Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and ICO challenge myths around reporting cyber attacks

Security

NCSC and ICO challenge myths around reporting cyber attacks

In a new joint blog post, the UK's National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) have identified six misconceptions that can discourage organisations from reporting attacks - particularly ransomware attacks - and is setting out to dispel them.

Image copyright Shutterstock

The misconceptions include the mistaken belief that reporting cyber attacks to the authorities makes it more likely the incident will become public, and that paying a ransom automatically makes the incident go away.

With cyber attacks continuing to cause significant disruption, the NCSC and ICO are concerned about incidents which go unreported because every 'hushed up' case that isn't shared or fully investigated makes other attacks more likely as no one can learn from them.

Advertisement
Cranfield

However, being open with the authorities will give victims access to expert support and advice and will be taken into account favourably by the ICO when considering their regulatory response.

The six ‘myths’ which the NCSC and the ICO have identified as commonly held by organisations that have fallen victim to cyber incidents are:

  • If I cover up the attack, everything will be ok
  • Reporting to the authorities makes it more likely your incident will go public
  • Paying a ransom makes the incident go away
  • I’ve got good offline backups, I won’t need to pay a ransom
  • If there is no evidence of data theft, you don’t need to report to the ICO
  • You’ll only get a fine if your data is leaked

Eleanor Fairford, NCSC Deputy Director for Incident Management, said: “The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward.

“Keeping a cyber attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout.

Advertisement
ODU RT

“By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well break the cycle of crime to prevent others from falling victim.”

 

 

 

Advertisement
Aviation Africa LB Aviation Africa LB
Cambridge Sensoriis introduces RadarAware DAA tech for drones

Aerospace Defence Security

Cambridge Sensoriis introduces RadarAware DAA tech for drones

24 January 2025

Radar tech specialist Cambridge Sensoriis has expanded its product portfolio by introducing a Detect-and-Avoid (DAA) system called RadarAware, that supports beyond visual line of sight (BVLOS) operations.

Splunk and Oxford Economics release The CISO Report 2025

Security

Splunk and Oxford Economics release The CISO Report 2025

24 January 2025

In collaboration with Oxford Economics, Cisco's Splunk has released The CISO Report 2025, a global research report detailing the goals, priorities and business strategies for Chief Information Security Officers (CISOs) and their boards of directors.

Wescom Group acquires BCB International

Defence Security

Wescom Group acquires BCB International

24 January 2025

Survival solutions manufacturer Wescom Group has acquired BCB International Ltd., the Cardiff based global supplier of safety equipment in the defence and marine sectors.

Darktrace delivers NDR advances

Security

Darktrace delivers NDR advances

23 January 2025

Darktrace has delivered some significant new advances in network detection and response (NDR) with multiple new innovations for its Darktrace / NETWORK.

Advertisement
ODU RT
Smith Myers launches ARTEMIS-Flex

Security

Smith Myers launches ARTEMIS-Flex

22 January 2025

Smith Myers has launched ARTEMIS-Flex, an innovation in rescue technology and evolution of the award-winning ARTEMIS Mobile Phone Detection & Location System (MPDLS).

New proposals to counter ransomware

Security

New proposals to counter ransomware

22 January 2025

The Home Office has announced a public consultation seeking views on three proposals aimed at striking a significant blow to the ransomware criminal business model.

Advertisement
ADS S&P RT