Public Sector Focus


Public sector cyber security needs to fight back

Getting security wrong during the transition from paper to digital could mean a loss of public confidence in new services, argues Graeme Stewart, director of public sector at Fortinet UK&I.

From ransomware attacks against the NHS, to cyber-attacks on parliamentary email accounts, it’s safe to say that it’s been a bad year for cyber security in the public sector. Technology may be one of the UK’s fastest-growing industries, but the public sector is still faced with risks that arise during the transition from paper to digital.

Public sector organisations across every service stand to lose valuable data which is vulnerable to criminals. This can range from high-value research from universities to patient records and even sensitive information shared by government officials. So why is the public sector struggling to prevent cyber-attacks?

Budget constraints are universal across all public sector services, and IT managers are increasingly finding themselves tasked to do more with less. As a result, basic security hygiene has always been an Achilles heel for public sector organisations. The most high-profile example of this is the recent WannaCry attack, which crippled the NHS and was able to spread due to a failure to patch a known exploit. Security is unfortunately not seen as an enabler to business operations, so even basic security practices can fall by the wayside. Fostering a culture of security amongst employees at every level is key to putting a stop to preventable cyber-attacks and must be factored into any cyber security program. This means encouraging employees to update systems regularly and to be wary of suspicious emails and links.

The rapid transition from paper to digital means that the public sector is also faced with a widening cyber security skills gap, with industry estimates suggesting that there could be up to three million unfilled jobs in the cyber security industry by 2021.

The issue is compounded by few graduates with the necessary skills. The government has started to take action with initiatives such as the Cyber Schools Programme, which aims to provide young people aged 14-18 with cyber skills by 2021. A complete overhaul in how cyber security talent is developed should play a key part in defending the public sector from cyber-attacks.

Another issue holding back public sector cyber security efforts is that many organisations see cyber security spend as an unnecessary cost of business, with minimal ROI. This is a damaging misconception, especially for public sector organisations looking to minimise costs. When you consider that a medical record is worth 10 times as much as a credit card number on the black market, it’s no surprise that research shows 34.4% of all breaches worldwide are hitting the healthcare industry. There is a cost associated with breaches but, aside from the financial impact, breaches can bring about lawsuits and regulatory penalties and compromise not only patient data but patient care. As we saw with WannaCry, when malware prevents NHS staff from accessing systems, the ability to deliver care is affected.

With research from Vanson Bourne showing that the NHS alone is projected to save £15m a year by investing in cyber security, it should be viewed as an enabler to allow operations to not only become more agile, but to also save money. In order to unlock the potential of digitisation, public sector organisations must prioritise cyber security, which will in turn improve quality of patient care and levels of patient trust.

Whilst the UK government has pledged to bolster the public sector’s cyber security systems with a £21m investment, it is pivotal that escalating issues such as the skills gap, legacy systems and employee education are addressed. At a time when public sector budgets are already being cut, getting security wrong during the transition from paper to digital could mean a loss of public confidence in new services. Not only this, but with the introduction of the General Data Protection Regulation in May 2018, public sector bodies must ensure that they avoid fines. However, loss of public confidence in services could be much more damaging in the long term. It’s vital that organisations prioritise educating employees about the dangers of phishing and social engineering.



There are no comments. Why not be the first?

Add your comment


public sector executive tv

more videos >

latest public sector news

High Court allows London council to fine and imprison illegal campers

17/08/2018High Court allows London council to fine and imprison illegal campers

A council has successfully obtained a High Court injunction allowing it to use greater powers – from fines and asset seizure to imprisonmen... more >
Northamptonshire report to propose splitting region into two unitaries

17/08/2018Northamptonshire report to propose splitting region into two unitaries

A report on the future of the debt-ridden Northamptonshire region due to be published this afternoon will likely recommend replacing all eight lo... more >
Council forced to apologise after telling ‘intimidating’ football fans they were unwelcome

16/08/2018Council forced to apologise after telling ‘intimidating’ football fans they were unwelcome

A Lancashire council has apologised after sending a letter that stated football fans “will no longer be welcome” in the town centre f... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

The importance of openness after Grenfell

The importance of openness after Grenfell

Following the recent Grenfell Tower tragedy, Lord Porter, chairman of the LGA, argues that if the public are going to have faith in the safety testing process then everything must be out in the o... more > more last word articles >
149x260 PSE Subscribe button

the raven's daily blog

Don’t horse around! Council finds new home for house-bound pony

13/08/2018Don’t horse around! Council finds new home for house-bound pony

A council that took four years in a legal wrangle to remove a pony from an Isle of Lewis house may have found the four-legged beast a new home. Western Isles council removed Grey Lady Too – a Connemara pony that was taken into the home by pensioner Stephanie Noble on Christmas Eve in 2011 – from its residence in 2014 because i... more >
read more blog posts from 'the raven' >


A new era of opportunity for the north

13/08/2018A new era of opportunity for the north

It’s time to stop seeing transport investment as a nice-to-have: it’s a cut-through catalyst for growth in sectors across the north. ... more >
Council mergers: little gain, less democratic

13/08/2018Council mergers: little gain, less democratic

Dr Linze Schaap, associate professor at the Tilburg Centre for Regional Law and Governance, and Dr Niels Karsten, assistant professor at the Tilb... more >
Creating a council cloud-first approach

13/08/2018Creating a council cloud-first approach

Georgina Maratheftis, programme manager for local government at techUK, makes the case for wider adoption of cloud technology by local authoritie... more >
The strength of districts

13/08/2018The strength of districts

Cllr Isobel Darby, member lead for quality of life at the District Councils’ Network (DCN) and leader of Chiltern District Council, shares ... more >


Modern policing: the future is bright

06/08/2018Modern policing: the future is bright

SPONSORED INTERVIEW The public sector, and policing in particular, has often been criticised as being slow to adapt to change. But now, says L... more >
Michael King: Time for Ombudsman reform

06/08/2018Michael King: Time for Ombudsman reform

Michael King first joined the Local Government Ombudsman service back in 2004 as deputy ombudsman. At the start of 2017, he was appointed as the ... more >
Helping a city understand itself

06/08/2018Helping a city understand itself

SPONSORED INTERVIEW The urban landscape is changing. How can local authorities keep up with citizen behaviour? Stephen Leece, managing directo... more >
Data at the heart of digital transformation

03/04/2018Data at the heart of digital transformation

SPONSORED INTERVIEW Grant Caley, UK & Ireland chief technologist at NetApp, speaks to PSE’s Luana Salles about the benefits of movin... more >