Cyber risk increased for businesses since Russian invasion of Ukraine

Businesses could be at a heightened risk of cyber attacks following Russia’s invasion of Ukraine, a cyber-security expert has warned.

Ukrainian banking and government websites were knocked offline last week by a spate of distributed denial of service (DDoS) attacks, which are designed to crash sites by bombarding them with excessive requests at the same, causing server overloads and shutdowns.

UK and US governments claim the attacks were carried out by Russian-backed military hackers – prompting concerns from the Home Office and GCHQ that a similar virtual onslaught could be attempted in a bid to disrupt businesses and cripple Britain.

Mike Wills, director of strategy and policy at cyber and data security firm CSS Assure, said: “Businesses should make themselves as hard to hack as possible at all times – but more so than ever.

“From a strategic perspective, there is a significant risk that Russia may seek to create instability within Western countries and, specifically, the UK so as to distract focus and attention away from the situation in Ukraine and onto closer, acute problems at home.

“In this day and age, this is easier to achieve virtually by means of cyber-attacks. To achieve instability and distraction, we may find attacks targeting services that we rely on heavily on a day-to-day basis, such as health, banking, utilities, water, transport infrastructure and supply chains.

“Critical national infrastructure should be relatively hardened to attacks and they will, more than ever, be at a heightened state of vigilance. The attackers know this and, therefore, may be looking to find less obvious routes to target these institutions – potentially through suppliers, which are typically easier to hack.”

Wills added: “No business will want the association or ignominy of being the weakest link. While a security programme cannot be established overnight, the best time to start is today. In the interim, heightened vigilance and discipline is critical to defending against a cyber attack.

“At minimum, businesses should consider resetting passwords in case they have already been breached and are enabling access to web portals and email accounts, as well as remind employees to think twice before opening or clicking links on any suspicious emails.

“Multi-factor authentication – which requires users to provide two or more verification factors to gain access to a resource – should be implemented wherever possible, and software upgrades and patches should be up to date.

“Businesses should also dust off, review and rehearse incident respond plans so they know how to react swiftly to any attack and are able to minimise its potential scope and scale. Finally, ensure all critical information is backed-up off network in case of a ransomware attack.”

• Comment below on this story. Or let us know what you think by emailing us at [email protected] or tweet us to tell us your thoughts or share this story with a friend.

Government update on bad umbrellas “underwhelming”

Industry commentators have dismissed yesterday’s promise to introduce a statutory due diligence requirement later this year as “a big fat nothing burger”.

Legislation 19 April 2024

APSCo appoints Torr and Hart in senior roles

The Association of Professional Staffing Companies (APSCo) has appointed two new senior hires to support member services and events.

People 17 April 2024

British Airways Speedbird Pilot Academy programme opens for new applications

British Airways has opened the application window for the second year of its fully funded Speedbird Pilot Academy cadet scheme yesterday [16 April, 2024].

New to Market 17 April 2024

Hospitality recruitment drive to fill 50 roles in luxury Scottish hotel

Crossbasket Castle, a luxury hotel on the outskirts of Glasgow, is set to create 50 new jobs in the hospitality industry.

17 April 2024
Top