Cyberwar: UK PLC attacked 1000 times per hour

Updated happygeek 0 Tallied Votes 404 Views Share

Earlier this year Jonathan Evans, the Director General of MI5 (the UK Security Service), warned that cyber attacks against UK plc were as much of a security challenge as terrorism as far as Britain was concerned. He claimed that UK businesses were being targeted at an 'astonishing' rate driven by "many thousands of people lying behind both state-sponsored cyber espionage and organised cyber crime". Now Foreign Secretary William Hague has joined the fray to warn that "not an hour goes by when a system in the UK is not being attacked" and how hackers and foreign spies are 'bombarding' government departments and business alike.

mi5 The Telegraph newspaper reveals that intelligence sources it approached have stated that the true figure is closer to 1000 cyber attacks each and every hour. Attacks that attempt to either disable some systems or steal secrets from others, with infrastructure and communications disruption a favourite aim. My only surprise at this story is that the number is so low to be honest.

Only last year in the aftermath of a Zeus attack which infected British government computers, Hague warned that "sophisticated attacks such as these are becoming more common". Now he's referring to these attacks as "one of the greatest challenges of our time" and is calling on UK businesses to do their bit to ensure that Britain retains the 'Great' when it comes to cyber security.

Jay Huff, a director with HP Enterprise Security, reckons that the UK government has hit the issue firmly on the head. "It is clear that cyber crime is on the up and that as a result the impact is also ever increasing. By putting in place the right thorough procedures however, business can act early to help stave off the multitude of threats they are facing. Our research uncovered that companies using security intelligence technologies were more efficient in detecting and containing cyber attacks. As a result, these companies enjoyed an average cost savings of £0.4 million when compared to companies not deploying security intelligence technologies. However it also showed that compared to the USA, UK businesses suffer only about a third of the cost as a result of cyber crime".

Dani AI

Generated

The posts raise two useful points that too often get lost in headlines: reported high “attack” counts are a mixture of automated scanning, opportunistic crime and a smaller number of focused intrusions; and terminology differences can confuse discussion about who or what is being targeted. rightly flags surprise at the scale; highlights how acronyms cause cross‑discipline misunderstandings; and is correct to flag supply‑chain and state‑aligned threats as a different class of risk that needs distinct controls.

Practical priorities for organisations (start here and work outward):

  • Inventory and classify assets: document crown‑jewel systems, admin accounts and third‑party access points.
  • Reduce attack surface: remove unused services, block direct RDP/SMB to the internet and enforce allowlists for critical systems.
  • Strong authentication & least privilege: apply MFA to all remote and privileged accounts (prefer hardware-backed keys for admins) and minimise standing admin rights.
  • Patch & config hygiene: implement risk‑based patching, baseline configurations, and automated deployment for high‑risk fixes.
  • Detection & visibility: centralise logs (endpoint, Sysmon/Windows event logs, DNS, proxy, firewall, network flows) and deploy EDR with containment capabilities.
  • Segmentation & vendor controls: isolate third‑party access, use jump hosts, and limit vendor networks to only needed resources.
  • Backup & restore testing: maintain immutable/offline backups and verify restores regularly.
  • Incident preparedness: formal IR runbooks, communication plans and regular tabletop exercises.

If compromise is suspected, prioritise containment and evidence preservation: isolate affected hosts, collect volatile telemetry (EDR, memory/network captures) if possible, preserve disk images and correlate across logs to build a timeline. If internal capability is limited, engage an experienced IR team quickly—early containment dramatically reduces impact. Also review contractual and regulatory reporting obligations before public disclosure.

Adopt a simple risk framework (for example CIS or NIST CSF), measure basic metrics (MTTD/MTTR) and iterate. High‑volume hostile activity is a given; the practical win comes from getting the fundamentals right and improving detection and response.

Reverend Jim 6,665 Hi, I'm Jim, one of DaniWeb's moderators. Moderator Featured Poster

That's distressing but not surprising. One little clarification, for us non-Brits, I think plc means public limited company (a limited company whose shares may be sold to the public). On this side of the pond it usually means (at least to we computer geeks) programmable logic controller.

johnedwards095 0 Newbie Poster

The US TV current affiars program 60 Minutes last year aired a piece or two on Chinese cyber attacks. The US have admitted that cyberwar is the biggest threat at this time to there national security. Its about time that the people of this country woke up to the threat we all face and the dire consequences that could follow. The Chinese company, telecoms Hauwei that has been the subject of examination in the US by thier security services with regard to national security being compromised, has had thier sentiments echoed here in the UK by the former head of the MODs cyber security unit. We should not be dealing with companies and countrys that are known to be attacking the electronic fabric of our country and its security.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.