IT Systems and Data Protection

25.04.17

A period of inevitable risk

Source: PSE Apr/May 17

Dr Daniel Dresner, information and cyber security governance lecturer at the University of Manchester, explains how the public sector’s approach to cyber security is improving.

The public sector’s approach to cyber security governance in the past could be summed up like many school reports: ‘getting better, but room for improvement’, PSE has been told. 

But according to Dr Daniel Dresner from the University of Manchester, the important thing that, particularly with the formulation of the new National Cyber Security Centre (NCSC), “getting the right activities in place is improving – probably much faster than we have seen for a long time”. 

While we are working in what Dr Dresner calls a ‘period of inevitable risk’, he argues that huge strides, like the introduction of Domain-based Message Authentication, Reporting & Conformance (DMARC), are now being made to “improve the systems that we use, to remove and disrupt the vectors that people can attack through”. 

All about the money 

Discussing the major threats facing the sector, Dr Dresner said it always comes down to one underlying factor: money. 

“There are two sides to this,” he argued. “On the whole, there are threats and then there is the crime. I’m fond of saying that, despite the statistics, on the whole there is very little cybercrime. What there is, however, is lots and lots of cyber-enabled crime: theft, fraud and extortion are now being done from the comfort of the criminal’s own premises in countries far away. 

“As has been pointed out, local government handle something like 23 pence in the pound of the finances which are in the public purse. In any government arena there is money to be had. Government, by its very nature, is complex and so it is difficult to communicate at a level where the variety of the criminality can be identified and stopped. 

“The DMARC makes things more difficult, but it is a matter of being aware that criminals will try and use phishing to get in, so they can then plant malware to find out what is going on, understand processes and then attack the processes to get money out.” 

Reflecting on the increasing threat of ransomware attacks, Dr Dresner stated it is somewhat reminiscent of the early days of the web where “one of the big concerns was physical computer sets, where people would have a break-in, lose all their kit, and buy new kit thinking that they were safe. But, of course, they weren’t safe, because the criminals knew that there was going to be a lot of new kit there worth stealing – so they put in the extra effort”. 

He added that while councils may be tempted to pay a ransom in order to get their processes back online quickly, they actually expose themselves to a greater level of risk: “There is a business model in the criminal world in that they sell on their lists of people who will pay up ransoms.” 

One of the big advantages about the NCSC, added Dr Dresner, is that it makes it easier for people to know where to report threats, which helps strengthen the national intelligence.

Good, basic protection 

While acknowledging that there are always going to be risks, he stated that a way to get good, basic protection in place is by using Cyber Essentials. 

“Cyber Essentials is very basic, but I love it because it finally answers the question of where do I start?” explained Dr Dresner. “In a complex organisation, it is still difficult to implement some of its points. But it is a starting point for making things better and for people to ask: ‘what does good look like?’, ‘how good am I?’, and if they are falling down on some of the basics they can look further down the line. 

“It can be good for small departments for creating frameworks to do good stuff, rather than being bowled over by these huge handbooks, which the consultants like, and resemble those magazines that tell you there are 340 ways to make Christmas simple. 

“We are in this period of inevitable risk. People are under pressure, people are still going to click on those dodgy links and the like, but what is getting better now are the systems which make those harder to come through.”

Comments

There are no comments. Why not be the first?

Add your comment

public sector executive tv

more videos >

latest public sector news

Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower e... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. ... more >
Colleges set to receive £200m in Funding

19/08/2020Colleges set to receive £200m in Funding

Over 180 colleges are set to receive a share of £200m, in order to repair and refurbish buildings and campuses. The funding makes up p... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

Prevention: Investing for the future

Prevention: Investing for the future

Rob Whiteman, CEO at the Chartered Institute of Public Finance (CIPFA), discusses the benefits of long-term preventative investment. Rising demand, reducing resource – this has been th... more > more last word articles >
Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower emissions during the lockdown period. The coun... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. Between April 2019 and March 2020, London boroug... more >

the raven's daily blog

Cleaner, greener, safer media: Increased ROI, decreased carbon

23/06/2020Cleaner, greener, safer media: Increased ROI, decreased carbon

Evolution is crucial in any business and Public Sector Executive is no different. Long before Covid-19 even became a thought in the back of our minds, the team at PSE were looking at innovative ways to deliver its content to our audience in a more dynamic and responsive manner. We’re conscious to take the time to both prot... more >
read more blog posts from 'the raven' >

comment

Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Being on the receiving end of some “thanks” can make communit... more >
How community-led initiatives can help save the housing shortage

19/06/2019How community-led initiatives can help save the housing shortage

Tom Chance, director at the National Community Land Trust Network, argues that community-led initiatives are a productive way of helping to solve... more >
Aberdeen's green transport fleet attracting international attention

19/06/2019Aberdeen's green transport fleet attracting international attention

Aberdeen City Council’s hydrogen spokesperson, councillor Philip Bell, highlights the Granite City’s determination to play a leading ... more >
A fifth of public sector workers have never received a thank you from the people they serve

13/06/2019A fifth of public sector workers have never received a thank you from the people they serve

A fifth of the country’s public sector workers say they have NEVER received a ‘thank you’ for doing their job as Public Service... more >

interviews

Artificial intelligence: the devil is in the data

17/12/2018Artificial intelligence: the devil is in the data

It’s no secret that the public sector and its service providers need to invest in technology to help make better use of their resources. Bu... more >
Digital innovation in the public sector: The future is now

17/12/2018Digital innovation in the public sector: The future is now

One of the public sector’s key technology partners has recently welcomed a new member to its team. Matt Spencer, O2’s head of public ... more >
New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

05/11/2018New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

The new chief executive of one of the new unitary authorities in Dorset has outlined his approach to culture and work with employees, arguing tha... more >
Keeping the momentum of the Northern Powerhouse

15/10/2018Keeping the momentum of the Northern Powerhouse

On 6 September, the biggest decision-makers of the north joined forces to celebrate and debate how to drive innovation and improvement through th... more >

public sector focus

View all News