World News
Warning Over Collateral Cyber Threats
Businesses are just urged to be wary of risks from cyber threats.
The Office of Cyber-Security & Information Assurance has warned businesses to be wary of cyber threats arising from an increase in tensions in Russia and the Ukraine.
Since Russia attacked Ukraine, a number of cyber attacks have occurred across the region which have attacked websites or seen systems, such as those operating railways, compromised.
Sharing the statement from OCSIA, the Financial Services Authority said: ‘During times of increased tension between Russia and neighbouring countries, there is a historical pattern of increased malicious or hostile cyber activity coming from Russia or its allies.
‘Whilst OCSIA is not aware of any current specific threats to the Isle of Man, UK or any UK organisations in relation to events in and around Ukraine, we would urge businesses to consider following the below actionable steps that reduce the risk of falling victim of an attack, including:
- patching systems;
- improving access controls and enabling multi-factor authentication;
- implementing an effective incident response plan;
- checking that backups and restore mechanisms are working;
- ensuring that online defences are working as expected, and;
- keeping up to date with the latest threat and mitigation information.’
Collateral
While the OCSIA says there is no specific threat to the island, they are warning this doesn’t exclude the possibility of ‘indiscriminate or collateral impacts as a result of cyber activity’.
Giving the example of the WANNACRY ransomware that impacted the NHS, this had not originally been the intended target, equally while NOT-PETYA was intended for the Ukraine but it impacted global supply chains and logistics.
They have offered simple advice to protect from these threats such as not not clicking on suspicious links, reporting suspicious emails and taking care when working remotely, OCSIA also suggest businesses should prepare for the event of systems outage.
As a minimum, OCSIA would recommend: ‘Confirm they have an up to date and tested incident response plan or business continuity plan. This should include details of key systems and, where appropriate, manual contingency plans in the event of a systems outage.
- Confirm that escalation routes and contact details are all up to date
- Ensure that the incident response plan contains clarity on who has the authority to make key decisions, especially out of normal office hours
- Ensure the incident response plan and the communication mechanisms it uses will be available, even if business systems are not.’
If any business requires further advice or support please, in the first instance review the OCSIA website – www.ocsia.im.
