UK PLC loses billions to hacker attacks

happygeek 1 Tallied Votes 507 Views Share

It's never easy calculating the true cost of inadequate security to business, not least as there are so many variables and such reticence when it comes to full disclosure for fear of brand damage. However, the latest (ISBS) from PwC/Infosecurity Europe has had a good bash at it, at least as far as the UK is concerned, and the answer is breathtakingly big: billions of pounds. And that was just last year!

dweb-secreport According to the survey which investigated a total of 447 UK-based businesses, the number of large enterprises being hacked into is at an all-time high right now with one in seven experiencing a breach of some kind during the last year. While the smaller business can expect a 'significant outsider attack' at the rate of one per month, that increases to one per week for the larger organisation.

That one in seven detecting hack attacks figure represents the highest level recorded since the PwC/Infosecurity Europe survey started back in the early 1990s which signals either a lack of security awareness from the defence perspective or a jump in attack methodology from the hacking side of the fence, and possibly a bit of both. Certainly the hackers are getting more active, as another record figure reveals: 70% of large companies have detected 'significant attempts' to break into their networks. The fact that these are attempts which have been spotted, and one assumes stopped, does at least show that defence systems can be properly implemented.

Which is just as well when you understand that each large enterprise saw some 54 'significant attacks' by an 'unauthorised outsider' during the year, and that's twice as many as they were experiencing in 2010. When it comes to successful hacks, 15% of those large enterprise defences were penetrated at an average cost of between £110,000 and £250,000. Smaller businesses were faced with an average cost, in terms of disruption, brand damage and clear up of between £15,000 and £30,000.

If you look further than just hack attacks, then the picture gets even worse: broaden the security breach definition to include data loss events and computer fraud then 93% of large companies and 76% of small ones had experienced at least one.

Chris Potter, a security partner at PwC, reckons that “the UK is under relentless cyber attack and hacking is a rising risk to businesses. The number of security breaches large organisations are experiencing has rocketed and as a result, the cost to UK plc of security breaches is running into billions every year."

Dani AI

Generated

Good summary from — the PwC piece you referenced put the spotlight on business impact — and ’s question about “who’s doing this” is exactly the right follow‑up. The National Crime Agency (NCA) and UK cyber agencies make the same point: attackers are a mixed bag (organised, financially motivated ransomware groups, opportunistic criminals, insider threats and, in some cases, state‑backed actors). Because attribution is often slow and uncertain, defence and resilience are the practical priorities for firms of every size. (nationalcrimeagency.gov.uk)

Practical priorities that materially reduce risk: enforce multi‑factor authentication for all privileged and remote access; keep patching and vulnerability management current; use network segmentation and least‑privilege for admin accounts; deploy endpoint detection/response and central logging so incidents are detected quickly; and maintain regular, encrypted backups with an offline copy and a tested restore process. The UK NCSC recommends a defence‑in‑depth approach and stresses offline, tested backups as a core mitigation against ransomware. (ncsc.gov.uk)

Prepare for the inevitable: document an incident response (IR) plan, create simple playbooks (ransomware, data leak, credential compromise), and run tabletop exercises so staff actually know their roles. The NCSC’s “Exercise in a Box” is a free starter toolkit for running realistic drills. Also be aware of legal duties: where personal data is involved, the ICO expects a notifiable breach to be reported promptly — usually within 72 hours of discovery — so keep an incident log and decision timeline. (ncsc.gov.uk)

Quick checklist (SME friendly): enable MFA; set a weekly patch cadence for internet‑facing systems; separate admin accounts and lock down remote admin; keep daily encrypted backups with an offline copy and test restores quarterly; run short phishing awareness exercises and keep an IR contact list. These low‑cost steps map to the UK small‑business guidance and markedly reduce exposure to the common attacks highlighted here. (gov.uk)

No single silver bullet exists — continuous basics, exercised response plans, and sensible governance are what stop a headline becoming an existential business loss.

Member Avatar for Member #949455
Member #949455

When it comes to successful hacks, 15% of those large enterprise defences were penetrated at an average cost of between £110,000 and £250,000. Smaller businesses were faced with an average cost, in terms of disruption, brand damage and clear up of between £15,000 and £30,000.

Wow, that's alot of pound's. I am really curious what kind group is targeting UK business.

I mean UK economy is not as bad as the US economy but still somebody must really rub one of those Hackers the wrong way.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.