Cyber Security Insights February 2025

Cyber Security Insights February 2025

Written by Bryan Altimas

In the February edition of Cyber Security Insights we look at:

  • The cost of a hack is not just the cost of recovery but remediation and, most importantly, the cost to a business's reputation.
  • Assume a hack mentality to maintain digital trust - a hack can happen at any time and it is seldom a sophisticated attack although most organisations say it is. Most cyber security professionals recommend to assume you have been breached.
  • Why are data privacy ethics as important as compliance with regulations. With privacy laws in more than 130 countries and sector specific regulations the data privacy landscape is complex. Compliance should be the floor and not the ceiling of a data privacy programme. Considering ethics alongside a compliance programme can enable organisations to act fairly and transparently.

The Cost of a Hack

When we talk to organisations about the cost of a hack in many instances it is restricted to the cost of recovery and some remediation or what their cyber insurance will cover.

Let's take the example of a simple hack. An organisations website is taken over and visitors to the website are diverted to gambling and pornography websites leading to the site being blacklisted by the likes of Google and cyber security companies. 

Technically this is relatively simple to fix. Strengthening access controls to the back office (complex password and 2FA), anti-malware detection and response software and a web application firewall will provide adequate protection in the future.

The costs so far are the consultancy and investigation to find out what is happening and the new technical controls in the above paragraph.

However, the issue was raised by customers and potential customers. The cost to the businesses reputation and the loss of trust in that organisation leading to lost sales as customers and potential customers go to competitors and the spreading of the news of the hack and its consequences through, for example, Google and Trustpilot reviews also has to be considered. 

Talk to us about your cyber security. Contact us via LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message "reputation".

Assume a Hack Mentality

As outlined in the article above (The Cost of a Hack) threat actors pose an ever increasing risk to an organisations digital trust. It does not matter whether an attack comes from state sponsored threat actors or cyber criminals they are after your data and money. An attack against a company, government agency, education establishment or a healthcare organisation is going to be more profitable than attacking an individual.

A hack can occur at any time and most hacks are not sophisticated attacks but exploiting basic vulnerabilities, many cyber security professional recommend adopting assume a hack has already occurred mentality. Assume threat actors are already in the environment and seek to detect, contain, and eject them while maintaining or restoring capability as quickly as possible.

All organisations want their systems, processes and services to be available and fully functioning for their customers and clients which will maintain their trust in the organisation. Having visibility of the whole IT estate with no shadow IT enables the detection of a cyber incident more quickly.

Resilience is the ability to keep operating when there are challenges to the operating environment. The ability to detect cyber incidents quickly and rapidly resolve them is part of resilience. However, we also need to design systems with resilience inbuilt so that a single failure does not take down the whole system. For example deploying to the cloud in multiple regions and service providers. Backing up to the cloud is another measure of resilience.

Zero trust security practices, surface area reduction and hardening of configurations also contributes to resilience. Such measures will restrict the impact of an attack to a smaller area of the organisation rather than the whole organisation.

Containment of the attack to to where the attack originated and preventing lateral movement to other systems allows the organisation to keep more of its services available reducing the financial loss in the short term and, hopefully minimising the loss of trust in the longer term.

Proactive penetration testing as well as passive vulnerability scanning combined with threat hunting is required but not just automated tools. Skilled personnel who can properly interpret the results are needed.

Successful prevention and rapid detection, response and recovery is a competitive advantage.

Want to talk about cyber security message us on LinkedIn or email us at info@riversidecourtconsulting.co.uk with the message hack mentality.

Data Privacy Ethics

130 plus countries have data privacy laws and certain industries have specific laws and regulations, e.g. healthcare or financial services, making the regulatory landscape incredibly complex and challenging. Compliance should be the lowest bar for privacy professionals and privacy programmes. 

In September 2024 LinkedIn caused concern when they changed user settings by default to allow permission for the site to use personal data and content to train generative AI models. LinkedIn were not transparent about this change and most users found out by social media posts about it. The exception to this scenario is that users in the European Economic Area, European Union and Switzerland were not automatically enrolled in this data sharing because of the EU GDPR and Swiss data privacy laws. This case highlights that peoples data privacy relies on their geographic location and local laws and regulation rather than an ethical organisation.

Acting ethically means that organisations take on the burden of data protection even though people are not protected by local laws. 

Organisations can be compliant with laws and regulations but not behave ethically. 25 US car manufacturers investigated in a privacy report received a failing privacy score. These car companies can collect information about users’ medical history, sex life, and genetic information, and most of them share or sell data. These vehicle manufacturers claim that users have consented to this excessive data processing, in some cases simply by being inside the car. Other than not purchasing the car or being inside the car, consumers do not have much ability to oppose this excessive data collection. The companies were able to get away with excessive data collection in the US because there were no laws or regulations outlawing it. 

Just because there is a data privacy law does not mean that compliance is guaranteed. Some companies may just accept they are going to be fined as a cost of business. 

Organisations who focus purely on compliance are reactive, the privacy regulation landscape is constantly evolving so they are wading through quick sand. Also, these companies are less likely to be looking at AI for privacy related tasks. This could be because of the lack or regulation around the safe and ethical use of AI meeting their compliance agenda.

Compliance must be considered but following an ethics pathway can make compliance easier because the standards of ethical considerations are likely to be higher than compliance with laws and regulations. Ethical privacy obligations are often understood better compared to compliance obligations. Better understanding of privacy obligations can help organisations avoid the reputational harm of a high profile non-compliance incident and the subsequent loss of trust with customers and clients.

Where ethics are prioritised organisations can connect more strongly with their customers and clients and, therefore, potentially improve profitability.

Talk to us about data privacy by messaging us on LinkedIn or by email at info@riversidecourtconsulting.co.uk with the message data privacy.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right