Select Page

What the government must do to tackle cyber crime

CYBSAFE-SebDB Webinar-preblog-221011MS-36

12 February 2021

Almost half of UK businesses (46%) and a quarter of UK charities (26%) reported cyber security breaches or attacks in the last 12 months.

The figures are higher for medium-sized businesses (68%) and large businesses (75%).

Cybercrime is on the rise.

So it’s just as well the UK government is doing something about it.

National Cyber Security Strategy

In 2016, the UK government published a 78-page National Cyber Security Strategy

The new Strategy was underpinned by £1.9 billion in investment. A five-year plan (2016-2021) was set out to improve cyber secure practices across the nation. 

The government pledged to pay due attention to “human and behavioural aspects” of cyber security. It recognised the need to “deliver a step-change in public behaviour” to bolster defences against cyber criminals.

Initiatives to improve public knowledge of cyber security threats were put in place. One of these was the Cyber Aware campaign, which has continued to evolve in response to developing threats. In 2020, the campaign responded to Covid-19, publishing new information on secure home working and safe online shopping.

Clearly, the government recognises people play a part in cyber security. But has it gone far enough to address the human factor?

 

The costs of human error

In 2019, our research found that 90% of UK data breaches were caused by human error

For the most part, we’re kind, helpful, curious and obedient. And that can make us vulnerable to cyberattacks.

It’s incredible how deep these human traits run. To hammer the point home, consider Connecticut, 1961.

 

Understand people are people

In 1961, Professor Stanley Milgram carried out a study on obedience.

Each participant was instructed to send voltages of current through the body of an unseen but audible fellow human being. The voltages wouldn’t actually be administered. But those administering the shocks didn’t know this.

The voltage of each shock increased in increments throughout the experiment. Initial shocks were bearable. But the voltage rose quickly. Eventually, the shocks would be lethal. 

Milgram’s fellow researchers predicted less than 3% of participants would administer the final lethal shock.

Incredibly, 65% of participants ended up doing so, despite showing overt signs of distress themselves. 

The authority of the ‘scientist’ overseeing the experiment won out over the participants’ own sense of right and wrong. 

All because, as humans, we like to trust, and we often do as we’re told.

 

What we must do when fighting cyber crime

It’s not hard to see how cyber criminals might exploit our tendencies to trust and obey.

Throw helpfulness, hope, laziness, myopia, and a whole host of other human vulnerabilities into the mix. You might wonder why the situation is not much worse than this.

You might also start to see how important changing behaviour is when addressing cyber security. And to be fair, the government’s current strategy indicates awareness of the importance of behavioural change.

But, in reality, how far do existing initiatives go towards impacting and changing poor security behaviours?

 

Keeping up with the criminals

As the government’s five-year strategy draws to an end, a new strategy will be on the horizon.

If behaviour change can take centre stage moving forwards, we may well finally begin to take the higher ground.

And let’s hope we can – sooner rather than later.

Cybercrime is advancing. We need to keep up.

Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

An open letter to CISOs & Security Leaders

An open letter to CISOs & Security Leaders

The human side of cybersecurity is evolving. Fast.But there’s a good chance you might be stuck in the past. You probably have well-established views on security awareness, culture, and human risk.You genuinely believe they matter. But if we’re being honest - you mostly pay lip service to them. And...

Why security awareness still isn’t taken seriously (and how to fix it)

Why security awareness still isn’t taken seriously (and how to fix it)

Let’s start with a painful truth:Security awareness, culture, and human risk professionals are often undervalued. Despite the rising threat of human-enabled cyber attacks, many organizations still treat addressing the human aspect as a checkbox. A communications initiative. A nice-to-have....

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

“Humans are the weakest link.”“Security Awareness training = better behaviour”"If we can nail engagement, we’ll nail risk reduction.""Security Awareness is *actually* about so much more than awareness.”“Security culture is the golden ticket to risk reduction.”“Good communication, messaging,...

Can BS make SA&T stick? Hot takes from the experts…

Can BS make SA&T stick? Hot takes from the experts…

Using insights from “Oh, Behave!” to strengthen security training and drive lasting behavioral change Security training. It’s as commonplace in an organization as writing “see attached” and forgetting to attach anything. It can help to tackle cybersecurity risks—but only when done well. Simply...