“While manufacturing took top billing in the 2018 GTIR, with 46% of all cyber attacks in the UK, this year’s report shows a significant fall to second place with 20% of attacks,” according to NTT. “However, the tech sector, which attracted 23% last year, jumps to top spot with 47% of attacks in the UK.
Finance, which is apparently the most attacked EMEA sector, is lucky in the UK because it only gets third spot with 13%, followed by business-and-professional services (4%) and 3% for healthcare.
“While manufacturing may have dropped down a position, the fact that it is still attracting a fifth of all attacks against UK organisations is a major concern,” said NTT cyber security manager David Gray. “The critical national infrastructure sectors tend to grab the headlines, such as the attacks on the Ukrainian national grid in 2016, or the Wannacry attack on the NHS in 2017. However, the recent attacks on Norsk Hydro demonstrate the impact that cyber attacks can have on other sectors, such as manufacturing, and highlight the importance of effective incident response.”
While NTT is inviting you to participate in a webinar on 22 May – ‘How to shine a light on operational technology risk’, it is also offering some advice now:
Focus on four areas:
- Get the basics right. Without the right fundamentals in place, attacks do not need to be advanced to succeed. People are often a manufacturer’s greatest threat, so invest in staff awareness and training, and highlight the importance of collective responsibility.
- Take an intelligence-driven approach to security. IT and security should avoid working in silos and having a ’not in my backyard’ mentality by developing robust holistic processes and procedures.
- Develop threat intelligence capabilities. There is no such thing as an isolated incident and there is a need to manage the whole incident by developing threat intelligence – pervasive visibility is essential.
- Manufacturers are still failing to prepare. There is still an element of ‘head in the sand’, where they do not think it is going to happen to them. Having effective incident response capabilities that are tested regularly is key and enables organisations to respond quickly in order to mitigate the threat and identify the cause.
And wake up to what counts as vulnerable.
“The lines between traditional and digital manufacturing are blurring,” said Grey, “where high value manufacturing and advanced technologies are key for global competitiveness and there is greater convergence of IT with operational technology, which brings with it greater complexity and risk. The problem is that operational technology has traditionally been something of a dark art for IT and security teams who lack the knowledge and skills to effectively map their operational technology risk landscape and implement practical plans and processes.”
Where are those attacks coming from?
Once again China is the number one source of attacks (20%) by country against UK organisations, followed by the US (16%) and France (10%).
Apart from Sweden, the UK is the only country to see most attacks coming from China.
Across EMEA, China is second (13%) just behind the US (16%).
Globally, again the US is top attack source (22%) followed by China on 13%.
Download the NTT Security 2019 GTIR – requires registration.
To download the NTT Security 2019 GTIR: https://www.nttsecurity.com/2019GTIR or I can send a copy on request.
Thanks, Mandy
UK manufacturing drops to second place in league table of most attacked industry sectors – 2019 Global Threat Intelligence Report reveals
NTT Security report shows technology sector move up to first place; and China top source of attacks
About NTT Security
NTT Security is the specialized security company and the center of excellence in security for NTT Group. With embedded security, we enable NTT Group companies (Dimension Data, NTT Communications and NTT DATA) to deliver resilient business solutions for clients’ digital transformation needs. NTT Security has multiple SOCs, seven R&D centers, over 1,500 security experts and handles hundreds of thousands of security incidents annually across six continents.
NTT Security ensures that resources are used effectively by delivering the right mix of Managed Security Services, Security Consulting Services and Security Technology for NTT Group companies – making best use of local resources and leveraging our global capabilities. NTT Security is part of the NTT Group (Nippon Telegraph and Telephone Corporation), one of the largest ICT companies in the world. Visit nttsecurity.com to learn more about NTT Security or visit www.ntt.co.jp/index_e.html
Methodology for the Global Threat Intelligence Report (GTIR)
The NTT Security 2019 Global Threat Intelligence Report contains global attack data gathered from NTT Security and supported operating companies from October 1, 2017, to September 31, 2018. The analysis is based on log, event, attack, incident and vulnerability data from clients. It also includes details from NTT Security research sources, including global honeypots and sandboxes located in over 100 countries in environments independent from institutional infrastructures. Leveraging the indicator, campaign and adversary analysis from our Global Threat Intelligence Platform has played a significant role in tying activities to actors and campaigns.
NTT Security summarizes data from trillions of logs and billions of attacks for the 2019 GTIR. NTT Security gathers security log, alert, event and attack information, enriches it to provide context, and analyzes the contextualized data. This process enables real-time global threat intelligence and alerting. The size and diversity of our client base, with over 10,000 security clients on six continents, provides NTT Security with security information which is representative of the threats encountered by most organizations.
The data is derived from worldwide log events identifying attacks based on types or quantities of events. The use of validated attack events, as opposed to the raw volume of log data or network traffic, more accurately represents actual attack counts. Without proper categorization of attack events, the disproportionately large volume of network reconnaissance traffic, false positives, authorized security scanning and large floods of DDoS monitored by Security Operations Centers (SOCs), would obscure the actual incidence of attacks.
The inclusion of data from the 10 SOCs and seven research and development centers of NTT Security provides a highly accurate representation of the ever-evolving global threat landscape.
This email is private and confidential and may contain information which is privileged and protected from disclosure. If you have received this email in error, please notify the sender and delete it from your system. Email communications are not secure and therefore the Company does not accept legal responsibility for the contents of this email. Any opinions expressed in this email are solely those of the author and do not represent those of the Company. If verification of the contents of this email is required, please request a hard copy version from the appropriate person. Emails to and from the Company may be monitored for operational reasons. Although the Company operates anti-virus scanning systems, it does not accept responsibility for any damage caused by attachments transmitted with this email.