Attacks on UK Firms Increase Five-Fold During Pandemic

Attacks on UK Firms Increase Five-Fold During Pandemic

Attacks on UK firms surged five-fold during the pandemic and now cost way more than the global average, according to Accenture.

The global consultancy polled 500 UK executives to compile its State of Cybersecurity Resilience 2021 study.

It found that large organizations experienced 885 attempted cyber-attacks in 2020 – up from 156 the previous year and more than triple the global average of 270.

They’re also more expensive than elsewhere. Accenture calculated that incidents and breaches cost over £1.3m a year – £350,000 more than the global average.

Over 80% of respondents said the cost of staying ahead of cyber-criminals is unsustainable, a fifth more than the previous year, and a quarter said they’ve been forced to increase cybersecurity budgets by 10% or more.

Worryingly, supply chain attacks accounted for 64% of breaches in the UK last year, up by a quarter (26%) from the previous year.

This chimes with a recent report from BlueVoyant , which revealed 93% of global organizations suffered a direct breach due to their supply chains over the past year.

Accenture UK security lead, Giovanni Cozzolino, argued that British firms are under siege from digital attackers.

“It’s clear that cyber-criminals are taking full advantage of the overnight shift to home working and digital operations,” he added. “Enterprises need to be on high alert. Whether sophisticated nation-state actors or run of the mill cyber-criminals, adversaries are clearly getting more resourceful and launching attacks from every angle.”

The report claimed that nearly half (49%) of large businesses lost over 100,000 customer records over the course of the past year, an increase of 28% from the previous year.

“Faced with high costs in a difficult economic environment, UK firms must be smart with how they spend on security,” concluded Cozzolino.

“Spending more without being closely aligned to the business doesn’t make your organization safer. To achieve sustained cyber resilience, CISOs need to collaborate with the right executives in their organization to understand where to prioritize.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Friday Squid Blogging: UK Recognizes Squid as Sentient Beings

This seems big:

The UK government has officially included decapod crustaceans–including crabs, lobsters, and crayfish–and cephalopod mollusks–including octopuses, squid, and cuttlefish–in its Animal Welfare (Sentience) Bill. This means they are now recognized as “sentient beings” in the UK.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New Jersey Cancer Care Providers Settle Data Breach Claim

New Jersey Cancer Care Providers Settle Data Breach Claim

A trio of healthcare providers in New Jersey has agreed to pay $425,000 and adopt new security measures to settle a legal claim involving a double data breach. 

The state of New Jersey alleged that Regional Cancer Care Associates LLC, RCCA MSO LLC, and RCCA MD LLC (collectively “RCCA”) failed to adequately safeguard the personal data and protected health information (PHI) of thousands of cancer patients.

More than 105,200 patients (including 80,333 New Jersey residents) were affected by two data breaches, both of which occurred in 2019. 

In the first incident, patient data was exposed when several RCCA employee email accounts were compromised in a phishing attack carried out between April and June. Sensitive data accessed in the attack included health records, driver’s license numbers, Social Security numbers, financial account numbers, and payment card numbers.

The second data breach occurred in July, when a third-party vendor, hired by RCCA to mail out data breach notification letters to patients impacted by the incident, erroneously sent letters to patients’ prospective next-of-kin.

Under the Health Insurance Portability and Accountability Act (HIPAA), notification of a data breach to a victim’s next-of-kin is allowed only in cases where the victim is deceased.

“New Jerseyans battling cancer should never have to worry about whether their medical providers are properly securing and protecting their personal information from cyber threats,” said New Jersey’s acting attorney general, Andrew Bruck. 

“We require healthcare providers to implement adequate security measures to protect patient data, and we will continue to hold accountable companies that fall short.”

New Jersey accused RCCA of five violations, including a failure to protect against reasonably anticipated threats or hazards to the security or integrity of patient data, and failing to implement a security awareness and training program for all members of its workforce.

The RCCA companies, which are all headquartered in Hackensack, New Jersey, and have 30 locations throughout Connecticut, New Jersey, and Maryland, disputed the allegations. 

However, the healthcare group agreed to a settlement consisting of $353,820 in penalties and $71,180 in attorneys’ fees and investigative costs. RCCA also agreed to adopt new security measures, which included hiring a chief information security officer.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains