are also offered through the programme, with an upcoming session on <a href="https://www.itpro.com/development/34728/learn-to-code-for-free-the-best-uk-coding-and-app-development-courses">coding</a> led by Coding Black Females founder Charlene Hunter MBE and Teach the Nation to Code founder Shafeeq Muhammad.</p><p>The programme, which was launched in 2022, has now been taken on over 2,000 schools. It is aimed at key stage 2 and 3 students, with a particular focus on fostering cyber skills in 11-14-year-olds before they select their GCSEs.</p><p>Students are also given information through interactive quizzes and videos, ranging from broad <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs">cyber security skills</a> to knowledge that could fire students’ interest in specific sectors or roles.</p><p>Broad topics covered include how to use <a href="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface"><u>command line interfaces</u></a>, what the <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot"><u>Internet of Things</u></a> is, how to secure IoT to avoid network-threatening malware like <a href="https://www.itpro.com/security/malware/358932/new-mirai-variant-spotted-targeting-network-devices"><u>Mirai</u></a>, and a look at <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>DDoS attacks</u></a>.</p><p>More sector-specific guidance includes a lesson plan focused on <a href="https://www.itpro.com/security/cyber-security/363052/ics-and-ot-vulnerabilities-more-than-doubled-in-2021"><u>industrial control systems (ICS)</u></a> which are used throughout the energy, manufacturing, and telecommunications sectors.</p><h2 id="core-skills-for-a-new-generation-of-workers">Core skills for a new generation of workers</h2><p>Matt Lorentzen, principal consultant at information security consultancy Cyberis, told <em>ITPro </em>that the programme would make an “excellent” introduction to cyber security roles for students and can foster inquisitiveness as well as provide a firm grip on key computing concepts.</p><p>“As we continue to build society on layers of technology, we will continue to need a workforce to implement, support and secure it,” he said.</p><p>“There is a significant shortage of people with the knowledge and areas of expertise and with the pace of change within technology, this gap will continue to widen. This initiative can introduce younger people to the technology around them which could serve to ignite a passion for technology and outline a career path. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iDLoZ6aPYgSNDWRMEfn7X9" name="Threat_Intelligence_listing.jpg" caption="" alt="Dark whitepaper cover with faint data connection lines rising from the bottom" src="https://cdn.mos.cms.futurecdn.net/iDLoZ6aPYgSNDWRMEfn7X9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn how to use threat intelligence to fight ransomware attacks and how threat intelligence data is used at all defense levels</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/threat-intelligence-critical-in-the-fight-against-cyber-attacks-but-tough-to-master">DOWNLOAD FOR FREE</a></p></div></div><p>“Covering a broad range of topics such as IoT, malware analysis and incident response can introduce areas they may have not previously understood or considered. The earlier you can educate a potential "pipeline" of the workforce with foundational knowledge that then extends into more specialist areas of cyber security, the better for society.”</p><p>A <a href="https://www.itpro.com/business/careers-and-training/female-representation-in-uk-cyber-drops-amid-growing-skills-demand"><u>recent UK government report</u></a> found that approximately 50% of UK businesses have a gap in basic cyber security skills, while 33% have suffered from a lack of advanced security skills.</p><p>There are signs of growing interest in the field among young people. This year’s A-Level <a href="https://www.itpro.com/business/careers-and-training/a-level-results-2023-whats-driving-the-uptake-in-computing-degrees"><u>results show record computing degree uptake</u></a> with 26,430 students accepted onto computing-related degrees, a rise of more than 10% since 2019.</p><p>Earlier in the year, the <a href="https://www.itpro.com/business-strategy/careers-training/370084/record-computing-degree-applications-ai-bcs"><u>British Computer Society (BCS) reported</u></a> that more than 92,980 18-year-olds had applied to start computing degrees in 2023, with record interest having been sparked by <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a>.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53601829&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="diverting-would-be-hackers-into-cyber-security-roles">Diverting would-be hackers into cyber security roles</h2><p>In addition to the positive skills taught through the lessons and material, the programme also aims to provide guidance for computing-inclined students who could go down the path of cyber crime without the proper support and teaching.</p><p>It is hoped that this could have the effect of reducing the number of cyber criminals in the UK in the long term, as well as providing these students with a viable career path within cyber security. The Cybersecurity and Infrastructure Security Agency <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report"><u>recently called</u></a> for similar measures to identify and guide at-risk juveniles to be implemented in the USA.</p><p>One lesson plan titled ‘City Saved - Cyber Choices’ provides a breakdown of the ethical and legal restrictions for using technology with a key focus on the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act"><u>Computer Misuse Act</u></a>.</p><p>“Those students who have a natural tendency to want to test things and try to find "security holes" are more than likely unaware of the ramifications of performing unauthorised activities,” said Lorentzen.</p><p>“One strength of the programme is raising awareness of the computer misuse act and how people have a responsibility to govern their own activities whilst interacting with systems and resources online. Asking students to consider the types of crimes that are committed using a computer and orientating conversations around what they consider appropriate actions is a great way of highlighting how someone could breach this act.”</p><p>Schools, parents, and guardians have been urged to sign up for the programme for free on its dedicated website.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC expands incident response scheme to support smaller at-risk organizations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ncsc-expands-incident-response-scheme-to-support-smaller-at-risk-organizations</link>
                                                                            <description>
                            <![CDATA[ Charities, small public sector organizations, and local authorities will be covered by the expanded scheme ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L2N5DjgwU7o2r2MomFd8DT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Aug 2023 11:06:22 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Aug 2023 13:18:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Security Centre (NCSC) has announced an expansion to its Cyber Incident Response (CIR) scheme in a move that has been welcomed by industry figures. </p><p>In a statement on Wednesday, the authority revealed that it plans to introduce a new level of coverage through the scheme, meaning that more companies will be able to provide incident response services to a “wider range and larger number” of organizations across the country. </p><p>The move is aimed specifically at providing support for charities, local authorities, smaller public sector organizations, and firms operating outside of critical national infrastructure, the NCSC said. </p><p>In its prior setup, the CIR scheme focused on providing incident response services to organizations “running networks of national significance”. This applied to central government departments, <a href="https://www.itpro.com/security/cyber-attacks/threat-of-cyber-attacks-to-national-security-compared-to-that-of-chemical-weapons">critical national infrastructure organizations</a>, and regulated industries. </p><p>While this aimed to offer protection to organizations at high risk of targeted attacks by cyber criminals and nation-state-backed groups, many industry stakeholders were excluded from coverage due to their size. </p><p>Chris Ensor, deputy director of cyber growth at the NCSC, said the expansion of the CIR will give confidence to a wider range of organizations at risk of cyber attacks. </p><p>“Falling victim to a cyber attack is really stressful. Finding someone with the skills and knowledge to help can also be hard, if, like many, you are not familiar with the cyber security world,” he said. “For many years, we have Assured Cyber Incident Response services for organizations targeted by the most sophisticated threat actors.</p><p>“I am really pleased that we can now assure a similar service for any organizations affected by criminal threat actors, a service that will be good enough for the majority of incidents that smaller organizations face. The NCSC badge will give confidence that the company they use has the right expertise to help them.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iDLoZ6aPYgSNDWRMEfn7X9" name="Threat_Intelligence_listing.jpg" caption="" alt="Dark whitepaper cover with faint data connection lines rising from the bottom" src="https://cdn.mos.cms.futurecdn.net/iDLoZ6aPYgSNDWRMEfn7X9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn how to use threat intelligence to fight ransomware attacks and how data is used to give you an advantage.<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/threat-intelligence-critical-in-the-fight-against-cyber-attacks-but-tough-to-master">DOWNLOAD FOR FREE</a></p></div></div><p>Joseph Carson, chief security scientist and advisory CISO at Delinea, welcomed the move, noting that the expansion of the scheme is a well-needed “refresh”. </p><p>“The new update is an important and needed refresh that will provide all organizations with a service that will be relevant for most cyber security incidents, rather than a focus on purely organizations running networks of significance, such as central government, critical national infrastructure, and regulated industries,” he said. </p><h2 id="growing-cyber-security-threats">Growing cyber security threats</h2><p>The move by the NCSC comes against a backdrop of heightened <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> threats facing businesses across the UK. </p><p>Third-sector organizations in particular have become lucrative targets for threat actors in recent years, representing easier prey than their private-sector counterparts, according to the NCSC’s own analysis. </p><p>Statistics from the UK government’s data breach report, published in late 2022, found that 30% of UK charities were hit with a cyber attack across the year. </p><p>87% of those reported experiencing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attempts, while nearly one-quarter (23%) were subjected to <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Electoral Commission hit by ‘complex’ 15-month cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/electoral-commission-hit-by-complex-15-month-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals, who first breached the organization’s systems in August 2021, were identified in October last year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Gi5dLkPnfAZJDYYdgfM47U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bMrMpeGHAcJtiRYA53sF3o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Aug 2023 15:33:56 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 15:17:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bMrMpeGHAcJtiRYA53sF3o-1280-80.jpg">
                                                            <media:credit><![CDATA[n/a]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Parliament]]></media:description>                                                            <media:text><![CDATA[Parliament]]></media:text>
                                <media:title type="plain"><![CDATA[Parliament]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bMrMpeGHAcJtiRYA53sF3o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s Electoral Commission has warned that hostile actors have accessed voter data, including names and addresses, belonging to anyone registered to vote in elections between 2014 and 2022.</p><p><br></p><p>The attackers gained access to full names, addresses, and the date on which a person achieves voting age – which is 18 for UK parliamentary elections.</p><p><br></p><p>The attackers also had access to the commission’s email and control system as well as the names of those registered as overseas voters, but not their addresses, since the organization doesn’t hold this data. Personal data contained in the email system was also affected and includes name, email, address, telephone numbers, and any personal images along with webform data.</p><p><br></p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> risk assessment doesn’t suggest that exposing such personal by itself puts individuals at high risk, given much of this information is already in the public domain. But combined with other pieces of information, it could be used to identify or profile individuals.</p><p><br></p><p>Webform data or email attachments, meanwhile, could potentially contain sensitive information such as medical or personal financial details.</p><p><br></p><p>No group has claimed responsibility for the attack at the time of writing. The Electoral Commission has reported the incident to the <a href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/362048/ncsc-cyber-essentials-overhaul-takes-effect">National Cyber Security Centre</a>, and said it notified the ICO within 72 hours of identifying the breach.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iDLoZ6aPYgSNDWRMEfn7X9" name="Threat_Intelligence_listing.jpg" caption="" alt="Dark whitepaper cover with faint data connection lines rising from the bottom" src="https://cdn.mos.cms.futurecdn.net/iDLoZ6aPYgSNDWRMEfn7X9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Read how real-time threat data can give you an advantage</em>.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/threat-intelligence-critical-in-the-fight-against-cyber-attacks-but-tough-to-master"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The fact that systems were first accessed in August 2021, more than a year before suspicious activity was identified, suggests the cyber criminals were patient and possibly surveilling internal operations.</p><p><br></p><p>The commission has been quick to reassure voters that the data can’t be used to interfere with the UK’s electoral process, and insisted the exposed data isn’t enough to impersonate a voter under current rules. But the stolen data could help fuel future attacks and other forms of fraud, according to Matt Aldridge, principal solutions consultant at OpenText Cybersecurity.</p><p><br></p><p>“If a nation-state actor was at work here, this data could be used to boost any influence campaigns they are running against UK targets in an effort to support that nation’s competitive agenda,” he said.</p><p><br></p><p>The potential theft of name and home addresses could be used to contribute to targeted social engineering attacks, for example. Aldridge urged organizations to learn from this breach, check their defenses, and ensure staff are trained in cyber security best practices.</p><p><br></p><p>“Rather than viewing data protection as a box-ticking exercise,” he continued, “it should be a key priority and integrated into every aspect of an organization.”</p><p><br></p><p>The commission hasn’t disclosed how it became aware of the attack, but said it’s been implementing a number of mitigations: “We have strengthened our network login requirements, improved the monitoring and alert system for active threats and reviewed and updated our firewall policies.”</p><p><br></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top 12 most-exploited security vulnerabilities revealed by national cyber security agencies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/top-12-most-exploited-security-vulnerabilities-revealed-by-national-cyber-security-agencies</link>
                                                                            <description>
                            <![CDATA[ Cyber leaders from the Five Eyes alliance said attackers favor older vulnerabilities rather than new ones ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wnJsKARtb4pSe6K68N64Ye</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Aug 2023 15:45:41 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Aug 2023 10:28:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top 12 most-exploited security vulnerabilities: NCSC logo superimposed with a translucent background in front of an office building]]></media:description>                                                            <media:text><![CDATA[Top 12 most-exploited security vulnerabilities: NCSC logo superimposed with a translucent background in front of an office building]]></media:text>
                                <media:title type="plain"><![CDATA[Top 12 most-exploited security vulnerabilities: NCSC logo superimposed with a translucent background in front of an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVTMjZ6UmEQAhwxsGt2JDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are favoring the exploitation of older vulnerabilities more so than recently disclosed flaws.</p><p>That’s according to the latest security advisory from the UK’s <a href="https://www.itpro.com/security/cyber-crime/ncsc-neutralizes-fewer-cyber-crime-campaigns-for-first-time-in-six-years"><u>National Cyber Security Centre</u></a> and its equivalent partners in the Five Eyes alliance.</p><p>On Thursday, it made public a list of the top 12 most commonly exploited vulnerabilities in 2022, many of which appeared in the previous year’s list.</p><p>The findings offer insight into the strategies behind cyber criminal activity, highlighting the apathy organizations are evidently taking towards patching security flaws affecting their software and equipment.</p><p>“This advisory reinforces one of the foundational aspects of cyber security, said Lisa Fong, deputy director-general at New Zealand’s National Cyber Security Centre. </p><p>“Malicious actors continue to succeed using the same techniques over and over. I can’t emphasize enough the importance of doing the basics well by understanding your assets, and rapidly applying patches when they become available. Acting on CVE reporting is the difference between getting onto your to-do list and getting onto someone else’s to-do list.”</p><p>Attackers generally experienced the greatest exploit success in the first two years following a vulnerability’s public disclosure. </p><p>The value of these <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now"><u>vulnerabilities</u></a> gradually decreases as organizations <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>patch</u></a> or upgrade software.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6ioYHWRxniA3Ra8werZ8nX" name="Thwart cyberthreats_listing.jpg" caption="" alt="eBook cover with green title text over image of business man wearing glasses and smiling at a workstation" src="https://cdn.mos.cms.futurecdn.net/6ioYHWRxniA3Ra8werZ8nX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Thwart cyberthreats fast with security operations + AI Ops</strong></p><p class="fancy-box__body-text"><em>Bridge the gap between your IT and security operations. Deliver seamlessly connected vulnerability and incident management </em><strong><br></strong><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/thwart-cyberthreats-fast-with-security-operations-ai-ops">DOWNLOAD FOR FREE</a></p></div></div><p>The advice from the security agencies is to apply patches in a timely manner, thus forcing attackers to seek other - potentially more costly - avenues of attack. These include developing <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale"><u>zero-day exploits</u></a> or conducting software supply chain attacks.</p><p>Failing to swiftly apply patches means attackers can scan for the number of exposed systems to any given vulnerability, giving them information on its value for attacks. </p><p>If security issues go unpatched by many organizations, it can motivate attackers to develop exploitation tools that enable faster attacks. These tools can be sold to other cyber criminals and they can be used for years if the vulnerability remains unpatched.</p><p>The most routinely exploited vulnerabilities of 2022 are:</p><ul><li><a href="https://www.itpro.com/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited">CVE-2018-13379</a>: Affect Fortinet SSL VPNs and was exploited as far back as 2020. Its continued presence on the list is an indicator that many organizations have thus far failed to apply available patches</li><li>CVE-2021-34473, CVE-2021-31207, and CVE-2021-34523 - also known as <a href="https://www.itpro.com/security/zero-day-exploit/369263/third-microsoft-exchange-sever-zero-day-exploit-fix-bypassed">ProxyShell</a>: Affect Microsoft Exchange email servers</li><li><a href="https://www.itpro.com/security/cyber-security/361739/researchers-warn-increase-attacks-zoho-software">CVE-2021-40539</a>: A remote code execution flaw in Zoho ManageEngine ADSelfService Plus that first saw exploitation in late 2021 and into 2022</li><li><a href="https://www.itpro.com/security/hacking/360783/us-officials-warn-mass-exploitation-of-atlassian-confluence-flaw">CVE-2021-26084</a>: A vulnerability in Atlassian’s Confluence Server and Data Center collaboration tools. Mass exploitation of this vulnerability was attempted in late 2021, according to the NCSC advisory</li><li>CVE-2021-44228, also known as <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell</a>: Affect Apache’s Log4j library. It was first disclosed at the end of 2021, but the NCSC noted high interest in the vulnerability from attackers throughout the first half of 2022</li><li><a href="https://www.itpro.com/security/367741/us-security-emergency-alert-vulnerable-vmware-products">CVE-2022-22954 and CVE-2022-22960</a>: Vulnerabilities in VMware’s products that allowed for remote code execution, privilege escalation, and authentication bypass. Exploits were noted at the beginning of 2022 and continued throughout the year</li></ul><p>Also exploited in 2022 were <a href="https://www.itpro.com/security/zero-day-exploit/367913/chinese-hackers-exploit-microsoft-zero-day"><u>CVE-2022-30190</u></a> - a vulnerability impacting the Microsoft Support Diagnostic Tool, <a href="https://www.itpro.com/security/zero-day-exploit/368086/exploitation-of-atlassian-confluence-zero-day-surges-fifteen-fold"><u>CVE-2022-26134</u></a> - a critical remote code execution vulnerability in Atlassian Confluence and Data Center, and CVE-2022-1388 - a vulnerability permitting attackers to bypass iControl REST authentication on F5 BIG-IP application delivery and security software.</p><p>“Today, adversaries commonly exploit categories of vulnerabilities that can and must be addressed by technology providers as part of their commitment to secure by design,” said Eric Goldstein, executive assistant director for cyber security at CISA. </p><p>“Until that day, malicious actors will continue to find it far too easy to exploit organizations around the world. With our partners, we urge all organizations to review our joint advisory, for every enterprise to prioritize mitigation of these vulnerabilities, and for every technology provider to take accountability for the security outcomes of their customers by reducing the prevalence of these vulnerabilities by design.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>