Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Staff and supply chains are greatest cyber security risk for CNI

Security

Staff and supply chains are greatest cyber security risk for CNI

New research has revealed that more than half of senior industry figures have low confidence in the cyber security of critical national infrastructure (CNI) supply chains, while 50% cite people/staff as CNI's greatest cyber resilience weakness.

The research forms part of Atkins’ new Cyber Resilient Infrastructure Report, which was published today as part of European Cyber Security Month. The report, which outlines how the UK might become a more cyber resilient nation, includes a contribution from General Sir Richard Barrons, former Commander Joint Forces Command and Chief of Staff of the UK Armed Forces (until April 2016).

Advertisement
ODU RT 2

The research findings reflect the views of senior figures across a wide range of CNI, government and defence organisations. These include Airbus Defence & Space, Anglian Water, Department for Culture, Media & Sport, Ministry of Defence, Qinetiq, and the UK Space Agency.

Fifty eight per cent of respondents reported low levels of confidence in the cyber resilience of CNI supply chains, with half of those expressing no confidence at all. Although people were confident in the security protecting their own organisation, it was considered to be much more difficult to protect information assets and intellectual property once it entered a wider supply chain.

When asked to rank their top three cyber security concerns today, half of respondents identified people/employees as their top concern. This response covered a range of issues including insider threat, user browsing, board-level awareness, and staff understanding of the part they play in helping to protect their organisation.

The second highest concern was network compromise and insufficiently protected legacy systems (25 per cent), including issues around the Internet of Things and Cloud-based services. This was then followed by concerns around the pervasive growth of organised and state-sponsored cyber-crime (8 per cent).

Two thirds of respondents consider their top three concerns to be the same this year as last, with any difference being a greater understanding of the scale of the threats presented and breadth of the risk.

Advertisement
Advanced Engineering RT

When asked to look ahead and cite their top CNI cyber security concerns for the future, 28 per cent suggested it was the rapid advance of technology, especially the Internet of Things and convergence. This was followed by the growth of organised and state-sponsored cyber-crime (24 per cent), and then a shortage of skills required for the UK’s cyber defence (20 per cent).

When asked to gauge whether advantage currently lay with the cyber attacker or defender, 70 percent believed it was with the attacker (compared to 61 per cent last year), 13 per cent said it was currently balanced (compared to 17 per cent last year) and 17 per cent believed it was with the defender (compared to 22 per cent last year).

Andy Wall, Atkins’ head of cyber security explained: “As well as serving as a confidence barometer, the research results also help paint a picture of the CNI and defence industry’s major cyber security concerns, both today and in the future. Although some of these results are concerning, there are of course some CNI organisations – particularly the civil nuclear industry – who are leading in this area, and there is much that parallel sectors could learn from their example.

“Alongside the concerns outlined above, transparency was also raised as an enduring industry challenge. A lack of clear definitions of risk terms and reliance upon confusing technical language to define the cyber threat is turning off senior leaders. This in turn is preventing them from fully understanding the risks and potential mitigation measures. Hopefully this report will help to overcome some of those barriers.”

 

Advertisement
Advanced Navigation LB 1
AST Networks acquires Reygar

Security

AST Networks acquires Reygar

25 April 2024

AST Networks has expanded its ecosystem further through the acquisition of Reygar Ltd, an award-winning provider of fully integrated performance monitoring and control solutions for crewed and uncrewed vessels, to form AST Reygar.

PPM Systems enables 5x increase in detection range

Defence Security Events

PPM Systems enables 5x increase in detection range

25 April 2024

Swindon based PPM Systems are increasing observational antenna radius by solving signal distribution limitations.

Kromek receives US nuclear security contract

Defence Security

Kromek receives US nuclear security contract

25 April 2024

Kromek Group plc has been awarded a contract, worth up to $2.9 million, from a US federal entity for the provision of nuclear security products.

Review to shape next phase of The Alan Turing Institute

Defence Security

Review to shape next phase of The Alan Turing Institute

25 April 2024

A new review outlining the impact and value of The Alan Turing Institute, the UK’s national institute for data science and AI, has been published.

Advertisement
Advanced Engineering RT
Report sees AI as key to national security decision making

Defence Security

Report sees AI as key to national security decision making

25 April 2024

A new report from The Alan Turing Institute has outlined the importance of AI to support strategic decision-making on national security.

CCL, Trellis Data and Cairn Advisory partner on AI powered solution

Security

CCL, Trellis Data and Cairn Advisory partner on AI powered solution

25 April 2024

CCL Solutions Group and Trellis Data have announced a partnership forged by Cairn Advisory, to combine Trellis Data’s AI-powered solutions with CCL's scalable device extraction and analysis platform, so users can enjoy faster evidence-gathering, self-defined business rules and information sharing/analysis, automatically powered by AI.

Advertisement
ODU RT